Last revised and effective as of: March 31, 2019

Welcome to our website! Please take a few minutes to carefully review these terms and conditions. By accessing and using this website you agree to follow and be bound by these terms and conditions. If you do not agree to follow and be bound by these terms and conditions, you may not access, use or download materials from this website.

This Privacy Policy relates to information collected online by HiFiBiO Inc. and its Corporate Affiliates (“HiFiBiO,” “we” or “us” or “our”) through your use of the HiFiBiO website at hifibio.com and any subdomains or associated sites linked thereto by HiFiBiO, its subsidiaries and affiliates (excluding third-party websites) and any features, and information available thereon (along with associated and successor websites, applications, features and information, or any part thereof, the “Site”). As used herein, “you” and “your” mean a user of the Site. You should carefully read this Privacy Policy. By using the Site, you are signifying your acceptance of this Privacy Policy. If you do not agree to this Privacy Policy, you may not use the Site.

This Privacy Policy does not apply to personal information that HiFiBiO collects and uses for employment-related purposes, whether through this Site or through a website operated on our behalf by a third-party service provider.

To the extent that the Site is available to individuals located in the European Economic Area and the United Kingdom, this Privacy Policy sets out our practices and obligations under the General Data Protection Regulation 2016/679 (the “GDPR”). If your affiliated organization engages us for the provision of services, we may receive personal information about you directly from your affiliated organization, which will only be used as necessary to provide the services to your affiliated organization. Under the GDPR, in this context and to the extent applicable, we will act as a processor (as defined in the GDPR) on behalf of your affiliated organization in respect of that personal information and your affiliated organization will act as a controller (as defined in the GDPR) in respect of that personal information and is responsible for obtaining all necessary consents and providing you with all requisite information as required by applicable law.

As used in this Privacy Policy, the terms “using” and “processing” information include using cookies on a computer, subjecting the information to statistical or other analysis and using or handling information in any way, including, but not limited to collecting, storing, evaluating, modifying, deleting, using, combining, disclosing and transferring information within our organization or among our affiliates within the United States or internationally.

Please click on the headings below for more information.

What information about me is collected?
Where and when is information collected (including through the use of cookies and action tags)?
Does HiFiBiO collect information from children?
What does HiFiBiO do with the information it collects?
When does HiFiBiO disclose information to third parties?
Does this Privacy Policy apply when I link to other websites or services?
Is the information collected through the Site secure?
Could my information be transferred to other countries?
For how long will my personally identifiable information be kept?
What choices do I have regarding my personally identifiable information?
What does HiFiBiO do in response to “Do Not Track” requests?
How will I know if there are any changes to this Privacy Policy?
Who do I contact if I have any privacy questions?

WHAT INFORMATION ABOUT ME IS COLLECTED?

Depending on your use of the Site, we may collect two types of information: personally identifiable information and non-personally identifiable information.

Personally Identifiable Information

Personally identifiable information is information that identifies you or can be used to identify or contact you. Such information may include your name, address, e-mail address and telephone number. Personally identifiable information amounts to ‘personal data’ for the purposes of and as defined in the GDPR. All references to personally identifiable information shall be deemed to include ‘personal data’ as defined and used in the GDPR.

For purposes of this Privacy Policy, “Personal Information” means any information from or about a person that either identifies that person directly or that makes that person identifiable when it is combined with other information from or about that person from any source. Personal Information stops being personal information when it has been aggregated, de-identified, or otherwise anonymized sufficiently that the individual is no longer identified or identifiable using reasonable efforts, resources, and technology.

If you choose to communicate with us through an online form, by sending us an email, by requesting additional information, or by otherwise contacting us, we will collect whatever information, including personal information, that you choose to provide us with. We will combine that information with other information that we collect from and about you as described in this Privacy Policy.

WHERE AND WHEN IS INFORMATION COLLECTED (INCLUDING THROUGH THE USE OF COOKIES AND ACTION TAGS)?

We will collect personally identifiable information that you submit to us. We may also receive personally identifiable information and non-personally identifiable information about you from third parties providing analytics as part of your use of the Site.

Cookies and Action Tags

We may collect non-personally identifiable information passively using “cookies” and “action tags.”

“Cookies” are small text files that can be placed on your computer or mobile device in order to identify your Web browser and the activities of your computer on the Site and other websites. Cookies can be used to personalize your experience on the Site (such as dynamically generating content on webpages specifically designed for you), to assist you in using the Site (such as saving time by not having to reenter your name each time you use the Site), to allow us to statistically monitor how you are using the Site to help us improve our offerings, and to determine the popularity of certain content.

