Privacy Notice 

TOLREMO therapeutics AG (‘TOLREMO’), a company registered in Zurich, Switzerland, provides a Platform via the website www.tolremo.com (‘the Platform’). The Platform's purpose is to provide information about the company.

At TOLREMO we highly value your privacy and adhere to the applicable privacy laws when collecting and processing your data. This Privacy Notice outlines the principles of data collection and processing for the Platform.

1.     Controller name and contact information

This Privacy Notice applies to the processing of your personal data by TOLREMO. For questions or requests related to data processing by us, you may revert by mail to the address in our imprint or write us an e-mail at info@tolremo.com.

2.     Data processing activities and data processing purposes when you visit and use the Platform

a.         Data automatically collected

When you visit the Platform, the browser on your device automatically sends information to the server(s) on which the Platform runs. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until it is automatically deleted:

•                IP address of the requesting computer,
•                date and time of access,
•               name and URL of the retrieved file,
•                website from which access is made (referrer URL),
•                the browser used and, if applicable, the operating system of your computer as well as the name of your access provider.

The mentioned data will be processed by us for the following purposes:

•                ensuring a smooth connection of the website,
•                ensuring comfortable use of the Platform,
•                evaluation of system security and stability, as well as
•                for other administrative purposes.

Our legal basis for processing the above listed data is our legitimate interest of pursuing the purposes listed above for data collection.

In addition, we use cookies and analysis services when you visit the Platform. For more information, please refer to section 3 of this Privacy Notice.

b.         Data you provide to us

If you register for an account we ask you to provide your name, e-mail address and telephone number. We use your personal data only for the purpose of providing you the service or information requested by you. We will store this data on our serves for as long as necessary to provide the services or information requests, unless a longer retention period is based on our legitimate interests or prescribed by law. 

c.         How we use personal data

We store and process personal information for the following general purposes:

·       to enable you to access and use the Platform;
·       to operate, protect, improve and optimize the Platform and our business for example by performing analytics, conducting research, personalizing or otherwise customizing user experience, and to provide customer service and support;
·       to help maintain a trusted environment on the Platform, such as detection and prevention of actual and potential fraud and other harmful activity, conducting investigations and risk assessments, verifying any identifications provided by you, and conducting checks against databases and information sources for fraud detection and prevention, risk assessment and harm prevention purposes;
·       to send you service, support and administrative messages, reminders, technical notices, updates, security alerts, and information requested by you;
·       to comply with our legal obligations, resolve any disputes that we may have with any of our users and to enforce our agreements with third parties.

We do not rent, sell or otherwise share your personal data with third parties, except with your consent.

Further we may use third party service providers to help us deliver our service and run or analyse the Platform (e.g. third party data analytics services to analyse, among other things, server load).

We also reserve the right to disclose your personal data to (a) comply with relevant laws, regulatory requirements and to respond to lawful requests, court orders, and legal process; (b) to protect and defend the rights or property of us or third parties, including enforcing agreements, policies, and terms of use; (c) in an emergency, including to protect the safety of our employees or any person, or (d) in connection with investigating and preventing fraud.

We also aggregate data into anonymized system usage statistics.

3.     Cookies

We use cookies on our site. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our site. Information is stored in the cookie that results in each case in connection with the specifically used terminal device. However, this does not mean that we immediately become aware of your identity.

The use of cookies serves on the one hand to make the use of our offer more pleasant for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of the Platform. These will be deleted automatically after leaving our site. In addition, we also use temporary cookies that are stored on your end device for a specified period of time to optimize user-friendliness. If you visit our site again to use our services, it will automatically recognize that you have already been with us and what entries and settings you have made so that you do not have to enter them again.

On the other hand, we use cookies to statistically record the use of the Platform and to evaluate it for the purpose of optimising our offer. These cookies enable us to automatically recognize when you return to our site that you have already been with us. These cookies are automatically deleted after a defined period of time.

The basis for data processing by cookies for the aforementioned purposes is our legitimate interests.

Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or a message always appears before a new cookie is created. However, the complete deactivation of cookies can lead to the fact that you cannot use all functions of the Platform.

4.     Analytics-Tools

We use tracking tools to ensure the design and continuous optimization of the Platform. We use the tracking measures to record the use of the Platform statistically and to evaluate it for the purpose of optimising our offer. We use the tracking measures listed below based on our legitimate interests.

