Ascletis Website Privacy Notice

Please refer to the version published on the official website for the last updated date

Introduction

Ascletis Pharma (China) Co., Limited (of Room 1903, 19/F, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong, referred to as “Ascletis”, “We”, “Our” or “Us”) are committed to protecting the privacy and security of your Personal Data.

This Privacy Notice applies to you if you are:

We have developed this Privacy Notice to inform you of the data we collect, what we do with your information, what we do to keep it secure as well as the rights and choices you have over your Personal Data. It is important that you read this notice so that you are aware of how and why we are using such information.

Definitions

For the purposes of this Ascletis Privacy Notice:

Cookies are small files that are placed on Your computer, mobile device, or any other device by a website, containing the details of Your browsing history on that website among its many uses.

Data Controller, for the purposes of both UK and EU GDPR, refers to the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data. For the purpose of both UK and EU GDPR, Ascletis is the Data Controller. This definition also covers similar definitions in applicable Data Protection Legislation as outlined below.

Data Processor, for the purposes of both UK and EU GDPR, refers to Ascletis’ Service Providers. This definition also covers similar definitions in applicable Data Protection Legislation as outlined below.

Data Protection Legislation, as defined in the Data Protection Legislation section below.

Personal Data is any information that relates to an identified or identifiable natural person. For the purposes of both UK and EU GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity. This definition also covers similar definitions in applicable Data Protection Legislation as outlined below.

Service refers to the Website, unless otherwise stated.

Service Provider means any natural or legal person who processes the data on behalf of Ascletis. It refers to third-party companies or individuals employed by Ascletis to facilitate the Service, to provide the Service on behalf of Ascletis, to perform services related to the Service or to assist Ascletis in analysing how the Service is used. For the purpose of both UK and EU GDPR, Service Providers are considered Data Processors.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Website refers to the website, accessible from https://www.ascletis.com/

You means the individual accessing or using the Service, or Ascletis, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under both UK and EU GDPR (General Data Protection Regulation), You can be referred to as the Data Subject or as the User as you are the individual using the Service.

Data Protection Legislation

Throughout this document we refer to Data Protection Legislation.

European Union (EU) and European Economic Area (EEA)

In the context of the European Union (“EU”) and European Economic Area (“EEA”), Data Protection Legislation means the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) as well as any local data protection implementation laws. This includes any replacement legislation coming into effect from time to time.

United Kingdom

In the context of the United Kingdom (“UK”), Data Protection Legislation means the United Kingdom General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“DPA 2018”), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), the Data (Use and Access) Act 2025 (“DUAA”), and any legislation implemented in connection with the aforementioned legislation.

United States

In the context of the United States of America (“US”), Data Protection Legislation refers to any federal, state, sectoral, or case laws and regulations governing the privacy and security of personal data. This includes applicable state privacy legislation, including, but not limited to, the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), as well as other relevant state and federal regulations. This definition also encompasses any legislation implemented under these laws and any replacement or additional legislation enacted from time to time.

People’s Republic of China

In the context of the People’s Republic of China (“PRC”), Data Protection Legislation refers to the Personal Information Protection Law (“PIPL”), the Data Security Law (“DSL”), the Cybersecurity Law (“CSL”), as well as other relevant laws, regulations, and national standards which may apply on a sectoral basis. This definition also encompasses any legislation, regulations, measures, or rules, including those issued by the Cyberspace Administration of China (“CAC”) or other competent authorities, implemented under these laws and any replacement or additional legislation enacted from time to time.

In the context of the Hong Kong Special Administrative Region of the People’s Republic of China (“Hong Kong”), Data Protection Legislation refers to the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), as amended from time to time, together with its subsidiary legislation and the codes of practice, guidance notes, and other regulatory guidance issued by the Office of the Privacy Commissioner for Personal Data (“PCPD”), as well as other relevant ordinances, regulations, and standards which may apply on a sectoral basis. This definition also encompasses any legislation, regulations, measures, or rules implemented under these laws and any replacement or additional legislation enacted from time to time.

Other Jurisdictions

Depending on your jurisdiction, additional Data Protection Legislation may apply. If you have any questions, you can contact our DPO using the details in the Contact Us section below.

