Privacy Statement
ONL Therapeutics Global Privacy Notice
ONL Therapeutics, Inc. (“ONL,” “we,” “us,” or “our”) is committed to protecting the privacy of your personal information. This Global Privacy Notice (“Notice”) describes how ONL may collect, use, store, process, share, and transfer your personal information, along with how we protect your personal information. ONL, as the Controller of your personal information, adheres to applicable privacy laws and regulations including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and the European Union General Data Protection Regulation (GDPR). This Notice describes our general practices, but where local laws or regulations require that we process your personal information differently, we will comply with those local laws.
Information We Collect
“Personal information” refers to any information which could identify you directly (such as your name) or indirectly (such as your date of birth). We may collect the following categories of personal information, depending on the context of our interaction with you:
- Identifiers: Name, address, email, phone number.
- Professional and employment information: Job history, qualifications, resume details, interview notes.
- Clinical and health-related information: Medical history, treatment responses, clinical assessment data, safety reports (collected only where permitted and necessary for clinical research or safety monitoring).
- Contact and communication data: Correspondence, consent forms, preferences.
- Device and usage data: IP address, browser type, device identifiers, referring pages, access times, cookies and similar technologies, and information about how visitors interact with our website.
- Regulatory and compliance data: Licensing, credentials, certifications, audit and monitoring records.
- Other personal information: Any data reasonably necessary to provide services, manage clinical trials, fulfill legal obligations, or operate our business.
We collect personal information directly from you, from our affiliates, from clinicians or clinical research sites, and from service providers.
Processing Use
ONL may collect and use your personal information for reasons including, but not limited to, those listed below:
Please note that specific arrangements, contracts, consents, notices, or other forms of disclosure provided or made available to you may specify more detailed and/or additional uses of your personal information.
1. Participants in Clinical Trials (Subjects)
Third parties may process your personal data on our behalf as part of a clinical trial. Personal data collected by the third party may include your name, address, health related information, age, and biometric data relating to the trial. This information is pseudonymized (meaning you are assigned a subject identifier, not your name) when available to ONL, absent specific situations described in the subject consent.
2. Clinical Investigators and Site Personnel
We may process personal data relating to clinical investigators, sub investigators, research staff, and other site personnel for the following purposes:
- To identify, evaluate, qualify, and engage investigators and clinical trial sites for participation in ONL sponsored clinical trials or other research activities.
- To initiate, conduct, manage, monitor, audit, and close out clinical trials and related research activities, including regulatory submissions and inspections.
- To communicate scientific, medical, safety, and operational information relating to investigational products and clinical trial protocols.
- To collect, review, and report safety information, including adverse events, serious adverse events, suspected unexpected serious adverse reactions, and other safety signals associated with investigational products.
- To comply with pharmacovigilance, regulatory reporting, transparency, disclosure, and clinical trial registration requirements under applicable laws and regulations.
- To process payments, reimbursements, grants, and other financial interactions related to clinical research activities, and to maintain documentation required under applicable transparency laws.
- To document and maintain records of training, qualifications, delegation, and oversight in accordance with Good Clinical Practice and applicable regulatory requirements.
- To coordinate study related meetings, investigator meetings, site visits, and other communications necessary for the conduct of clinical research.
- To maintain appropriate oversight of vendors, contract research organizations, and other third parties involved in the conduct of clinical trials.
3. Employment Applicants
- To process employment applications and contact applicants regarding potential employment or engagement;
- To discuss and make hiring decisions, and to respond to queries about the result of recruitment;
- To ensure compliance with applicable employment laws and regulations.
4. Current and Former Employees
- To plan and manage personnel assignment, assessment, treatment, development, conditions of work, welfare program, health and safety;
- To effectuate compensation and the provision of employee benefits, including communications with insurance companies and brokers;
- To communicate with unions or works councils;
- To communicate with the employee and their family members in case of emergency;
- To assign and track training records;
- To communicate employee news internally or externally;
- To make notifications and reports to government agencies.
5. Technical
- To monitor ONL website usage levels, diagnose problems, and detect cybersecurity threats;
- To provide you with a more personal and interactive experience and improve our marketing efforts using cookies;
- To analyze website usage and performance through analytics tools such as Google Analytics, which use cookies and similar technologies to collect information about how users interact with the website (such as pages visited, time spent on pages, and navigation patterns) in order to improve website performance, functionality, and user experience
- To collect information about the type of devices accessing ONL websites;
- To manage teleconferencing, videoconferencing, or web conferencing with ONL;
- To capture data related to when you contact us via our “Contact” page.
