IMBRIA PHARMACEUTICALS, INC.
WEBSITE PRIVACY POLICY

This Privacy Policy describes the privacy practices of Imbria Pharmaceuticals, Inc. (“Imbria”, “we”, “us’ or “our”). Protecting the privacy and security of your personal information is important to Imbria. This privacy policy is designed to help you understand what data Imbria may collect, how Imbria uses and safeguards that data and who we may share it with.

Please read this Privacy Policy before using or submitting information to our Website. Using our Website is voluntary, and by using it, you consent to our collection and use of your information as described in this Privacy Policy.

  1. Personal Information we Collect on our Website

    When you use the Website, Imbria will collect the personally identifiable information you provide Imbria, if any, such as your name, home address, personal telephone number, personal e-mail address, company name, company mailing address, company e-mail address and company telephone number. We also may collect any information you provide us when you apply for employment via our Website, or when you contact us via e-mail for information or assistance, including the content of your e-mail. We also may collect usage, viewing and technical Information, including your IP address or device identifier when you use the Website. If you access the Website from a mobile device, that mobile device may also provide us with details of your location. We also may collect information as set forth in Section 4 below.

    We may use the information you provide us or that we otherwise collect to do any of the following: contact you; provide support; process your employment application; respond to your comments and questions; create anonymized and aggregated data sets that may be used for a variety of functions, including research, internal analysis, analytics, and other functions; ensure compliance with applicable laws, detect, investigate and prevent activities that may violate our policies or be illegal; optimize or improve the content and features of the Website; increase the functionality and user friendliness of the Website; monitor and analyze the Website usage and trends and otherwise measure the effectiveness of the Website.

    Our web server logs certain technical information automatically, such as the identity of your Internet Service Provider and your computer’s IP address and other technical information.

    We do not sell personal information collected from our website for monetary or other valuable consideration, but may share your personal information with third parties only in the ways that are described in this Privacy Policy.

    We may use a third party to gather information about how you and others use the Website. For example, we will know how many users access a specific page and which links they clicked on. We use this aggregated information to understand and optimize how the Website is used.

    We may also use services hosted by third parties, such as Google Analytics and Google Tag Manager, web analytics services provided by Google, Inc. (“Google”), to assist in providing the Website. Google Analytics and Google Tag Manager use cookies to help us analyze how users use the Website. The information generated by the cookie about your use of the Website (including your IP address) will be transmitted to, and stored by, Google on their servers. Google will use this information for the purpose of evaluating your use of the Website, compiling reports on website activity for us and providing other services relating to website activity and Internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, or unchecking these services in the website’s Cookie and Privacy Settings, however please note that if you do this you may not be able to use the full functionality of the Website. By using the Website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

  2. Disclosure of Personal Information

    We may disclose your personal information if Imbria believes in good faith that such disclosure is necessary (i) in connection with any legal investigation; (ii) to comply with relevant laws or to respond to and comply with legal process, including orders, rules, subpoenas or warrants served on Imbria; (iii) to protect or defend the rights or property of Imbria or users of the Website or services; (iv) to investigate or assist in preventing any violation or potential violation of the law, or this Privacy Policy; or (v) to enforce our Terms of Use, Privacy Policy or other rules.

    We may provide information about you to third parties that provide services to help us in operating the Website, responding to your requests, conducting quality assurance testing, providing technical support, and/or providing other services to us. Such sharing may include such as sharing information about you with third party service providers who provide services such as IT and system administration and hosting, research and analytics, and customer support, and sharing information about you with third parties such as media agencies or email service providers that are assisting us in sending direct marketing messages for the purposes and pursuant to the legal bases described above. We may share de-identified information (such as the number of daily visitors to a particular web page or the size of an order placed on a certain date or other aggregated usage data) with third parties.

  3. Users Outside of the United States

    However, IMBRIA has committed to comply with the GDPR and protects your information according to GDPR principles and obligations Our company is based in the United States and our Website is hosted in the United States. Before providing your information via the Website, you should understand that your information will be sent to the United States. Data protection laws in the United states do not provide the same level of protection as data protection laws in other jurisdictions, such as the European Union, raising the risk that your information will not have the same level of protection as your local jurisdiction. However, we have elected to comply with the European Union’s General Data Protection Regulation (“GDPR”), and shall protect information from the European Union in accordance with the GDPR’s principles and obligations.

    If you are from the European Union, the processing of any personal data you provide us is governed by the GDPR. The GDPR requires us to provide certain information concerning our processing of personal data.

