Patient Recruitment Platform Privacy Notice

This Privacy Notice explains how Priovant Therapeutics ("Priovant", "we", "us", or "our") collects, uses and discloses information in connection with your use of our Patient Recruitment Platform through the Patient Landing Page (hereinafter "the Website") aiming to facilitate patient recruitment for specific clinical trials sponsored by Priovant.

Priovant acts as a Data Controller (responsible for the data processing) for this activity and has committed to comply with the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (hereinafter the "U.K. GDPR") and the U.K. Data Protection Act 2018 (amended 2020) (hereinafter the "Data Protection Act").

Priovant has committed to comply with the Australian Privacy Act 1988 (Cth) and the 13 Australian related Privacy Principles (APPs).

With this Privacy Notice, Priovant wants to make sure that you understand what personal information is collected about you, how your personal information is used, by which party, and how it is kept safe.

Access to the Website implies the User’s full and unreserved acceptance of this Privacy Notice (hereinafter the “Notice”), as well as its general terms of use and its Cookies Notice. The User acknowledges having read the information below.

The Notice is valid for all pages hosted on the Website. It is not valid for the pages hosted by third parties to which Priovant may refer and whose privacy policies may differ. Priovant cannot therefore be held responsible for any data processed on these websites or by them.


Information We Collect

We collect and store information about you when you provide information directly to us. Your information will be used exclusively for processing your request of participation in our clinical trial.


Disclosure of Your Information

We do not sell or trade to outside parties your personal data.

Nevertheless, Priovant has contracted with the following services providers to manage the Website and store your personal data during the retention period:

  • Google Cloud Services
  • Heroku
  • Twilio
  • WP Engine

In certain situations, cookies associated with your use of the Website may be transferred to third parties. For further information, please consult our Cookies Notice.

We may disclose your information to our clinical trial sites, if it is determined you may be eligible for a clinical trial.

We may also provide (or reserve the right to provide) information to regulators, law enforcement authorities, courts, and other governmental authorities, consistent with applicable laws.


Transfers to Third Countries

Transfers of U.K. personal data outside of the U.K. to third countries (such as United States) will only be made in compliance with U.K. GDPR. If the personal data are transferred by Priovant to countries that have not been recognized by the U.K. secretary of state as providing an adequate level of data protection, we will put in place contractual safeguards to protect the data (e.g., International data transfer agreement (IDTA) and the Addendum to the SCCs in accordance with Article 46 of the U.K. GDPR).

In case of transfers of Australian personal data outside of Australia (“overseas recipient”), Priovant will take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to your information.

If you want to have more details about the mechanism supporting data transfers, please contact us. Our contact information is provided in the “Contact Information” section.


Security

Priovant has established safeguards to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure.

Your personal data are contained behind secured networks and are only accessible by a limited number of persons who have special access rights to such systems and are required to keep the information confidential.


Your Rights

We will provide you with the ability to exercise the following rights under the conditions and within the limits set forth in the law:

  • The right to withdraw your consent at any time, without justification, without affecting the lawfulness of the processing before such withdrawal, when you have given your consent for the processing of your data.
  • The right to access your information as processed by us and the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, all necessary information to make the process transparent.
  • The right of rectification if you believe that any information relating to you is incorrect, obsolete or incomplete, to request its correction or updating.
  • The right to request the deletion of your information.
  • The right to object, in whole or in part, to the processing of your information.
  • The right to restrict the processing of data under certain specified circumstances.
  • The right to request data portability, i.e., that the information you have provided to us be returned to you or transferred to the person or organization of your choice in a structured, commonly used and machine-readable format without hindrance from us and subject to your confidentiality obligations.

Please, note that all of these rights are not absolute and will be assessed on a case-by-case basis.

If you want to exercise your rights, please contact us. Our contact information is provided in the “Contact Information” section.

If you are a U.K. resident, you can lodge a complaint to the Information Commissioner’s Office (ICO), the supervisory authority of U.K., through https://ico.org.uk/make-a-complaint/.

If you are an Australian resident, you can lodge a complaint to the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us.


Contact Information

If you have any questions or concerns about this Privacy Notice or our privacy or security practices, or if you wish to exercise your data privacy rights, you may contact us by e-mail at info@priovant.com or write to us in care of: Priovant Therapeutics, Inc., 1007 Slater Road, Suite 250, Durham, NC 27703.

The data protection representative of Priovant in U.K. is MyData-TRUST Ltd located at Belmont Building, Belmont Road, Uxbridge, England, UB8 1HE, United Kingdom.

Priovant has also appointed a Data Protection Officer/Privacy Officer (DPO), who can be contacted at priovant.dpo@mydata-trust.info.


This Privacy Notice is effective as of: October 14, 2024.

We may change this Notice from time to time. Please refer to this Notice on a regular basis.