You do not have to accept cookies to use the Site. Although most browsers are initially set to accept cookies, you may reset your browser to notify you when you receive a cookie or to reject cookies generally. Most browsers offer instructions on how to do so in the “Help” section of the toolbar. However, if you reject cookies, certain features or resources of the Site may not work properly or at all and you may experience some loss of convenience.

For the avoidance of doubt, the Site uses third-party service platforms (including to help analyze how users use the Site). In addition to cookies that we may place on your computer or mobile device, cookies might also be placed on your computer or mobile device by third parties that we use to provide analytics and other services. In the course of providing such services, such third parties could place or recognize unique cookies on your browser, computer or mobile device. If you would like to disable “third party” cookies, you may be able to turn them off by going to the third party’s website.

Here is a link to the main third-party platform we use:
https://www.google.com/policies/privacy/

“Action tags,” also known as web beacons or gif tags, are a web technology used to help track website usage information, such as how many times a specific page has been viewed. Action tags are invisible to you, and any portion of the Site, including e-mail sent on our behalf, may contain action tags.

By using cookies and action tags together, we are able to gain valuable information to improve the Site.

Finally, you should be aware that third parties may use their own cookies or action tags when you click on a link to their websites or services on or from the Site. This Privacy Policy does not govern the use of cookies or action tags or the use of your information by such third-party websites or services.

Log Files

We also collect non-personally identifiable information through our Internet log files, which record data such as user IP addresses, internet service provider, device types, date and time of usage, the way in which your device navigates the Site, requested URL, referring URL, the content you view on the Site and any searches or queries that you conduct during your visit to the Site, browser types, domain names, and other anonymous statistical data involving the use of the Site. This information may be used to analyze trends, to administer the Site, to monitor the use of the Site, and to gather general demographic information. We may link this information to personally identifiable information for these and other purposes such as personalizing your experience on the Site and evaluating the Site in general.

DOES HIFIBIO COLLECT INFORMATION FROM CHILDREN?

We are committed to protecting the privacy of children. The Site is not designed for or directed to children under the age of majority in the countries where the Site is accessed. We do not collect personally identifiable information from any person we actually know is under the age of majority in that country where the Site is accessed.

WHAT DOES HIFIBIO DO WITH THE INFORMATION IT COLLECTS?

We will only use your personally identifiable information to the extent that the law allows us to do so. Pursuant to the GDPR, legal bases for our processing your personally identifiable information may include (without limitation):

(a) where you have given consent to the processing;

(b) where it is necessary to perform the contract we have entered into or are about to enter into with you (whether in relation to the provision of the Site or otherwise); and/or

(c) where it is necessary for the purposes of our legitimate interests (or those of a third party) and your interests or fundamental rights and freedoms do not override those legitimate interests.

We use the information collected to provide the Site to you and process your transactions, to help us understand who uses the Site, for administrative and technical operations such as operating and improving the Site, and, if you “opt in”, so that we can contact you about products and services that may be of interest to you.

If you opt in, we and third parties may send you electronic newsletters, contact you about the Site, products, services, information and news that may be of interest to you. If you no longer desire to receive these communications, we will provide you with the option to change your preferences. If you identify yourself to us by sending us an e-mail with questions or comments, we may use your information (including personally identifiable information) to respond to your questions or comments, and we may file your questions or comments (with your information) for future reference.

We may also use the information gathered to perform statistical analysis of user behavior or to evaluate and improve the Site. We may link some of this information to personally identifiable information for internal purposes or to improve your experience with the Site.

WHEN DOES HIFIBIO DISCLOSE INFORMATION TO THIRD PARTIES?

We generally disclose information we gather from you through the Site to the following types of third parties and as otherwise set forth in this Privacy Policy or as specifically authorized by you.

Laws and Legal Rights

We may disclose your information (including personally identifiable information) if we believe in good faith that we are required to do so in order to comply with an applicable statute, regulation, rule or law, a subpoena, a search warrant, a court or regulatory order, lawful requests by public authorities, including to meet national security or law enforcement requirements, or other valid legal process. We may disclose personally identifiable information in special circumstances when we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone to detect fraud, to meet contractual obligations with content and technology providers, to protect our rights to our property, for assistance with a delinquent account, or to protect the safety and/or security of our users, the Site or the general public. Without limitation of the foregoing, although unlikely, HiFiBiO or a trusted third party may need to access personally identifiable information in connection with a digital forensic investigation of a potential security incident.

Third Parties Generally

We may provide to third parties non-personally identifiable information, including where such information is combined with similar information of other users of the Site. For example, we might inform third parties regarding the number of unique users who use the Site, the demographic breakdown of our users of the Site, or the products and/or services purchased using the Site and the vendors of such products and services. In addition to the above, when users use our Site, third parties (including analytics providers) may directly collect information about our users’ online activities over time and across different websites. The third parties to which we may provide or who may independently directly collect information may include providers of products or services (including analytics service providers, vendors (including providers of hosting services and cloud storage) and website tracking services), merchants, affiliates and other actual or potential commercial partners, sponsors, licensees, researchers and other similar parties.

