Last updated: June 2019
Welcome to the website of Eidos Therapeutics, Inc. (“Eidos”, “we”, “us” and/or “our”). Eidos is a clinical stage biopharmaceutical company that specializes in developing and commercializing certain therapies targeting diseases caused by transthyretin, or TTR, amyloidosis, or ATTR. Our research activities (“Research”) include investigation of this well-defined family of diseases at their collective source by stabilizing TTR. Our product candidate, AG10, is an orally-administered small molecule designed to potently stabilize TTR, a potentially best-in-class treatment aiming to halt the progression of ATTR diseases. Our website and our online research participant portal (each a “Site” and collectively, the “Sites”) allows you to easily access and use content, including features, resources and other information intended to help you learn about Eidos’s Research, products we may offer, and information for investors.
INFORMATION WE COLLECT AND HOW WE USE IT:
- RESEARCH PARTICIPANTS
Information We Collect: When you participate in Research, we collect information that, alone or in combination with other information, could be used to identify you (“Personal Data”), described below.
How We Use Research Participant Personal Data:
To conduct Research, including performing drug development research and Research-related activities such as reporting to industry regulators.
As necessary for certain legitimate business interests, which include the following:
- To (a) comply with legal obligations and legal process; (b) respond to requests from public and government authorities including public and government authorities outside your country of residence; (c) enforce our Terms and Conditions Agreement; (d) protect our operations or those of any of our affiliates; (e) protect our rights, privacy, safety or property, and/or that of our affiliates, you or others; (f) as necessary to establish an efficacy and safety database for our investigative product as required by global regulatory agencies; and (g) to allow us to pursue available remedies or limit the damages that we may sustain, as required or permitted by the law;
- To send administrative information to you, for example, information regarding the Research trial, changes to, or termination of the Research;
As a participant in Research, you may instruct Us to discontinue collecting data by withdrawal of consent. However, in order to safeguard the validity of the Research and comply with regulatory obligations related to clinical trials, your research data cannot be deleted even if you decided to stop participating in the Research.
- SITE USERS
Information We Collect: When you engage with a Site, we collect information that, alone or in combination with other information, could be used to identify you.
Personal Data You Provide Us. We collect Personal Data that visitors to the Sites send to us electronically, for example when completing any “free text” boxes in our forms (such as on our “Information Request” or “Contact Us” page) requesting information or subscribing to emailing lists, or information you provide when entering responses and data into our research participant portal. While the type of data we collect depends on the nature of the inquiry, it typically includes name and email address.
Automatically Collected Data. When you use or interact with the Sites, the following information is created and automatically logged in our systems:
- Log Data: Information (“log data”) that your browser automatically sends whenever you visit the Sites. Log data includes your IP address (so we understand which country you are connecting from when you visit the Sites), browser type and settings, the date and time of your request, and how you interacted with the Sites
- Device Information: Includes type of device you are using, operating system, settings, unique device identifiers, network information and other device-specific information. Information collected may depend on the type of device you use and its settings.
- Usage Information: Information about how you use our Site, such as the types of content that you view or engage with, the features you use, the actions you take, the other users you interact with and the time, frequency and duration of your activities.
How We Use Site Personal Data:
As necessary for certain legitimate business interests, which include the following:
- To authenticate users and provide access to the Sites;
- To respond to your inquiries and fulfill your requests for products, services, and information;
- If you ask us to delete your data and we are required to fulfil your request, to keep basic data to identify you and prevent further unwanted processing;
- To prevent fraud or criminal activity, misuse of our products or services, and ensure the security of our IT systems, architecture and networks; and
For individuals in the European Union (“EU”), please see the “European Union (EU) Users” section below for information on what we mean by legitimate interests and your rights.
SHARING AND DISCLOSURE OF INFORMATION
We may share or disclose your information at your direction, such as when you authorize a third-party service to access your account or when you voluntarily share information or content via the Sites.
There are certain circumstances in which we may share your Personal Data with certain third parties without further notice to you, unless required by the law, as set forth below:
- Vendors, Service Providers, and Research Partners: To assist us in conducting Research and to perform certain Research services and functions, including providers of clinical trial operations services such as trial site personnel, investigators, clinical laboratories, clinical research organizations (“CROs”), and others conducting Research-related activities on our behalf (“Research Partners”); providers of administrative services such as email communication (including appointment reminders, investment information you request through a Site) and Site support services; to assist us in meeting business operations needs and to perform certain services and functions; and analytics (for more details on the third parties that place cookies through the Sites, please see the “Cookies” section below). For example, we use Google Analytics to understand how our Sites are used, and Flywheel for hosting. Pursuant to our instructions, these parties will access, process or store Personal Data in the course of performing their duties to us.
- Business Transfers: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of all or a portion of our assets, or transition of service to another provider, your Personal Data and other information may be transferred to a successor or affiliate as part of that transaction along with other assets.
- Legal Requirements: If required to do so by law or in the good faith belief that such action is necessary to (a) comply with a legal obligation, (b) protect and defend our rights or property, (c) act in urgent circumstances to protect the personal safety of users of the Site or the App, or the public, or (d) protect against legal liability.
To determine the appropriate retention period for your Personal Data, we will consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we use your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
UPDATE YOUR INFORMATION
If you need to change or correct your Personal Data, other than the Personal Data collected through your participation in Research, or wish to have it deleted from our systems, you may contact us. We will address your request as required by applicable law. In the event you wish to correct or change your Personal Data as a Research participant, please contact the site or Privacy Representative. You may also request that we update your Personal Data by contacting us at firstname.lastname@example.org.
