This “Privacy Policy” describes the online privacy practices of Crinetics Pharmaceuticals, Inc. and our third parties (collectively, “Crinetics”, “we”, “us”, or “our”) in how we collect, use, disclose, and otherwise process personal information, and explains the rights and choices available to individuals with respect to their information.

Crinetics may provide additional privacy notices to individuals at the time we collect their data. For example, we provide a specific privacy notice to clinical trial participants that describe our privacy practices in connection with conducting clinical trials. This type of an “in-time” notice will govern how we may process the information you provide at that time.

This document can be printed for reference by using the print command in the settings of any browser.

DATA CONTROLLER

Crinetics Pharmaceuticals, Inc is the controller of your Personal Data.  Our contact details are below:

6055 Lusk Blvd, San Diego, CA 92121

Owner contact email: [email protected]

Whose personal information we collect

We collect personal information about the following types of individuals:

  • clinical trial participants
  • patients and patient family members, caregivers or advocates
  • physicians and other health care professionals
  • clinical trial investigators
  • researchers
  • pharmacists and other health care providers
  • other individuals who interact directly with Crinetics or its service providers or business partners, including users of websites and mobile applications

How we collect personal information

We collect personal information:

  • Directly from individuals
  • Through our websites and mobile apps
  • From healthcare professionals
  • From contract research organizations and clinical trial investigators
  • From government agencies or public records
  • From third party service providers, data brokers, or business partners
  • From industry and patient groups and associations 

Types of personal information we collect

The types of personal information we collect and share depend on the nature of the relationship you have with Crinetics and the requirements of applicable laws. We may collect:

  • Health and medical information (such as medical insurance details, information about physical and mental health conditions and diagnoses, treatments for medical conditions, genetic information, family medical history, and medications an individual may take, including the dosage, timing, and frequency) in connection with managing clinical trials, conducting research, providing patient support programs, managing compassionate use and expanded access programs, and tracking adverse event reports. Any information that is “protected health information” for purposes of the U.S. Health Insurance Portability and Accountability Act (“HIPAA”) is subject to the HIPAA covered entity’s Notice of Privacy Practices.
  • Personal and business contact information and preferences (such as name, job title and employer name, email address, mailing address, phone number, and emergency contact information).
  • Biographical and demographic information (such as date of birth, age, gender, marital status, and information regarding any parents or legal guardians).
  • Professional credentials, educational and professional history, and institutional affiliations
  • Payment-related information we need to pay for professional services, such as consulting, that individuals may provide to us (such as tax identification number and financial account information).
  • If you are a healthcare professional, we collect information about the programs and activities in which you have participated and the agreements you have executed with us
  • Your photograph, social media handle, or digital or electronic signature.
  • Publicly available information (such as comments describing support for and experience with Crinetics products).
  • Other information you provide to us (such as in emails, on phone calls, in market research surveys, or in other correspondence with Crinetics or its service providers or business partners).

We may combine other publicly available information, such as information related to the organization for which you work, with the personal information that you provide to us through our Services.

Unless specified otherwise, all personal information collected by this Website is required by Crinetics in order to provide its Services.  If you do not provide certain information, it may make it impossible for this Website to provide you with Services.

If you are uncertain about which personal information, it is mandatory to provide please contact us using the contact details below.

Any use of Cookies – or of other tracking tools – by this Website or by the owners of third-party services used by this Website serves the purpose of providing the Service you require, in addition to such other purposes as described in this Privacy Policy document and in the Cookie Policy.

You are responsible for any third-party personal information obtained, published, or shared through this Website and confirm that they have the third party’s consent to provide the Data to the Owner.

HOW WE PROCESS PERSONAL INFORMATION

METHODS OF PROCESSING

We put appropriate security measures in place to prevent unauthorized access, disclosure, modification, or unauthorized destruction of information.

Processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to our access, in some cases, the personal information may be accessible to individuals involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by us.  You may request the updated list of these parties from us at any time.

LEGAL BASIS OF PROCESSING

Certain privacy laws require us to set out the lawful basis on which we rely to process Personal Data.  We may process personal information relating to you if one of the following applies:

  • You have given consent for one or more specific purposes;
  • provision of information is necessary for the performance of an agreement with you and/or for any pre-contractual obligations relating to such an agreement;
  • processing is necessary for compliance with a legal obligation to which we are subject;
  • processing is related to a task that we carry out in the public interest or in the exercise of official authority;
  • processing is necessary for the purposes of our legitimate interests or those of a third party.