Please note in particular that the Site uses Google Analytics integrated via Google Tag Manager, including its data reporting features. Information collected by Google Analytics includes but is not limited to web metrics. For information on how Google Analytics collects and processes data, please see the site “How Google uses data when you use our partners’ sites or apps,” currently located at www.google.com/policies/privacy/partners/. For information on opting out of Google Analytics, we encourage you to visit Google’s website, including its list of currently available opt-out options presently located at https://tools.google.com/dlpage/gaoptout.

Outside Contractors

We may employ independent contractors, vendors and suppliers (collectively, “Outside Contractors”) to provide specific services and products related to the Site, such as hosting and maintaining the Site, providing technical or other customer support services, billing, receivable or payable services, content acquisition or licensing services, and fraud screening, and developing applications for the Site. In the course of providing products or services to us, these Outside Contractors may have access to information collected through the Site, including your personally identifiable information. We use reasonable efforts to ensure that these Outside Contractors are capable of (1) protecting the privacy of your personally identifiable information consistent with this Privacy Policy, and (2) not using or disclosing your personally identifiable information for any purpose other than providing us with the products or services for which we contracted or as required by law.

Sale of Business

We reserve the right to transfer information to a third party in the event of a sale, merger or other transfer of all or substantially all of the assets of HiFiBiO or any of its Corporate Affiliates (as defined below), or that portion of HiFiBiO or any of its Corporate Affiliates to which the Site relates, or in the event that we discontinue our business or file a petition or have filed against us a petition in bankruptcy, reorganization or similar proceeding, provided that the third party agrees to adhere to the terms of this Privacy Policy.

Affiliates

We may disclose information (including personally identifiable information) about you to our Corporate Affiliates. For purposes of this Privacy Policy: “Corporate Affiliate” means any person or entity which directly or indirectly controls, is controlled by or is under common control with HiFiBiO, whether by ownership or otherwise; and “control” means possessing, directly or indirectly, the power to direct or cause the direction of the management, policies or operations of an entity, whether through ownership of fifty percent (50%) or more of the voting securities, by contract or otherwise. Any information relating to you that we provide to our Corporate Affiliates will be treated by those Corporate Affiliates in accordance with the terms of this Privacy Policy.

DOES THIS PRIVACY POLICY APPLY WHEN I LINK TO OTHER WEBSITES OR SERVICES?

Our Site may provide you with access to other websites and services. This may include providing you with the ability to automatically post updates on Facebook and Twitter. Please be aware that we are not responsible for the privacy practices of any websites or services other than the Site. We encourage you to read the privacy policies or statements of each and every such website and service. This Privacy Policy applies solely to information collected by us through the Site.

IS THE INFORMATION COLLECTED THROUGH THE SITE SECURE?

We want your information (including personally identifiable information) to remain secure. We strive to provide transmission of your information from your computer or mobile device to our servers through techniques that are consistent with commercially reasonable standards and to employ administrative, physical, and electronic measures designed to protect your information from unauthorized access.

Notwithstanding the above, you should be aware that there is always some risk involved in transmitting information over the Internet. There is also some risk that others could find a way to thwart our security systems. As a result, while we strive to protect your information, we cannot ensure or warrant the security or privacy of any information you transmit to us, and you do so at your own risk.

COULD MY INFORMATION BE TRANSFERRED TO OTHER COUNTRIES?

Personally identifiable information collected on the Site may be transferred from time to time to our offices or personnel, or to third parties, located throughout the world, and the Site may be viewed and hosted anywhere in the world, including countries that may not have laws of general applicability regulating the use and transfer of such data. By using the Site and submitting such information on it, you voluntarily consent to the trans-border transfer and hosting of such information. Without limitation of the foregoing, you hereby expressly grant consent to HiFiBiO to: (a) process and disclose such information in accordance with this Privacy Policy; (b) transfer such information throughout the world, including to the United States or other countries that do not ensure adequate protection for personally identifiable information (as determined by the European Commission); and (c) disclose such information to comply with lawful requests by public authorities, including to meet national security or law enforcement requirements. If you are a user accessing the Site from a jurisdiction with laws or regulations governing personal data collection, use, and disclosure that differ from those of the United States, please be advised that all aspects of the Site are governed by the internal laws of the United States and the Commonwealth of Massachusetts, USA, regardless of your location.

FOR HOW LONG WILL MY PERSONALLY IDENTIFIABLE INFORMATION BE KEPT?

We will only retain your personally identifiable information for as long as necessary to fulfill the purposes for which we collected it.

