Effective as of March 18, 2019
Cyclerion Privacy Statement
Cyclerion Therapeutics, Inc., (hereafter “Cyclerion”) collects Personal Data (as defined below) in order to serve you and communicate with you. Cyclerion respects the privacy of visitors to this website and this Privacy Statement explains how Cyclerion collects, uses, and discloses your Personal Data and answers specific questions that you may have regarding privacy and security.
This Privacy Statement applies to the operation of this website and other applications (including mobile applications), that directly link to this statement.
- Types of Personal Data Cyclerion May Collect
This Privacy Statement explains our practices with regard to “Personal Data.” Personal Data is any information that can be used to identify, locate, or contact you. It also includes other information that may be associated with such Personal Data. Examples of types of Personal Data:
- Contact Data, which includes information such as your name, email address, mailing address, email address or phone numbers;
- Relationship Data, including information about products, treatments and health conditions that are of interest to you;
- Transaction Data, including purchases, inquiries, and information about how you use the Cyclerion websites and mobile applications;
- Financial Account Data, such as your credit card number or Social Security number;
- Geo-location Data, as may be transmitted to us by your smart phone or other location-aware devices; and/or
- Job Applicant Data, such as your Contact Data, resume, previous work experience, education, transcript, driver’s license information, social security number or national identification number and information relating to references.
- How Cyclerion Collects Personal Data
In most cases, we collect Personal Data directly from you that you voluntarily submit to us. We will ask you for Personal Data when you interact with us, such as registering on our websites, using any interactive features or applications, signing up to receive a newsletter or a rebate, participating in a savings program, making a direct purchase, or calling or emailing us to ask questions. We may collect additional data from other sources, such as public records, and/or third-party data suppliers who enhance our files, and/or from social media sites such as Facebook. While we may not presently collect information on our website using any/all of these features at any given time, we may add and remove features from time to time that will ask for Personal Data.
From time to time we may obtain from third party sources Personal Data on healthcare professionals. This information is used to verify such things as professional status, identity and specialty when providing tailored information, communications or products/and or services.
- How Cyclerion Uses Personal Data
Cyclerion may use your Personal Data for its current or future business purposes, such as:
- To respond to your requests for information, products, services, including managing your online accounts with us;
- To provide you with general health information (such as information on certain health conditions) as well as information about our products and services;
- To provide you with marketing communications and offers for products and services;
- To deliver our products;
- To administer promotional programs, such as sweepstakes, rewards, and rebate programs;
- To determine if you are eligible for certain products, services, or programs (such as patient savings programs);
- If you have a business or professional relationship with Cyclerion, to develop our business relationship with you;
- If you apply for a job via our career center, to consider you for employment;
- For our research and development efforts;
- To monitor and analyze our respective business operations and website and other applications usage;
- To anonymize data so that it is no longer Personal Data;
- For product safety, such as adverse event reporting, product complaint reporting, or to communicate product safety information to you; and/or
- For other everyday business purposes, such as payment processing and financial account management, product development, contract management, website administration, fulfillment, analytics, fraud prevention, corporate governance, reporting, and legal compliance.
- When and Why Personal Data Is Disclosed by Cyclerion
Cyclerion does not sell, share, or otherwise distribute your Personal Data with third parties for their marketing purposes. Cyclerion will share your Personal Data only in compliance with applicable laws and regulations. For example, we may share your Personal Data as follows:
- We may share your Personal Data with your consent or as you direct. For example, we may share data with your doctor as part of programs in which you agree to participate.
- We may share your Personal Data with our affiliated companies, licensees, product co-promotion and co-marketing partners, which may only use your Personal Data for the purposes listed herein.
- We may share your Personal Data with our service providers, who are bound by law or contract to protect your Personal Data and only use your Personal Data in accordance with our instructions. For example, we may share your Personal Data with vendors who provide data processing or fulfillment services for us.
- We may also disclose your Personal Data where needed to affect the sale or transfer of business assets, to investigate legal issues, enforce our rights, protect our property, or protect the rights, property or safety of others, or as needed support external auditing, compliance and corporate governance functions.
- We may also disclose your Personal Data when requested under legal process or otherwise required by law, such as in response to a subpoena, including to law enforcement agencies and courts in the United States and other countries where we operate.
- Please note that we may also disclose data about you that is not personally identifiable. For example, we may publish reports that contain aggregate and statistical data about our customers. These reports do not contain any data that would enable the recipient to contact, locate, or identify you.
- Cookies and Other Data Collection Technologies
When you visit our website or use our mobile applications, we collect certain data by automated means, using technologies such as cookies, pixel tags, browser analysis tools, server logs and web beacons.