The respective data processing purposes and data categories can be found in the information on the corresponding tracking tools below.

a.         Google Analytics

For the purpose of the continuous optimization of our pages and its design, we use Google Analytics, a web analysis service provided by Google Ireland Ltd. and Google Inc. (https://www.google.de/intl/de/about/) ("Google"). In this context, pseudonymised user profiles are created and cookies are used. The information generated by the cookie about your use of the Platform such as

•                Browser type/version,
•                the operating system used,
•                Referrer URL (the previously visited page),
•                Host name of the accessing computer (IP address),
•                Time of the server request

are transferred to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on the website activities and to provide further services associated with the use of the website and the Internet for the purposes of market research and demand-oriented design of these Internet pages. This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf of Google. Under no circumstances will your IP address be merged with other data from Google. The IP addresses are anonymized so that an assignment is not possible (IP masking).

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of the Platform.

You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=en).

Further information on data protection in connection with Google Analytics can be found in the Google Analytics Help (https://support.google.com/analytics/answer/6004245?hl=en). 

5.     Sharing of data

Your personal data will not be shared with third parties for purposes other than those listed below.

We will only pass on your personal data to third parties if:

•                you have given your express consent,
•                the disclosure is necessary to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data,
•                in the event that a legal obligation exists for the transfer; or
•                this is legally permissible and necessary for the execution of contractual relationships with you.

We reserve the right to transfer, store, use and process your data, including any personal information, to countries outside of the European Economic Area (“EEA”) including the United States and possibly other countries. By using the Platform, you consent to us transferring your data to these countries. You should note that laws vary from jurisdiction to jurisdiction, and so laws and regulations relating to privacy and data disclosure, applicable to the places where your information is transferred to or stored, used or processed in, may be different from the laws and regulations applicable to your place of residency. We take the legally required safeguards and contractual measures to ensure that any parties we transfer personal data to do so in keeping with the level of data protection and security prescribed by the applicable data protection regulation.

6.     Your rights

You have the right:

•                to request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, deletion, restriction of processing or objection, the existence of a right of appeal, the origin of your data, if these have not been collected by us, and the existence of automated decision-making including profiling and, if applicable, meaningful information on their details;
•                request the correction of incorrect or complete personal data stored by us;
•                to demand the deletion of your personal data stored by us, unless the processing is justified by our legitimate interests, necessary to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
•                to demand the restriction of the processing of your personal data if you dispute the accuracy of the data;
•                if our data processing is based on your consent, you have the right to revoke your consent to us at any time. As a result, we are no longer allowed to continue processing data based on this consent in the future;
•                to complain to a supervisory authority.  

7.     Objection

In those cases where we base processing on our legitimate interests, you have the right to object to the processing of your personal data.

For withdrawing consent or objecting to any data processing as described above, simply send an e-mail with your specific request to info@tolremo.com.

8.     Data retention

We may retain information regarding you and your use of the Platform, including personally identifying information, for as long as needed to provide you with our services and the uses described in this Privacy Policy. Generally this means that we will keep information for the duration of your account.

If you choose, you may delete your account and the data connected therewith directly via the Platform.

While the Platform strives to provide the possibility of a full deletion of personal data, note that any information that we have copied may remain in back-up storage for some period of time after your account deletion.

Irrespective of your account deletion, we may in any event retain and use such data as necessary to comply with our legal obligations, maintain accurate accounting, financial and other operational records, resolve disputes, and enforce our rights connected to your use of the Platform.

9.     Data security

We take commercially reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. Accordingly, we store all the personal information you provide on secure (password- and firewall-protected) servers.

You also acknowledge that no technical and organisational measures can fully eliminate security risks connected with the transmission of information over the internet. We therefore cannot guarantee the security of data sent over the internet.

We also use suitable technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.

Validity of this privacy notice

This is our currently valid Privacy Notice as of April 2019.

Due to the further development of the Platform and offers above or due to changed legal or official requirements, it may become necessary to change this Privacy Notice. We therefore reserve the right to update and modify this Privacy Policy from time to time.

© TOLREMO therapeutics AG -  Privacy Notice - Version 02, 04.04.2019