To determine the appropriate retention period for personally identifiable information, we consider the amount, nature, and sensitivity of that information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personally identifiable information and whether we can achieve those purposes through other means, and the applicable legal requirements.

WHAT CHOICES DO I HAVE REGARDING MY PERSONALLY IDENTIFIABLE INFORMATION?

We generally use personally identifiable information as described in this Privacy Policy or as authorized by you or as otherwise disclosed at the time we request such information from you. You generally must “opt in” and give us permission to use your personally identifiable information for any other purpose. You may also change your preference and “opt out” of receiving certain marketing communications from us by following the directions provided in association with the communication or such other directions we may provide or by contacting legal@hifibio.com.

Under certain circumstances and in compliance with the GDPR, you have the right to:

Request access to your personally identifiable information (commonly known as ‘subject access request’). This enables you to receive a copy of the personally identifiable information we hold about you and to check that we are lawfully processing it;

Request correction of the personally identifiable information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected;

Request erasure of your personally identifiable information. This enables you to ask us to delete or remove your personally identifiable information where there is no good reason for us to continue processing it. You also have the right to ask us to delete or remove all of your personally identifiable information in certain circumstances;

Object to processing of your personally identifiable information where we are relying on a legitimate interest (or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground;

Request the restriction of processing of your personally identifiable information. This enables you to ask us to suspend the processing of your personally identifiable information, for example, if you want us to establish its accuracy or the reason for processing it;

Request the transfer of your personally identifiable information to another party;

Lodge a complaint with the relevant supervisory authority (as defined in the GDPR). If you have any complaints about the way we process your personally identifiable information, please do contact us. Alternatively, you may lodge a complaint with the supervisory authority which is established in your country.

If you want to update, review, verify, correct or request erasure of your personally identifiable information, object to the processing of your personally identifiable information, or request that we transfer a copy of your personally identifiable information to another party, please contact legal@hifibio.com.

Such updates, corrections, changes and deletions will have no effect on other information that we maintain, or information that we have provided to third parties in accordance with this Privacy Policy prior to such update, correction, change or deletion. To protect your privacy and security, we may take reasonable steps (such as requesting a unique password) to verify your identity before granting you profile access or making corrections. You are responsible for maintaining the secrecy of your unique password and account information at all times.

You should be aware that it may not be technologically possible to remove each and every record of the information you have provided to us from our system. The need to back up our systems to protect information from inadvertent loss means that a copy of your personally identifiable information may exist in a non-erasable form that will be difficult or impossible for us to locate. After receiving your request, we will use commercially reasonable efforts to update, correct, change, or delete, as appropriate, all personally identifiable information stored in databases we actively use and other readily searchable media as appropriate, as soon as and to the extent reasonably practicable.

WHAT DOES HIFIBIO DO IN RESPONSE TO “DO NOT TRACK” REQUESTS?

The term “Do Not Track” refers to a HTTP header offered by certain web browsers to request that websites refrain from tracking the user. We take no action in response to automated Do Not Track requests. However, if you wish to stop such tracking, please contact us with your request, using our contact details provided below.

HOW WILL I KNOW IF THERE ARE ANY CHANGES TO THIS PRIVACY POLICY?

We may revise this Privacy Policy from time to time. We will not make changes that result in significant additional uses or disclosures of your personally identifiable information without allowing you to “opt in” to such changes. We may also make non-significant changes to this Privacy Policy that generally will not significantly affect our use of your personally identifiable information, for which your opt-in is not required. We encourage you to check this page periodically for any changes. If any non-significant changes to this Privacy Policy are unacceptable to you, you must immediately contact us and, until the issue is resolved, stop using the Site. Your continued use of the Site following the posting of non-significant changes to this Privacy Policy constitutes your acceptance of those changes.

WHO DO I CONTACT IF I HAVE ANY PRIVACY QUESTIONS?

If you have any questions or comments about this Privacy Policy or feel that we are not abiding by the terms of this Privacy Policy, please contact our Legal Department in any of the following ways:

By e-mail:
legal@hifibio.com

By postal mail or courier:
Attn: Legal Department
HiFiBiO Inc.
237 Putnam Avenue
Cambridge, MA 02139

BY USING THE SITE, YOU SIGNIFY YOUR ACCEPTANCE OF THIS PRIVACY POLICY. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, YOU SHOULD NOT USE THE SITE. CONTINUED USE OF THE SITE, FOLLOWING THE POSTING OF CHANGES TO THIS PRIVACY POLICY THAT DO NOT SIGNIFICANTLY AFFECT THE USE OR DISCLOSURE OF YOUR PERSONALLY IDENTIFIABLE INFORMATION, MEANS THAT YOU ACCEPT THOSE CHANGES.