Rgenta Website Privacy Notice

Last updated: May 15, 2024

Introduction

The purpose of this Privacy Notice (“Notice”) is to outline what data we collect and hold about our website visitors and about customers/potential customers who get in contact with us. If you are an HCP with an ongoing business relationship with us, a participant in a clinical research study, a Rgenta employee or a job applicant, you will have received a dedicated Privacy Notice outlining how Rgenta collects and uses your data.

We collect your data:

    • When you visit rgentatx.com and any other websites and applications that link to this Privacy Notice and

    • When you interact with us by other means and we collect or process Personal Data as part of that interaction.
        • This could include Personal Data collected in-person, by telephone, or by mail and where you are not provided a more specific privacy notice at the beginning of our relationship or, in the case of a single interaction, at the time of our interaction.

        • For example, you may engage Rgenta and provide your information to us in-person when you attend a conference, contact us, or interact with us in other ways.

Information we hold 

Rgenta may hold the following details about you:

    • Online identifiers such as device ID or cookie ID;

    • Personal information such as your name and address and any information you may have given us

    • Other contact details if you have come in contact with us (such as your email address and/or the number that you telephoned us on)

Rgenta collects information about you only if we need the information for a legitimate business purpose or because you have freely provided your consent.

Rgenta obtains the categories of personal information listed above from the following categories of sources:

    • Directly from you. For example, from your written correspondence, emails and phone calls to us.

    • Indirectly from you. For example, from observing your actions on our website.

    • From 3rd parties. We only use a reputable source, and we make sure that personal information has been collected and maintained in compliance with applicable privacy and data protection legislation. Please note that the term “personal information” does not include publicly available information from government records, as well as deidentified or aggregated consumer information.

Data retention 

We will hold your personal information for the minimum amount of time required for the purpose for which it was collected and delete it afterwards – unless you ask us to remove your information beforehand or we have a legitimate business reason to hold it longer, such as contractual obligations we may have with you or because it is necessary for us in order to fulfil our legal obligations.

Responding to your enquiry 

If you make a request for product or service information and provide us with your details, we will use these to fulfil your request and periodically follow up your enquiry. For example, if you share your name and contact information or ask a question about our products or services, we will use that personal information to respond to your inquiry. This response and follow-up process will be conducted under the grounds of our legitimate business interests. We will ask for your consent to contact you via email.

You can tell us to stop following up at any time.

Marketing 

Your details may be used to send you marketing information relevant to your enquiry.

We will ask for your specific consent for any additional marketing activity, for example if we wanted to send you something we thought you might be interested in but was unrelated to your original enquiry. We will maintain a record of when and how we obtained your consent. You can withdraw your consent at any time.

Preventing transactional fraud, safety, security and reporting purposes

We may use your personal information to maintain the safety, security and integrity of our website, products and services, databases, as well as other technology assets. We may also use it to respond to law enforcement requests, court orders or governmental regulations, as required by applicable law.

Please note that Rgenta will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

Children 

This website does not provide services or sell products to children under the age of 18. If you are under the age of 18 years old, please do not use this site. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you are aware of any information we may have collected from a child under 18 years of age, please let us know so that we can delete that information.

Sharing your personal information 

Within Rgenta 

Personal information about you and your interactions with us may be used across Rgenta in order for us to fulfil an enquiry/contract with you and for legal and regulatory compliance.

With other organizations 

We may share your personal information with other organizations if the following applies:

    • they provide products, services or research on behalf of Rgenta, for example subcontractors. Our contract with them will not allow them to use your personal information for anything other than the fulfilment of our contract with you;

    • they provide administrative, processing, development, analytical or other services to help us in our sales, marketing, digital, administration and product development activities;

    • we transfer rights or obligations of our contractual relationship with you;

    • we have asked and been given your consent;

    • we are required or permitted to do so by law or regulation.

Where we share personal information with agents and sub-contractors, we will ensure that is supported by a written contract and that your personal information is treated confidentially and securely, and in accordance with this Notice, as well as the applicable privacy and data protection legislation. We may also be required to share your data with public bodies and supervisory authorities.

Rgenta will not sell, share or give any data to external companies for the marketing purposes of those companies. 

