Last updated: September 18, 2019

Aspa Therapeutics Global Privacy Policy

Welcome to this website established by Aspa Therapeutics, Inc. (“Aspa”, “we”, “us” and/or “our”). Aspa is a company that specializes in developing and commercializing gene therapies targeting Canavan disease. Our website (“Site”) allows you to easily access and use content, including features, resources and other information intended to help you learn about recent developments in Canavan disease, our activities and products we may offer.

Aspa is committed to protecting your privacy. This Privacy Policy describes how Aspa collects, uses, and shares your information when you use or interact with our Site, and applies to all persons who access this Site (“Users”). Before accessing, using, or interacting with the Site you should carefully review the terms and conditions of this Privacy Policy. If you do not agree to this Privacy Policy, please do not access or use the Site.

This Privacy Policy forms part of our Terms of Use, which are available at the following link: Terms of Use.

INFORMATION WE COLLECT AND HOW WE USE IT:

Information We Collect

 When you engage with the Site, we collect information that, alone or in combination with other information, could be used to identify you (“Personal Data”). Aspa collects information about you and your use of the Site through various means, including when you provide information to us—such as when you provide us with your email address so you can receive updates from us—and when we automatically collect information about you when you access, use, or interact with the Site. We use this information for a variety of different reasons, including to improve the Site.

The types of information Aspa may collect about you include:

Information You Provide Us

We collect Personal Data that visitors to the Site send to us electronically. For example, if you complete any “free text” boxes in our forms (such as on our “Information Request” or “Contact Us” page), requesting information or subscribing to emailing lists, we may keep your message, email address, and contact information to respond to your requests, and to provide notifications or other correspondence to you. If you do not want to receive email from us in the future, you may let us know by sending us an email or by writing to us at the address below.

Information We Collect Automatically

When you use or interact with the Site, the following information is created and automatically logged in our systems:

  • Log Data: Information (“log data”) that your browser automatically sends whenever you visit the Site. Log data can include your IP address (so we understand which country you are connecting from when you visit the Site), browser type and settings, the date and time of your request, the referring web page(s), your mobile carrier, device information (including device and application IDs), search terms, and how you interacted with the Site.
  • Cookies, Web Beacons, Links, and Other Tracking Technologies: Aspa may keep track of how you use and interact with the Site through the use of cookies, web beacons, links, and other tracking technologies. We do this to help analyze the use of and improve the Site. Through these technologies we may automatically collect information about your use of the Site and other online activities, including our email correspondences, third-party services, and client applications, and certain online activities after you leave the Site.

How We Use Site Personal Data:

As necessary for certain legitimate business interests, which include the following:

  • To authenticate Users and provide access to the Site;
  • To respond to your inquiries and fulfill your requests for products, services, and information;
  • To provide, maintain and improve the content and functionality of the Site. For example, we regularly fix bugs or User experience issues that may be tied to particular Users. We use cookies to analyze how Users interact with our Site, and that analysis can help us build a better Site;
  • If you ask us to delete your data and we are required to fulfil your request, to keep basic data to identify you and prevent further unwanted processing;
  • To prevent fraud or criminal activity, misuse of our products or services, and ensure the security of our IT systems, architecture and networks; and
  • To (a) comply with legal obligations and legal process; (b) respond to requests from public and government authorities including public and government authorities outside your country of residence; (c) enforce our Terms of Use; (d) protect our operations or those of any of our affiliates; (e) protect our rights, privacy, safety or property, and/or that of our affiliates, you or others; and (f) allow us to pursue available remedies or limit the damages that we may sustain, as required or permitted by the law.

For individuals in the European Union (“EU”), please see the “European Union (EU) Users” section below for additional information on what we mean by “legitimate interests” and your rights.

SHARING AND DISCLOSURE OF INFORMATION

We may share or disclose your information at your direction, such as when you voluntarily share information or content via the Site.

There are certain circumstances in which we may share your Personal Data with certain third parties without further notice to you, unless required by the law, as set forth below:

  • Vendors and Service Providers: Pursuant to our instructions, certain third-party providers of administrative services (such as email communication and Site support services) will access, process or store Personal Data in the course of performing their duties for us. Such duties may include (a) assisting us in operating the Site and in meeting business operations needs and, (b) assisting us in conducting analytics about the Site (for more details on the third parties that place cookies through the Site, please see the “Cookies” section below). For example, we use Google Analytics to understand how our Site is used, and Media Temple for hosting.
  • Business Transfers: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of all or a portion of our assets, or transition of service to another provider, your Personal Data and other information may be transferred to a successor or affiliate as part of that transaction along with other assets.
  • Legal Requirements: If required to do so by law or in the good faith belief that such action is necessary to (a) comply with a legal obligation, (b) protect and defend our rights or property, (c) act in urgent circumstances to protect the personal safety of Users of the Site or the App, or the public, or (d) protect against legal liability.

