worldwide

worldwide

Merck and Co., Inc., Rahway, NJ, USA, which has a tradename of MSD outside of the U.S. and Canada (“our company”, “we”, “us”, “our”), provides this U.S. Supplemental Privacy Notice (“U.S. Supplemental” or “Notice”) to provide additional information to U.S. residents whose personal information is collected, used, and/or disclosed by our company pursuant to applicable U.S. law. This Notice is in addition to our Global Cross Border Privacy Rules Policy that describes the company’s global practices for the collection, use, and disclosure of personal information, and our Global Internet Privacy Policy (“GIPP”) that describes our company’s cross-border privacy practices when you use the online resources that display a link to the GIPP. Please also see our company’s Consumer Health Data Privacy Policy for disclosures concerning our collection and use of Consumer Health Data pursuant to applicable U.S. law.

Please note that this Notice does not apply to individuals with whom we interact in an employment-related context or a business context. For our disclosures applicable to California residents with whom we interact in those contexts, please see our Privacy Notice for Employment & Workplace-Related Purposes and our Privacy Notice for Contractors, Consultants & Other External Partners.


Our company has collected and/or disclosed for our business purposes the following categories of personal information during the preceding 12 months:

  • Identifiers, such as your name, alias, contact information including postal address, Internet Protocol (IP) address, online identifiers, and other unique similar identifiers.
  • Financial information, such as bank account number, credit card number, debit card number, or any other financial information that does not allow or withdrawal of funds.
  • Commercial information, such as products purchased or purchasing or consuming histories.
  • Medical and health information, where that information is processed outside the scope of the Health Insurance Portability and Accountability Act and human subject research frameworks.
  • Internet and other electronic network activity information, such as browsing history, site visits, search history, and your interactions with our websites, advertisements, and other online resources.
  • Geolocation data, such as device location that is more granular than a city or town.
  • Audio, electronic, and visual information, such as call recordings and video testimonials.
  • Professional or employment-related information, such as work history and prior employer.
  • Education information, such as medical specialty and expertise.
  • Inferences we derive from the information that we collect as set forth in this policy to create a profile about you reflecting preferences, characteristics, and other traits.
  • Sensitive personal information, such as physical and mental health information, race, ethnicity, social security number, government identification, financial account information, and precise geolocation data.
  • Other information that you provide as may be disclosed to you at the time of such collection, such as in our GIPP.

Our company does not knowingly collect personal information from children under 13 years of age without obtaining verifiable parental consent prior to collection.

Our company may collect personal information from the following categories of sources:

  • Directly from you when you share it with us, from your interactions with our products and services;
  • Through our websites and mobile apps. With your permission, we and our business partners may collect your personal information over time and across different internet websites or online services when you use any internet website or online service of a regulated entity;
  • From third parties, including collaboration and other business partners; and
  • From social media platforms (for more information, please see our Privacy Notice of Social Media Monitoring).

Our company may collect, process, and disclose personal information, including sensitive personal information, for the following business purposes:

  • Operating, administering, managing, and maintaining our business;
  • Performing the services or providing the goods reasonably expected by an average consumer who requests those goods or services;
  • Developing, improving, repairing, and maintaining our products and services;
  • Patient assistance, prescription discount and reimbursement support programs;
  • Communicating with you, including communicating information about diseases, products and services through our web sites, via e-mail, direct mail and other channels;
  • Personalizing, advertising, and marketing our products and services;
  • Inferring characteristics about a consumer, such as when you choose to answer a survey so we can send you information and products about which you may be interested;
  • Performing identity verification;
  • Adverse experience and product complaint reporting;
  • Auditing our programs and resources for compliance and security purposes;
  • Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information;
  • Resisting malicious, deceptive, fraudulent, or illegal actions directed at us and prosecuting those responsible for those actions;
  • Verifying or maintaining the quality or safety of a product, program, service, treatment, or device that is owned, manufactured, manufactured for, or controlled by us;
  • Analyzing improving, evaluating, developing, upgrading, or enhancing the products, programs, services, treatments and devices, including those that are owned, manufactured by, manufactured for, or controlled by us;
  • Protecting our and others’ rights, including by monitoring, protecting, enforcing, and defending our legal rights, and monitoring, protecting against, enforcing, and defending against violations of our Terms of Use, policies and procedures, fraud, and other behavior that is illegal or harmful;
  • As required or authorized by laws applicable to our business globally; and
  • De-identifying your personal data to use or disclose it for the above purposes and other purposes permitted under applicable law.

