Enterprise Therapeutics

Enterprise Therapeutics Limited (company number 09022750) (Enterprise Therapeutics / we / our / us) takes your privacy very seriously and is committed to protecting and respecting your privacy. We are registered with the Information Commissioner’s Office (the ICO) in the United Kingdom with registration number ZA772377.

If you wish to contact us regarding this privacy and cookies policy, please contact us using the contact details set out here . Our registered office is at Sussex Innovation Centre Science Park Square, Falmer, Brighton, England, BN1 9SB.

Enterprise Therapeutics is the data controller for the data it collects about you on our website. We have therefore developed this privacy and cookie policy to inform you of the data we collect, what we do with your information, what we do to keep it secure, as well and the rights and choices you have over your personal data when you interact with us or that is provided by you through your use of our website (www.enterprisetherapeutics.com) (the Website) or by the organisation you represent (if applicable).

This privacy and cookies policy does not apply to websites that you may be able to access via links on the Website and/or activities offered by third parties. Please ensure you review any relevant policies on any third party websites before proceeding. We are not responsible for the collection or use of your personal data from third party websites.

Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

TOPICS COVERED

  • 1     Introduction
  • 2     Definitions
  • 3     Data Protection Legislation
  • 4     The information we collect
  • 5     Cookies, Analytics and Tracking Technologies
  • 6     How we use your information
  • 7     Who we might share your information with
  • 8     How long we keep your information for
  • 9     How we keep you updated on our products and services
  • 10       Giving your reviews and sharing your thoughts
  • 11       Your rights over your information
  • 12       Security
  • 13       International Transfers
  • 14       What happens if our business changes hands?
  • 15       Contact Us
  • 16       Changes to Our Privacy Notice

1 Introduction

Enterprise Therapeutics Limited. (referred to as “Enterprise Therapeutics ”, “We, “Our” or “Us”), are committed to protecting the privacy and security of your Personal Data.

This Enterprise Therapeutics Privacy Notice applies to you if you are:

  • A service user of this website (Enterprise Therapeutics – Enterprise Therapeutics);
  • An Enterprise Therapeutics clinical trial participant;
  • A healthcare professional conducting an Enterprise Therapeutics clinical trial;
  • An employee, contractor or other associated party associated with Enterprise Therapeutics or Enterprise Therapeutics ’s affiliates;
  • An employee, contractor or other associated party contracted by Enterprise Therapeutics’ Service Providers; or,
  • Any other individual with whom Enterprise Therapeutics may conduct commercial operations.

We have developed this Privacy Notice to inform you of the data we collect, what we do with your information, what we do to keep it secure as well as the rights and choices you have over your Personal Data. It is important that you read this notice so that you are aware of how and why we are using such information.

All clinical trial participants, healthcare professionals, contractors and employees will also receive privacy notices directly which are specific to their data processing. You may request replacement copies of these individual privacy notices at any time by making a request to the DPO via the Contact Us section.

2 Definitions

For the purposes of this Enterprise Therapeutics Privacy Notice:

Affiliate means an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.

Company (referred to as either “Enterprise Therapeutics ”, “the Company”, “We”, “Us” or “Our” in this Agreement) refers to Enterprise Therapeutics Limited, Sussex Innovation Centre, University of Sussex, Science Park Square, Flamer, Brighton, BN1 9SB.

Cookies are small files that are placed on Your computer, mobile device, or any other device by a website, containing the details of Your browsing history on that website among its many uses.

Data Controller, for the purposes of both UK and EU GDPR, refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data. For the purpose of both UK and EU GDPR, the Company is the Data Controller.

Data Processor, for the purposes of both UK and EU GDPR, refers to the Company’s Service Providers.

Data Protection Legislation, as defined in the Data Protection Legislation section below.

Device means any device that can access the Service such as a computer, a mobile phone, or a digital tablet.

Personal Data is any information that relates to an identified or identifiable individual.
For the purposes of both UK and EU GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.

Service refers to the Website, unless otherwise stated.

Service Provider means any natural or legal person who processes the Personal Data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analysing how the Service is used. For the purpose of both UK and EU GDPR, Service Providers are considered Data Processors.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Website refers to the Enterprise Therapeutics website, accessible from https://enterprisetherapeutics.com

You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under both UK and EU GDPR (General Data Protection Regulation), You can be referred to as the Data Subject or as the User as you are the individual using the Service.