If we decide to use your personal information for a purpose other than originally intended when we first collected your data, we will provide you with new Notice.
Legal Basis for Processing
ONL can collect and use your personal information when any of the following apply:
- You give us your explicit consent to use your data. You can withdraw this consent at any time.
- We need your personal information in order to enter into or perform a contract.
- We need your personal information to comply with legal requirements.
- We have a legitimate interest in processing your personal information for the purposes described above in order to identify, initiate, conduct, manage, and oversee clinical trials and other research activities involving investigational products, and to improve the design, quality, safety oversight, and operational effectiveness of our clinical development programs and website.
Sharing and Disclosure
We may share personal information with:
- Affiliates and subsidiaries for processing consistent with this notice.
- Contractors and service providers who support our operations, including data hosting providers, website analytics providers (such as Google Analytics), recruitment services, event planners, or study management vendors.
- Regulatory authorities as required by law or for safety reporting and compliance.
- Healthcare institutions, study sites, and investigators for clinical research purposes.
- Potential stakeholders, including in the event of a merger, legal restructuring operation, or joint venture.
- Professional service providers such as accountants and auditors.
- Law enforcement or legal representatives to comply with legal processes.
We do not sell your personal information.
When sharing personal information, as noted above, ONL will require that such third parties:
- Comply with applicable data protection laws and the principles of this Notice;
- Only process the personal information for the purposes permitted in this Notice; and
- Implement appropriate technical and organizational security measures designed to protect the integrity and confidentiality of your personal information.
Cookies and Analytics
Our website uses Google Analytics, a web analytics service provided by Google LLC. Google Analytics uses cookies and similar technologies to help us analyze how users interact with our website. Information generated by these technologies may be transmitted to and stored by Google on servers located outside your country of residence, including in the United States. We use this information to understand website usage and improve our services.
International Transfers
To facilitate our global operations, personal information may be transferred to, stored at, or processed in locations outside the country where you reside, including the United States. Laws in these countries may differ from each other and from your country of residence. ONL takes appropriate steps to ensure personal information is processed and transferred according to applicable laws, but not all countries are subject to the same data protection laws. When necessary by applicable law, ONL ensures appropriate safeguards are in place through the use of written agreements with recipients that require them to provide certain protections to your personal information, such as Standard Contractual Clauses adopted by the EU and UK. Please contact ONL at privacy@onltherapeutics.com for more information regarding these safeguards.
Data Retention
We retain personal information only as long as necessary for the purposes described in this Notice, to comply with legal obligations, resolve disputes, enforce agreements, or fulfill regulatory requirements. During these periods, we will take appropriate steps to ensure that the privacy of your personal information is maintained.
Your Rights and Choices
You have certain rights with respect to your personal information, although some exceptions may apply depending on our basis for processing your personal information and the law in your jurisdiction.
Depending on these, you may have the right to:
- Ask ONL about the processing of your personal information including access to this information;
- Ask ONL to correct information you think is inaccurate or incomplete;
- Ask ONL to delete your personal information;
- Ask ONL to restrict the processing of your personal information;
- Object to the processing of your personal information;
- Ask that we transfer personal information you have given us;
- Withdraw your consent to process your personal information if you have provided it, such as for receiving newsletters;
- Complain to your local data protection authority, although we ask that you contact us first.
To exercise your rights, please contact us at privacy@onltherapeutics.com. We will review each request individually and, where legal or regulatory restrictions prevent us from fulfilling it, we will explain the basis for our decision. In accordance with applicable law, we may request information necessary to confirm your identity before processing your request regarding your personal data.
Security
We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration. Although we take appropriate steps to safeguard data, no method of transmission or storage is entirely secure.
Changes to this Notice
We may update this Notice to reflect changes in our practices or legal requirements. We will post the revised Notice on our platforms with an updated effective date.
Contact Information
If you have questions, requests, or concerns about this Notice or our privacy practices, please contact:
Email: privacy@onltherapeutics.com
Address:
ONL Therapeutics, Inc.
110 Miller Ave., Suite 300
Ann Arbor, MI 48104
Effective Date: March 9, 2026