PRIVACY POLICY

 Diamond Therapeutics Incorporated (“Diamond”) values privacy and is committed to being transparent about how information, including personal information, is used by us. This Privacy Policy describes the personal information that Diamond collects from or about visitors to our website (“Visitors”), as well as how we use it and to whom we disclose that information. Please review this entire document carefully.

PRIVACY POLICY EFFECTIVE FOR CANADA

It is Diamond’s policy to comply with the privacy legislation within each jurisdiction in which we operate. Sometimes such legislation and / or an individual’s right to privacy are different from one jurisdiction to another. This Privacy Policy covers only those activities that are subject to the provisions of Canada’s federal and provincial privacy laws, as applicable.

This Privacy Policy has a limited scope and application. Consequently, the rights and obligations contained in this Privacy Policy may not be available to all individuals or in all jurisdictions.

 WHAT IS PERSONAL INFORMATION?

For the purposes of this Privacy Policy, “personal information” is any information about an identifiable individual, other than an individual’s business contact information when collected, used or disclosed for the purposes of enabling the individual to be contacted in relation to their business responsibilities.

WHAT PERSONAL INFORMATION DO WE COLLECT?

We collect and maintain different types of personal information in respect of the individuals with whom we interact. This includes:

  • Contact and identification information, such as your name, address, telephone number, e-mail address

  • Device IDs

  • IP address

  • Geolocation information

  • Information collected via technology such as cookies and web beacons

  • Usage Information ex. operating system, browser type, time and duration of access, and page views

  • Other personal information as necessary

As a general rule, Diamond collects personal information directly from you. In most circumstances where the personal information that we collect about you is held by a third party, we will obtain your permission before we seek out this information from such sources (such permission may be given directly by you, or implied from your actions).

From time to time, we may utilize the services of third parties and may receive personal information collected by those third parties in the course of the performance of their services for us or otherwise. Where this is the case, we will take reasonable steps to ensure that such third parties have represented to us that they have the right to disclose your personal information to us.

Our website

We may collect information related to your visit to our website, including the IP address and domain used to access our websites, the type and version of your browser, the website you came from to access our website(s), the page you entered and exited at, any website page within our website(s) that is viewed by that IP address and what country you are from. We use this information to monitor our website’s performance (such as number of visits, average time spent, page views) and for our business purposes such as: (i) customizing certain content that we think you might like based on your usage patterns; (ii) improving our products and services; and (iii) upgrading our websites.

Use of cookies

We may place a “cookie” on the hard drive of your computer to track your visit. A cookie is a small data file that is transferred to your hard drive through your web browser that can only be read by the website that placed the cookie on your hard drive. The cookie acts as an identification card and allows our websites to identify you and to record your passwords and preferences. The cookie allows us to track your visit to our website(s) so that we can better understand your use of our website(s) so that we can customize and tailor them to better meet your needs. Most web browsers are set to accept cookies. However, on most web browsers you may change this setting to have your web browser either: (i) notify you prior to a website placing a cookie on your hard drive so that you can decide whether or not to accept the cookie; or (ii) automatically prevent the placing of a cookie on your hard drive. It should be noted that if cookies are not accepted, you may not be able to access a number of web pages found on our websites.

Third party links

Our websites may contain links to other websites that may be subject to less stringent privacy standards. We cannot assume any responsibility for the privacy practices, policies or actions of the third parties that operate these websites. Diamond is not responsible for how such third parties collect, use or disclose your personal information. You should review the privacy policies of these websites before providing them with personal information.

WHY DO WE COLLECT PERSONAL INFORMATION?

 Diamond collects and uses the minimum amount of personal data necessary to communicate with Visitors and to improve our communications, services and marketing, in addition to other legitimate business needs, including:

  • to send you informational and marketing materials that we think might be of interest to you; 

  • to create Aggregated Information (as defined below);

  • to protect Diamond against error, fraud, theft and damage to our goods and property;

  • to enable us to comply with applicable law or regulatory process; and

  • any other reasonable purpose to which you consent.

 Diamond collects and uses the minimum amount of personal data necessary to communicate with Users and, provide and improve services and marketing, in addition to other legitimate business needs, including:

·       Visitor engagement - your information helps us suggest content and services and communicate with you when you contact us through the website or sign up for Diamond alerts

·       Performance measurement - information helps us understand how our website and services are performing. Diamond may use anonymized and aggregated data for overall analytics and improving the usefulness of its services

·       Account maintenance - information helps us detect and prevent security risks and technical issues

·       Prevent, detect and stop fraudulent activities

Diamond only uses data and information for its own legitimate business needs. Therefore, Diamond does not and will not sell Visitors personal information.

 HOW DO WE USE PERSONAL INFORMATION?

We may use your personal information:

  • as permitted or required by applicable law or regulatory requirements;

  • for the purposes described in this Privacy Policy; and

  • for any additional purposes for which we have obtained your consent to the use or disclosure of your personal information.

As above, we may use your personal information to create Aggregated Information for the purposes of managing, maintaining, and developing our operations. Such purposes include: (i) identifying the demographics of our Users; (ii) creating benchmarks, reports, summary metrics, predictive algorithms; and (iii) developing new or improving our services or communications. Personal information helps us understand how our website and services are performing. Diamond may use anonymized and aggregated data for overall analytics and improving the usefulness of its services

In this Privacy Policy, “Aggregated Information” means information that: (i) arises from the compilation, combination and/or analysis of personal and other information; and (ii) is anonymized.

