Privacy Policy

Effective as of 3/29/2024 and was last updated on 3/29/2024.

Your privacy is important to us. It is Delix Therapeutics' policy to respect your privacy and comply with any applicable law and regulation regarding any Personal Data we may collect about you, including across our website, https://delixtherapeutics.com, and other sites or digital portals we own and operate (the “Site”) as well as personal data collected via email, all personal data collected in connection with applications for employment, Personal Data we collect as necessary to conduct our research and other business activities, and all Personal Data we may collect when you enter our premises.

This policy explains what Personal Data (defined below) we collect, how we use and share that data, and your choices concerning our data practices.

Before engaging in activities with or submitting any Personal Data to Delix Therapeutics, please review this Privacy Policy carefully and contact us if you have any questions. By engaging in these activities, you agree to the practices described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not access the Site or otherwise engage in the activities.

In this Privacy Policy, “Personal Data” means any information alone or in combination that can be used to directly or indirectly identify an individual or an individual’s household, in particular by reference to an identifier such as a name, an identification number, location data or an online identifier. Personal Data also refers to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of an individual. This Personal Data may also be referred to as “personal information”, “personally identifiable information” or “protected health information” in some contexts.

INFORMATION WE COLLECT

Information we collect includes both information you knowingly and actively provide us and from other sources as part of our research and other business activities, and any information automatically sent by your devices in the course of accessing our Site or interacting with us.

WHOSE PERSONAL DATA WE COLLECT

We collect personal data about the following types of individuals: clinical trial participants, patients, patient family members, caregivers or advocates, physicians and other health care professionals, clinical trial investigators, researchers, pharmacists, contractors, consultants, job applicants, volunteers, visitors to our offices, and other individuals who interact directly with Delix Therapeutics or its service providers or business partners, including users of websites and mobile applications.

TYPES OF PERSONAL DATA WE COLLECT

The types of personal data we collect, and share depend on the nature of the relationship you have with Delix Therapeutics and the requirements of applicable laws. The types of personal data we collect include:

  • Health and medical information we collect in connection with managing clinical trials, conducting research, providing patient support programs, and tracking adverse event reports
  • Personal and business contact information and preferences (such as name, job title and employer name, email address, mailing address, phone number, and emergency contact information)
  • Biographical and demographic information (such as date of birth, age, gender, marital status, and information regarding any parents or legal guardians)
  • Professional credentials, educational and professional history, institutional and government affiliations, background checks, performance reviews, and information of the type included on a resume or curriculum vitae education and work history
  • If you are a third party with whom we have or are contemplating a contractual relationship, such as a health care professional, we collect publicly available information related to your practice, such as license information, disciplinary history, prior litigation and regulatory proceedings, and other due diligence related information  
  • Payment-related information we need to pay for services and products that individuals may provide to us (such as tax identification number and financial account information)
  • From health care professionals, we may collect information about the programs and activities in which you have participated, our interactions with you, and the agreements you have executed with us
  • Internet Activity, Technical Data and Usage Information including your computer's or mobile device's IP address, login credentials, device fingerprints, behavioral inferences Device data, such as your computer's or mobile device's IP address, unique identifiers, and general location information such as city, state or geographic area
  • Online activity data through cookies and other automated means, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the website, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access
  • Your photograph, social media handle or digital or electronic signature
  • If you are a visitor to a Delix Therapeutics office location, we may collect information through closed circuit television (CCTV)
  • Other information you provide to us (such as in emails, on phone calls, through our websites or mobile applications, or in other correspondence)

We will specify which of these types of data we use at the point we begin to collect this information from you. For instance, if you are an investigator and have signed an Agreement with us, we provided a Privacy Notice along with such Agreement, the terms of which apply to all Personal Data related to same.

HOW WE COLLECT PERSONAL DATA

We may collect personal data:

  • Directly from individuals as part of our research or recruitment activities
  • Automatically through our websites and mobile device apps
  • From healthcare professionals
  • From contract research organizations and clinical trial investigators
  • From government agencies or public records
  • From third party service providers, data brokers or business partners
  • From industry and patient groups and associations
  • From social media or other public forums (including adverse event information or product quality complaints)
  • From recruiters

Cookies and Use of Automated Data Collection Technologies

Delix Therapeutics does not use automated data collection methods and technologies such as cookies and web beacons (together “Collection Technologies”) to store or collect Usage Information when you visit or interact with the Site (“Usage Information”).