3 Data Protection Legislation

Throughout this document we refer to Data Protection Legislation.

In the United Kingdom (UK), Data Protection Legislation means the Data Protection Act 2018 (‘DPA 2018’), United Kingdom General Data Protection Regulation (‘UK GDPR’), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (‘PECR’) and any legislation implemented in connection with the aforementioned legislation.

Where data is processed by a controller or processor established in the European Union (EU) or comprises the data of people in the European Union, it also includes the General Data Protection Regulation (Regulation (EU) 2016/679) (‘EU GDPR’) as well as any local data protection implementation laws. This includes any replacement legislation coming into effect from time to time.

3.1        Controller and DPO appointment

Enterprise Therapeutics Limited. is the Data Controller (‘controller’) for the Personal Data we process, unless otherwise stated.

Enterprise Therapeutics consists of the parent company, Enterprise Therapeutics Ltd and an Affiliate company Enterprise Therapeutics, S.R.L (number MI-2714781), registered in Milan, Italy at Via Alberico Albricci 8, 20122 (“Enterprise Therapeutics Italy”).

In certain situations, Enterprise Therapeutics Ltd may act as the Data Processor (‘processor’) where we are processing your information upon the instructions of our Affiliates – in these instances our Affiliates act as the Data Controller.

We have appointed a Data Protection Officer (DPO) within both Enterprise Therapeutics Ltd and Enterprise Therapeutics Italy, to help us monitor internal compliance, inform, and advise on data protection obligations, and act as a point of contact for data subjects and supervisory authorities. For further details on how you can contact our DPO, please see the Contact Us section below.

4 The information we collect

We only collect Personal Data that we know we will genuinely use and in accordance with the Data Protection Legislation and/or legislation related to clinical trials, such as the EU Clinical Trial Regulation (EU CTR). The type of Personal Data that we will collect about you will depend on whether you are a clinical trial participant, a healthcare professional, an employee, or a user of this website. Any additional categories collected in your specific circumstance will be set-out in the privacy notice you receive directly from Enterprise Therapeutics or the trial site administering the study you are involved in :

Clinical Trial participant^

  • Your name*
  • Your date of birth*
  • Your contact information (telephone number or email address)*
  • Where applicable, the name of your legally authorized representative*
  • Your pseudonymised unique identification number(s)
  • Your health data

Healthcare professional (HCP)

  • Your name
  • Your employment details
  • Your contact information

 

Employees of Enterprise Therapeutics  or Enterprise Therapeutics ’s Service Providers

  • Your name
  • Your date of birth
  • Your contact information (telephone number, email address, or mailing address)
  • Your employment details
  • Where relevant, your pseudonymised unique identification number(s) (e.g., payroll no.)
  • Where relevant, your financial information (e.g., bank information)
  • Where relevant, your Right to Work information (e.g., nationality)
  • Where relevant, your health data (e.g., sick leave information)

 

Website User

  • Your name
  • Your contact information (email address)
  • Your Contact Us form responses
  • Your Usage Data (e.g., your IP address)
  • Online identifiers via Cookies and Tracking Technologies

* This participant identifiable information is collected by Enterprise Therapeutics’ Research Sites, acting on Our behalf as Data Processors. This data may be shared with clinicians, health authorities, ethics bodies and other personnel as authorised by Enterprise Therapeutics, but only where Enterprise Therapeutics is legally obligated to provide this data in accordance with Clinical Trial Regulations and other applicable laws. Enterprise Therapeutics will not directly receive participant identifiable information and will not instruct Our Data Processors to process or share this information other than where the law requires.

† You are under no statutory or contractual requirement or obligation to provide us with your Personal Data; however, we require at least the information above in order for us to deal with you as a Service User in an efficient and effective manner.

^Clinical Trial Participants will find their privacy notice information attached to the Informed Consent Forms issued by the investigator sites administering the study you take part in. Enterprise will only ever receive information about you in pseudonymised or ‘coded’ format with your name removed. Should you wish to action any of your rights, it is often best to contact the specific investigator site rather than Enterprise Therapeutics directly as we will require further information to identify you prior to facilitating your request.

5 Cookies, Analytics and Tracking Technologies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyse Our Service.

You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close your web browser. We use both session and persistent Cookies for the purposes set out below:

Necessary / Essential Cookies
Type: Session Cookies
Administered by: Us
Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.