    Imbria is the data controller for the personal information you provide us. The purpose of the processing of your personal data and the categories of personal data we may collect, are described in Sections 1 and 2 above. The lawful basis for the processing of the personal data you provide us through this Website is our legitimate interest in conducting our business in a manner typical in the pharmaceutical industry in the USA, having taken into account any risks to your rights, including your right to privacy. Our specific legitimate interests are described in Sections 1 and 2 above. We also may process personal data on other bases permitted by the GDPR and other applicable laws, such as when the processing is necessary for us to comply with our legal obligations.

    You have the right to request access to your personal data, to have your personal data corrected, restricted or deleted, and to object to our processing of your personal data. Your rights may be subject to various limitations under the GDPR. If you wish to exercise any of these rights, or if you have any concerns about our processing of your personal data, please contact us via email at – imbria.dpo@mydata-trust.info. You have also the right to file a complaint concerning our processing of your personal data with your national (or in some countries, regional) data protection authority. The EU Commission list can be found at: http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm

    This Privacy Policy only applies to personal data collected via our Website. If you have provided personal data to us through some other means besides our Website (for example, in connection with a clinical study sponsored by Imbria in Europe), you will have received a separate notice concerning your personal data. Please refer to that notice first if you have any concerns about our processing of your personal data, as that notice will contain important information and a designated contact person for concerns – but you can always contact us (see contact information below).

  4. Functions and use of cookies

    a. Cookies are small files that are placed on your desktop, notebook or mobile device by a website you visit. From this we can, for example, recognize whether there has already been a connection between your device and our websites, or which language or other settings you prefer. Cookies may also contain personal data. We use cookies to gather general information about your use of the Website, the files you have designated for backup, the configuration of your computer and your computer’s interaction with the Website, and store this information in log files, and to collect data that enable us to better understand and improve the usability, performance and effectiveness of our Website. We may also use other Internet technologies, such as web beacons or pixel tags and other similar technologies, to perform similar activities and deliver or communicate with cookies and analyze your use of the Website. We use this information to understand traffic on our Website, enabling us to improve the Website, provide the best online experience possible, and improve our customer service.
    b. By using our websites, you agree to the use of cookies. You can also visit our website without consenting to the use of cookies. This means that you can refuse such use and delete cookies at any time by making the appropriate settings on your device.
    c. If you decide against the use of cookies, it is possible that not all functions of our websites are available to you or that individual functions are only available to you to a limited extent.

    Do Not Track (DNT) is a privacy preference that users can set in some web browsers, allowing users to opt out of tracking by websites and online services. Imbria and the Website do not recognize or respond to DNT requests.

  5. Security of your Information

    Imbria is committed to protecting the security of your personal information. We use a variety of industry-standard security technologies and procedures to help protect your personal information from unauthorized access, use or disclosure. However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while Imbria uses reasonable efforts to protect your personal information, Imbria cannot guarantee its absolute security.

  6. Changing Your Information

    If you later decide that you do not want your personally identifiable information used for the purposes described in this policy, you may contact us to request removal of your personally identifiable information from our database. You may also contact us to correct or update any personally identifiable information you have provided us. You may also “opt-out” of receiving e-mails and other communications from us by using the unsubscribe feature included in the e-mails we send.

  7. Minors

    This website is not intended or designed to attract or collect any information from or about children under the age of 16. We do not collect information about the age of any visitors to our website. If you are a parent or guardian of a child under the age of 16 who you believe may have provided personally identifiable information to us, please contact us and we will promptly delete such information from our databases.

  8. Links to Other Websites

    As a convenience to our visitors, the Website may contain links to a number of websites that we believe may offer useful information. The privacy policies and procedures described herein do not apply to such websites or their content, or to any collection of your personal information after you click on links to such third-party websites. We do not control such other websites and are not responsible for their content, their privacy policies, or their use of your personal information. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators except as disclosed on the Website. The information the third-party website collects is subject to the third-party online platform’s privacy practices. Privacy choices you make on the third-party online platform will not apply to our use of the information we collect directly through our Website. Your linking to any other websites is at your own risk, and you are responsible for complying with the terms of usage and other conditions posted on those websites. We expressly disclaim any and all liability for the actions of third parties, including without limitation to actions relating to the use and/or disclosure of personal information by third parties.

  9. Contact Us

    Imbria Pharmaceuticals, Inc.
    Park Plaza #439
    Boston, MA 02116
    United States
    Attention: Chief Legal Officer
    email: privacy@imbria.com

    You may also contact us here.

  10. Changes to this Privacy Policy.

    This Privacy Policy is effective as of April 23, 2020. We may change this policy at any time, based on the needs of our business or the evolution of our Website. Any material changes to the policy will be published on this Website. By your continued use of the Website, you consent to the terms of the revised policy.