When we deidentify personal information, we take reasonable measures to ensure that the information cannot be associated with a consumer or household, and we maintain and use the information in deidentified form. We will not attempt to reidentify the information, except that we may attempt to reidentify the information solely for the purpose of determining whether our deidentification processes satisfy applicable legal requirements. After it has been deidentified, the information is no longer personal information and is not subject to this Notice.

Our company may collect, process, and disclose personal information, including sensitive personal information, for the following business purposes:

  • With service providers to assist us in providing the services;
  • With advertising networks and data analytics providers for the purposes of cross-contextual advertising;
  • With affiliates within our family of companies for everyday business purposes described in this Notice;
  • With other companies we collaborate with solely for activities related to products and services jointly offered or developed by us and that company;
  • To other entities, including actual or prospective purchasers, if we decide to reorganize or divest part or all of the business through sale, merger or acquisition;
  • As legally required in relevant legal proceedings and otherwise to the extent required or authorized by applicable law; and
  • Otherwise with your consent.

Retention of personal information: We generally retain personal information for as long as reasonably needed for the specific business purpose or purposes for which it was collected and the duration of your use of our web sites, apps and other relevant online tools. In some cases, we may be required to retain information for a longer period of time based on laws or regulations that apply to our business, such as applicable rules on statute of limitations or for other necessary business purposes. Where possible, we aim to anonymize, de-identify, or remove unnecessary identifiers from records that we may need to keep for periods beyond the original retention period.

Sales and Sharing of Personal Information.

  • Sale: Some state privacy laws define “sale” broadly to mean the exchange of personal information for anything of value, not just money. Based on that definition, we “sell” and have “sold” in the past twelve months personal information collected via cookies and other tracking technologies, such as IP addresses and browsing data, including when we allow third parties, such as advertising networks and data analytics providers, to place certain types of cookies or other tracking technologies on our websites for marketing and analytics purposes.
  • Share: We also “share” and have “shared” in the past twelve months the categories of personal information listed in the above paragraph with third parties, such as advertising networks and data analytics providers, for targeted advertising.

We do not otherwise “sell” or “share” other types of personal information we may collect about you, such as your name or email address. See our Global Online Tracking Policy for more information.

We do not sell or share personal information about individuals that we know are under age eighteen (18). In general, our websites and online resources are not directed at children and most of the online services that we offer are designed for individuals who are 18 years of age or older. From time to time, some of our web sites and other online resources may provide optional features for children. When we do offer those features, we will take appropriate steps to ensure that verifiable parental consent is obtained prior to any collection, use or disclosure of personal information from children in accordance with applicable law.

Your Choices and Rights

You may be entitled to certain data subject rights pursuant to applicable U.S. law. These rights are identified below. Except as instructed otherwise therein, you, a legal representative, or another legally authorized agent, can exercise available rights here by selecting the right you would like to exercise and providing the requested information, which will be used to verify your identity and to match the personal data we have about you. For more information on your data subject rights, you can also contact our company via email at msd_privacy_office@msd.com or at our Privacy Office, UG4B-24, 351 N. Sumneytown Pike, North Wales, PA 19454.

  • Right to access, know, confirm, and/or obtain a copy of the personal information we hold about you, the categories of sources of that information, the third parties to whom it has been disclosed, and similar details. You also may have the right to request a copy of the personal information that is collected, including, in some cases, in a portable and readily usable format that allows you to transmit the data to a third party.
  • Right to delete the personal information we hold about you.
  • Right to correct inaccurate personal information we hold about you.
  • Right to opt out of sale and sharing of your personal information for cross-context behavioral or targeted advertising. Some state privacy laws define “sale” broadly to mean the exchange of personal information for anything of value, not just money. Based on that definition, we “sell” and “share” personal information collected via cookies and other tracking technologies, such as IP addresses and browsing data, when we allow third parties to place certain types of cookies or other tracking technologies on our websites for cross-context behavioral or targeted advertising. We do not otherwise “sell” or “share” other types of personal information we may collect about you.
  • Right to withdraw consent for processing of, and to limit the use and disclosure of, your sensitive personal information. We may collect and use sensitive personal information about you, including for purposes other than those expressly permitted by the California Consumer Privacy Act. You may have the right to withdraw your consent for our processing of or limit our collection, processing, use and disclosure of your sensitive personal information.
  • Right to appeal a decision by our company not to comply with your exercise of these rights. You may have the right to appeal, which you can exercise via our online portal by selecting “Other” as the request type, providing the other required personal information, and specifying that you want to appeal a decision in the “Additional information”.