Cookies Policy / Notice Acceptance Cookies
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies identify if users have accepted the use of cookies on the Website.

Functionality Cookies
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies allow Us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter Your preferences every time You use the Website.

Tracking and Performance Cookies
Type: Persistent Cookies
Administered by: Third-Parties
Purpose: These Cookies are used to track information about traffic to the Website and how users use the Website. The information gathered via these Cookies may directly or indirectly identify You as an individual visitor. This is because the information collected is typically linked to a pseudonymous identifier associated with the device You use to access the Website. We may also use these Cookies to test new pages, features, or functionality of the Website to see how Our users react to them.

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of Our Service. This data is shared with other Google services. Google may use the collected data to contextualise and personalise the ads of its own advertising network.

You can opt-out of having made Your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity.

For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: https://policies.google.com/privacy?hl=en

Purpose of processingType of personal dataLegal basis for processing
To enable us to process any enquiry you make via the Website or otherwise Your name, your job title, work email address, subject, message, work phone number and organisation details (if applicable). Legitimate interest – to enable us to respond to your enquiry
To enable us to work with you or the organisation you represent (for example, when we receive research funding from your organisation or to receive products or services from you or the organisation you represent)Your name, your job title, work email address, work phone number, work address, organisation details (if applicable) and organisation bank details (if applicable) Performance of our contract with you if we are working with you
Legitimate interest – to enable us to work with your organisation
To deal with any concerns or complaints you have raisedYour name, job title, information about the issue raised, organisation details (if applicable), work phone number and work email addressLegitimate Interest – to allow us to deal with your complaint and improve -the Website
To ensure that the Website is presented in the most effective manner for you and for your deviceThe information referred to in the “data we collect about you” section above Legitimate Interest – to allow us to present the Website in an appropriate manner
For our internal operations, including data analysis, testing, research, statistical purposes and troubleshootingThe information referred to in the “data we collect about you” section above Legitimate Interest – to better understand users of the Website and to continuously improve the Website
As part of our efforts to keep the Website safe and secureThe information referred to in the “data we collect about you” section above Legitimate Interest – to improve and ensure the safety of the Website
Marketing/analytics from our website using cookiesThe information referred to in the “data we collect about you” section aboveConsent
To provide you with information about us, our research or any other information which we feel may interest you about us or our business, where you have opted inYour name, job title, work email address and organisation details (if applicable) Consent

6 How we use your information

We will only process Your Personal Data when the law allows us to do so. We will have provided You with Our lawful basis for processing Your Personal Data at the point the information was initially collected from You. We will not store, process, or transfer Your data unless we have an appropriate lawful reason to do so.

Under Data Protection Legislation, the lawful bases We rely on for processing Your information are:

  • GDPR Article 6(1)(a) – Your consent;*
  • GDPR Article 6(1)(b) – We have a contractual obligation;
  • GDPR Article 6(1)(c) – We have a legal obligation;
  • GDPR, Article 6(1)(d) – In order to protect the vital interests of You or a third party;
  • GDPR, Article 6(1)(e) – We have a public interest; or,
  • GDPR, Article 6(1)(f) – We have a legitimate interest.

* Where the lawful basis for processing is Consent, You are able to remove Your consent at any time. You can do this by contacting Our DPO using the contact details provided in the Contact Us section below.

We may use Your information for the following purposes:

Processing ActivityLawful Basis
Where You are a clinical trial participant in a jurisdiction where clinical trials occur on the lawful basis of Consent, to collect information from You and process Your health information in order to conduct a clinical trialConsent
Where You are a clinical trial participant in a jurisdiction where clinical trials occur on the lawful basis of Legitimate Interest, to collect information from You and process Yyour health information in order to conduct a clinical trialLegitimate Interest
Where You are a Health Care Professional (HCP) involved in the planning, delivery, or oversight of Enterprise Therapeutics clinical trials, to collect information from You and process Your employment information in order to conduct a clinical trialLegitimate Interest
Where You are an employee of Enterprise Therapeutics, to collect information from You and service the contract between UsContractual Obligation
Where You are an employee of Enterprise Therapeutics’ Service Providers, to collect information from You or Your employer and make available our services to Your employerLegitimate Interest
Where You are an employee of Enterprise Therapeutics’ Service Providers, to collect information from You or Your employer and liaise with Your employer about Your contact details and/or the nature and performance of Your work, as requiredLegitimate Interest
To collect information from You and monitor, provide and maintain Our ServiceLegitimate Interest
To contact You following Your enquiry where You have provided your contact information and to reply to any questions, suggestions, issues, or complaints, including any Data Subject Requests, about which You have contacted UsLegitimate Interest
To collect Your Usage Data in order to power Our security measures and services so You can safely access Our website and other ServicesLegitimate Interest
To contact You, where You have provided your contact information, about news and information relating to Our Services through service messagesLegitimate Interest
To provide You with information about Us, Our research or any other information which We feel may interest You about Us or Our businessLegitimate Interest
To retain any accounting information generated during the course of Our interaction for statutory accountancy retention periodsLegal Obligation
To respond to and defend against legal claims, where You have provided Us with information which may give rise to legal claimsLegal Obligation