Data Controllership

Ascletis is the Data Controller (‘controller’) for the Personal Data we process, unless otherwise stated. We have appointed a Data Protection Officer (DPO) to help us monitor internal compliance, inform, and advise on data protection obligations, and act as a point of contact for data subjects and supervisory authorities. For further details on how you can contact our DPO, please see the Contact Us section below.

The information we collect

We only collect Personal Data that we know we will genuinely use and in accordance with the Data Protection Legislation and/or legislation related to clinical trials, such as Regulation (EU) No 536/2014 of the European Parliament and of the Council of 16 April 2014 on clinical trials on medicinal products for human use, and repealing Directive 2001/20/EC (Text with EEA relevance) (“EU CTR”) and/or The Medicines for Human Use (Clinical Trials) Regulations 2004 (as amended) (“UK CTR”). The type of Personal Data that we will collect on you will depend on whether you are a clinical trial participant, a healthcare professional, an employee, contractor, or consultant, or a user of this website:

Clinical Trial participant (inclusive of any parents, partners, and children)

Healthcare professional (HCP)

Employees, Consultants, and Contractors of Ascletis or Ascletis’ Service Providers

Website User

* This participant identifiable information is collected by Ascletis’ Research Sites, acting on their behalf as either Data Controllers or Data Processors. This data may be shared with clinicians, health authorities, ethics bodies and other personnel as authorized by Ascletis, but only where Ascletis is legally obligated to provide this data in accordance with Clinical Trial Regulations and other applicable laws. In certain circumstances, such as where Ascletis, their Contract Research Organization, and/or Trusted Data Processors inspect Research Sites and their activities, Ascletis or the relevant parties may have limited, temporary access to your identifiable medical records. However, in general, Ascletis will not directly receive participant identifiable information and will not instruct their Data Controllers and/or Data Processors to process or share this information other than where the law requires.

You are under no statutory or contractual requirement or obligation to provide us with your Personal Data; however, we require at least the information above in order for us to deal with you as a Service User in an efficient and effective manner.

Cookies, Analytics and Tracking Technologies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyse Our Service.

You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close your web browser. We use both session and persistent Cookies for the purposes set out below:

Tracking and Performance Cookies

Type: Persistent Cookies
Administered by: Third-Parties
Purpose: These Cookies are used to track information about traffic to the Website and how users use the Website. The information gathered via these Cookies may directly or indirectly identify you as an individual visitor. This is because the information collected is typically linked to a pseudonymous identifier associated with the device you use to access the Website. We may also use these Cookies to test new pages, features, or functionality of the Website to see how our users react to them.

Cookie NameCookie DescriptionCookie Type
HM_lpvt_[xxx]; HM_lvt_[xxx]; HMACCOUNT; HMACCOUNT_BFESSBaidu cookies used for analytics purposes.Tracking and Performance Cookies

We and the third parties we work with use cookies and similar tracking technologies to collect information about your use of the Services, such as your IP address, browser type, browser version, pages viewed, time spent on pages, links clicked and conversion information. This information may be used by us and others to, among other things, analyse and track data, determine the popularity of certain content, deliver advertising and content targeted to your interests on the Services and other websites, provide customer support, troubleshoot issues with and improve the operation of our Website and Services, and better understand your online activity.

How we use your information

We may use your information for the following purposes:

Where applicable, the GDPR Lawful Basis and Special Category Personal Data ConditionPurpose
Your Consent
GDPR, Article 6(1)(a)
GDPR, Article 9(2)(a)
Clinical Trial Operations (Your Consent)
Where you are a clinical trial participant in a jurisdiction where clinical trials occur on the lawful basis of Consent, or where you have consented to Future Research, to collect information from you and process your health information in order to conduct a clinical trial
Our Legitimate Interest in conducting scientific research
GDPR, Article 6(1)(f)
GDPR, Article 9(2)(j)
Clinical Trial Operations (Legitimate Interest)
Where you are a clinical trial participant in a jurisdiction where clinical trials occur on the lawful basis of Legitimate Interest, to collect information from you and process your health information in order to conduct a clinical trial.
Legal Obligation to comply with applicable Clinical Trial Law
GDPR, Article 6(1)(c)
GDPR, Article 9(2)(j)
Clinical Trial Compliance
Where you are a clinical trial participant in a jurisdiction where clinical trial regulations require sponsors to conduct certain activities, such as safety reporting, to collect information from you and process your health information in order to safely conduct a clinical trial and meet our legal obligations regarding clinical trial regulations.
Our Legitimate Interest in conducting clinical activities
GDPR, Article 6(1)(f)
Research Operations (Healthcare Professional Administration)
Where you are a Health Care Professional (HCP) involved in the planning, delivery, or oversight of Ascletis clinical trials, to collect information from you and process your employment information in order to conduct a clinical trial.
Contractual Obligation
GDPR, Article 6(1)(b)
Employment
Where you are an employee, contractor, or consultant of Ascletis, to collect information from you and make available our Services to you for the purposes of fulfilling our contractual obligations with you.
Our Legitimate Interest in managing our affairs
GDPR, Article 6(1)(f)
Service Providers (Legitimate Interest)
Where you are an employee, contractor, or consultant of Ascletis’ Service Providers, to collect information from you or your employer and make available our Services to your employer.
Contractual Obligation
GDPR, Article 6(1)(b)
Service Providers (Contractual Obligation)
Where you are an employee, contractor, or consultant of Ascletis’ Service Providers, to collect information from you and take payment from you, make a payment to you, give you a refund or request a refund.
Our Legitimate Interest in managing our affairs
GDPR, Article 6(1)(f)
Service Providers (Performance)
Where you are an employee, contractor, or consultant of Ascletis’ Service Providers, to collect information from you or your employer and liaise with your employer about your contact details and/or the nature and performance of your work, as required.
Our Legitimate Interest in providing Services to you
GDPR, Article 6(1)(f)
Service Provision
To collect information from you and monitor, provide and maintain our Services.
Our Legitimate Interest in providing Services to you
GDPR, Article 6(1)(f)
Inquiries
To contact you following your inquiry where you have provided your contact information and to reply to any questions, suggestions, issues, or complaints, including any Data Subject Requests, about which you have contacted us.
Our Legitimate Interest in providing a secure platform
GDPR, Article 6(1)(f)
Security
To collect your Usage Data in order to power our security measures and Services so you can safely access our website and other Services.
Our Legitimate Interest in contacting you about our Services
GDPR, Article 6(1)(f)
Service Messages
To contact you, where you have provided your contact information, about news and information relating to our Services through Service messages.
Our Legitimate Interest in marketing our Services to you
GDPR, Article 6(1)(f)
Direct Marketing (Legitimate Interest)
B2B direct marketing to you, where you have provided your contact information, about Services from us where you are classified as a corporate subscriber and/or the ‘soft opt-in’ applies under the UK PECR and/or EU ePrivacy legislation.
Your Consent
GDPR, Article 6(1)(a)
Direct Marketing (Consent)
B2B direct marketing to you, where you have provided your contact information, about Services from us where you are a sole trader, partnership or otherwise classified as an individual subscriber and/or the ‘soft opt-in’ does not apply under UK PECR and/or EU ePrivacy legislation.
Vital Interest
GDPR, Article 6(1)(d)
GDPR, Article 9(2)(c)
Vital Interest
Monitor your health in order to safeguard and protect you, or to act in your vital interest, or the vital interest of a third party.
Legal Obligation, including, but not limited to, our Legal Obligation to comply with Employment Law
GDPR, Article 6(1)(c)
GDPR, Article 9(2)(b)
Legal Obligation
To comply with our legal obligations, such as retaining any accounting information generated during the course of our interaction for statutory accountancy retention periods.
Our Legitimate Interest in managing any legal claims
GDPR, Article 6(1)(f)
GDPR, Article 9(2)(f)
Legal Claims
To respond to and defend against legal claims, where you have provided us with information which may give rise to legal claims.

Within the context of the People’s Republic of China, including, for these purposes, Hong Kong, we will process your Personal Data where you have consented to this processing, or where we are otherwise permitted to do so under applicable laws and/or required by applicable laws.

We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.