We do not process your personal information for the purposes of profiling in furtherance of decisions that produce legal or significant effects.

Opt-Out Preference Signals (Do Not Track and Global Privacy Control)

You may exercise your rights here. We will process your request(s) in accordance with applicable law. If you choose to exercise any of these rights, we will not discriminate against you.

Some browser features or add-ons allow consumers to send an “opt-out preference signal” to companies whose websites they visit, such as the “Do Not Track” signal or the “Global Privacy Control” signal. These signals, when turned on, tell the websites you visit that you do not wish to be tracked or do not want your information shared for targeted advertising purposes. We recognize the “Do Not Track” signal and we are currently incorporating recognition of the “Global Privacy Control” signal into our websites. We treat these signals as a request to opt-out of sale and sharing for the browser or device through which the signal is sent and any consumer profiles we have associated with that browser or device, including pseudonymous profiles. Accordingly, if you use different devices or browsers to interact with us at different times, you need to turn these features on for all of the internet browsers and devices you use, separately. If we know the identity of the consumer from the opt-out preference signal, we will also treat the signal as a request to opt out of sale and sharing for the consumer.

In addition to these features, you can select your cookie preferences via the Cookie Preferences link in our website footer.

Loyalty or Discount Programs

We may offer certain loyalty or discount programs that involves the collection and sharing of personal information, such as your name and email, which our company may use to provide the relevant loyalty and/or discount programs. Based on our reasonable and good faith estimate, personal data collected through such programs do not have monetary value. You may withdraw from such programs at any time and may do so by completing an online form or calling us at 1-855-344-4971 (toll free in the US). If you make a data subjects rights to delete your personal data, then you may not be able to continue your participation in such programs.

Questions?

Questions about this Notice or our company’s privacy practices can be submitted via email at msd_privacy_office@msd.com or by contacting our company at: Privacy Office, UG4B-24, 351 N. Sumneytown Pike, North Wales, PA 19454.

We may update this Notice periodically in response to changing laws, regulations, and industry practices. We reserve the right to modify, add or remove portions of this Notice at our discretion. If we decide to change this Notice, we will post the updated version on www.msdprivacy.com. If the changes are material, we will contact you directly where we have your contact information and appropriate under applicable law, and we will post the changes prior to the effective date of the change.

Last Updated: January 6, 2025

Calendar Year 2023 Metrics (including Sure Petcare and Harpoon Therapeutics, Inc.)

Requests to Know:
Number received: 19
Number complied with in whole or in part: 9
Number denied: 10

Requests to Delete:
Number received: 168
Number complied with in whole or in part: 161
Number denied: 7

Requests to Opt-Out:
Number received: 0
Number complied with in whole or in part: n/a
Number denied: n/a

Requests to Correct:
Number received: 23
Number complied with in whole or in part: 20
Number denied: 3

Requests to Limit:
Number received: 58
Number complied with in whole or in part: 52
Number denied: 6

The median number of days within which we substantively responded to Requests to Know, Requests to Delete, and Requests to Correct: 31.5 days

The median number of days within which we substantively responded to Requests to Opt-Out and Requests to Limit: 7.2 days

Calendar Year 2022 Metrics (including Imago BioSciences, Inc.)

Requests to Know:
Number received: 19
Number complied with in whole or in part: 19
Number denied: 0

Requests to Delete:
Number received: 31
Number complied with in whole or in part: 31
Number denied: 0

Requests to Opt-Out:
Number received: 73
Number complied with in whole or in part: 73
Number denied: 0

The median number of days within which we substantively responded to Requests to Know, Requests to Delete, and Requests to Opt-out: 6.9 days