We will only use Your Personal Data for the purposes for which We collected it, unless We reasonably consider that We need to use it for another reason and that reason is compatible with the original purpose.

If We need to use Your Personal Data for an unrelated purpose, We will notify You and We will explain the legal basis which allows Us to do so.

Please note that We may process Your Personal Data without Your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

7 Who we might share your information with

We may share Your Personal Data with other organisations in the following circumstances:

  • If the law or a public authority says We must share the Personal Data;
  • If We need to share Personal Data in order to establish, exercise or defend Our legal rights – this includes providing Personal Data to others for the purposes of detecting and preventing fraud; or
  • From time to time, We employ the services of other parties for dealing with certain processes necessary for the operation of Our services.

We use Service Providers (“Data Processors”) who are third parties who provide elements of services for Us. Examples of these Data Processors include, but are not limited to:

  • – Our Contract Research Organisation (CRO) and EU representative;
  • Our Clinical Trial Data Processors, such as Medidata Solutions, Inc.; and,
  • Our IT Service Providers, such as Microsoft, Inc.

We have Data Processor Agreements in place with Our Data Processors. This means that they cannot do anything with Your Personal Data unless We have instructed them to do it. They will not share Your Personal Data with any organisation apart from Us or further sub-processors who must comply with our Data Processor Agreement. They will hold Your Personal Data securely and retain it for the period We instruct.

If You have received a specific Privacy Notice directly, this will provide further details of those entities who may receive Your Personal Data as part of Our processing activities. You may request a replacement copy of this specific Privacy Notice at any time from the DPO via the Contact Us section below.

8 How long we keep your information for

We retain a record of Your Personal Data in order to provide You with a high quality and consistent service. We will always retain Your Personal Data in accordance with the Data Protection Legislation and never retain Your information for longer than is necessary. Enterprise Therapeutics follows a Retention Schedule which outlines how long Enterprise Therapeutics will retain Your Personal Data. Enterprise Therapeutics considers the retention period to begin from the point at which We last contacted You or otherwise reviewed Your record to determine whether it was still active, unless otherwise required by law. As such, unless otherwise required by law, Your data will be retained for the period specified in the summarised table below and then securely deleted in accordance with Our internal policies and procedures.

PurposeRetention Period
Processing data in relation to You as a clinical trial participant25 years following the conclusion of the clinical trial,
as determined by EU Clinical Trial Regulations (EU-CTRs)
Processing data in relation to You as a Health Care Professional (HCP) involved in the planning, delivery, or oversight of an Enterprise Therapeutics clinical trial25 years following the conclusion of the clinical trial,
as determined by EU Clinical Trial Regulations (EU-CTRs)
Processing data in relation to You as an employee, contractor or other associated party contracted by Enterprise Therapeutics 6 years following the termination of your employment
Processing data in relation to You as an employee, contractor or other associated party contracted by Enterprise Therapeutics’ Service Providers6 years
Processing data in relation to You as a service user of this website (https://Enterprisetherapeutics.com)1 year
Processing data in relation to You as any other individual with whom Enterprise Therapeutics may conduct commercial operations6 years

9 How we keep you updated on our products and services

Where You are a clinical trial participant or a Health Care Professional involved in the planning, delivery, or oversight of an Enterprise Therapeutics clinical trial, We will contact You through Our Contracted Research Organisation (CRO) where it is necessary to do so.

Where You are an employee of Enterprise Therapeutics, We will contact You through existing Enterprise Therapeutics communication channels, including email, where it is appropriate to do so.

