ONCOHEROES BIOSCIENCES PRIVACY NOTICE
Introduction
This Privacy Notice applies to Personal Information collected by Oncoheroes Biosciences Inc. (“Oncoheroes,” “we” or “us”) through www.Oncoheroes.com, and any other website, application or digital service on or to which this Privacy Notice is linked or referenced. (collectively, the “Services” or “Site”). This Privacy Notice does not apply to our data collection practices conducted offline. Unless we notify you, this Privacy Notice does not apply to any third-party website or service that you may access through the Services.
By using our Services, you agree to this Privacy Notice and our Terms of Use. If you disagree, please do not use our Services.
Information We May Collect
Information you voluntarily provide: name, contact details, job applications, clinical trial participation, support requests. This can be through subscription to newsletters, applications, clinical trial participation, and in connection with your inquiries
Automatically collected data: IP address, device type, usage patterns.
Social media information (based on your settings).
Personal Information does not include either (i) aggregated information to the extent that an individual’s identity cannot reasonably be derived from it, or (ii) publicly available information that has not been combined with non-public Personal Information. For example, we may use such third-party information to confirm contact, to verify licensure of healthcare professionals or to better understand your interests by associating graphical and/or industry information with the information you have provided. We may collect personal data from social media platforms and plug-ins, such as Facebook and X (collectively, “Social Media”). When accessing the Services through a Social Media account, we may (depending on the applicable user privacy settings) automatically receive information from that Social Media platform. We may collect and use this information for the purposes described in this Privacy Notice or as described at the time the information was collected.
Use of Personal Data
We may use the information that we collect about you for the following purposes:
· Conducting business operations and delivering products and services
· Communicating with you effectively
· Providing information about our business, services, and health topics
· Connecting with third parties as necessary
· Confirming registrations, responding to inquiries, and fulfilling requests, including emailing requested materials
· Sending information, such as legal updates and event announcements, that may be of interest
· Maintaining records of contact information and correspondence when you contact us to facilitate responsive communication
· Notifying you about important changes to our terms, conditions, and policies
Where we collect data in our legitimate interests to manage our business, we rely on the GDPR legal basis of legitimate interests under Article 6(1)(e). This includes where you have shown an interest in our work and where we have added you to our mailing list. You can opt out from this at any time. We will also rely on this legal basis in the case of mergers and acquisitions where we need to share information to support that process.
We may also ask for your consent when you wish to receive information from us, and for this purpose we rely on the legal basis of consent under Article 6(1)(a).
Where we have a legal obligation to process your personal data, or share it with others such as law enforcement agencies, we rely on the legal basis of legal obligation under Article 9(1)(c).
We may provide functionality on the Site that will allow you to forward and share certain content with another person, or we may offer access to third party sharing functionality, such as third-party social media widgets/tools/buttons. If you choose to use our sharing functionality or a third party’s sharing functionality to refer someone to our content or service, we will use both of your data to send the content or link you request. If you use that functionality, your use is subject to the third party’s Privacy Notice and terms as Controller.
How we may disclose Personal Information
We may share your Personal Information as follows:
With your consent. We may disclose your Personal Information to any party for whom your consent has been provided.
· To our service providers. Oncoheroes might share your data with other organizations that provide us with services such as Quality Assurance, Pharmacovigilance, Information Technology and individual specialized consultants. These organizations are held under strict contractual obligations in compliance with the GDPR.
Kaleidoscope-– who we contract to support Oncoheroes from the GDPR perspective and to provide Oncoheroes with DPO services.
In relation to a corporate transaction. We may disclose and transfer Personal Information if we are involved in a merger, sale, acquisition, restructuring, reorganization, dissolution, bankruptcy, or other change of ownership or control (whether in whole or in part).
As we believe to be necessary and appropriate. We may also disclose Personal Information: (i) as permitted by law; (ii) if we determine that the disclosure of specific information is necessary to comply with the request of a law enforcement or regulatory agency or other legal process; (iii) to protect the legitimate rights, privacy, property, interests or safety of our company or our affiliated entities customers, business partners, employees or the general public; (iv) to pursue available remedies or limit damages; (v) to enforce our Terms and Conditions of Use; and (vi) to respond to an emergency.
Oncoheroes may also disclose aggregate or de-identified data that is not personally identifiable to third parties for any purpose.
International Data Transfers
As a company registered in the United States of America, your data will be stored and processed in the U.S. or other countries. Where we use vendors or supplier to process our data for us, Oncoheroes ensures that the appropriate EU Standard Contractual Clauses are applied to all data stored transferred outside the European Economic Area where an adequacy decision has not been published between the European Union and the country concerned. We apply consistent protections regardless of location. However, Oncoheroes will handle your personal data in accordance with this Privacy Notice regardless of where your personal data is stored and accessed.
