PRIVACY NOTICE
Effective Date: March 4, 2025
Introduction
At Rubedo Life Sciences (“we,” “our,” “us”), we are committed to protecting and respecting your privacy. This Privacy Notice explains how we collect, use, disclose, and safeguard Personal Data from individuals (“you” or “your”) when you visit our website (including rubedolife.com) and you interact with us or our services (our “Services”), in accordance with applicable data protection laws.
As used in this Privacy Notice, “Personal Data” means any information relating to an identified or identifiable individual. Please read this Privacy Notice carefully to understand how we handle your Personal Data. By using our Services, you agree to the collection, use, disclosure, and procedures described in this Privacy Notice.
Sources of Personal Data Collected
We may collect a variety of Personal Data from or about you or your devices from various sources, as described below. Where applicable, we indicate whether and why you must provide us with your Personal Data, as well as the consequences of failing to do so. If you do not provide your Personal Data when requested, you may not be able to use our Services if that Personal Data is necessary to provide you with our Services or if we are legally required to collect it.
We collect personal data about you from the following sources:
- Directly from you – We may collect Personal Data that you directly provide to us such as when you participate in our clinical trials, you interact with us in person, in webinars/webcasts or trade shows and conferences, or when you apply to our jobs.
- Automatically – Through cookies and analytics when you visit our website as described in our Cookie Policy
- From third parties – Including healthcare providers, business partners, regulatory authorities, and our vendors.
From publicly available sources – we may collect Personal Data from publicly available sources such as clinicaltrials.gov to ensure we conduct the proper due diligence on physicians, health care professionals and others for purposes of clinical trials.
Categories of Personal Data We Process
We process the following categories of personal data:
Categories of Personal Data | Examples |
Contact Information | Name, email address, phone number, postal address, username and password (where applicable). |
Professional Information | Job title, employer, industry, and professional qualifications. |
Financial Information | Bank account details for processing payments, invoicing details, and payment history (where applicable). |
Health Information | Personal health data, clinical trial data, medical conditions, and genetic data (where required for research or clinical trials). |
Technical Data | IP addresses, browser type, operating system version, application installations, device identifiers, cookies, data from user tracking and usage data. |
CV Data | Resumes, reference letters, employment history (where applicable) |
Optional Data | Any Personal Data that you may voluntarily provide to us |
Purpose of Processing Personal Data
We collect and process Personal Data for the following purposes:
Processing of Personal Data | Purposes |
Clinical Trials & Research | To identify clinical trial sites, investigators and for the purpose of conducting clinical trials, medical research, and the analysis of clinical data. |
Regulatory Compliance | To comply with our legal and regulatory obligations, including reporting requirements to health authorities, enforcing our legal rights, or as may be required by applicable laws and regulations or requested by any judicial process or governmental agency. |
Product awareness | To share company informational materials, to collaborate with healthcare professionals, to submit medical publications and other communications. |
Provide Services | To provide our website, and otherwise to make our Services available to you |
Contractual Performance | To fulfill contractual obligations arising from our relationship with you or your employer |
Communication | To communicate with you, provide you with updates and other information relating to our Services, provide information that you request, respond to comments and questions, and otherwise provide support; |
AI-Assisted Drug Selection | To identify potential drug compounds. AI-driven insights are always subject to several sets of human reviews. |
Security & protection of rights | To protect our business, ensuring security and preventing fraud and abuse, unauthorized access and misuse. |
Business purposes | For our everyday business purposes, including for internal product testing, to develop new products, services, features and functionality, for recruitment practices and responding to your requests |
Aggregate/Anonymize | To generate anonymized or aggregate data containing only de-identified, non-Personal Data that we may use for any lawful purposes. |
Other Purposes | For other purposes for which we provide specific notice at the time the information is collected. |
Legal Bases for Processing European Personal Data
If you are located in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, we only process your Personal Data when we have a valid “legal basis,” including as set forth below.
- Consent. We may process your Personal Data where you have consented to certain processing of your Personal Data.
- Contractual Necessity. We may process your Personal Data where required to provide you with the Services. For example, we may need to process your Personal Data to respond to your inquiries or requests.
- Compliance with a Legal Obligation. We may process your Personal Data where we have a legal obligation to do so. For example, we may process your Personal Data to comply with tax, labor and accounting obligations.
- Legitimate Interests. We may process your Personal Data where we or a third party have a legitimate interest in processing your Personal Data. Specifically, we have a legitimate interest in using your Personal Data for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of the Services. We only rely on our or a third party’s legitimate interests to process your Personal Data when these interests are not overridden by your rights and interests.
- Processing of special categories of Personal Data. We may process special categories of Personal Data (as defined under Article 9 of the EU/UK General Data Protection Regulation). When doing so, we will rely on an appropriate legal basis for special categories of Personal Data, including: (i) your explicit consent; (ii) processing is necessary to carry out the obligations and exercise specific rights in the field of employment and social security and social protection law; (iii) processing is necessary to protect applicable vital interests; (iv) processing relates to Personal Data which are manifestly made public; (v) processing is necessary for the establishment, exercise or defense of legal claims; (vi) processing is necessary for reasons of substantial public interest; (vii) processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services; (viii) processing is necessary for reasons of public interest in the area of public health; or (ix) processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes.