Where You are an employee of Enterprise Therapeutics’ Service Providers, a user of this website who has provided Us with Your contact information, or any other business contact, We will send You relevant news about Our services in a number of ways including by email, but only if We have a Legitimate Interest to do so. Where We do not have a Legitimate Interest, We will not send You marketing communications unless We have asked for Your consent.

We make every effort to ensure that We only send such communications to those acting in a business capacity and do not send such materials to consumers via personal email addresses if it is clear they are not acting in such a capacity or have not otherwise provided their consent.

All email communications will have an option to unsubscribe and so if You wish to amend Your marketing preferences, You can do so by following the link in the email and updating Your preferences. Alternatively, You can contact Our DPO using the contact details provided in the Contact Us section below

10 Giving your reviews and sharing your thoughts

When using Our website and other Services, You may be able to share information through social networks like Facebook and Twitter. For example, when You ‘like’, ‘share’ or review Our Services. When doing this, Your Personal Data may be visible to the providers of those social networks and/or their other users. Please remember it is Your responsibility to set appropriate privacy settings on Your social network accounts so You are comfortable with how Your information is used and shared on them.

11 Your rights over your information

11.1.1       The Right to be Informed about Our collection and use of Personal Data;

You have the right to be informed about the collection and use of Your Personal Data. We ensure We do this with Our internal and external Privacy Notices (including this document). These are regularly reviewed and updated to ensure these are accurate and reflect Our data processing activities.

11.1.2       Right to Access Your Personal Data

You have the right to access the Personal Data that We hold about You in many circumstances, by making a request. This is sometimes termed ‘Data Subject Access Request’. If We agree that We are obliged to provide Personal Data to You (or someone else on Your behalf), We will provide it to You or them free of charge and aim to do so within 1 month from when Your identity has been confirmed.

We would ask for proof of identity and sufficient information about Your interactions with Us that We can locate Your Personal Data.

If You would like to exercise this right, please Contact Us as set out below.

11.1.3       Right to Rectify Your Personal Data

If any of the Personal Data We hold about You is inaccurate, incomplete, or out of date, You may ask Us to correct it.

If You would like to exercise this right, please Contact Us as set out below.

11.1.4       Right to Erasure

You have the right to have Personal Data erased. This is also known as the ‘right to be forgotten’. The right is not absolute and only applies in certain circumstances. For instance, the right to erasure does not apply where We have a legal obligation to retain Your Personal Data.

If You would like to exercise this right, please Contact Us as set out below.

11.1.5       Right to Restrict Processing

You have the right to ask Us to restrict the processing of Your Personal Data. For example, this may be because You have issues with the accuracy of the data We hold or the way We have processed Your data. The right is not absolute and only applies in certain circumstances.

If You would like to exercise this right, please Contact Us as set out below.

11.1.6       Right to Portability

The right to portability gives You the right to receive Personal Data You have provided to a controller in a structured, commonly used, and machine-readable format. It also gives You the right to request that a controller transmits this data directly to another controller.

If You would like to exercise this right, please Contact Us as set out below.

11.1.7       Right to Object

You have the right to object to Our processing of some or all of the Personal Data that We hold about You. This is an absolute right when We use Your data for direct marketing but may not apply in other circumstances where We have a compelling reason to do so, e.g., a legal obligation.

If You would like to exercise this right, please Contact Us as set out below.

11.1.8       Rights Related to Automated Decision-Making

You have the right to object to Our processing where a decision is made about You solely based upon automated processed and which has significant or legal effects. Enterprise Therapeutics does not intend to conduct any automated decision-making using Your Personal Data.

If You would like to contact us regarding this right, please Contact Us as set out below.

11.1.9       For more information about Your privacy rights

Clinical Trial Participants

Rights and methods of accessing your data specific to your study information will be contained within the privacy notice information attached to your informed Consent Form for the study you joined. If you would like another copy of this, please contact the investigator site who administered your participation in the study or contact our DPO via Contact Us below.

All Data Subjects

In the UK, the Information Commissioner’s Office (ICO) regulates data protection and privacy matters. They make a lot of information accessible to consumers on their website, which You can access here: https://ico.org.uk/for-the-public

For data subjects of Enterprise Therapeutics Italy, You may contact the Garante Per La Protezione Dei Dati Personali (GPDP) , which You can access via this link: Home – Garante privacy en – Garante Privacy

Depending on Your jurisdiction, it is possible that a different regulator or supervisory authority may govern the processing of Personal Data. Your government’s website should be able to point You in the right direction of the relevant regulatory body. If You have any questions about which supervisory authority applies in Your jurisdiction, please Contact Us as set out below.