Clinical Trials Data
INFORM2-VolVin Trial
Purpose: Evaluation of clinical safety and efficacy
Types of data: Health and Trial data
Lawful basis: Article 6(1)(c) legal obligation and Article 9(2)(i) necessary for ensuring high standards and quality of medicinal products
Retention: 25 years as per the EU Clinical Trials Regulation (536/2014)
Dovitinib Trial
Purpose: Maintenance of safety database
Types of data: Health and Trial data
Lawful basis: Article 6(1)(c) legal obligation and Article 9(2)(i) necessary for ensuring high standards and quality of medicinal products
Retention: 25 years as per the EU Clinical Trials Regulation (536/2014)
Oncoheroes processes pseudonymised legacy data from Novartis relating to drug safety monitoring. We process this data for the purpose of maintaining the safety database for an Investigational New Drug. As this data is pseudonymised, in order to exercise your rights please refer to Novartis’ Privacy Notice. https://www.novartis.com/privacy
For EU participants in the INFORM2-VolVin Investigator Sponsored trial. Oncoheroes, as a Joint Controller, processes pseudonymised trial data under the GDPR and EU/UK clinical trial regulations. As part of our Joint Controllership, Heidelberg are responsible for running the trial and managing your personal data for the purposes of the trial. For our part, Oncoheroes only have responsibility for the pharmacovigilance, which relates to safety monitoring of the Investigational Medicinal Prodcut (IMP) provided.
Oncoheroes only uses data where your name and contact details have been removed.
We are carrying out this clinical trial to explore whether this IMP is safe and effective for humans. We also rely on our legal obligation under the EU Clinical Trial Regulation (536/2014) and the UK Clinical Trials Directive (2001/20/EC) to ensure the safety of our participants.
All individuals who have consented to be part of the clinical trial, can withdraw from the study at any time. To exercise this right and to understand what happens to your data before Oncoheroes received it, please refer to Kitz Heidelberg’s Privacy Notice. (https://www.heidelberg-university-hospital.com/data-protection-policy)
If you have any queries regarding the processing activities, please refer to the Contact us section below.
Your Rights
You have the right to request:
information about how your personal data is processed
a copy of that personal data
that anything inaccurate in your personal data is corrected immediately
You can also:
raise an objection about how your personal data is processed
request that your personal data is erased if there is no longer a justification for it
ask that the processing of your personal data is restricted in certain circumstances
These rights may only apply in certain circumstances. This means that we may be unable (e.g., due to legal requirements) or not obligated to satisfy your request. In some cases, we may need to collect additional information from you in order to verify your identity before providing you access to or deleting your information, such as a government-issued identification.
Oncoheroes will not discriminate against you for exercising your rights, but we may not be able to provide you with Services that you have requested if we are not able to use your information.
If you have provided permission to Oncoheroes to process your Personal Data, you have the right to withdraw your consent for such processing at any time by contacting us using our contact details below.
In most cases, it will be free to exercise these rights and Oncoheroes will respond to your request within a period of one month.
Retention Period
We will retain your personal data for as long as needed or permitted considering the purpose(s) for which it was obtained and as outlined in this Privacy Notice. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you and provide the Site to you; (ii) whether there is a legal obligation to which we are subject; or (iii) whether retention is advisable considering our legal position.
Third Parties
Our Site may contain links to third party websites, content, and services that are not owned, controlled, or controlled by Oncoheroes. We are not responsible for the privacy practices of third-party sites linked through our Services.
Security
We will use reasonable technical, administrative, and procedural security measures in an attempt to prevent the loss, misuse or unauthorized alteration of your information under our control. However, given the inherent risks, we cannot guarantee absolute security and consequently, we cannot ensure or warrant the security of any information you transmit to us.
Children’s Privacy
The Services are not directed to or intended for use by minors. Consistent with the requirements of the US Children’s Online Privacy Protection Act (COPPA), if we learn that we have received information directly from a child under age 13 without his or her parent or legal guardian’s verified consent, we will use that information only to respond directly to that child (or his or her parent or legal guardian) to inform the child that he or she cannot use the Services. Subsequently, we will make commercially reasonable efforts to delete such information.
California Residents
California Civil Code Section 1798.83 permits individual California residents to request certain information regarding our disclosure of certain categories of Personal Information to third parties for those third parties’ direct marketing purposes. To make such a request, please contact us at contact@oncoheroes.com. This request may be made no more than once per calendar year. We reserve our right not to respond to requests submitted other than to the email or mailing addresses specified in this Section.
Updates to Oncoheroes Privacy Notice
We may update this Privacy Notice to reflect changes to our information practices. We encourage you to periodically review this page for the latest information on our privacy practices. We welcome your questions and comments about this Notice or how we process your Personal Information. Please contact us using the information below, and we will respond to you as soon as reasonably possible.
Contact us
If you have any queries or concerns about the processing of your information that is available with us, or have questions about this Privacy Notice, please contact us via a contact point below.
Oncoheroes Biosciences Inc. 62 Cypress Street #5, Brookline, Massachusetts 02445, USA
Email: contact@Oncoheroes.com
Data Protection Officer: Kaleidoscope Consultants LTD at dpo.Oncoheroes@kdpc.uk
If you are unhappy with how we process your personal data, and after you have first made a complaint to us, you can complain to your local data protection regulator. Here is a list of countries and contact details of the relevant supervisory authorities: European Data Protection Board for Europe and Information Commissioner’s Office (ICO) for United Kingdom.