Privacy Policy
- When you use our websites (www.kiniksa.com or any website that links to this Policy), mobile applications, online services, or otherwise interact with us online (“Online Services”);
- If you are in or interested in a clinical trial or otherwise involved in our research or patient support programs;
- If you are a healthcare professional or researcher who works with us or would like to work with us;
- When you apply for or receive a charitable donation, grant, or sponsorship from us;
- When you attend one of our events, contact customer services, or otherwise interact with us;
- When you interact with us in an employment context, such as if you are an employee or applicant for employment;
- When you interact with us in a commercial context, such as if you are employed by one of our vendors or a business partner; and
- In other situations in which this Policy is provided.
Privacy Policy Updates
Personal Data We May Collect About You
- Identifiers. Such as your first name, maiden name, last name, username or similar identifier, Internet Protocol address, title, date of birth, and government provided identifiers which may include Special or Sensitive Categories of Personal Data as defined below.
- Contact Information. Such as your billing address, delivery address, email address and telephone numbers.
- Commercial Information. Such as the types of information requested, purchases or orders made by you, details about your transactions with us, and feedback and survey responses.
- Internet or Other Electronic Network Activity (“Technical and Usage”) Information. Such as information about your interactions with our Online Services, geolocation data, internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Online Services.
- Demographic Information. Information which may include protected characteristics under U.S. state or Federal law, such as age, gender, marital status, or disability status.
- Marketing and Communications Data. Such as your preferences in receiving product, program, marketing or other information and your communication preferences.
- Audio, Electronic, Visual, or Similar Information. Such as CCTV or call recordings if you contact us by telephone.
- Financial Data. Such as your bank account, payment card details, insurance information and payroll data.
- Professional or Employment-Related Information. Such as the name of your employer, business contact information, and employment history.
- Education Information. Such as colleges or universities attended, and degrees earned.
- Inferences Drawn from the Personal Data Described Above. Such as your preferences or characteristics.
- Special or Sensitive Categories of Personal Data. Such as Social Security, driver’s license, or state identification number; account login information; details about your race or ethnicity; information about your health (including health-related personal data that Kiniksa or its agent may use to determine your eligibility for clinical research or to conduct a clinical trial); and genetic and biometric data.
How We May Collect Information About You
Direct Interactions
- create an account on our website;
- subscribe to our e-mail notifications, services, or publications;
- request scientific, product, program or marketing materials to be sent to you;
- enter information into a survey;
- provide us with feedback;
- provide unsolicited information to us;
- seek to do business with us;
- apply for employment with us or when you are employed by us; or
- express interest in participating in our clinical trials or other studies and research programs.
User-Generated Information
Automated Interactions
- Cookies. Cookies are small text files that are placed on your computer or mobile device in order to identify your web browser and the activities of your computer or mobile device when using our website. Cookies are used to personalize your experience, to assist you in using the website (such as saving time by not having to re-enter your name each time you use the website), and to allow us to statistically monitor how you are using the website to help us improve our products and services.
- Action Tags. Action tags, also known as web beacons or gif tags, are a web technology used to help track usage information, such as how many times a specific page on a website has been viewed. Action tags are invisible to you, and accessing any online service, including advertisements, from the Online Services may result in the creation of action tags.
Third Parties or Publicly Available Sources
- Internet or other electronic network activity data from analytics providers such as Adobe, Google, advertising networks and search information providers;
- Contact, financial, and commercial data from providers of technical, payment, and delivery services;
- Identifiers and contact information from data brokers, aggregators or recruitment agencies;
- Identifiers and contact information from publicly availably sources; and
- Special or sensitive categories of data including health data from entities such as those assisting us with our clinical trials and other studies and research programs.
How We May Use Your Personal Data
- To operate our business;
- To deliver information, products and services, including Online Services;
- To process, complete and fulfill your requests and transactions;
- To communicate with you;
- To maintain or service accounts;
- To provide customer service and respond to your inquiries;
- To screen for clinical trials or other studies and research program eligibility;
- To conduct scientific and market research and publish related results;
- To tailor our research, programs and marketing campaigns;
- To maintain and improve our Online Services, including debugging to identify and repair errors;
- To help ensure the security and integrity of our data, systems, and Online Services;
- To verify and maintain the quality and safety of our services;
- For advertising and marketing purposes;
- To evaluate your application for employment and fulfill our duties as an employer;
- In the context of commercial relationships with our business contacts, partners, and third parties that provide services to us;
- To provide you with newsletters, articles, alerts, announcements, invitations, and other information about science, research, products, brands, health topics and disease states;
- To comply with lawful requests and legal process, including to respond to requests from public and government authorities; enforce this Policy and our other terms and conditions; and protect our rights, privacy, safety or property, and/or that of you or others; and
- As described under the heading “HOW WE MAY DISCLOSE YOUR PERSONAL DATA”.
