Zynerba Privacy Policy

This Privacy Policy (“Privacy Policy”) explains how Zynerba Pharmaceuticals, Inc. and our directly or indirectly controlled affiliates or subsidiaries (“Zynerba,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information about you when you access or use our website located at https://zynerba.com/, and any other website or application owned and operated by Zynerba and its affiliates or subsidiaries that links to this Privacy Policy (collectively, the “Site”).  This Privacy Policy describes how Zynerba handles and protects that information, and the rights and choices available to you with respect to such information.

By using the Site and/or providing us with Personal Data as described in this Privacy Policy, you agree to the practices described in this Privacy Policy and the Cookie Notice referenced below and to the updates to these policies posted here from time to time.

This Privacy Policy serves as notice of how we process your Personal Data.  If we require your consent, we will request it formally, in adherence with applicable data protection laws.  As an international company, Zynerba has legal entities in different countries that may be responsible for the Personal Data they process, and we process Personal Data in accordance with these laws.

To the extent permitted by applicable law, by interacting with us and providing Personal Data to us, you agree to the collection and use of your Personal Data in accordance with this Privacy Policy.

TABLE of CONTENTS

  1. PERSONAL DATA WE COLLECT ABOUT YOU
    1. Personal Data You Provide to Us
    2. Personal Data We May Automatically Collect About You
      1. Use of Cookies and Other Technologies
      2. Do Not Track
    3. Personal Data We May Receive from Third Parties
  2. HOW WE USE YOUR PERSONAL DATA
    1. Use and Purpose of Processing Your Personal Data
    2. Sharing of Personal Data
    3. Managing Your Privacy Choices
  3. SECURITY
  4. CHILDREN UNDER 13
  5. LINKS TO OTHER WEBSITES AND SERVICES
  6. YOUR RIGHTS REGARDING YOUR PERSONAL DATA
  7. TRANSFER
  8. RETENTION OF PERSONAL DATA
  9. HOW TO CONTACT US
  10. CHANGES TO THIS PRIVACY POLICY

 

I.               PERSONAL DATA WE COLLECT ABOUT YOU

We may collect the following types of Personal Data about you and you can find more detail below: (A) information you provide to us, (B) information we may automatically collect, and (C) information we may receive from third parties.

“Personal Data” is a type of information—as electronically or otherwise recorded—that can be used to identify a person or that we can link to or associate with a specific individual, such as a name, address, email address, or telephone number.  Personal Data in some countries can include information that indirectly identifies a person, even absent other identifying information.

Personal Data may include information considered sensitive in some countries, such as biometric information, genetic information, health information, financial account information, specific geolocation, ethnic or racial origin, information concerning your sex life or your sexual orientation, social security number, driver’s license number, state identification card number, passport number, and other similar information.

We will process any Personal Data we collect in accordance with law and as described in this Privacy Policy (unless, as explained above, a separate policy or notice governs).  In some circumstances, if you do not provide us with certain Personal Data, there may be some services that are unavailable to you.

A.            Personal Data You Provide to Us

You may provide us with Personal Data, including:

  • Contact information such as name, email address, employer or company information, postal address, and telephone number(s);
  • Contact information for related persons, such as designated representatives;
  • Demographic information such as age, gender, disability, or date of birth;
  • Health information including information related to your health or past treatments;
  • Bank or financial number and details;
  • Preferences for communications;
  • Access to your geo-location or to other data held on social media platforms (e.g., Twitter or LinkedIn) and other software (for example, access to your contacts, calendar, or photos);
  • When you visit the “Careers” portion of our website as a job applicant, we collect the information that you provide to us in connection with your job application. This includes personal contact information, professional credentials and skills, educational and work history, and other information that may be included in a resume; and
  • Additional information as otherwise described to you at the point of collection or pursuant to your consent.