If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your Personal Data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

Criminal convictions and offences data

Where you are an employee, contractor, or consultant for Ascletis, or a healthcare professional working on one of Ascletis’ clinical trials – or you are a candidate for such a role – and depending on the jurisdiction in which you operate and on the specific role in question, we may collect information about your criminal convictions and offences. We do this to satisfy ourselves that there is nothing in your criminal convictions and offences history which makes you unsuitable for the role. Our roles require a high degree of trust and integrity, and it is therefore best practice to undertake such checks and a pre-requisite in some instances.

We will only collect and use information relating to criminal convictions where the law allows us to do so. This will usually be where such processing is necessary to carry out our obligations, or where we have an overriding legitimate interest to do so and provided we do so in line with our Data Protection Policy. We have in place appropriate policies and safeguards which we are required by law to maintain when processing such data.

Automated technologies and AI use

As part of our ongoing efforts to improve the efficiency and quality of our research and clinical trial activities, we may use artificial intelligence (AI) tools (“AI tools”) to support data analysis, communication, and system functionality.

Where AI tools are used, we take steps to ensure that personal data is minimised, protected, and processed in accordance with applicable data protection law, and we do not intentionally submit personal data to publicly available AI models without appropriate safeguards.

Our use of AI tools for processing your personal data is carried out on the basis of our Legitimate Interests to conduct clinical research. We balance our interests against your data protection rights and apply appropriate safeguards to protect your personal data.

If you have any questions or concerns about this processing, please contact our Data Protection Officer on the contact email address set out in the Contact Us section.

Who we might share your information with

We may share your personal data with other organizations in the following circumstances:

We use Service Providers (“Data Processors”) who are third parties who provide elements of services for us. Examples of these Data Processors include, but are not limited to:

We have Data Processor Agreements in place with our data processors. This means that they cannot do anything with your Personal Data unless we have instructed them to do it. They will not share your Personal Data with any organization apart from us or further sub-processors who must comply with our Data Processor Agreement. They will hold your Personal Data securely and retain it for the period we instruct.

How long we keep your information for

We retain a record of your Personal Data in order to provide you with a high quality and consistent service. We will retain your Personal Data in accordance with the Data Protection Legislation and retain your information for longer than is necessary. Where relevant Data Protection Legislation applies, Ascletis follows a Retention Schedule which outlines how long Ascletis will retain your Personal Data. Ascletis considers the retention period to begin from the point at which Ascletis last contacted you or otherwise reviewed your record to determine whether it was still active, or from the end of the applicable study, contract, or legal obligation, whichever is later, unless otherwise required by law. As such, relevant Data Protection Legislation applies, unless otherwise required by law, your data will be retained for the period specified in the summarized table below and then securely deleted in accordance with our internal policies and procedures.

PurposeRetention Period
Processing data in relation to You as a clinical trial participant25 years following the conclusion of the clinical trial, as determined by the EU CTR and/or UK CTR
Processing data in relation to You as a Health Care Professional (HCP) involved in the planning, delivery, or oversight of an Ascletis’ clinical trial25 years following the conclusion of the clinical trial, as determined by the EU CTR and/or UK CTR
Processing data in relation to You as an employee, contractor or other associated party contracted by Ascletis6 years following the termination of your employment
Processing data in relation to You as an employee, contractor or other associated party contracted by Ascletis’ Service Providers6 years following the termination of your employment
Processing data in relation to You as a service user of this website1 year
Processing data in relation to You as any other individual with whom Ascletis may conduct commercial operations6 years

How we keep you updated on our products and services

Where you are a clinical trial participant or a Health Care Professional involved in the planning, delivery, or oversight of an Ascletis clinical trial, we will contact you through our Contracted Research Organization (CRO) where it is necessary to do so.

Where you are an employee of Ascletis, we will contact you through existing Ascletis communication channels, including email, where it is appropriate to do so.

Where you are an employee of Ascletis’ Service Providers, a user of this website who has provided us with your contact information, or any other business contact, we will send you relevant news about our services in a number of ways including by email, but only if we have a Legitimate Interest to do so. Where we do not have a Legitimate Interest, we will not send you marketing communications unless we have asked for, and gained, your consent.

