This Policy applies to the information we collect:
• On this Website;
• In email, text, and other electronic messages between you and Nexus;
• Through the Website and other electronic communications sent through or in connection with the Website and Services;
• When you interact with our advertising and applications on third-party websites and services if those applications or advertising include links to this Policy.
This Policy does NOT apply to information you provide to or that is collected by any third party, including through application or content (including advertising) that may link to or be accessible from or on the Website or through a sponsored clinical trial, which is subject to other data collection processes and policies.
Information We Collect About You and How We Collect It
We collect several types of information from and about users of our Website, including:
1. Personal Information. This includes, but is not limited to, information that we use to identify you, such as your name, address, and telephone number.
2. Non-Personal Information. This includes, but is not limited to, user behavior on our Services and aggregated generic information. This is information that is about you but does not identify you.
3. Usage information. This includes, but is not limited to, information about your device including IP address, browser type, and version, time zone setting, and page interaction collected through cookies and other tracking technologies.
We collect this information:
1. Directly from you when you provide it to us. We collect information that you provide to us, including but not limited to, the information you provide by filling in forms on our Services, such as information provided at the time of registering to use our Website, posting material on the Website, or requesting further services on the Website. We may also ask for this information when you report a problem with our Services, or exercise your privacy rights and choices.
2. Automatically as you navigate through the Website. Information collected automatically may include usage information as described above, and we may use these technologies, at times in connection with third-party services, to collect information about your online activities over time and across third-party websites or other online services
We do not control these third parties tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.
How We Use Your Information
We use information that we collect about you or that you provide to us, including any Personal Information, for several reasons:
• To present our Services and its contents to you;
• To provide you with information, products, or services that you request from us;
• To set up, maintain, and support our Services;
• To monitor the use of our Services in order to detect security incidents;
• For internal marketing purposes, such as marketing research;
• To notify you about changes to our Website, or any products or services we offer to provide through the Website;
• For any other purpose with your consent.
Disclosure of Your Information
• With affiliates or subsidiaries, business partners, service providers, or other third parties we use to provide you with the Services and its contents and functions. We use third party service providers that perform functions on our behalf, such as billing and payment processing.
• To third parties to market their products or services to you if you have not opted out of these disclosures;
• To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about our users is among the assets transferred;
• To fulfill the purpose for which you provide it;
• For any other purpose disclosed by us when you provide the information; and
• With your consent.
We may also disclose your Personal Information:
• To comply with any court order, law, or legal process, including to respond to any government or regulatory request;
• If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Nexus, our customers, or others.
Data Transfers to Other Countries/Territories
At times we may need to share your personal data with our affiliates and third-party service providers. For Data Subjects from the European Economic Area (“EEA”), we may transfer your Personal Information outside the EEA for processing pursuant to the purposes outlined above. When you provide us with Personal Information, you understand and agree that it may be transferred across national boundaries and processed outside the EEA, including by trusted third parties. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy. If we do this, we have procedures in place to ensure your personal data receives the same protection as if it were being processed inside the EEA. Including, but not limited to, entering into contracts with our affiliates and third-party service providers which stipulate the standards they must follow at all times including the Standard Contractual Clauses.
Your Privacy Rights and Choices
We strive to provide you with choices regarding the Personal Information you provide to us. If you have questions regarding privacy-related rights, you may contact us at the information provided in the Contact Us section below.
We do not control third parties' collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way.
Certain data protection laws may provide you with more privacy rights than those listed above, depending on your citizenship or residency.
Additional Privacy Rights for Individuals in the European Economic Area (“EEA”) and California
There are certain laws that provide individuals with additional privacy rights. Under the European Union’s General Data Protection Regulation (“GDPR”), individuals in the EEA have additional privacy rights:
• Right to be Informed. Individuals have the right to transparency regarding our collection of personal data.
• Right of Access. Individuals have the right to know exactly what information is held about them and how it is processed.
• Right of Rectification. Individuals will be entitled to have personal data rectified if it is inaccurate or incomplete.
• Right to Erasure. Also known as “the right to be forgotten”, this refers to an individual’s right to have their personal data deleted or removed without the need for a specific reason as to why they wish to discontinue.
• Right to Restrict Processing. An individual’s right to block or suppress the processing of their personal data.
• Right to Data Portability. This allows individuals to retain and reuse their personal data for their own purpose.
• Right to Object. In certain circumstances, individuals are entitled to object to their personal data being used.
• Rights of Automated Decision Making and Profiling. The GDPR has put in place safeguards to protect individuals against the risk that a potentially damaging decision is made without human intervention.