Use for New Purposes

  • We may use your personal information for reasons not described in this Privacy Policy where permitted by law and when the reason is compatible with the purpose for which we collected it. If we need to use your personal information for an unrelated purpose, we will notify you and explain the applicable legal basis.

PLACE OF PROCESSING

Personal information is processed at our operating offices and in any other places where the parties involved in the processing are located.

Depending on your location, your personal information may be transferred to a country other than where you live. To find out more about data transfers, you can check the section containing details about the processing of personal information.

If any such transfer takes place, you can find out more by checking the relevant sections of this Privacy Policy or by contacting us using the information provided in the contact section.

RETENTION TIME

Personal information shall be processed and stored for as long as required for the purpose for which it was collected.

Therefore:

  • Personal information collected for purposes related to the performance of a contract between Crinetics and you shall be retained until such contract has been fully performed, and for such period thereafter as may be required in order that we can meet our legal obligations.
  • Personal information collected for the purposes of our legitimate interests shall be retained for as long as needed to fulfill such purposes. You may find specific information regarding the legitimate interests pursued by us within the relevant sections of this document or by contacting us.

We may retain personal information for a longer period whenever you have given consent to such processing, as long as such consent is not withdrawn. Furthermore, we may be obliged to retain personal information for a longer period whenever required to do so to comply with the law, for the performance of a legal obligation or upon order of an authority.

THE PURPOSES OF PROCESSING

We collect personal information to allow us to provide our Service, comply with our legal obligations, respond to enforcement requests, protect our rights and interests (or your interests, or third parties’ interests), detect any malicious or fraudulent activity, as well as to contact you, and for Analytics and Displaying content from external platforms.

For specific information about the personal information used for each purpose, see below.

DETAILED INFORMATION ON THE PROCESSING OF PERSONAL INFORMATION

Personal information is collected for the following purposes and using the following services:

ANALYTICS

The services contained in this section enable us to monitor and analyze web traffic and can be used to keep track of User behavior.

Google Analytics (Google LLC)

Google Analytics is a web analysis service provided by Google LLC (“Google”). Google utilizes the Data collected to track and examine the use of this Website, to prepare reports on its activities and share them with other Google services.

Google may use the Data collected to contextualize and personalize the ads of its own advertising network.

Personal information processed: Cookies; Usage Data.

Place of processing: United States – Privacy Policy – Opt Out.

CONTACTING YOU

Contact form (this Website)

By filling in the contact form with your Data, you authorize this Website to use your details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.

Personal information processed: company name; email address; first name; last name; phone number; profession.

Mailing list or newsletter (this Website)

By registering on the mailing list or for the newsletter, your email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Website. Your email address might also be added to this list as a result of signing up to this Website or after making a purchase.

Personal information processed: email address; first name; last name.

DISPLAYING CONTENT FROM EXTERNAL PLATFORMS

This type of service allows you to view content hosted on external platforms directly from the pages of this Website and interact with them.

This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.

Google Fonts (Google LLC)

Google Fonts is a typeface visualization service provided by Google LLC that allows this Website to incorporate content of this kind on its pages.

Personal information processed: Usage Data; various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy.

YOUR RIGHTS

Depending on their geographical location and applicable privacy laws you may be able to exercise certain rights regarding the information we process.

In particular, you may have the right to do the following:

  • Withdraw consent at any time. You have the right to withdraw consent where you have previously given consent to the processing of your personal information.
  • Object to processing of their Data. You have the right to object to the processing of your personal information if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
  • Access Data. You have the right to learn if we are processing personal information and request a copy of the personal information that we are processing.
  • Verify and seek rectification. You have the right to verify the accuracy of your personal information and ask for it to be updated or corrected.
  • Restrict the processing of their personal information. You have the right, under certain circumstances, to restrict the processing of your personal information. In this case, we will not process your personal information for any purpose other than storing it.
  • Request Personal Information be deleted or otherwise removed. You have the right, under certain circumstances, to request that we erase your personal information.
  • Receive personal information and have it transferred to another controller. You have the right to receive your personal information in a structured, commonly used and machine- readable format and, if technically feasible, to have it transmitted to another controller. This provision is applicable provided that the personal information is processed by automated means and that the processing is based on your consent, on a contract to which you a party or pre-contractual obligations thereof.
  • Lodge a complaint. You have the right to bring a claim before their competent data protection authority, as may be applicable.

