GLOBAL PRIVACY& DATA PROTECTIONNOTICE
The Biocryst Privacy Commitment
BioCryst is committed to protecting the privacy of your personal information. This Global Privacy and Data Protection Notice (“Notice”) describes how BioCryst and its affiliates (collectively “BioCryst”, “we,” “us,” or “our”) may collect, use, store, process, share, and transfer your personal information, along with how we protect your personal information. BioCryst, as the Controller of your personal information, adheres to applicable privacy laws and regulations including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the European Union General Data Protection Regulation (GDPR) and the California Privacy Rights Act (CPRA). This Notice describes our general practices, but where local laws or regulations require that we process your personal information differently, we will comply with those local laws.
What type of personal information does Biocryst Collect?
“Personal information” refers to any information which could identify you directly (such as your name) or indirectly (such as your date of birth). The types of personal information BioCryst collects depends on how you interact with us.
Personal information we may collect and process from you may include:
- Contact and personal information (including demographics like race or ethnic origin);
- Educational information and professional experience;
- Financial information;
- Health data;
- Information related to work activities;
- Technical and network activity information;
- Product use information.
You can choose not to provide personal information when asked for it, but it may restrict BioCryst’s ability to provide you with some services you have requested.
We may collect this information directly from you, or through other sources, such as third-party vendors.
How may Biocryst use my personal information?
BioCryst may collect and use your personal information for reasons including, but not limited to, those listed below.
Please note that specific arrangements, contracts, consents, notices, or other forms of disclosure provided or made available to you may specify more detailed and/or additional uses of your personal information:
1) Patients and the General Public
- To initiate communications consistent with your consent;
- To review, investigate, and respond to details of queries and communications;
- To facilitate the availability of patient support services;
- To support interactions with patient associations;
- To plan and evaluate disease state awareness activities;
- To coordinate the logistics of your participation at a BioCryst event;
- To conduct research and survey of medical needs.
2) Participants in Clinical Trials (Subjects)
- Third parties may process your personal data on our behalf as part of a clinical trial. Personal data collected by the third party may include your name, address, health related information, age, and biometric data relating to the trial. This information is pseudonymized (meaning you are assigned a patient identifier, not your name) when available to BioCryst, absent specific situations described in the patient consent.
3) Healthcare Professionals and Scientists
- To provide, collect, review and communicate information on the proper use of drugs developed, sold or marketed by BioCryst (“BioCryst Products”);
- To provide, collect, review, and communicate information on quality, safety, or effectiveness of BioCryst Products;
- To report on the occurrence of accidents or recalls of BioCryst Products;
- To handle adverse events or complaints related to BioCryst Products;
- To request and implement clinical, post-marketing surveillance, and other studies or grants;
- To coordinate the logistics of your participation at a BioCryst event;
- To disclose, notify, or report research and financial relationships as required by law and regulation;
- To cultivate better communications with Healthcare Professionals.
4) Employment Applicants
- To process employment applications and contact applicants regarding potential employment or engagement;
- To discuss and make hiring decisions, and to respond to queries about the result of recruitment;
- To ensure compliance with our Affirmative Action Plan;
- To review medical claims data with third party administrators at the time of benefits enrollment and re-enrollment;
- To implement internship programs and related hiring.
5) Current and Former Employees
- To plan and manage personnel assignment, assessment, treatment, development, conditions of work, welfare program, health and safety;
- To effectuate compensation and the provision of employee benefits, including communications with insurance companies and brokers;
- To communicate with unions or works councils;
- To communicate with the employee and their family members in case of emergency;
- To assign and track training records;
- To communicate employee news internally or externally;
- To make notifications and reports to government agencies.
- To send a notice of the shareholder meeting and a voting form;
- To pay dividends to shareholders;
- To provide a list of shareholders to a transfer agent;
- To exercise BioCryst’s rights and obligations under the law.
7) Media and the Investment Community
- To distribute news and information on BioCryst;
- To analyze our stakeholders’ needs and plan accordingly;
- To cultivate better communication;
- To contact media representatives, securities analysts, and investors.
- To monitor BioCryst website usage levels, diagnose problems, and detect cybersecurity threats;
- To provide you with a more personal and interactive experience and improve our marketing efforts using cookies;
- To collect information about your use of BioCryst websites so that they can provide advertising about products and services tailored to your interests (if you opt-in);
- To collect information about the type of devices accessing BioCryst websites;
- To manage teleconferencing, videoconferencing, or web conferencing with BioCryst;
- To capture data related to when you open our message or click on any links or banners in the message;
- To reply to requests for support or in response to feedback.