If you wish to exercise your rights under the GDPR, please contact us using any of the methods provided in the Contact Us section below. We will consider and process your request within a reasonable period of time. Please be aware that under certain circumstances, the GDPR may limit your exercise of these rights.
You may file a complaint with EU data protection authorities (“DPAs”). A list of DPAs from the European Commission may be found here: http://ec.europa.eu/newsroom/article29/document.cfm?action=display&doc_id=50061
California Privacy Rights
This section is our Privacy Notice for California Residents (“Notice”) and applies to visitors, users, and others who reside in the State of California (“consumers” or “you”/”your”)and use our Services, as contemplated under the California Consumer Privacy Act of 2018 (“CCPA”) and the California Privacy Rights Act of 2020 (“CPRA”).
If you wish to exercise your rights under the CCPA/CPRA, please contact us using any of the methods provided in the Contact Us section below. We will consider and process your request within a reasonable period of time. Please be aware that under certain circumstances, the CCPA/CPRA may limit your exercise of these rights
We collect different types of information from users, and we use and/or disclose this information or different business purposes. The chart below identifies the Personal Information we may collect and lists the parties with whom we may share this information and for what business purpose.
Use of Personal Information
We do not sell your Personal Information. We do not share your personal information as defined under Cal. Civ. Cd. 1798.140(ah). We may use or disclose the personal information we collect for one or more the purposes listed in the chart. We will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
Your Rights and Choices
The CCPA/CPRA provides California residents with specific rights regarding their Personal Information. This section describes your CCPA/CPRA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past twelve (12) months. Once we receive and confirm your verifiable consumer request (see “Exercising Your Rights” section), we will disclose to you:
• The categories of personal information we collected about you;
• The categories of sources for the personal information we collected about you;
• Our business or commercial purpose for collecting or selling that personal information;
• The categories of third parties with whom we share that personal information;
• The specific pieces of personal information we collected about you (also called a data portability request;
• If we disclosed your personal information for a business purpose, a list of the disclosures made identifying the personal information categories that each category of recipient obtained.
You have the right to rectify (correct, update, or modify) the personal information we collect about you. After making such a request, we will take commercially reasonable efforts to correct inaccurate personal information within 45 days of receiving the request. In the event an extension is needed, we may take an additional 45 days when reasonably necessary. In this case, We will provide you a notice of extension within the first 45-day period.
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service providers to:
• Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
• Detect security incidents, protect against malicious, deceptive, fraudulent or illegal activity, or prosecute those responsible for such activities.
• Debug products to identify and repair errors that impair existing intended functionality.
• Exercise free speech, ensure the right of another consumer to exercise their free speech rights or exercise another right provided for by law.
• Comply with the California ElectronicCommunications Privacy Act (Cal. Penal Code § 1546 seq.).
• Engage in public or peer-reviewed scientific, historical or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, specifically if you previously provided informed consent and deleting that information may seriously impair or render impossible the research’s achievement.
• Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
• Comply with a legal obligation.
• Make other internal and lawful uses of personal information that are compatible with the context in which you provided it.
Exercising Access, Rectification, Data Portability, and Deletion Rights
To exercise the limitation, data sharing opt-out, access, rectification, data portability and deletion rights described above, please submit a verifiable consumer request to us by email at:
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf may make a verifiable consumer request related to your personal information.
You may only make a verifiable consumer request for access or data portability twice within a twelve (12) month period. The verifiable consumer request must:
• Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
• Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Response Timing and Format
We will try our best to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the receipt of the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another and should allow you to further transmit information if you desire.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive or unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We will not discriminate against you for exercising any of your CCPA/CPRA rights. Based solely on the exercise of your CCPA/CPRA rights, we will not:
• Deny you goods or services;
• Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
• Provide you a different level or quality of goods or services; or
• Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
Changes to this Notice
We reserve the right to amend this CCPA/CPRA Policy at our discretion and at any time. When we make changes to this CCPA/CPRA Policy, we will notify you by email or through a notice on our website homepage.
We have implemented measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure.Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to us in connection with our Services. Any transmission of Personal Information is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained in the Services.
It is our policy to post any changes we make to this Policy on this page. If we make material changes to how we treat our users’ Personal Information, we will notify you by the email address specified in your account and/or through a notice on the Website. The date the Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting this Policy to check for any changes.
To ask questions or comment about this Policy and our privacy practices contact us at:
Nexus Pharmaceuticals, Inc.
Effective Date: February, 13 2022