Privacy Policy
Scope
This privacy policy (“Policy”) describes how Deciphera Pharmaceuticals AG and its affiliates and subsidiaries (collectively “Deciphera,” “we,” “our,” or “us”) collects and uses information (“Personal Data”) about visitors (“Users”) who access and utilize the website www.thinktgct.eu (“this “Website”) in the course of operating our business.
Please note, Deciphera may have other unique privacy policies that apply to certain specific situations, such as privacy notices that cover data processing activities related to contractual arrangements and/or marketing communications. To the extent those policies or notices apply and conflict with this Policy, those policies govern our interactions with you.
This Website is intended exclusively for healthcare professionals (HCPs) in the European Union and provides scientific, disease awareness, and educational information about tenosynovial giant cell tumor (TGCT). This Policy applies specifically to Personal Data collected through this Website and not to other Deciphera platforms, clinical study portals, or promotional websites.
Information We Collect
Information You Provide
We collect the Personal Data you voluntarily provide to us when you access or use the Website. When you access and use this Website, we may collect personal information that can indirectly identify you as an individual. This may include:
- Confirmation that you are a healthcare professional (HCP) located in the European Union or other eligible regions, which is required to access the content;
- Your country of residence or location, if requested when navigating content or contact forms;
- Any information you submit voluntarily through forms, such as when you sign up to receive updates or contact us with inquiries.
Information We Collect Automatically
When you access and use the Services, we and our third-party service providers may collect information, including usage and technical data, automatically from your device, including, for example:
- Automated Identifiers, such as device identifiers;
- Internet or other electronic network activity information, such as IP address;
- Geolocation Information, to ensure that the Website is only accessible to healthcare professionals in the Europe.
Sensitive Categories of Personal Data. We do not collect sensitive categories of Personal Data, such as information about your race, political views, religious views, or health conditions.
How We Use Your Personal Data
We will use your Personal Data or other information we collect about you for the following purposes:
- To manage access control: We use information such as your country of residence and confirmation of HCP status to ensure that the Website is accessed only by its intended audience, licensed HCPs in the EU.
- To perform website analytics: With your consent, we use cookie data (e.g., from Google Analytics 4) to understand how visitors use the Website. This helps us improve the structure, content, and relevance of the information we provide about tenosynovial giant cell tumor (TGCT). For more details, please refer to our Cookie Policy.
- To respond to your inquiries: If you voluntarily contact us using forms on the Website, we will use your submitted information to respond to your request.
- To protect our legal rights and ensure compliance: We may use Personal Data to enforce our Terms of Use, to detect and prevent misuse or fraudulent behavior, or to comply with applicable legal and regulatory obligations.
We may use de-identified aggregate or anonymized information to help us analyze the use of the Services. Where permitted by law, this Policy does not limit our use or disclosure of de-identified, aggregate, or anonymous information, and we reserve the right to use and disclose such information to other third parties in our discretion.
Legal Bases for Processing
We need to have a legal basis to process your Personal Data. There are different legal bases that we rely on to use Personal Data, namely:
- Legitimate interests. It is in our legitimate interests to process Personal Data in order to improve our products and services, perform administrative tasks, and, where consent is not required by applicable law, to identify and authenticate you, secure our systems and information, conduct research, and develop new products.
- Consent. We will rely on consent, which, in some cases where local laws allow, may be implied, to use: (i) technical information, such as cookie data; (ii) Personal Data for certain marketing purposes in accordance with your preferences. You may withdraw your consent at any time by clicking on the relevant preferences button that is persistent on the page.
Furthermore, it is in our legitimate interest to protect the legal rights, safety, and security of Deciphera, our affiliates, and our business partners; to respond to and resolve claims or complaints; to prevent fraud; and to manage risks associated with our business.
- Legal obligations. We may use Personal Data to comply with legal obligations to which we are subject. For example, we may disclose Personal Data for regulatory reporting requirements or to law enforcement in accordance with legal process.
Disclosure of Personal Data
We may share your Personal Data with third parties under the following circumstances which include:
- Our affiliates: We may share Personal Data with our affiliated entities for their own research and analytics purposes or for internal reporting purposes.
- Service providers and business partners: We may share your Personal Data with our service providers and business partners that perform services for us including third-party providers for website hosting, maintenance, business operations, and identity verification. These service providers and business partners are only given access to your information to the extent necessary to process your information and/or provide the Services, and they are prohibited from using or sharing your information for any other purposes.
- Third parties as necessary to protect our interests and interests of others: We may disclose your Personal Data as is necessary to identify, contact, or bring legal action against a person or entity who may be violating our Terms of Use, or who may be causing harm to, or interfering with, other users of the Services.
- Law enforcement agencies, courts, or other government authorities or third parties where required by law: We may share your Personal Data with law enforcement agencies, courts, other government authorities or other third parties where we believe necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights or the rights of any third party.
Data Subjects Rights
You may have certain rights regarding your personal data, subject to local data protection laws. These include the following rights:
- Access your Personal Data;
- Rectify the information we hold about you;
- Erase your Personal Data;
- Restrict our use of your Personal Data;
- Object to our use of your Personal Data;
- Receive your Personal Data in a usable electronic format and transmit it to a third party (right to data portability); and
- Lodge a complaint with your local data protection authority.
Please note, we do not make automated decisions about you based on your Personal Data.
If you would like to discuss or exercise these rights, please contact us at the details below. We encourage you to contact us to update or correct your information if it changes or if the Personal Data we hold about you is inaccurate. We may contact you if we need additional information from you in order to honor your requests.
Please note that we may require additional information from you in order to honor your request, and there may be circumstances where we will not be able to honor your request.
For example, if you request deletion, we may need to retain certain Personal Data to comply with our legal obligations or other permitted purposes.
International Data Transfer
Any information you provide to us or that we automatically collect may be shared with our affiliates entities in the United States, Japan and other countries outside of the EU, UK and Switzerland.
As such, your Personal Data may be transferred to, stored and processed in various countries, including those that are not regarded as ensuring an adequate level of protection for Personal Data under European Union law or by the European Commission.
We have put in place appropriate safeguards (such as the EU Standard Contractual Clauses) in accordance with applicable legal requirements to ensure that your data is adequately protected. For more information on the appropriate safeguards in place, you may contact us at the details below.
Retention
We will retain your Personal Data as long as we have a relationship with you. When deciding how long to keep your Personal Data after our relationship with you has ended, we take into account our legal obligations, including, for example, fraud prevention, dispute resolution, investigations, and enforcement of our Terms of Use.
Security
Deciphera uses commercially reasonable physical, electronic, and procedural safeguards to protect Personal Data against loss or unauthorized access, use, modification, or deletion. However, we cannot guarantee the absolute security of Personal Data or other information.
Changes in Privacy Notice
We may modify or update this privacy notice from time to time. If we make any revisions that materially change the ways in which we process your Personal Data, we will notify you of these changes before applying them to that Personal Data. We may notify you by email or other reasonable means, including through notifications on the Services.
Contact Us
Deciphera Pharmaceuticals AG is the controller responsible for the Personal Data we collect and process.
If you have any questions about this Privacy Policy or wish to exercise your rights under applicable laws, please contact us at: Email: dataprotection@deciphera.com Postal address: Deciphera Pharmaceuticals (Switzerland) AG Dammstrasse 21 6300 Zug Switzerland.
DCPH-P02500 | August 2025