9) Other BioCryst Business Operations
- To meet BioCryst’s regulatory pharmacovigilance requirements;
- To establish an account with BioCryst;
- To fulfill an order you have placed.
If we decide to use your personal information for a purpose other than originally intended when we first collected your data, we will provide you with new Notice.
Why is Biocryst allowed to collect personal information?
BioCryst can collect and use your personal information when any of the following apply:
- You give us your explicit consent to use your data. You can withdraw this consent at any time.
- We need your personal information in order to enter into or perform a contract.
- We need your personal information to comply with legal requirements.
- We have a legitimate interest in using your personal information for the purposes above, which is to allow us to create, enhance, personalize, or improve our websites, products, and services. We also have a legitimate interest in determining the effectiveness of promotional campaigns and advertising.
With whom may Biocryst share your personal information?
BioCryst may share your personal information in accordance with data privacy legislation with authorized third-parties for legitimate business purposes, including, but not limited to:
- BioCryst affiliates;
- Healthcare professionals and organizations, distributors, and other members of the healthcare and pharmaceutical industry;
- Selected suppliers, vendors, and service providers, including event planners, marketing agencies, technology suppliers, and companies processing adverse event information;
- Legal or administrative authorities;
- Potential stakeholders, including in the event of a merger, legal restructuring operation such as an acquisition, joint venture, or divestiture;
- Professional service providers such as accountants and auditors.
In any case, BioCryst will require that such third-parties:
- Comply with applicable data protection laws and the principles of this Notice;
- Only process the personal information for the purposes permitted in this Notice; and
- Implement appropriate technical and organizational security measures designed to protect the integrity and confidentiality of your personal information.
To facilitate our global operations, BioCryst may transfer, store, or process your personal information within our corporate locations or with service providers based around the world, including in the United States and the European Union (EU). Laws in these countries may differ from each other and from your country of residence. BioCryst takes appropriate steps to ensure personal information is processed and transferred according to applicable laws, but not all countries are subject to the same data protection laws. When necessary by applicable law, BioCryst ensures appropriate safeguards are in place through the use of written agreements with recipients that require them to provide certain protections to your personal information, such as Standard Contractual Clauses adopted by the EU and UK. Please contact BioCryst at firstname.lastname@example.org for more information regarding these safeguards.
How long will Biocryst retain your personal information
BioCryst will maintain your personal information only as long as is reasonably deemed required for legal, contractual, or business purposes. During these periods, we will take appropriate steps to ensure that the privacy of your personal information is maintained.
Your rights with regards to your personal information
You have certain rights with respect to your personal information, although some exceptions may apply depending on our basis for processing your personal information and the law in your jurisdiction.
Depending on these, you may have the right to:
- Ask BioCryst about the processing of your personal information including access to this information;
- Ask BioCryst to correct information you think is inaccurate or incomplete;
- Ask BioCryst to delete your personal information;
- Ask BioCryst to restrict the processing of your personal information;
- Object to the processing of your personal information;
- Ask that we transfer personal information you have given us;
- Withdraw your consent to process your personal information if you have provided it, such as for direct marketing purposes;
- Complain to your local data protection authority, although we ask that you contact us first.
To exercise any of these rights, please Email us at email@example.com. If limitations apply, BioCryst will look at each circumstance and provide you with the reason if we cannot comply with your request. As required by law, BioCryst may take steps to verify your identity prior to taking any actions with regard to your personal information.
Residents of California
RESIDENTS OF CALIFORNIA
In addition to the information and rights provided above, BioCryst adheres to the requirements of the California Privacy Rights Act (CPRA). If you are an employee or applicant, BioCryst may collect data that is considered “sensitive,” which may include:
- Social Security Number
- Driver’s license
- Passport Number
- Financial account details or credentials
- Health data
- Race or ethnicity
- Geolocation details
- Communication or correspondence including emails or text messages.
This information will be kept throughout your employment term, as needed, or as required by applicable local laws. BioCryst will never sell your personal data.
Changes to this notice
This Notice may be modified from time to time, particularly in the event of changes in the law or BioCryst’s practices. The date on which this Notice was last updated is shown at the end of this document. Please email firstname.lastname@example.org for the current version.
If you have any questions pertaining to BioCryst’s privacy practices, use of your personal information, or your rights described above, you may contact us at email@example.com. Our EU Data Protection Officer provided by privacy consultants Foxon may also be contacted at firstname.lastname@example.org.
Effective: January 1, 2023