We make every effort to ensure that we only send such communications to those acting in a business capacity and do not send such materials to consumers via personal email addresses if it is clear they are not acting in such a capacity or have not otherwise provided their consent.

Email communications may have an option to unsubscribe – if you wish to amend your marketing preferences, you can do so by following the link in the email and updating your preferences. Alternatively, you can contact our DPO using the contact details provided in the Contact Us section below.

Security

We have put in place appropriate technical and organizational measures to prevent your Personal Data from being accidently lost, used, or accessed in an unauthorized way, altered, or disclosed.

We take security measures to protect your information including:

International Transfers

Your Personal Data is processed at Ascletis’ operating offices in the People’s Republic of China and the United States, and in any other places where the parties involved in the processing are located. This means that this information may be transferred outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction. In particular, when Ascletis shares clinical trials data with Trusted Data Processors, your Personal Data would be stored and processed within third countries. Where EU GDPR and/or UK GDPR apply, Ascletis will ensure that:

Where EU GDPR or UK GDPR applies and we transfer your Personal Data outside of the EEA or UK, as applicable, to countries not deemed by the European Commission or UK government, as relevant, to provide an adequate level of Personal Data protection, the transfer will be based on safeguards that allow us to conduct the transfer in accordance with the Data Protection Legislation, such as the specific contracts containing standard data protection clauses approved by the European Commission or UK government, as relevant, providing adequate protection of Personal Data. You can obtain a copy of this documentation by contacting our DPO identified in the Contact Us section below.

In other cases, we may seek your explicit consent to internationally transfer your Personal Data. If we do so, we will provide you with more information relating to the transfer at the time.

Where applicable, where we transfer your Personal Data outside of the PRC, and where no exemptions apply under applicable Data Protection Legislation, we will enter into the standard contractual clauses appended to the “Standard Contractual Measures for Cross-border Transfer of Personal Information” (the “Chinese SCCs”), as required.

What happens if our business changes hands?

We may, from time to time, expand or reduce our business and this may involve the sale and/or the transfer of control of all or part of our business. Any personal data that you have provided will, where it is relevant to any part of our business that is being transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this Privacy Notice, be permitted to use that data only for the purposes for which it was originally collected by us.

Third Party websites and links

Our Website may contain links to other sites operated by third parties. Ascletis does not control such other sites and is not responsible for their content, their privacy policies, or their use of personal information. Ascletis’ inclusion of such links does not imply any endorsement of the content on such sites or of their owners or operators except as disclosed through the Services. Any information submitted by you directly to these third parties is subject to that third party’s privacy policy.

We expressly disclaim any and all liability for the actions of third parties, including but without limitation to actions relating to the use and/or disclosure of personal information by third parties.

Children’s privacy

Notwithstanding where we may process the Personal Data of the children of clinical trial participants in order to meet our obligations under clinical trial legislation, such as in the event that a participant or their partner becomes pregnant during the course of a clinical trial, we do not seek or knowingly collect any personal information about children under 13 years of age. If we become aware that we have unknowingly collected personal information from a child under the age of 13, we will make commercially reasonable efforts to delete such information from our database.

If you are the parent or guardian of a minor child who has provided us with personal information, you may contact us using the information below to request it be deleted.

Your rights over your information

Where EU GDPR and UK GDPR apply, you have certain following rights over your Personal Data. For your protection, and to protect the privacy of others, we may need to verify your identity before completing what you have asked us to do. If you would like to exercise these rights, or if you would like more information about your rights or have any concerns about how we process your personal information, please Contact Us as set out below.

European Union (EU), European Economic Area (EEA) and United Kingdom (UK)

Where EU GDPR and UK GDPR apply, you have certain following rights over your Personal Data. For your protection, and to protect the privacy of others, we may need to verify your identity before completing what you have asked us to do. If you would like to exercise these rights, or if you would like more information about your rights or have any concerns about how we process your personal information, please Contact Us as set out below.

The right to be informed about our collection and use of personal data;

You have the right to be informed about the collection and use of your personal data. We ensure we do this with our internal and external Privacy Notices (including this document). These are regularly reviewed and updated to ensure these are accurate and reflect our data processing activities.

