Privacy Policy
TAT Analyzer — internal application
Effective from: 19 September 2026
This Privacy Policy (the “Policy”) describes how personal data is processed in connection with the “TAT Analyzer” web application (the “Application”; available at https://tatanalyzer.sightagency.com), an internal tool operated by Roche (Magyarország) Kft. for the exclusive use of the employees and authorised users of the Roche group. The purpose of this Policy is to provide clear and transparent information about the processing of users’ personal data before such processing begins.
The processing complies with Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”) and Hungarian Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (the “Privacy Act”).
The Application is not public; it can be accessed only by authorised, invited users after signing in with their corporate (Roche) identity. Access rights are managed jointly with the “Customer Segmentation - Hungary” application: the two applications share a single user register, so an invitation, role change or withdrawal of access made there applies to this Application as well.
1. Data controller
2. Categories of personal data processed
- Identification and sign-in data: the user’s name, corporate (work) email address, and the unique user identifier (subject identifier) provided by the corporate identity provider (SSO) / Google.
- Authorisation data: the role assigned to the user (administrator or member), user type (sales, logistics, service or other), access territory codes, access status (invited / active / disabled), and the identifier of the person who issued the invitation.
- Usage and technical data: session identifier, sign-in / sign-out and last-login timestamps, the IP address and browser identifier (user agent) of the requesting device, and technical data recorded in the Application’s server logs.
- Cookies: the Application uses one technically necessary session cookie to maintain the signed-in session (see Section 8).
The Application also processes business data (e.g. laboratory turnaround-time measurements and the operational data of healthcare institutions); this is not personal data of the users and is therefore, unless otherwise stated, outside the scope of this Policy.
3. Purposes of processing
- secure identification and sign-in of users (authentication);
- management of user access and permissions (based on roles, user type and access territories);
- ensuring the proper operation and internal services of the Application;
- maintaining the IT security of the Application and the data stored in it, preventing misuse, and logging and investigating events;
- compliance with legal obligations.
4. Legal basis for processing
The legal basis for the processing is the legitimate interest of the Controller pursuant to Article 6(1)(f) GDPR: the Controller has a legitimate interest in ensuring that only authorised staff can access its internal application, in managing those accesses, and in safeguarding the security of its IT systems.
As the Application is available only to Roche employees and authorised users in connection with their work, the data is processed to the extent necessary for the employment relationship and the performance of work. In certain cases the processing may also be necessary for compliance with a legal obligation pursuant to Article 6(1)(c) GDPR.
Given the subordinate relationship within employment, the processing of personal data in the Application is not based on the user’s consent.
Where processing is based on legitimate interest, the Controller has carried out a balancing test and, upon request, will inform the data subject of its outcome.
5. Retention period
The Controller processes the personal data associated with a user account for as long as the user’s access right exists. Following the termination of access (disabling or deleting the account) or the termination of the employment relationship, the data is deleted or blocked, unless its further retention is required by law or is necessary for the Controller’s legitimate interest (e.g. the establishment or defence of legal claims).
Technical log data is stored for as long as necessary for operation and security, and thereafter for the retention period applicable to the given log type. Session cookies and session identifiers expire when the session ends (on sign-out or after the configured expiry time).
6. Recipients and data processors
The personal data may be accessed by the Controller’s authorised staff (in particular the Application’s administrators and the relevant IT staff) to the extent necessary to perform their duties.
The Controller uses data processor(s) to operate the Application:
- Developer and operator of the Application (hosting and operations provider): Sight Innovative Kft., which performs the technical operation and maintenance of the Application;
- Provider of the sign-in (authentication) service: the Roche corporate identity provider (SSO) and — in the case of Google-based sign-in — Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), which identifies the user during sign-in.
The data processors process personal data solely in accordance with the Controller’s instructions, for the performance of the tasks set out in their contract, and provide appropriate technical and organisational security guarantees.
The Controller may also transfer personal data to, or make it accessible for, other member companies of the Roche group for the purposes set out above and to the extent necessary.
7. Transfers to third countries
Where the above data processors or Roche group companies process data outside the European Economic Area (EEA) (e.g. as part of authentication or cloud services), such transfers take place only in compliance with the GDPR: either on the basis of an adequacy decision of the European Commission, or subject to appropriate safeguards (e.g. the Standard Contractual Clauses adopted by the European Commission, “SCC”). Information about the safeguards applied can be requested via the contact details in Section 9.
8. Cookies
The Application uses one strictly necessary session cookie (tat_sid) to maintain the signed-in state
(session). This cookie contains only a random session identifier, is transmitted over a secure connection (HTTPS),
cannot be read from the browser (HttpOnly), and expires on sign-out or when the session ends. As this cookie is
necessary for the Application to function, no separate consent is required for its use. The Application does not use
marketing or tracking cookies.
9. Data security
The Controller and its data processors take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These measures include transmission over an encrypted connection (HTTPS/TLS), access controls and authentication, and storing sign-in tokens and session identifiers only in hashed form rather than in plain text.
10. Rights of data subjects
Within the limits set out in law, the data subject may exercise the following rights in relation to the processing of their personal data:
- Right of access: to obtain confirmation as to whether their data is being processed and, if so, to access that data and information about the processing.
- Right to rectification: to request the correction of inaccurate data and the completion of incomplete data.
- Right to erasure (“right to be forgotten”): to request the deletion of their data in the cases set out in the GDPR.
- Right to restriction of processing: to request the restriction of processing in the cases set out in the GDPR.
- Right to data portability: in respect of data they have provided and that is processed by automated means, where the conditions are met, to receive it in a structured, machine-readable format or to have it transmitted to another controller.
- Right to object: where processing is based on legitimate interest, to object — on grounds relating to their particular situation — to the processing of their data.
The data subject may submit a request to exercise these rights using the contact details in Section 1. The Controller will examine and respond to the request within the time limit set out in the GDPR (as a general rule, one month).
11. Remedies
If the data subject considers that the processing of their personal data infringes the law, they may lodge a complaint with the Controller, with the supervisory authority, or with a court.
Supervisory authority:
The data subject may also bring an action before a court. At the data subject’s choice, the action may also be brought before the court (tribunal) competent for their place of residence or stay.
12. Amendments to this Policy
The Controller reserves the right to amend this Policy unilaterally, with effect for the future, in particular in the event of a change in the law or in the circumstances of the processing. The Policy in force at any given time is available within the Application.
Effective from: 19 September 2026.
← Back to sign in