DATA RETENTION

We will keep your Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a legitimate business need to do so, or as required by law (e.g. for regulatory reporting, legal, tax, accounting or other purposes), whichever is the longest.

To determine the appropriate retention period for your Personal Data, we will consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we use your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.

UPDATE YOUR INFORMATION

If you need to change or correct your Personal Data or wish to have it deleted from our systems, you may contact us. We will address your request as required by applicable law. You may also request that we update your Personal Data by contacting us at webadmin@AspaTx.com

DO NOT TRACK SIGNALS

The Site currently does not respond to “Do Not Track” (“DNT”) signals and operates as described in this Privacy Policy whether or not a DNT signal is received. If we do respond to DNT signals in the future, we will update this Privacy Policy to describe how we do so.

EUROPEAN UNION (EU) USERS

Scope. This section applies if you are an EU User (for these purposes, reference to the EU also includes the European Economic Area countries of Iceland, Liechtenstein and Norway).

Data Controller. Aspa is the data controller for Personal Data provided to us through your interactions with the Site. To find out our contact details, please see the “Contact Us” section below, which also provides the contact details of our EU Representative pursuant to Article 27 of the General Data Protection Regulation

Your Rights. Subject to applicable EU law, you may have the following rights in relation to your Personal Data that we hold about you that is collected through your use of our Site depending upon the EU member state in which you reside:

  • Right of Access: If you ask us, we will confirm whether we are processing your Personal Data and, if so, provide you with a copy of all Personal Data you are lawfully entitled to receive along with certain other details. If you require additional copies, we may need to charge a reasonable fee.
  • Right to Rectification: If your Personal Data is inaccurate or incomplete, you are entitled to ask that we correct or complete it. If we shared your Personal Data with others, we will tell them about the correction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
  • Right to Erasure: You may ask us to delete or remove your Personal Data, such as where you withdraw your consent, where applicable. If we shared your data with others, we will tell them about the erasure where possible. We have no current plans to share your Personal Data. But, should we ever share your Personal Data, if you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data with so you can contact them directly.
  • Right to Restrict Processing: You may ask us to restrict or ‘block’ the processing of your Personal Data in certain circumstances, such as where you contest the accuracy of the data or object to us processing it (please read below for information on your right to object). We will tell you before we lift any restriction on processing. If we shared your Personal Data with others, we will tell them about the restriction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
  • Right to Data Portability: You have the right to obtain your Personal Data from us that you consented to give us or that was provided to us as necessary in connection with our contract with you, and that is processed by us by automated means. We will give you your Personal Data in a structured, commonly used and machine-readable format.  You may reuse it elsewhere.
  • Right to Object: You may ask us at any time to stop processing your Personal Data, and we will do so:
    • If we are relying on a legitimate interest to process your Personal Data — unless we demonstrate compelling legitimate grounds for the processing; or
    • If we are processing your Personal Data for direct marketing.
  • Right to Withdraw Consent: If we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect any processing of your data before we received notice that you wished to withdraw consent.
  • Rights in Relation to Automated Decision-making: You have the right to be free from decisions based solely on automated processing of your Personal Data, (including profiling) unless this is necessary in relation to a contract between you and us or you provide your explicit consent to this use.
  • Right to Lodge a Complaint with the Data Protection Authority: If you have a concern about our privacy practices, including the way we handled your Personal Data, you can report it to the data protection authority that is authorized to hear those concerns.

Please see the “Contact Us” section below for information on how to contact us to exercise your rights.

Legitimate Interest. “Legitimate interest” means our interest in conducting our business, managing and delivering the best experiences on the Site to you. This Privacy Policy describes when we process your Personal Data for our legitimate interests, what these interests are and your rights. We will not use your Personal Data for activities where the impact on you overrides our interests, unless we have your consent or those activities are otherwise required or permitted to by law.

INFORMATION FROM CHILDREN                                                          

The Site is not directed to children who are under the age of 13. Aspa does not knowingly collect Personal Data from children who are under 13.  If you have reason to believe that a child under the age of 13 has provided Personal Data to Aspa through the Site please contact us and we will endeavor to delete that information from our databases.

