Skip to content
PHARMEQAG

PQ-COM-11 · Rev. 2026-01

Information Security Policy

Minimum requirements for the handling of systems, access rights and data.

1. Access

  • Personal accounts, no shared access credentials.
  • Two-factor authentication for e-mail, accounting and remote access.
  • Password manager instead of written-down passwords.
  • Withdrawal of all access rights on the last working day.

2. Devices

  • Encrypted hard drives and automatic screen lock.
  • Up-to-date operating system and application updates.
  • No processing of business data on private, unprotected devices.

3. Data

  • Access only within the scope of the respective task.
  • Daily backup of business-critical data and regular restore tests.
  • Confidential documents to be sent only in encrypted form or via protected channels.

4. Incidents

Lost devices, suspicious e-mails and possible data leaks must be reported to Executive Management without delay. If an incident concerns personal data with a high risk, we examine whether to report it to the Federal Data Protection and Information Commissioner (FDPIC).

These policies describe the internal order of PHARMEQ AG. They create no third-party entitlements and do not replace any contractual agreement.