For example, when you visit our website, we may place cookies on your computer. Cookies are small text files that websites send to your computer or other Internet-connected device to uniquely identify your browser or to store data or settings in your browser. Cookies allow us to recognize you when you return. They also help us provide a customized experience and enable us to detect certain kinds of fraud.
Cyclerion uses Flash Cookies (also known as Local Stored Objects), Microsoft Silverlight and similar technologies to personalize and enhance your online experience in compliance with Network Advertising Initiative standards. The Adobe Flash Player is an application that allows rapid development of dynamic content, such as video clips and animation. Flash Cookies (and similar applications) use technology to remember settings, preferences and usage similar to browser cookies, but these are managed through a different interface than the one provided by your web browser. For more information about how to manage Flash Cookies and/or Silverlight Cookies, you should refer to those sites’ privacy and data sharing statements.
Pixel tags and web beacons are tiny graphic images placed on website pages or in our emails that allow us to determine whether you have performed a specific action. When you access these pages or open or click an email, the pixel tags and web beacons generate a notice of that action. These tools allow us to measure response to our communications and improve our web pages and promotions.
We collect many different types of data from cookies and other technologies. For example, we may collect data about the device you use to access our website, your operating system type, browser type, domain, and other system settings, as well as the language your system uses and the country and time zone where your device is located and the date and time you visit our sites and the pages you visit. Our server logs also record the IP address of the device you use to connect to the Internet. An IP address is a unique identifier that devices use to identify and communicate with each other on the Internet. We may also collect data about the website you were visiting before you came to Cyclerion and the website you visit after you leave our site.
In many cases, the data we collect using cookies and other tools is only used in a non-identifiable way, without any reference to Personal Data. For example, we use data we collect about all website users to optimize our websites and to understand website traffic patterns.
In some cases, we do associate the data we collect using cookies and other technology with your Personal Data. This Privacy Statement governs how we use that all of this data when we associate it with your Personal Data.
Cyclerion has relationships with third party advertising companies such as Google to perform tracking and reporting functions for this website and other websites. These third-party advertising companies may place cookies on your computer when you visit our website or other websites so that they can display targeted advertisements to you. These third-party advertising companies do not collect Personal Data in this process, and we do not give any Personal Data to them as part of this process. However, this Privacy Statement does not cover the collection methods or use of the data collected by these vendors. For more information about third party advertising, please visit the Network Advertising Initiative (NAI) at www.networkadvertising.org.
- Social Media Plugins
This website may from time to time use social media plugins (e.g., the Facebook “Like” button, “Share to Twitter” button) to enable you to easily share information with others. If we are using social media plug-ins, when you visit our website, the operator of the social plugin can place a cookie on your computer, enabling that operator to recognize individuals who have previously visited our site. If you are logged into the social media website (e.g., Facebook, Twitter) while browsing on our website, the social plugins allow that social media websites to share data about your activities on our website with other users of their social media website. For example, Facebook Social Plugins allow Facebook to show your Likes and comments on our pages to your Facebook friends. Facebook Social Plugins also allow you to see your friends’ Facebook activity on our website. Cyclerion does not control any of the content from the social media plugins. For more information about social plugins from other social media websites you should refer to those sites’ privacy and data sharing statements.
- Do-Not Track Signals and Similar Mechanisms
Some web browsers may transmit “do-not-track” signals to websites with which the browser communicates. Websites linked to this Privacy Statement may not respond to these “do-not-track” signals.
- Your Choices
You can always limit the data you provide to Cyclerion, but if you choose not to provide certain requested information, you may be unable to access some of the services, offers, and content on our websites.
You can manage cookie preferences and opt out of having cookies and other data collection technologies used by adjusting the settings on your browser. All browsers are different, so visit the “Help” section of your browser to learn about cookie preferences and other privacy settings that may be available.
You can opt-out of being targeted by those third-party advertising companies that are NAI members online at www.networkadvertising.org.
- Access and Correction
Cyclerion takes reasonable measures to maintain updated and accurate Personal Data and we respect your right to access and correct your Personal Data. You may update your Personal Data at any time by contacting us online at https://cyclerion.com/contact. You can also write us at the address in the “How to Contact Us” section below. If you send us a letter, please provide your name, address, email address, and detailed information about the change(s) you would like to make.
- Data Security
Cyclerion has implemented a data security program that contains administrative, technical and physical controls that are designed to reasonably safeguard your Personal Data from unlawful use and unauthorized disclosure. However, no system is completely secure or error-free. We do not, and cannot, guarantee the complete security of your personal information.