LINKS TO OTHER WEBSITES

This Privacy Policy only applies to the Site. The Site may contain links to other websites not operated or controlled by Aspa (“Third Party Sites”), including social media services such as Twitter, YouTube, Vimeo, or LinkedIn (“Social Media Services”). The information that you share with Third Party Sites will be governed by the specific privacy policies and terms of service of the Third-Party Sites and not by this Privacy Policy. We do not own, control or operate such linked sites, and we are not responsible for the privacy policies or practices of such linked sites. By providing these links, we do not imply that we endorse or have reviewed these sites. Privacy policies and practices for such linked sites may differ from this Privacy Policy and our practices. We encourage you to read the privacy policies of such linked sites before disclosing personal information on Third Party Sites.

COOKIES

Our Site uses cookies to operate and administer our Site and make it easier for you to use the Site during future visits and gather usage data on our Site.

What Are Cookies. A “cookie” is a piece of information sent to your browser by a website you visit. By choosing to use our Site after having been notified of our use of cookies in the ways described in this Privacy Policy, and, in applicable jurisdictions, through notice and unambiguous acknowledgement of your consent, you agree to such use.

Some cookies expire after a certain amount of time, or upon logging out (session cookies); others remain on your computer or terminal device for a longer period (persistent cookies). Our Site uses first party cookies (cookies set directly by Aspa) as well as third party cookies, as described below. For more details on cookies please visit All About Cookies.

Type of Cookies Used

CATEGORYDESCRIPTIONWHO SERVES THE TECHNOLOGY PRIVACY POLICY OPT OUT
Strictly necessaryWe use cookies that are strictly necessary to provide Users with access to the Site and to use some of their features, such as the ability to log-in and access to secure areas. These cookies are essential for using and navigating the Site.  Without these cookies, basic functions of our Site would not work. We also use a cookie to record when a User has agreed to the cookie consent banner. Aspa (PHPSESSID) https://treatcanavan.com/privacy-policy/Because these cookies are strictly necessary to deliver the Site, Users cannot refuse them.
Analytics / performanceWe use “analytics” cookies that allow us to recognize and count the number of visitors and to see how visitors move around the site when they are using it. This helps us to improve the way our Site works, for example by making sure Users are finding what they need easily. The collected data provides us only with anonymous traffic statistics (like number of page views, number of visitors, and time spent on each page).  These cookies also may allow us to track how often posts on third party websites, such as social media sites, are clicked on. Google Analytics https://policies.google.com/privacyUsers may download and install an opt-out add-on for their web browsers.
https://tools.google.com/dlpage/gaoptout
FunctionalityWe use cookies to enhance the performance and functionality of the Site and our services (such as collecting performance and error data). These cookies are not essential for using and navigating the Site. However, without these cookies, certain functionality may become unavailable. None used

Your Choices. On most web browsers, you will find a “help” section on the toolbar. Please refer to this section for information on how to receive a notification when you are receiving a new cookie and how to turn cookies off. Please see the links below for guidance on how to modify your web browser’s settings on the most popular browsers:

  • Internet Explorer
  • Mozilla Firefox
  • Google Chrome
  • Apple Safari

Please note that if you limit the ability of websites to set cookies, you may be unable to access certain parts of the Site and you may not be able to benefit from the full functionality of the Site.

If you access the Site on your mobile device, you may not be able to control tracking technologies through the settings.

CHANGES TO THE PRIVACY POLICY

Aspa may modify this Privacy Policy from time to time. The most current version of this Privacy Policy will govern our use of your information and can be accessed from the link at the bottom of each page of this Site.

INTERNATIONAL USERS

Aspa is based in the United States. If you are accessing our Site from or in the European Union or other regions with laws governing data collection and use, please note that your Personal Data will be transmitted to our servers in the United States as necessary to provide you with the information that you requested, administer our contract with you or to respond to your requests as described in this Privacy Policy, and such Personal Data may be transmitted to our service providers supporting our business operations (described above). The United States may have data protection laws less stringent than or otherwise different from the laws in effect in the country in which you are located. Where we transfer your Personal Data out of the EU we will take steps to ensure that your Personal Data receives an adequate level of protection where it is processed and your rights continue to be protected.

CONTACT US

Please feel free to contact us if you have any questions about Aspa’s Privacy Policy or the information practices of the Site.

You may contact us as follows: You may send an email to privacy@aspatx.com or send mail to:

Aspa Therapeutics, Inc.
4210 Kipling Street
Palo Alto, CA  94301
Attention:  Privacy Officer / Head of Development Operations

If you are an individual in the EU, you can also raise a question to Aspa, or otherwise exercise your rights in respect of your personal data, by contacting dataprivacy@aspatx.eu.