CALIFORNIA PRIVACY DISCLOSURE
EUROPEAN UNION (EU) USERS
Scope. This section applies if you are an EU User (for these purposes, reference to the EU also includes the European Economic Area countries of Iceland, Liechtenstein and Norway).
Data Controller. Eidos is the data controller for processing Personal Data provided to us through your interactions with the Sites and your participation in Research. To find out our contact details, please see the “Contact Us” section below, which also provides the contact details of our representative in the EU for purposes of the General Data Protection Regulation.
If you are an individual in the EU, you can also contact DPR Group who has been appointed as Eidos’s representative in the EU pursuant to Article 27 of the General Data Protection Regulation on matters related to the processing of Personal Data. If you want to raise a question to Eidos, or otherwise exercise your rights in respect of your personal data (described below), please contact our EU-based Representative at email@example.com.
Your Rights. Subject to applicable EU law, you may have the following rights in relation to your Personal Data that we hold about you, depending upon whether the Personal Data was collected for Research purposes or through use of our Sites, and depending upon the EU member state in which you reside:
- Right of Access: If you ask us, we will confirm whether we are processing your Personal Data and, if so, provide you with a copy of all Personal Data you are lawfully entitled to receive along with certain other details. If you require additional copies, we may need to charge a reasonable fee.
- Right to Rectification: If your Personal Data is inaccurate or incomplete, you are entitled to ask that we correct or complete it. If we shared your Personal Data with others, we will tell them about the correction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
- Right to Erasure: You may ask us to delete or remove your Personal Data, such as where you withdraw your consent, where applicable. If we shared your data with others, we will tell them about the erasure where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data with so you can contact them directly. However, due to the public interest in the availability of clinical trial data, this right may not apply to Personal Data collected during Research.
- Right to Restrict Processing: You may ask us to restrict or ‘block’ the processing of your Personal Data in certain circumstances, such as where you contest the accuracy of the data or object to us processing it (please read below for information on your right to object). We will tell you before we lift any restriction on processing. If we shared your Personal Data with others, we will tell them about the restriction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly. If you are a clinical trial Research participant, you may not be able to restrict the processing of Personal Data.
- Right to Data Portability: You have the right to obtain your Personal Data from us that you consented to give us or that was provided to us as necessary in connection with our contract with you, and that is processed by us by automated means. We will give you your Personal Data in a structured, commonly used and machine-readable format. You may reuse it elsewhere. However, this right may not apply to Personal Data from Research participants.
- Right to Object: You may ask us at any time to stop processing your Personal Data, and we will do so:
- If we are relying on a legitimate interest to process your Personal Data — unless we demonstrate compelling legitimate grounds for the processing or
- If we are processing your Personal Data for direct marketing, including sending information about investing in our company.
- Right to Withdraw Consent: If we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect any processing of your data before we received notice that you wished to withdraw consent.
- Rights in Relation to Automated Decision-making: You have the right to be free from decisions based solely on automated processing of your Personal Data, (including profiling) unless this is necessary in relation to a contract between you and us or you provide your explicit consent to this use.
- Right to Lodge a Complaint with the Data Protection Authority: If you have a concern about our privacy practices, including the way we handled your Personal Data, you can report it to the data protection authority that is authorized to hear those concerns.
Please see the “Contact Us” section below for information on how to contact us to exercise your rights.
Children in the EU: The Sites are not directed to EU data subjects who are children who are under the age of 16. Eidos does not knowingly collect Personal Data from children who are under 16. If you have reason to believe that a child under the age of 16 has provided Personal Data to Eidos through the Sites please contact us and we will endeavor to delete that information from our databases.
CHILDREN IN THE US:
The Sites are not directed to children who are under the age of 13. Eidos does not knowingly collect Personal Data from children who are under 13. If you have reason to believe that a child under the age of 13 has provided Personal Data to Eidos through the Sites please contact us and we will endeavor to delete that information from our databases.
Some cookies expire after a certain amount of time, or upon logging out (session cookies); others remain on your computer or terminal device for a longer period (persistent cookies). Our Sites uses first party cookies (cookies set directly by Eidos) as well as third party cookies, as described below. For more details on cookies please visit All About Cookies.
Type of Cookies Used. The Sites use the technologies described below.
We also use a cookie to record when a user has agreed to the cookie consent banner.
| PHPSESSID (wordpress login)
WihmAx (hosting management)
|http://www.EidosTx.com/privacy-policy/||Because these cookies are strictly necessary to deliver the Site, users cannot refuse them.
|We use “analytics” cookies that allow us to recognize and count the number of visitors and to see how visitors move around the site when they are using it. This helps us to improve the way our Site works, for example by making sure users are finding what they need easily. The collected data provides us only with anonymous traffic statistics (like number of page views, number of visitors, and time spent on each page). These cookies also may allow us to track how often posts on third party websites, such as social media sites, are clicked on.||• Google Analytics (GA, _GID)
|https://policies.google.com/privacy||Users may download and install an opt-out add-on for their web browsers.
Your Choices. On most web browsers, you will find a “help” section on the toolbar. Please refer to this section for information on how to receive a notification when you are receiving a new cookie and how to turn cookies off. Please see the links below for guidance on how to modify your web browser’s settings on the most popular browsers:
Please note that if you limit the ability of websites to set cookies, you may be unable to access certain parts of the Sites and you may not be able to benefit from the full functionality of the Sites.
If you access the Sites on your mobile device, you may not be able to control tracking technologies through the settings.
OTHER TERMS AND CONDITIONS
You may contact us as follows: You may send an email to info@ EidosTx.com or send mail to:
Eidos Therapeutics, Inc.
Attention: Privacy Officer
101 Montgomery St, STE 2550
San Francisco, California 94104