Sharing of Personal Data
We may share your personal data with the following recipients:
- Affiliates and Subsidiaries: We may disclose any Personal Data we receive to our current or future partners and affiliates within the Rubedo Life Sciences group for any of the purposes described in this Privacy Notice.
- Service Providers: We may disclose any Personal Data we receive to third-party service providers who assist with clinical trials, laboratories, research, data analytics, IT support, and communication.
- As required by Law and Regulatory Authorities: We may access, preserve, and disclose your Personal Data if we believe doing so is required or appropriate to comply with law enforcement requests and legal process, such as a court order or subpoena, to respond to health authorities, regulatory bodies, and government agencies, to respond to your requests, or protect your, our, or others’ rights, property, or safety.
- Professional Consultants: Lawyers, accountants, medical advisors, auditors and other consultants who provide legal, financial and professional services to us.
- Business Partners: Trusted business partners with whom we collaborate on initiatives, with your consent where necessary.
- Merger, Sale, or Other Asset Transfers. We may transfer your Personal Data to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company, or we sell, liquidate, or transfer all or a portion of our assets.
- Consent. We may also disclose your Personal Data with your permission.
International Transfers of Personal Data
Our Services are hosted in the United States. If you choose to use the Services from the EEA, the UK, Switzerland or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your Personal Data outside of those regions to the U.S. for storage and processing. We may transfer Personal Data from the EEA, the UK or Switzerland to the U.S. and other third countries based on European Commission-approved or UK Government-approved Standard Contractual Clauses, or otherwise in accordance with applicable data protection laws. We may also transfer your data from the U.S. to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the Services. For more information about the tools that we use to transfer Personal Data, or to obtain a copy of the contractual safeguards we use for such transfers (if applicable), you can contact us as described below.
Your Rights
If you are located in the EEA, the UK or Switzerland, you have the following rights regarding your Personal Data:
- Right to Access: You have the right to request access to your Personal Data that we process.
- Right to Rectification: You have the right to request the correction or update of inaccurate or incomplete Personal Data.
- Right to Erasure: You have the right to request the deletion of your Personal Data in certain circumstances.
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your Personal Data in certain situations.
- Right to Data Portability: You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format, and to transfer it to another controller.
- Right to Object: You have the right to object to the processing of your Personal Data in certain circumstances.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, including in your country of residence, place of work or where an incident took place.
To exercise any of your rights, please contact us at the details provided at the end of this Privacy Notice. Before fulfilling your request, we may ask you to provide reasonable information to verify your identity. Please note that there are exceptions and limitations to each of these rights, and that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain Personal Data for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.
Automated Decision-Making
As part of our commitment to innovation and precision medicine, we use Artificial Intelligence (AI) and machine learning algorithms to assist in drug selection. These technologies analyze large datasets, including clinical trial results, genetic information, and patient responses, to identify potential drug compounds. The AI models operate under strict oversight, ensuring compliance with applicable data protection laws, which governs automated decision-making. Any Personal Data processed through AI systems is pseudonymized or anonymized where possible, and human experts always review and perform rigorous testing of AI-driven insights before final decisions are made. If you are located in the EEA, the UK or Switzerland, and to the extent that our processing operations are classified as automated decision-making, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affect you. This right will not apply if the decision: (i) is necessary for entering into, or performance of, a contract between you and us; (ii) is authorized by EU or UK applicable law to which we are subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or (iii) is based on your explicit consent.
Security of Personal Data
We make reasonable efforts to protect your Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage by using technical and organizational measures designed to safeguard the Personal Data we maintain. This includes encryption, access control, and secure storage practices. However, because no electronic transmission or storage of information can be entirely secure, we can make no guarantees as to the security or privacy of your Personal Data.
Third Parties
Our Services may contain links to other websites, products, or services that we do not own or operate. We are not responsible for the privacy practices of these third parties. Please be aware that this Privacy Notice does not apply to your activities on these third-party services or any information you disclose to these third parties. We encourage you to read their privacy policies before providing any information to them.
Children’s Privacy
We do not knowingly collect, maintain, or use Personal Data from individuals under 18 years of age, and no part of our Services is directed to children. If you learn that a child has provided us with Personal Data in violation of this Privacy Notice, then you may alert us at: [email protected]
Data Retention
We retain your Personal Data for no longer than is necessary for the purposes for which it was collected. When you request that we do so, we take measures to delete your Personal Data or keep it in a form that does not permit identifying you when this Personal Data is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When we process Personal Data for our own purposes, we determine the retention period taking into account various criteria, such as the type of services provided to you, the nature and length of our relationship with you, possible re-enrollment with the Services, the impact on the Services we provide to you if we delete some Personal Data from or about you, and mandatory retention periods provided by law and the statute of limitations. In some cases, we may retain your Personal Data for longer periods, such as when required by law or in the context of ongoing research or clinical trials.
Changes to This Privacy Notice
We may update this Privacy Notice from time to time. When we do, we will post the updated notice on our website and update the “Effective Date” at the top of this notice. Please review this notice periodically to stay informed about how we are protecting your Personal Data. If we make a material update, we may notify you of such update through our Services, by email, or other means.
Contact Us
Rubedo Life Sciences Inc. is responsible and the data controller for processing your Personal Data. If you have any questions or concerns about this Privacy Notice or our data processing practices, please contact us:
Rubedo Life Sciences, Inc.
428 Oakmead Pkwy
Sunnyvale, CA 94085
[email protected]