HOW WE USE PERSONAL DATA

To the extent permitted by applicable local law, we may use personal data for the following purposes:

  • Evaluating and engaging with our service providers and business partners
  • Analyzing and enhancing our communications and strategies (e.g. effectiveness of emails or our websites and mobile applications)
  • Operating, securing, and improving our business (including both physical premises digital environments)
  • Developing, personalizing customer relationship management activities, including the delivery of programs and products, as well as surveys and market research
  • Staffing, facilitating, conducting, and managing our research activities
  • Tracking and responding to safety and product quality concerns (including product recalls)
  • Complying with regulatory monitoring and reporting obligations (including those related to adverse events, product complaints, spend transparency, and patient safety)
  • Defining and managing appropriate patient engagement and enrollment activities
  • Identifying, interacting, and engaging with health care professionals, including thought leaders and external experts
  • Facilitating and improving our recruitment activities (such as processing employment applications, evaluating a job candidate for an employment activity, analyzing trends, and monitoring recruitment statistics)

We will specify the purpose and basis on which we intend to use Personal Data when we collect or begin using the personal information. In some situations, we may have a separate agreement or relationship with you with respect to a specific type of processing of your data, and these situations will be governed by specific terms, privacy notices, or consent forms.

Sensitive Personal Data We do not use or disclose your sensitive Personal Data for purposes that are not necessary in order to provide our products or conduct health research as are reasonably expected by an average person engaging in these activities with us.

LEGAL BASIS FOR PROCESSING DATA

In some cases, Delix Therapeutics has a legitimate interest to process the personal data that we collect, such as to operate, evaluate and improve our business; to facilitate and manage clinical trials or other patient advocacy and engagement programs; to promote scholarly research; to support our recruitment activities; or to facilitate a sale of assets or merger or acquisition. We may also process your personal data as necessary for the protection against criminal offences, safeguarding of domestic law, and the maintenance of a safe workplace for staff.

In other cases, Delix Therapeutics processes personal data to fulfill our contracts with our business partners, such as healthcare professionals or our research partners.

It may be also necessary for Delix Therapeutics to process personal data to establish, exercise or defend against fraud, illegal activity, and claims and other liabilities, including by enforcing the terms and conditions that govern the activities we engage in.

Delix Therapeutics’ processing of certain health and other associated information may be necessary to comply with our legal obligations, and for reasons of public interest in the area of health or for scientific or historical research purposes, such as with respect to adverse event and product safety reporting.

Delix Therapeutics may also process personal data as specifically permitted or mandated by applicable legal requirements, such as laws and regulations that authorize Delix Therapeutics to process personal data for the purposes of our research.

If Delix Therapeutics relies on consent for the processing of your personal data, we will seek such consent at the time we collect your personal data. For information on how to withdraw consent, please see the “Personal Data Access Rights” section of this Privacy Notice.

SHARING AND DISCLOSURE OF PERSONAL DATA

In certain circumstances we may share Personal Data with third parties for purposes described in this Privacy Notice or through a specific “in-time” privacy notice provided at the time we collect the information, without further notice to you, unless required by the law. We may share personal data with the following categories of third parties:

  • Delix Therapeutics affiliates and research partners
  • Vendors and Service Providers: To assist us in meeting business operations needs and to perform certain services and functions, we may share Personal Data with vendors including:
    • Contract research organizations that conduct clinical trials on our behalf
    • Customer service and patient support providers (including for product quality and adverse event reporting etc.)
    • Data storage and analytics and technology providers (including technology support, marketing and advertising technology providers)
    • Event planning and travel organizations that help facilitate Delix Therapeutics programs
  • Regulators worldwide, as required by law, including in connection with monitoring, review and approval of our studies, products and services, and adverse event reporting
  • Health care professionals, researchers, academics, and public health organizations
  • Business Transfers: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.
  • Legal Requirements: If required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, including to meet national security or law enforcement requirements, (ii) protect and defend our rights or property, (iii) prevent fraud, (iv) act in urgent circumstances to protect the personal safety of users, or the public, or (v) protect against legal liability.

A list of such parties is available upon reasonable request using the details in the Contact Us section of this policy.

Except in the event that our company undergoes a merger, corporate restructuring, or the sale of all or substantially all of our assets, we will not sell your Personal Data in exchange for money.

INTERNATIONAL DATA TRANSFER

The Personal Data we collect is stored and/or processed where we or our partners, affiliates, and third-party providers maintain facilities. We may need to transfer your Personal Data to countries other than the country in which the data was originally collected for the purposes described in this Privacy Policy. Please be aware that the locations to which we store, process, or transfer your Personal Data may not have the same data protection laws as the country in which you initially provided the information. If we transfer your Personal Data to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we consider a variety of requirements that may apply to such transfers, but in any event we will only transfer your data to a destination and in a manner that ensures your Personal Data will remain protected to the same or equivalent level as in the country of origin. This may include executing standard contracts that have been provided by the relevancy regulatory authorities and which commit the recipient to collect and use Personal Data in accordance with applicable law in the country of origin.

SECURITY OF YOUR PERSONAL INFORMATION

When we collect and process personal information, and while we retain this information, we will implement reasonable technical, administrative, and organizational measures to prevent loss and theft, as well as unauthorized access, disclosure, copying, use, or modification.