B.             Personal Data We May Automatically Collect About You

Our Site may automatically collect certain Personal Data about you.  We use this Personal Data to help us design our Site to better suit our users’ needs.  This Personal Data may include:

  • IP address, which is the number associated with the service through which you access the Internet, like your ISP (Internet service provider);
  • Date, time and length of your visit or use of our Site;
  • Domain server from which you are using our Site;
  • Type of computer, web browsers, search engine used, operating system, or platform you use;
  • Data identifying the web pages you visited prior to and after visiting our website or use of our Site;
  • Data collected from cookies or similar technologies;
  • Your movement and activity within the Site, including which sections of the Site have been accessed, which is aggregated with other information; and
  • Mobile device information, including the type of device you use, operating system version, advertising ID, or the device identifier (or “UDID”).

We may also collect Personal Data about you from our security systems (including CCTV).

1.              Use of Cookies and Other Technologies

We collect the above Personal Data directly and through the use of third parties.  We collect this Personal Data by using certain technologies like “cookies,” which are small data files that the Site places on your hard drive for identification purposes.  Your web browser may be programmed not to accept “cookies,” or it may allow you to be notified when you are receiving a “cookie,” thus giving you the option of accepting it or rejecting it.  You are free to decline our cookies if your browser permits but doing so may interfere with your use of the Site.  Note that unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our website.

We may also use technologies similar to cookies to track your interaction with the Site.  Some of these technologies may include web beacons, pixels, tags, web server logs, and Flash objects.  As with cookies, you are free to decline such technologies if your browser permits.  You should refer to your browser’s instructions to remove cached history and images from your device.  Deleting or disabling cookies will not remove Flash objects.  You should refer to Adobe’s website (http://www.adobe.com) for more information on how to disable these objects.

The Site may use Google Analytics (“Analytics Services”) to analyze and provide us with information about traffic to and use of our Site.  You can find out more information about Google Analytics cookies here:   https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage.  Google may share this information with other services and websites who use the collected data to contextualize and personalize the ads of its own advertising network.  To opt-out of Google Analytics relating to your use of the Site, you can download and install the Browser Plugin available via this link: https://tools.google.com/dlpage/gaoptout?hl=en.

2.              Do Not Track

Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit.  We currently do not adjust the practices of our Site in response to a “Do Not Track” or similar signal.  To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.

C.             Personal Data We May Receive from Third Parties

We may collect additional Personal Data about you from third-party websites, social media platforms, such as but not limited to, Twitter and LinkedIn (“Social Media Platforms”), and/or sources providing publicly-available information (e.g., from the U.S. postal service) to help us provide services to you, help prevent fraud, evaluate the candidacy of job applicants and for internal marketing and research purposes.

Personal Data we may access about you, with your consent, may include, but is not limited to, your basic Social Media Platform information, your location data, your list of contacts or followers, and certain information about your activities on the Social Media Platform.  Please keep in mind that when you provide Personal Data to us on a third-party website, the Personal Data you provide may be separately collected by the third-party website or the Social Media Platform.

We may also receive Personal Data about you from those authorized to provide Personal Data on your behalf, such as an authorized representative, from clinical investigators, members of clinical investigation teams, your employer or company with which you are associated, entities that assist us with hiring, and business partners or other third parties that assist us in providing and improving our Site or offerings, or otherwise with conducting our business.

The Personal Data we collect is covered by this Privacy Policy, and the Personal Data the third-party website or Social Media Platform collects is subject to that third-party website or platform’s privacy practices.  We encourage you to be aware when you leave our sites or applications and to read the privacy policies of other sites as we cannot control and are not responsible for privacy policies, notices, or practices of third party websites, applications, products, and services.