DETAILS ABOUT THE RIGHT TO OBJECT TO PROCESSING

Where personal information is processed for a public interest, in the exercise of an official authority vested in us or for the purposes of the legitimate interests pursued by us, you may object to such processing by providing a ground related to your particular circumstances to justify the objection.

You may object to your personal information being processed for direct marketing purposes at any time without providing any justification.

HOW TO EXERCISE THESE RIGHTS

You should make any requests to exercise rights by contacting us using contact details provided in this document. These requests can be exercised free of charge and we will address them as early as possible and always within one month.

CHILDREN

We comply with the requirements of the US Children’s Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under age 13 through our Websites or mobile applications. If we learn that we have collected personal information directly from a child under the age of 13 through our websites or mobile applications, we will delete that information.

CALIFORNIA RESIDENTS

The following disclosures are made in compliance with the California Consumer Privacy Act (CCPA), as amended.

In the past 12 months, Crinetics has collected the personal information described above, under the section “Types of personal information we collect” from the sources listed under the section “How we collect personal information”.  This information falls into the following categories of personal information under the CCPA:

  • Identifiers,
  • Categories of personal information described in section 1798.80(e) of the California civil code,
  • Characteristics of protected classifications under California or federal law,
  • Commercial information,
  • Internet or electronic network activity information,
  • Professional or employment-related information,
  • Commercial information, and
  • Education information.

Crinetics does not sell Personal Information.

The Personal Information that Crinetics has disclosed to third parties in the past 12 months is described above, under the section “Methods of processing”, and includes data from the following categories of personal information under the CCPA:

  • Identifiers,
  • Categories of personal information described in section 1798.80(e) of the California civil code,
  • Characteristics of protected classifications under California or federal law,
  • Commercial information,
  • Internet or electronic network activity information,
  • Professional or employment-related information,
  • Commercial information, and
  • Education information.

 

 

COOKIE POLICY

This Website uses Trackers. To learn more, the User may consult the Cookie Policy.

ADDITIONAL INFORMATION ABOUT PERSONAL INFORMATION COLLECTION AND PROCESSING

LEGAL ACTION

We may use personal information for Court proceedings or in pre-proceedings arising from improper use of this Website or the related Services.  We may also disclose Personal Data upon request of public authorities.

ADDITIONAL INFORMATION ABOUT YOUR PERSONAL INFORMATION

In addition to the information contained in this privacy policy, this Website may provide you with additional and contextual information concerning particular Services or the collection and processing of personal information upon request.

SYSTEM LOGS AND MAINTENANCE

For operation and maintenance purposes, this Website and any third-party services may collect files that record interaction with this Website (System logs) use other personal information (such as the IP Address) for this purpose.

INFORMATION NOT CONTAINED IN THIS POLICY

If you have any questions about the collection or processing of personal information you may contact us at any time. Please see the contact information at the beginning of this document.

HOW “DO NOT TRACK” REQUESTS ARE HANDLED

This Website does not support “Do Not Track” requests.

To determine whether any of the third-party services it uses honor the “Do Not Track” requests, please read their privacy policies.

LINKS AND THIRD-PARTY WEBSITES

For your convenience and information, we may provide links to websites and other third-party content that is not owned or operated by us. These links are not an endorsement, authorization, or representation that we are affiliated with that third party. We do not exercise control over third-party websites or services and are not responsible for their actions. Other websites and services follow different rules regarding the use or disclosure of the personal information you submit to them. We encourage you to read the privacy policies of the other websites you visit and services you use.

CHANGES TO THIS PRIVACY POLICY

We reserve the right to make changes to this privacy policy at any time by notifying you on this page and/or sending you a notice. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.

Should the changes affect processing activities performed where we rely on your consent, we will collect new consent from you, as required.

DEFINITIONS AND LEGAL REFERENCES

Personal Information

Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.

Usage Data

Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers you utilize, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system you utilize, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.

Data Processor

The natural or legal person, public authority, agency or other body which processes personal information on behalf of the Controller, as described in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal information, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the Owner of this Website.

This Website (or this Application)

The means by which your personal information is collected and processed.

Service

The service provided by this Website as described in the relative terms (if available) and on this site/application.

Cookie

Cookies are Trackers consisting of small sets of data stored in your browser.

Tracker

Tracker indicates any technology – e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting – that enables us to track you, for example by accessing or storing information on your device.

Legal information

This privacy policy adheres to the requirements of the provisions of privacy laws applicable to us.

Latest update: June 6, 2023