How We May Disclose Your Personal Data
- Internal Parties. Such as other subsidiaries, affiliates or departments within the broader Kiniksa organization that provide services to other parts of the organization, or for information technology and system administration services, or who undertake reporting.
- External Third Parties. Such as service providers that provide information technology and system administration services and data analytics, or third parties who provide services to support a clinical trial or other study or research program sponsored by Kiniksa, or marketing activities as described under “MARKETING AND OTHER INFORMATION”.
- Other Third Parties. Such as third parties in connection with the potential sale or transfer of all or a portion of our business or assets or with whom we may choose to merge, or from whom we may seek to acquire all or a portion of their business or assets. If a such change happens to our business and results in a change in ownership of all or a portion of such business or assets, the new owners may use your personal data as set out in this Policy.
- Professional Advisors. Such as advisors (e.g., lawyers, bankers, auditors and insurers) who provide advisory and related services to us, including consultancy, banking, legal, accounting, insurance, and payroll services.
- Courts, Regulators, or Government Authorities. Such as revenue and customs, Internal Revenue Service (IRS), U.S. Food and Drug Administration (FDA), state and federal regulators and other authorities who require reporting of processing activities or data in certain circumstances.
Marketing And Other Information
- Scientific, Medical, Program and Marketing Materials. We may use your identifiers, contact information, commercial information, and demographic data to form a view on what we believe you may want or need, or what may be of interest to you. This helps us to decide which programs, products, services, information and promotional efforts may be relevant for you.
- Opting-In. You will only receive certain scientific, medical, program or marketing communications from us if you have requested this information from us or you have opted-in to receiving these communications.
- Opting-Out. You can ask us or third parties who we control to stop sending you scientific, medical, program or marketing communications at any time by following the opt-out links on any marketing message sent to you. By opting-out of the communications, it will not affect the personal data collected for purposes of products or services purchased, warranty information, product or service experience, or other transactions. To opt out of targeted digital advertising, please contact us as described under the heading “HOW TO CONTACT US”.
Personal Data Collected By Third Parties
How We Secure Your Personal Data
Children
Links To Other Sites
Supplemental U.S. Privacy Policy
How And Why We Collect Your Personal Data
- Where required for the provision of our services, including as related to research and clinical trials, for identity verification, maintaining or servicing accounts, providing customer service, or processing transactions;
- To fulfill our obligations as an employer, including to administer payroll or comply with our legal obligations;
- To prevent, detect, and investigate security incidents that compromise the availability, authenticity, or confidentiality of personal data;
- To resist malicious, deceptive, fraudulent, or illegal actions directed at Kiniksa (e.g., to detect fraud or potential identity theft) and to prosecute those responsible for those actions;
- To verify or maintain the quality or safety of the products or services that we offer; and
- For other purposes that do not involve inferring characteristics about individuals, such as to comply with our legal obligations or respond to requests from law enforcement.
How Disclose, Sell, Or Share Your Personal Data
Categories of personal data collected |
Categories of third parties to whom we disclosed this personal data for business purposes |
---|---|
Identifiers |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Contact information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Commercial information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Internet or other electronic network activity information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Biometric data |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Demographic information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Marketing and communications data |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Audio, electronic, visual, or similar information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Financial data |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Professional or employment-related information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Education information |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Inferences drawn from categories of personal data described above |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
Sensitive personal data |
Kiniksa Pharmaceuticals International, plc subsidiary companies; service providers |
How Long We Retain Your Personal Data
Privacy Rights
- Right to Know. Consumers may have the right to confirm that we have collected personal data about you and know what personal data we have collected about them, including as applicable, the categories of personal data we have collected, the sources from which we collected that personal data, the business or commercial purposes for which we collected, sold, or shared that personal data, the categories of personal data we sold, shared, or disclosed to third parties for business purposes, as well as the categories of third parties to whom we have disclosed, sold, or shared the personal data.
- Right to Access. Consumers may have the right to request a copy of the specific pieces of personal data that Kiniksa has collected about them in a portable and, to the extent technically feasible, readily usable format.