II.             HOW WE USE YOUR PERSONAL DATA

A.            Use and Purpose of Processing Your Personal Data

Zynerba may use the Personal Data that it gathers for purposes that may include, but are not limited to the following:

  • to contact you to provide information about Zynerba offerings, enroll you in our programs, or provide email alerts (e.g., SEC alerts), including through third-party service providers who assist in disseminating this information;
  • to otherwise communicate with you;
  • to administer our relationship with you;
  • to send you updates;
  • to identify and authenticate you;
  • for short-term, transient use;
  • for administrative purposes;
  • for quality assurance;
  • for marketing, internal research, and development;
  • in connection with adverse event and complaint tracking and reporting;
  • to provide support for, promote, and improve the Site and Zynerba offerings;
  • to ensure the appropriate use of the Site and Zynerba offerings;
  • to customize the Site to provide content most relevant to you;
  • to compare information for accuracy and verify our records;
  • to manage, improve, and foster relationships with third-party service providers, including vendors, suppliers, and parents, affiliates, subsidiaries, and business partners;
  • to comply with applicable laws and regulations and respond to lawful requests;
  • to respond to your inquires;
  • to facilitate our employment recruitment activities and process employment applications;
  • to detect, investigate, and prevent activities that may violate our policies or rules or that may be otherwise illegal; and/or
  • for any other purposes disclosed to you at the time we collect your Personal Data and/or pursuant to your consent.

Some countries require us to state the legal bases for processing your Personal Data, which are the legally recognized reasons for processing your Personal Data, but please note that not all countries recognize all legal bases.  The types of Personal Data we collect and disclose depends on your relationship with Zynerba.  Depending on what Personal Data we collect from you and how we collect it, we rely on various grounds for processing your Personal Data, including the following reasons:

  • for the purposes of our legitimate interests;
  • for medical diagnosis or to provide healthcare or treatment;
  • to comply with legal and regulatory obligations and to establish, exercise, or defend our legal claims and rights;
  • to process employee data, prevent against fraud, provide technology security, and other necessary Zynerba operational matters;
  • in preparation for or to perform a contract with you;
  • to protect vital interests or in the public interest;
  • for reasons of public health, including ensuring high standards of quality and safety of healthcare, medicinal products, and medical devices;
  • for scientific or historical research purposes; or
  • in circumstances where we have requested and received consent and for other purposes that may be required or allowed by law.

B.             Sharing of Personal Data

We do not “sell” your Personal Data as most people would typically understand the term.  However, we may share your Personal Data as set forth in this Privacy Policy and in the following circumstances:

  • Business Partners. Zynerba may share and disclose your Personal Data with Zynerba’s business partners or employees of business partners, including clinical trial investigators and study site staff, or business partners that assist us with improving our Site or offerings, marketing, or clinical research.
  • Third-Party Service Providers. We may share your Personal Data with service providers who are authorized to use your Personal Data as necessary to support our business operations, such as those who provide data storage, technology support and services, risk solution provision, analytics, fraud prevention, employment recruitment services, legal services, analytics and advertising services including cross-contextual behavioral advertising, and marketing/market research services.
  • Service providers or vendors (or processors) acting on our behalf must execute agreements requiring them to maintain confidentiality and to process Personal Data only to provide the services to us and in a way that aligns with this Privacy Policy, other applicable privacy notices, and as explicitly permitted or required by applicable laws, rules, and regulations.
  • Disclosure for Legal and Administrative Reasons. We may also share some of your Personal Data without notice as otherwise permitted or required by law or as authorized by you.  Although Zynerba makes every effort to preserve your privacy, Zynerba may need to disclose or provide access to Personal Data if Zynerba has a good faith belief that such action is necessary (i) to comply with the law, such as in connection with a judicial proceeding, court order or other legal process; (ii) to cooperate or undertake an internal or external investigation or audit; (iii) to protect and defend the rights, property, or safety of us, our subsidiaries, affiliates, and any of our or their officers, directors, employees, attorneys, agents, contractors, and partners, and Site users; (iv) to enforce or apply our Terms & Conditions; and (v) to verify the identity of a user of our Site.
  • Personal Data Shared with our Subsidiaries and Affiliates. We may share your Personal Data with our subsidiaries and affiliates.  If you do not want us to share your Personal Data with subsidiaries and affiliates, please email us at privacy@zynerba.com.
  • Business Transfers. In the event Zynerba goes through a business transition, such as a merger or an acquisition of its equity interests or assets, or a business reorganization, your Personal Data contained or stored by Zynerba may be part of the assets transferred.
  • Aggregate and De-Identified Information. We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”).  We may use Aggregate/De-Identified Information for any purpose, including without limitation for our internal marketing and research purposes, and may also share such data with any third parties, including advertisers, promotional partners, and sponsors, in our discretion.
  • Individuals or Entities you Designate.  We will share your Personal Data based on your instructions with individuals or entities you authorize.

