Customer Privacy Notice

Last Updated Date: 01.07.2026

Ascend GmbH, a subsidiary of Alkem Laboratories Limited, India, based in Germany (“Ascend”, “we”, “our”, or “us”), is committed to respecting and protecting the privacy of the Personal Data entrusted to us. We recognize the importance of safeguarding Personal Data and process it in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) (“GDPR”) and the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). When used in this Notice, the term “Personal Data” shall have the meaning assigned to it under applicable German and European Union data protection laws.

This Customer Privacy Notice (“Notice”) applies to individuals associated with customers of Ascend or individuals associated with Ascend as customers, including distributors, wholesalers, retailers, pharmacies, healthcare institutions, vendors, business partners, and other commercial counterparties (collectively, “Customers” or “Data Subjects”), who purchase products from, receive services from, or otherwise engage in business with Ascend.

This Notice describes how Ascend collects, receives, stores, uses, discloses, shares, and otherwise processes Personal Data of such Customers (“Customer Personal Data”) in connection with its business operations.

1. Types of Personal Data Collected

Ascend may collect, hold, use, and process the following categories of Customer Personal Data, including but not limited to:

i) General Personal Data: Name, Address, Email Address, Phone Number, Business Contact Details, Complaint Details, Correspondence Details.

ii) Government Identifiers: Tax Identification Number, VAT Identification Number, Import/Export Registration Information, and other government-issued identifiers required for regulatory or business purposes.

iii) Financial Data: Bank Account Details, Payment Information, Invoice Details, Tax Liability Information, Vendor Payment Information.

iv) Employment Data: Designation, Employer Information, Professional Qualifications, and Business Contact Information.

v) Medical Data (where necessary and permitted under applicable law): Names, contact details, adverse event information, medical history, laboratory test details, dosage information, self-medication details, and other information required for pharmacovigilance reporting and regulatory compliance.

2. Purpose of Collection

Ascend collects, holds, uses, and otherwise processes Customer Personal Data for the purposes described below, or for purposes which are reasonably compatible with the ones described below:

Processing based on contractual necessity, legal obligations, consent, legitimate interests, or any other lawful basis permitted under applicable law such as:

i. To onboard, manage, and maintain business relationships with Customers.

ii. To process customer orders, invoices, deliveries, and shipping activities.

iii. To manage and address customer complaints received from Customers.

iv. To receive, assess, report, and address pharmacovigilance complaints (adverse events) in accordance with applicable regulatory requirements.

v. To obtain import permissions, product registrations, and comply with applicable regulatory requirements.

vi. To verify, process, and execute invoices and payment disbursements.

vii. To respond to inquiries and communications voluntarily submitted by Customers.

Processing based on legitimate interests, legal obligations, or other lawful bases permitted under applicable law such as:

i. To ensure compliance with our legal obligations and to comply with our obligations towards regulatory authorities and public bodies.

ii. To enforce any legal rights or contractual claims.

iii. For legal and compliance purposes, including the prevention, detection, or investigation of fraud, misconduct, or other unlawful activities.

iv. To conduct internal and external audits.

v. To maintain the security and integrity of our business operations, systems, and records.

Where required under applicable law, Ascend will obtain consent prior to processing Personal Data.

3. Disclosure and Sharing of Customer Personal Data

As a part of its normal business operations, Ascend may disclose Customer Personal Data in the manner detailed below. Customer Personal Data is shared only with those parties that provide an adequate level of data protection by implementing appropriate technical and organizational security measures as prescribed by applicable law. We do not sell Customer Personal Data to anyone.

  • Internal stakeholders on a need-to-know basis.
  • Parent company, group entities and affiliates for business and operational purposes.
  • Business partners and third parties where such disclosure is related to the performance of services requested from Ascend.
  • Service providers and vendors (e.g., IT service providers, logistics providers, payment processors, compliance and risk management providers, and other business support providers), subject to appropriate safeguards.
  • Regulatory authorities, government bodies, courts, or law enforcement agencies, where required by law.
  • Third parties in connection with business restructuring, including mergers, acquisitions, or transfers.

4. Transfer of Customer Personal Data Outside the EEA

Ascend operates globally and may transfer Customer Personal Data to territories outside the European Economic Area (EEA) for the purposes described in this Notice and in accordance with applicable data protection laws.

Such transfers may include transfers to India, where our parent company is located, as well as to other countries where our group companies and service providers operate. Such transfer of Customer Personal Data may be to its parent company, affiliated or group companies, or to third parties, primarily for business and operational purposes.

Ascend will implement appropriate contractual, organizational, and technical safeguards, including where applicable Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms recognized under the GDPR, to ensure an adequate level of protection in accordance with applicable law.

5. Retention of Customer Personal Data

Ascend will retain Customer Personal Data for as long as reasonably considered necessary for achieving the purposes detailed in this Notice and as is permissible under applicable law.

Ascend may further retain Personal Data for longer periods where required for legal, regulatory, contractual, tax, accounting, pharmacovigilance, or compliance purposes, or for the establishment, exercise, or defence of legal claims.

6. Security Practices and Procedures

Ascend has adopted appropriate technical and organizational security measures in compliance with applicable laws to secure Customer Personal Data. Ascend also ensures that the third parties to whom Customer Personal Data is transferred or disclosed will maintain appropriate security standards and safeguards for the protection of Personal Data.

7. Your Rights in Connection with your Personal Data

     In relation to your Personal Data, you have the following rights:

  • Right of Access: Customers can request access to their Personal Data held by Ascend.
  • Right to Rectification: Customers have the right to correct any inaccurate or incomplete Personal Data. Customers are responsible for informing Ascend if there are any changes or inaccuracies in their Personal Data.
  • Right to Erasure: Customers have the right to request the erasure of their Personal Data in certain circumstances. If you believe that we should discontinue the use of your Personal Data, you have the option to request the deletion of your Personal Data. Ascend shall delete the Personal Data unless retention is necessary for compliance with applicable law.
  • Right to Restrict Processing: Customers may request restriction of the processing of their Personal Data in circumstances permitted by applicable law.
  • Right to Object: Customers may object to the processing of their Personal Data in circumstances permitted by applicable law.
  • Right to Data Portability: Customers may request the transfer of their Personal Data in a structured, commonly used, and machine-readable format, where applicable under law.
  • Right to Withdraw Consent: Customers have the right to withdraw their consent for the activities they had consented to. The withdrawal of consent previously granted for the processing of Personal Data does not affect the lawfulness of the processing carried out prior to such withdrawal. However, opting out may result in cessation of the respective activity or services.

To exercise any of the rights described above, or if you are not satisfied with how Ascend GmbH has handled your Personal Data, please contact our Group Data Protection Office at  privacy@ascend-de.eu.  We will review your request or concern and investigate the matter as appropriate.

If you consider that Ascend GmbH is not complying with the applicable data protection laws, you also have the right to file a complaint with the competent German data protection supervisory authority or the supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

We are committed to cooperating with the competent authorities in the resolution of any complaints and ensuring that all concerns are addressed in a timely and appropriate manner.

8. Changes to this Privacy Notice

We may update this Notice from time to time. We encourage you to review this Notice periodically so that you are aware of any changes. The updated Notice will take effect as soon as it has been uploaded or otherwise made available.