- Right to Request Correction. Consumers may have the right to request that we correct inaccurate information that we process about them.
- Right to Request Deletion. Consumers may have the right to request deletion of their personal data (subject to certain exceptions).
- Right to Opt-Out of Sales, Sharing and Targeted Advertising. Consumers may have the right to opt-out of the sale of their personal data or the use or sharing of their personal data for targeted advertising.
- Right to Opt-Out of Profiling. Consumers may have the right to opt-out of profiling in furtherance of decisions that produce legal or similarly significant effects.
- Right to Be Free from Discrimination. Consumers may have the right to receive equal service and price and not be discriminated against for exercising their privacy rights under the CCPA.
How To Contact Us
Attention: Data Protection Officer
100 Hayden Ave
Lexington, MA 02421
Phone: +1-781-431-9100
Email: privacy@kiniksa.com
Supplemental European Privacy And UK Policy
How We Use Your Personal Data
- We need to perform the contract we are about to enter into or have entered into with you.
- It is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- We need to comply with a legal or regulatory obligation.
- It is necessary for scientific research purposes.
- We need to protect your interests (or someone else’s interests).
- It is needed in the public interest or for official purposes.
Purpose/Activity |
Category of personal data (as described in the “Personal Data We May Collect About You” section) |
Lawful basis for processing including, as applicable, basis of legitimate interest |
---|---|---|
To register you as a new customer, contractor or employee |
(a) Identity (b) Contact |
Performance of a contract with you |
To process and deliver your service or product including: (a) Manage payments, fees and charges (b) Collect and recover money owed to us |
(a) Identifiers (b) Contact (c) Financial (d) Transaction (e) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary for our legitimate interests to recover debts due to us |
To manage our relationship with you which will include: (a) Notifying you about changes to our terms or privacy policy (b) Asking you to provide feedback or take a survey (c) As an employee |
(a) Identifiers (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Financial |
(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests to keep our records updated; to study how customers use our products/services; and to administer our employee relationships |
To enable you to complete a survey |
(a) Identifiers (b) Contact (c) Profile (d) Usage (e) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary for our legitimate interests to study how customers use our products/services; and to develop them and grow our business |
To administer and protect our business and our intranet and website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
(a) Identifiers (b) Contact (c) Profile (d) Technical (e) Usage |
(a) Necessary for our legitimate interests for running our business and employee relationships; provision of administration and IT services, network security; to prevent fraud; and in the context of a business reorganisation or group restructuring exercise (b) Necessary to comply with a legal obligation |
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you |
(a) Identifiers (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical |
Necessary for our legitimate interests to study how customers use our products/services; to develop them; to grow our business; and to inform our marketing strategy |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences |
(a) Technical (b) Usage |
Necessary for our legitimate interests to define types of customers for our products and services; to keep our website updated and relevant; to develop our business; and to inform our marketing strategy |
To make suggestions and recommendations to you about goods or services that may be of interest to you |
(a) Identifiers (b) Contact (c) Technical (d) Usage (e) Profile |
Consent (if legally required) or necessity for our legitimate interests to develop our products/services; and to grow our business |
To screen you for clinical study eligibility |
(a) Identity (b) Contact (c) Special Categories (Health Data) |
Consent |
To conduct a clinical study |
(a) Identifiers (b) Contact (c) Financial (d) Special Categories (Health Data) |
Consent (if legally required) or necessity for our legitimate interests to improve healthcare; and to conduct and analyze the research study. Necessary for scientific research purposes |
Clinical Trial Data
Change Of Purpose
International Transfers Of Personal Data
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- If we transfer your personal data to countries which do not benefit from an adequacy decision of the European Commission we have put in place appropriate safeguards that ensure that your data will be adequately protected at the level of data protection in the EEA/UK, e.g., by entering into EU Standard Contractual Clauses approved by European Commission, and, where necessary, by implementing supplementary safeguards.
How Long We Retain Your Personal Data
Your Data Protection Rights
- access to your personal data;
- rectification of your personal data;
- erasure of your personal data;
- object to processing of your personal data;
- restrict of processing your personal data;
- receive your personal data in a structured, commonly used and machine-readable format and the right to transmit or have transmitted those data to another controller;
- not to be subject to a decision based solely on automated processing (such automated decision making does not take place); and
- withdraw consent to any consent that you have previously given.