These activities may be considered a “sale” or “sharing” under some laws.  To opt-out of any sale or sharing of Personal Data, please email us at privacy@zynerba.com.

C.             Managing Your Privacy Choices

  • Email: By using our Site, you agree that we may contact you by email as set forth herein.  If you do not want to receive emails from us such as email alerts, you may click on the “unsubscribe” link in the email to unsubscribe and opt-out of such email communications or see the section How to Contact Us.
  • Location Choices: You can change the privacy settings of your device at any time to turn off the sharing of location information with our Site.  If you choose to turn off location services, this could affect certain features or services of our Site.  If you have specific questions about the privacy settings of your device, we suggest you contact the manufacturer of your device or your mobile service provider for help.

III.           SECURITY

We use commercially reasonable efforts to maintain and provide access to the Site.  However, you should assume that no data transmitted over the Internet or stored or maintained by us or our third-party service providers can be 100% secure.  Therefore, although we believe the measures implemented by us reduce the likelihood of security problems to a level appropriate to the type of data involved, we do not promise or guarantee, and you should not expect, that your Personal Data or private communications will always remain private or secure.  We do not guarantee that your Personal Data will not be misused by third parties.  We are not responsible for the circumvention of any privacy settings or security features.  You agree that we will not have any liability for misuse, access, acquisition, deletion, or disclosure of your Personal Data.

If you believe that your Personal Data has been accessed or acquired by an unauthorized person, you should promptly contact us via the section How to Contact Us so that necessary measures can quickly be taken.

IV.          CHILDREN UNDER 13

The Site is intended only for users over the age of eighteen (18) and is not intended for use by children, especially those under the age of 13.  We do not knowingly collect Personal Data from children under the age of 13 (“Child”) through the Site.  If you are a parent or guardian and you learn that your Child has provided us with Personal Data, please contact us.  If we discover that a Child has provided us with Personal Data, we will take reasonable steps to delete such information from our servers.

V.            LINKS TO OTHER WEBSITES AND SERVICES

We may provide links to other websites and online services operated by third parties, such as LinkedIn, Twitter, other third-party sites with resources for patients and caregivers, such as patient advocacy organizations, and other third-party sites that may provide access to press releases, securities filings, publications and other articles relating to our product candidates.  If you “click” on a link, the “click” may take you off our Site.  These links are not an endorsement of, or representation that we are affiliated with, any third party.  In addition, our content may be included on web pages or in mobile applications or online services that are not associated with us.  We do not control third-party websites, mobile applications or online services, and we are not responsible for the privacy practices of these third parties.  Other websites and services follow different rules regarding the collection, use and sharing of your Personal Data.  We encourage you to read the privacy policies and terms of use of the other websites, mobile applications, and online services you use.

VI.          YOUR RIGHTS REGARDING YOUR PERSONAL DATA          

Depending on where you live, you may have the following rights with respect to some or all of your, Personal Data :

  • to request that we restrict the way that we process and share your Personal Data;
  • to request to revoke your consent for processing of your Personal Data;
  • to request information about whether, and how, we process your Personal Data;
  • to request that we provide you with access to and a copy of your Personal Data, including to provide your Personal Data directly to another organization;
  • to request that we remove or delete your Personal Data if no longer necessary for the purposes collected;
  • to request that we update your Personal Data so it is correct and not out of date;
  • to object to our processing of your Personal Data; and/or
  • to lodge a complaint with the data protection authority in your jurisdiction.

