INTRODUCTION

We take your privacy seriously and want you to understand our practices with respect to the handling of your personal data when you interact with Replimune Group Inc., and its group of companies (“Replimune,” “we,” “us” and “our”) through this website (the “Website”). This privacy policy explains how we do this.

We may change this privacy policy from time to time and we advise you to review this privacy policy periodically to see the latest version.

WHAT PERSONAL INFORMATION DO WE COLLECT?

We collect personal information that you voluntarily provide to us when expressing an interest in obtaining information about us or our business, when participating in activities on this Website or otherwise contacting us.

The personal information that we collect depends on the context of your interactions with us and this Website, the choices you make and the features you use.

The personal information we collect can include the following:

  • Name and Contact Data. We may collect your first and last name, email address, phone number, and other similar contact data when you subscribe to our email alert, applying for careers or use our online contact form.

We do not collect or retain sensitive personal data relating to your health, ethnic origin, religious beliefs or political conviction etc. at this Website unless you submit such information to us which we will only be willing to accept through use of a specially designed contact form or other written indication of your agreement thereto. In the rare cases where we do seek to collect sensitive data we will do so in strict compliance with local data privacy law and you will be asked to actively consent to our processing.

HOW DO WE USE YOUR PERSONAL INFORMATION?

We may use your personal information to:

  • improve your experience when using our websites;
  • communicate with you, for example to respond to your request and process it;
  • provide you with information, about our product candidates;
  • comply with our business, regulatory and legal obligations.
ON WHAT BASIS DO WE USE YOUR PERSONAL INFORMATION?

We use personal information for:

Legitimate business purposes:

We use your personal information to make our communications with you more relevant and personalized to you. It also helps us to operate and improve our business and minimize any disruption to the services that we may offer to you. We use the personal information that we collect automatically when you visit this Website for such purposes as: counting and recognizing visitors to this Website; analyzing how visitors use this Website and various Site features; improving this Website and enhancing users’ experiences with this Website; creating new products and services or improving our existing products and services; enabling additional website analytics and research concerning this Website; and managing our business. Replimune may link non-personal information gathered using cookies and web beacons with personal information. But in that event, we will treat the combined information as personal information.

To comply with our legal obligations and other demands for information:

It is important to us that we are able to comply with laws, regulations and guidance, as well as the other requests or demands for data as set out here. They affect the way in which we run our business and help us to make our products and services as safe as we can.

You may have given your consent

At times we may need to get your consent to allow us to use your personal information for one or more of the purposes set out above.

SHARING YOUR PERSONAL INFORMATION WITH THIRD PARTIES

We may share your personal information with:

  • members of the Replimune group of companies; and
  • certain trusted third parties, including our agents and suppliers, including those who provide us with technology services such as data analytics, hosting and technical support; our professional advisors, auditors and business partners; regulators, governments and law enforcement authorities; and other third parties in connection with running or re-organizing all or any part of our business.

We do not sell or rent the personal information we collect from you.

HOW LONG WILL WE KEEP YOUR PERSONAL INFORMATION?

We keep your personal information for no longer than is necessary for the purpose for which the information is collected and to manage our relationship with you. Where personal information is kept, that period will be determined based on applicable local law.

PROTECTING YOUR PERSONAL INFORMATION

We will take appropriate legal, organizational, and technical measures to protect your personal data consistent with applicable privacy and data security laws. When Replimune uses a third-party service provider, that provider will be required to use appropriate measures to protect the confidentiality and security of personal data. We use a variety of security technologies and procedures to help protect your personal data from unauthorized access, use, or disclosure. Although we will do our best to protect your personal data, we cannot guarantee the security of the personal data you transmit to us. While we cannot guarantee that loss, misuse, or alteration to data will not occur, once we have received your data, we will employ appropriate technical security measures to prevent such unfortunate occurrences.

Personal data collected may be transferred to, stored, and processed in your country of residence or any other country in which Replimune (including its affiliates) maintain facilities, including the United States, United Kingdom, and countries in or outside the European Economic Area (EEA). This means that your data may be processed in countries with lower data protection standards than your country of residence. We will ensure that if data is transferred outside your country of residence, it will still be treated in accordance with this Privacy Statement. Additionally, such transfer will only be made if appropriate safeguards are in place, in the case of transfer from the EU/EEA to the US or UK by use of EU Model Clauses for data transfer, a copy of which can be obtained by contacting us.

WEBSITES THAT WE DO NOT OWN OR CONTROL

Our website may contain links to third-party sites. This privacy policy does not apply to those third-party sites. We recommend that you read the privacy statements of any other sites that you visit as we cannot accept responsibility for the privacy practices of these sites, which may be different to ours.

YOUR RIGHTS REGARDING YOUR PERSONAL INFORMATION

We set out below the rights that we will respect in relation to your personal data.

You may be entitled to:

  • ask Replimune for access to the personal information Replimune holds about you;
  • request the correction and/or deletion of your personal information;
  • request the restriction of the processing of your personal information, or object to that processing;
  • (if applicable) withdraw your consent to the processing of your personal information (where Replimune is processing your personal information based on your consent);
  • request for the receipt or the transfer to another organization of the personal information that you have provided to Replimune; and
  • complain to your local data protection authority if your privacy rights are violated, or if you have suffered as a result of unlawful processing of your personal information.

If you would like to exercise your rights, please let us know by getting in touch with us as set out in the “Contact us” section below.

WHAT IF YOU DO NOT WANT TO PROVIDE US WITH YOUR PERSONAL INFORMATION?

The provision of your personal information is voluntary for you and not required by law. Therefore, where you are given the option to share your personal information with us, you can always choose not to do so.

If you object to the processing of your personal information, or if you have provided your consent to processing and you later choose to withdraw it, we will respect that choice in accordance with our legal obligations. This could mean that we may not be able to perform the actions necessary to achieve the purposes for which the information was collected.

DATA CONTROLLER

Replimune Group Inc., is data controller of the personal data provided. We are established in the US and through our wholly-owned subsidiaries located in UK and EU.

QUESTIONS/CONTACT US

If you have any questions about this privacy policy, please email us at dataprotection@replimune.com or at:

In the US:
Replimune Group Inc.
500 Unicorn Park Dr., 3rd Floor
Woburn MA 01801, USA

In the UK:
Replimune Ltd.
Unit 69, Milton Park, Abingdon
Oxfordshire OX14 4RQ, UK