WHEN DO WE DISCLOSE YOUR PERSONAL INFORMATION?

We may share personal information with others only with your consent or as otherwise permitted by law. All such sharing is done in a manner consistent with this Privacy Policy. To the extent permissible, you will be informed if disclosure of your personal information is requested by law

We may also share your personal information with our employees, contractors, consultants, affiliates and other parties who require such information to assist us with managing our relationship with you, including third parties that provide services to us or on our behalf.

For example, we may share your personal information from time to time with our third-party information technology, data processing, advertising/marketing, service providers so that we may operate our business, some of which may be located in the United States. As a result, your personal information may be collected, used, processed, stored or disclosed in the United States.

In addition, personal information may be disclosed or transferred to another party during the course of, or completion of, a change in ownership of or the grant of a security interest in, all or a part of Diamond through, for example, an asset or share sale, or some other form of business combination, merger or joint venture, provided that such party is bound by appropriate agreements or obligations and required to use or disclose your personal information in a manner consistent with the use and disclosure provisions of this Privacy Policy, unless you consent otherwise.

Finally, your personal information may be disclosed:

  • for the purposes described in this Privacy Policy;

  • as permitted or required by applicable law or regulatory requirements;

  • to comply with valid legal processes such as search warrants, subpoenas or court orders;

  • as part of the regular reporting activities of Diamond;

  • to protect the rights and property of Diamond;

  • during emergency situations or where necessary to protect the safety of a person or group of persons; and

  • with your consent.

YOUR CONSENT IS IMPORTANT TO US

It is important to us that we collect, use or disclose your personal information where we have your consent to do so. Depending on the sensitivity of the personal information, your consent may be implied, deemed (using an opt-out mechanism) or express. Express consent can be given orally, electronically or in writing. Implied consent is consent that can reasonably be inferred from your action or inaction. For example, when you enter into an agreement with us, we will assume your consent to the collection, use and disclosure of your personal information for purposes related to the performance of that agreement and for any other purposes identified to you at the relevant time.

Typically, we will seek your consent at the time that we collect your personal information. In certain circumstances, your consent may be obtained after collection but prior to our use or disclosure of your personal information. If we plan to use or disclose your personal information for a purpose not previously identified (either in this Privacy Policy or separately), we will endeavor to advise you of that purpose before such use or disclosure.

We may collect, use or disclose your personal information without your knowledge or consent where we are permitted or required to do so by applicable law or regulatory requirements.

You may change or withdraw your consent at any time, subject to legal or contractual obligations and reasonable notice, by contacting our Privacy Officer, using the contact information set out below. All communications with respect to such withdrawal or variation of consent should be in writing and addressed to our Privacy Office.

We assume that, unless you advise us otherwise, you have consented to the collection, use and disclosure of your personal information as explained in this Privacy Policy.

 HOW IS YOUR PERSONAL INFORMATION PROTECTED?

Diamond will endeavor to maintain physical, technical and procedural safeguards that are appropriate to the sensitivity of the personal information in question. These safeguards are designed to prevent your personal information from loss and unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction. Unfortunately, we cannot guarantee complete security: (i) unauthorized access, use, or disclosure, (ii) hardware or software failure, and (iii) other events may potentially compromise the security of your personal information.

The security of your personal information is important to us, please advise our Privacy Officer immediately of any incident involving the loss of or unauthorized access to or disclosure of personal information that is in our custody or control.

ACCESS TO YOUR PERSONAL INFORMATION

You can ask to see your personal information. If you want to review, verify or correct your personal information, please contact our Privacy Officer. Please note that any such communication must be in writing.

Your right to access the personal information that we hold about you is not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse to provide some or all of the personal information that we hold about you. In addition, the personal information may have been destroyed, erased or made anonymous in accordance with our record retention obligations and practices. In the event that we cannot provide you with access to your personal information, we will endeavor to inform you of the reasons why, subject to any legal or regulatory restrictions.

 PRIVACY OFFICER INQUIRIES

Users may provide feedback about Diamond’s Privacy Policy, submit questions or concerns or exercise their rights related to personal data by contacting:

Diamond Therapeutics

Attn: Privacy Inquiries

Diamond Therapeutics Inc.

410 Adelaide Street West, suite 220.

Toronto, ON, M5V 1S8

Email: info@diamondthera.com

HOW ARE DO NOT TRACK REQUESTS HANDLED?

Various browsers offer users an option known as a Do Not Track header that allows users to control the tracking of their online activities across websites. Each browser handles DNT trackers differently.

Diamond currently does not respond to Do Not Track requests because no DNT standard has been adopted and we cannot promise we will be able to receive or honor browser DNT signals.

CHILDREN’S PERSONAL INFORMATION

Diamond’s online presence and services are not directed to children under the age of 13. Diamond does not knowingly request or collect personal data from any individual under 13 years of age. If an individual suspects a child under the age of 13 has submitted personal information to Diamond, please contact Diamond as follows:

Diamond Therapeutics

Attn: Privacy Inquiries

Diamond Therapeutics Inc.

410 Adelaide Street West, suite 220.

Toronto, ON, M5V 1S8

Email: info@diamondthera.com

REVISIONS TO THIS PRIVACY POLICY

Diamond, from time to time, may make changes to this Privacy Policy. We will post any revised version of this Privacy Policy on our websites, and we encourage you to refer back to it on a regular basis.

EFFECTIVE DATE

This Policy is effective October 1, 2020.