You can make a complaint to the ICO, GPDP or any other supervisory authority, at any time about the way We use your information. However, We hope that You would consider raising any issue or complaint You have with Us first. Your satisfaction is extremely important to Us, and We will always do Our very best to solve any problems You may have.

12 Security

Data security is of great importance to Enterprise Therapeutics. We have put in place appropriate technical and organisational measures to prevent Your Personal Data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed.

We take security measures to protect Your information including:

  • Limiting access to Our buildings and resources to only those that we have determined are entitled to be there (by use of passes, key card access and other related technologies);
  • Managing a data security breach reporting and notification system which allows Us to monitor and communicate information on data breaches with You or with the applicable regulator when required to do so by law;
  • Implementing access controls to Our information technology; and,
  • Deploying appropriate procedures and technical security measures (including strict encryption, anonymisation and archiving techniques) to safeguard Your information across all Our computer systems, networks, websites, mobile apps, offices, and stores.

Further information on Our security measures can be found in Enterprise Therapeutics’ IT Security Policy.

13 International Transfers

Your Personal Data is processed at the Company’s operating offices and in any other places where the parties involved in the processing are located. This means that this information may be transferred to Devices located outside of Your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those from Your jurisdiction. In particular, when Enterprise Therapeutics shares data with Our strategic clinical trials partner or certain other trusted Data Processors, Your Personal Data, which will be pseudonymised in any case, will be stored and processed in third countries. Where this occurs, Enterprise Therapeutics will ensure that:

  • the security and confidentiality of Your Personal Data is maintained at all times;
  • any Data Controller receiving Your Personal Data has entered into an agreement with Enterprise Therapeutics which contains standard data protection clauses as required by UK and/or EU GDPR or there is an alternative appropriate safeguard in place governing the transfer; and
  • any Data Processor receiving Your Personal Data has entered into an agreement with Enterprise Therapeutics which contains the required Data Processor clauses as well as standard data protection clauses as required by UK and/or EU GDPR or there is an alternative appropriate safeguard in place governing the transfer.

Where You are based in the UK or EU and We are required to transfer Your Personal Data out of the UK or EU to countries not deemed by the ICO or European Commission (as relevant) to provide an adequate level of Personal Data protection, the transfer will be based on safeguards that allow us to conduct the transfer in accordance with the Data Protection Legislation, such as the specific contracts containing standard data protection clauses approved by the ICO or European Commission (as relevant) providing adequate protection of Personal Data. You have a right to request a copy of the standard data protection clauses. You can do so by contacting Our DPO through the contact details specified below in the Contact Us section.

14 What happens if our business changes hands?

We may, from time to time, expand or reduce Our business and this may involve the sale and/or the transfer of control of all or part of Our business. Any Personal Data that You have provided will, where it is relevant to any part of Our business that is being transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this Privacy Notice, be permitted to use that data only for the purposes for which it was originally collected by Us.

15 Contact Us

If You would like to exercise one of Your rights as set out above, or You have a question or a complaint about this Privacy Notice or the way Your Personal Data is processed, please contact Our Data Protection Officer (DPO) by one of the following means:

By email: privacy@enterprisetherapeutics.com

By post: Sussex Innovation Centre Science Park Square, Falmer, Brighton, England, BN1 9SB

Enterprise Therapeutics Ltd’s EU Representative is The DPO Centre, who can be contacted:

By email: eurep@enterprisetherapeutics.com
By telephone: +33 1 53 45 54 72
By post at: The DPO Centre Europe Ltd, 10 Place Vendôme, 75001 Paris, France

For Employees and data subjects of Enterprise Therapeutics Italy, please contact:

By email: privacy@enterprisetherapeutics.com

By telephone: +39 0245075287

By post: Via A. Albricci 8, 20122 Milano

15 Changes to Our Privacy Notice

Thank You for taking the time to read Our Privacy Notice.

We may change this Privacy Notice from time to time (for example, if the law changes). We recommend that You check this Privacy Notice regularly to keep up-to-date.

This Notice was last updated on 9th September 2024.