Although we will do our best to protect the Personal Data you provide to us, we advise that no method of electronic transmission or storage is 100% secure, and no one can guarantee absolute data security. We will comply with laws applicable to us in respect of any data breach.

HOW LONG WE KEEP YOUR PERSONAL INFORMATION

We store Personal Data as needed to accomplish the purposes identified in this Privacy Policy and to meet legal requirements, including to comply with law, and for record retention, resolving disputes, and enforcing our agreements. We will not retain Personal Data or sensitive Personal Data for longer than is reasonably necessary for the purposes disclosed above. Our retention of your Personal Data is governed by applicable law. This storage period may extend beyond the term of your relationship with us.

When we no longer need personal information, or in any event, after legal authority to retain it has expired, we will destroy Personal Data in accordance with local law and pursuant to our relevant procedures.

CHILDREN'S PRIVACY

We do not aim any of our products or services at children under the age of 13, and we do not knowingly collect Personal Data about children under 13.

If you have reason to believe that a child under the age of 13 has provided Personal Data to Delix Therapeutics, please contact us and we will endeavor to delete that information from our databases.

YOUR RIGHTS AND CONTROLLING YOUR PERSONAL INFORMATION

We will not discriminate against you for exercising any of your rights over your personal information.

Individuals are able to exercise the following rights in relation to the personal data that we may have collected about you. Please note that if the exercise of these rights limits our ability to process personal data, we may not be able to provide our products to individuals who exercise these rights, or to otherwise engage with such individuals going forward.

We reserve the right to verify the identity of the individual in connection with any requests regarding personal data, to help ensure that we provide the information to individuals to whom the information pertains and allow only those individuals or their authorized representatives to exercise rights with respect to that information.

If we receive Personal Data about you from a third party, we will protect it as set out in this privacy policy.

Withdrawal of consent

Where you have provided consent to us to process your personal data, you may withdraw such consent by following the instructions provided at the time of collection or by contacting us using details in the Contact Us section below. In some instances, withdrawing your consent may mean we can no longer provide products to you or otherwise engage with you.

Access to personal data

You may request access to the personal data that we maintain about you and receive a copy of such data. to check that it is complete and accurate and that we are lawfully collecting, using and disclosing (together “processing”) it. This access request will include a list of the types of personal data we may have collected and to which third parties we have Sold or Shared your personal data over at least the last 12 months.

Request correction

You may request to correct any errors in your personal data. I the event we cannot comply fully or at all, with your request, we will notify you of the reasons for this.

Object to processing

To the extent provided by applicable law, you may object (or “opt-out”) at any time on legitimate grounds to the processing of your personal data. In some cases, we may not be able to comply with your request or comply fully. In the event we cannot comply, we will notify you of the reasons for this.

In any event, you have the right to file a complaint with a regulator or data protection supervisory authority in your jurisdiction.

You also have the right to object if we use your Personal Data for direct marketing purposes. This includes your right to request that your Personal Data not be Sold to or Shared with third parties for their own proprietary purposes including for cross-context behavioral advertising, which is the targeting of advertising to a consumer based on that consumer’s Personal Data from a number of sources. If you wish to modify your preferences in respect to updates or notifications, you can contact us using the details provided in the Contact Us section below. All commercial and marketing communications (e.g. notification emails and newsletters) include instructions on how to opt out of those communications in the future.

Request erasure

You can request we delete Personal Data where you do not believe there is reason for us continuing to process it, or where you believe we collected or are using it unlawfully, where erasure is required by law or where you have opted-out of our processing. In certain cases we may not be able to comply fully or at all with your erasure request for legal reasons, and to the extent we are permitted to, we will notify you of the reasons for this.

Exercising your data access rights

To exercise any of the rights described herein, please contact us using the details provided in the Contact Us section below. When submitting a request to exercise any of these rights, please describe your relationship with us and your request, with sufficient detail to allow us to properly understand, evaluate, and respond to it. We may need to verify your identity before processing your request, which may require us to request additional personal data from you.

If you would like an authorized agent to exercise these rights on your behalf, you (or the authorized agent) must provide a written request including your full name and all contact details (e.g. email address, mailing address) that we have in our records and with which we can authenticate you, as well as (if applicable) the relationship with Delix Therapeutics. The written request must include the full name and preferred contact details of the authorized agent. We may deny a request from an agent who cannot meet these requirements.

If you believe that we have breached relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.

LIMITS OF OUR POLICY

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites and cannot accept responsibility or liability for their respective privacy practices.

CHANGES TO THIS POLICY

At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.

If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.

CONTACT US

For any questions or concerns regarding your privacy, you may contact us using the following details:

DELIX THERAPEUTICS, Inc.

20 Authors Road

Concord

MA 01742

Telephone 617-301-1279

privacy@delixtherapeutics.com