Your rights 

Depending on your country or State of residence, you might have certain rights regarding the use of your personal information:

These are:

    • The right to access: You may request that we confirm whether we process your personal information. You may request that we disclose to you the categories and/or the specific pieces of personal information that we collect about you, the categories of sources from which we collected the personal information, the categories of personal information we shared or disclosed, our business or commercial purpose for collecting, or sharing the personal information, and the categories of third parties with whom we disclosed the personal information. You may also request a copy of the personal information you provided to us, which will be provided in a portable and readily usable format. To exercise this right, please include your customer number if possible and details of the information you require.

    • The right to rectification:  It is important that any personal information we hold is up-to-date and correct. Thus, you may request that we correct inaccurate personal information we maintain about you, taking into account the nature of the information and the purposes of processing.

    • The right to erasure: You may request that we delete personal information we have from or about you.

    • The right to limit/restrict processing: You may request that we pause processing your personal information (usually following your right to erasure)

    • The rights to data portability: You may request that we disclose your personal information to you in a common file format.

    • The right to opt out of the processing of personal information, including sale or sharing of such information.

    • The rights to opt out of any automated individual decision making, including profiling

Exercising your rights 

If you do not wish to receive any marketing materials from Rgenta or exercise any of your rights over your personal information, as described above, you can email, telephone or write to us using the contact information shared in the respective Section below.

Timelines

Once we receive your request, we will try to respond to you without undue delay, and in accordance with the timelines required under applicable law. The response period may be extended where reasonably necessary, considering the complexity and specific circumstances of your request. In case of such an extension, we will inform you accordingly in advance.

Verifying your request

When you make a request (e.g., to access or delete your personal information), we will take steps to verify your identity. These steps may include asking you for personal information, such as your name, address, or other information we maintain about you. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request. Please know that making a verifiable consumer request does not require you to create an account with us.

The verifiable consumer request must:

    • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.

    • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request, confirm the personal information relates to you, and your request lacks sufficient details to help us handle the request. In this case, we will notify you to explain the basis of the denial.

Limitations

Please also note that exercising your rights may be subject to certain exceptions, particularly in cases where processing your personal information is necessary for us or our service providers to:

    • Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.

    • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.

    • Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.

    • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.

    • Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.

    • Comply with a legal obligation or any other applicable law.

    • Make other internal and lawful uses of that information that are compatible with the context in which you provided it.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

For California residents only:

Please note that you may only make a verifiable consumer request for access/portability twice within a 12-month period. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt.

Authorized Agents

You may also designate an authorized agent to submit requests on your behalf. If you do so, you will be required to verify your identity by providing us with certain personal information as described above. Additionally, we will also require that you provide the agent with written and signed permission to act on your behalf, and we will separately confirm with you that you provided the agent with permission to submit the request. We will deny the request if the agent is unable to submit proof to us that you have authorized them to act on your behalf or if any of the above verification criteria are not met.

Security of your data 

All our data is held on secure servers or secure private cloud storage. We take data security very seriously and use a range of tools, protocols and services to ensure data is protected.

Unfortunately, no data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. As a result, while we strive to protect your personally identifiable information, you acknowledge that: (a) there are security and privacy limitations of the Internet which are beyond our control; (b) the security, integrity and privacy of any and all information and data exchanged between you and us through this site cannot be guaranteed; and (c) any such information and data may be viewed or tampered with in transit by a third party. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the website or other service.

Contact Information

If you want to exercise any of your rights, or you have any questions, comments or complaints about this Notice or the ways in which we collect and use your personal information, please do not hesitate to contact us at:

Rgenta Therapeutics Inc.
300 TradeCenter Suite 6600 Woburn, MA 01801
Tel: +1 774-425-6494
Email: privacy@rgentax.com
Website: https://rgentatx.com/

UK GDPR Representative:
PRECISION FOR MEDICINE (UK), LTD
2A Orchard Road
Royston, Hertfordshire, SG8 5HD UK
privacy@precisionmedicinegrp.com

Changes to this Notice

We reserve the right to amend this Notice at our discretion and at any time. When we make changes to this Notice, we will post the updated Notice on the website and update the Notice’s effective date. Your continued use of our website following the posting of changes constitutes your acceptance of such changes.