- Disclosure to Subsequent Owner or Operator
If all or part of Cyclerion is sold or merged into another entity, the data we have about you may be transferred to a third party as part of that transaction. We will try to assure that no Personal Data that is transferred will be used or shared in a manner inconsistent with this Privacy Statement without your consent. However, in the event of a sale or merger, your continued use of this site signifies your agreement to be bound by the privacy statement and other applicable terms of the subsequent owner or operator.
- Consent to Processing in the United States and Elsewhere
This site is owned and operated by Cyclerion in the United States, but the data you provide will be accessible to our partners (including any licensee, co-promotion or co-marketing partners), affiliates, vendors, and suppliers in other countries. Furthermore, if you are visiting this site from another country other than the United States, your communication with us will necessarily result in the transfer of data across international boundaries. The level of legal protection for Personal Data is not the same in all countries. However, we will take the security measures described in this Privacy Statement in an effort to keep your data secure. By using this site, you consent to the collection, storage, and processing of your data in the United States and in any country to which we may transfer your data in the course of our business operations.
- Privacy Statements of Third Parties
This Privacy Statement only addresses the use and disclosure of data by Cyclerion. We may provide links to outside websites or advertisements for third parties that have their own privacy statements and data collection, use and disclosure practices. Our independent dealers, suppliers and business partners have their own privacy statements too. We encourage you to familiarize yourself with the privacy statements provided by all third parties prior to providing them with data or taking advantage of an offer or promotion.
- Children’s Privacy
Cyclerion websites and applications are not intended to attract children, and we do not knowingly collect any Personal Data of anyone under the age of 13. If you believe your child is using our website, please contact us online at https://cyclerion.com/contact, so we can investigate and delete any inappropriate data.
- Forums, Product Reviews and Other Public Areas
- Changes to this Privacy Statement
We will only use Personal Data in the manner described in this Privacy Statement in effect when the data was collected from you. However, we reserve the right to change the terms of this Privacy Statement at any time by posting revisions to our site. If we make any material changes to this Privacy Statement, we will either notify you or place a prominent notice on our website. If at any point, we decided to use Personal Data in a manner different from that stated at the time it was collected, you will be given a choice to allow or disallow any additional uses or disclosures of your personally identifiable data, beyond that which was stated in this Privacy Statement at the time your data was collected.
Any portions of this policy are void to the extent they are prohibited by applicable law.
- Social Security Number Protection Policy
Cyclerion collects Social Security numbers in the ordinary course of its business. Cyclerion has implemented reasonable technical, physical and administrative safeguards designed to help protect the Social Security numbers from unlawful use and unauthorized disclosure. Cyclerion has policies that are designed to provide for the proper use and protection of Social Security numbers obtained in the course of doing business by Cyclerion. Such policies are intended to protect the confidentiality of Social Security numbers, prohibit unlawful disclosure of Social Security numbers, and limit access to Social Security numbers. The policies apply to multiple methods of collection of Social Security numbers, including Social Security numbers obtained by oral, written and electronic means. In particular, access to Social Security numbers is limited to those workers and service providers who have a need to access the data to perform tasks for Cyclerion. Social Security numbers are only disclosed to third parties in accordance with Cyclerion’s established Privacy Statement.
We will only disclose Social Security numbers: (i) with those service providers, auditors, advisors, and/or successors in interest who are legally or contractually obligated to protect them, or (ii) as required or permitted by law.
- How to Contact Us and Your Rights
Please contact us if you have any questions or comments about our privacy practices, your privacy choices, or this Privacy Statement. You can always reach us online at https://cyclerion.com/contact. You may contact us to update or correct much of your personal information that you provided to us through the Site.
If you choose to contact us via mail at the address below, please provide your name, address, email address, and information about the communication that you do not want to receive.
Attn: Privacy Officer
301 Binney Street
Cambridge, MA 02142
In addition, you may contact us at https://cyclerion.com/contact at any time to request access to the personal data we hold about you, to correct any mistakes or to request deletion of the same or withdraw your consent to certain types of processing of your personal data. If such a request places Cyclerion or its affiliates in breach of its obligations under applicable laws, regulations or codes of practice, then Cyclerion may not be able to comply with your request. However, you may be able to request that we block the use of your personal information for further processing. You may also have a right to data portability to another data controller under certain circumstances.
We have appointed GRCI Law to act as our EU Representative. If you wish to exercise your rights under the General Data Protection Regulation (GDPR) or have any queries in relation to your rights or privacy matters generally please email firstname.lastname@example.org or post your request or query to Head of Data Privacy Manager Service, GRCI Law Limited, Unit 3, Clive Court, Bartholomew’s Walk, Cambridgeshire Business Park, Ely, Cambridgeshire, CB7 4EA, UK