If you wish to object to the use and processing of your Personal Data or withdraw consent to this Privacy Policy, you can contact us in the following ways:

Contact our Compliance Officer at:
Via Email at: privacy@zynerba.com
Mail at:
Privacy
Zynerba Pharmaceuticals, Inc.
80 W. Lancaster Avenue, Suite 300
Devon, PA 19333Call us at:  484-581-7494

The requests above will be considered and responded to in the time-period stated by applicable law.  Note, certain Personal Data may be exempt from such requests.  We may require additional information from you to confirm your identity in responding to such requests.  You have the right to lodge a complaint with the supervisory authorities applicable to you and your situation, although we invite you to contact us through any of the means identified above with any concern as we would be happy to try and resolve it directly.

Representation for data subjects in the EU and the UK

We have appointed Prighter as our privacy representative and your point of contact.

If you want to contact us via our representative Prighter or exercise your data subject rights, please visit: https://prighter.com/q/16092587107/

If you are not from the EU or the UK and otherwise would like to ask a question or request to exercise privacy rights that you may have, you may email us at privacy@zynerba.com.

VII.        TRANSFER

Our Services are operated in the United States.  Please be aware that Personal Data, including Personal Data, that we collect will be transferred to, stored, and processed in the United States, a jurisdiction in which the privacy laws may not be as comprehensive as those in the country where you reside and/or are a citizen.  We collect and transfer to the U.S. only Personal Data: with your consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Zynerba in a manner that does not outweigh your rights and freedoms.  We apply suitable safeguards to protect the privacy and security of your Personal Data and to use it only consistent with your relationship with us and the practices described in this Privacy Policy.  We also enter into data processing agreements and model clauses with vendors when required by applicable data protection laws.

VIII.      RETENTION OF PERSONAL DATA

We generally retain Personal Data for as long as needed for the specific purpose or purposes for which it was collected or obtained, and as outlined in this Privacy Policy.  In some cases, we may be required to retain Personal Data for a longer period of time by law or for other necessary or required purposes.  Whenever possible, we aim to de-identify or anonymize your Personal Data or otherwise remove some or all information that may identify you from records that we may need to keep for periods beyond the specified retention period.  The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you; (ii) whether there is a legal obligation to which we are subject that affects the length of time we need to keep your Personal Data; and (iii) whether retention is determined to be necessary for Zynerba due to limitation periods, litigation, or other legal or regulatory obligations.  Zynerba takes reasonable steps to dispose of Personal Data upon the expiration of retention periods, taking into consideration these litigation, legal, or regulatory obligations.

IX.          HOW TO CONTACT US

If you have questions or comments about this Privacy Policy, please contact us as follows:

Email: privacy@zynerba.com
Mail:
Privacy
Zynerba Pharmaceuticals, Inc.
80 W. Lancaster Avenue, Suite 300
Devon, PA 19333
Call us at: 484-581-7494

To the extent you are a trial participant, any communications relating to participation in clinical trials should be made through the communication channels described in the applicable informed consent, patient information sheet, or other instructions provided to you when the trial commenced.

X.            CHANGES TO THIS PRIVACY POLICY

Zynerba reserves the right, at our discretion, to change, modify, add, or remove portions of this Privacy Policy at any time by posting the amended Privacy Policy on the Site.  You should review this Policy periodically.  Your continued use of the Site after we post any modifications to the Privacy Policy will constitute your acknowledgment of the modifications and your consent to our privacy practices as described in the modifications.  If we decide to use particular Personal Data collected about you in a manner materially different from that stated at the time it was collected, we will let you know through the Site, by email, or other communication.

Last updated: April 2023

 

You are now leaving the Zynerba website

You are being redirected to a third-party website. The terms and conditions of this third-party website may be different from zynerba.com and will govern your use of such website.

Continue (5) Cancel