Right to Access Your Personal Data

You have the right to access the Personal Data that we hold about you in many circumstances, by making a request. This is sometimes termed ‘Data Subject Access Request’. If we agree that we are obliged to provide Personal Data to you (or someone else on your behalf), we will provide it to you or them free of charge and aim to do so within 1 month from when your identity has been confirmed.

If your request is particularly complex, we may extend this response window to a total of 3 months. We would ask for proof of identity and sufficient information about your interactions with us that we can locate your Personal Data.

Right to Rectify Your Personal Data

If any of the Personal Data we hold about you is inaccurate, incomplete, or out of date, you may ask us to correct it. If we shared your Personal Data with others, we will tell them about the correction where possible.

Right to Erasure

You have the right to have personal data erased. This is also known as the ‘right to be forgotten’. The right is not absolute and only applies in certain circumstances. For instance, the right to erasure does not apply where we have a legal obligation to retain your Personal Data. If we shared your data with others, we will alert them to the need for erasure where possible.

Right to Restrict Processing

You have the right to ask us to restrict the processing of your personal data. For example, this may be because you have issues with the accuracy of the data we hold or the way we have processed your data. The right is not absolute and only applies in certain circumstances. We will tell you before we lift any restriction on processing. If we shared your Personal Data with others, we will tell them about the restriction where possible.

Right to Portability

The right to portability gives you the right to receive personal data you have provided to a controller in a structured, commonly used, and machine-readable format, where the lawful basis for processing relies upon consent or a contract entered into with you. It also gives them you the right to request that a controller transmits this data directly to another controller.

Right to Object

You have the right to object to our processing of some or all of the personal data that we hold about you. This is an absolute right when we use your data for direct marketing but may not apply in other circumstances where we have a compelling reason to do so, e.g., a legal obligation.

Rights Related to Automated Decision-Making

You have the right to object to our processing where a decision is made about you solely based upon automated processed and which has significant or legal effects. Ascletis does not intend to conduct any automated decision-making for your Personal Data. You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have otherwise notified you.

Right to Withdraw Consent

Where the lawful basis for processing is your consent, you have the right to withdraw your consent at any time.

Right to Lodge a Complaint

Where you are in the EU or EEA, you can lodge a complaint with your country’s regulatory body here: https://edpb.europa.eu/about-edpb/about-edpb/members_en. If you have any questions about which supervisory authority applies in your jurisdiction, please Contact Us as set out below.

In the UK, the Information Commissioner’s Office (ICO) regulates data protection and privacy matters. They make a lot of information accessible to consumers on their website, which you can access here: https://ico.org.uk/for-the-public.

Where you are in the UK, you have the right to lodge a complaint with us at any time. If you choose to do so, Contact Us as set out below. We will acknowledge your complaint, investigate and respond in line with our legal obligations. If you are not satisfied with our response or the outcome, you may also complain to the ICO.

In any case, you can lodge a complaint with the ICO about the way we use your information. However, we hope that you would consider raising any issue or complaint you have with us first. Your satisfaction is extremely important to us, and we will always do our very best to solve any problems you may have.

United States

California Data Protection Legislation

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (“CCPA”) requires that we provide you with a privacy policy of our online and offline information practices and your rights under this law regarding your personal information.

We currently collect, share, disclose, and use your personal information. In the 12 months prior to the last updated date of this Privacy Notice, we have collected, shared, disclosed the personal information set out in this Privacy Notice. We may collect personal information directly from California and other US state residents, credit reporting agencies, and/or our third-party service providers. We do not collect all categories of personal information from each source.

California Resident Rights

California residents are afforded the following rights:

  • to delete your personal information, unless we:
    • can prove this to be impossible;
    • it involves disproportionate effort; or
    • it is reasonably necessary for us to maintain records in order to fulfil the transaction(s) for which the personal information was collected;
  • to correct inaccurate personal information held about you;
  • to know what personal information is sold or shared and to whom (this right is fulfilled with the information provided within this Notice);
  • to request specific pieces of information from us;
  • to opt out of the sale or sharing of your personal information;
  • to limit use and disclosure of sensitive personal data; and,
  • to no retaliation following opt-out or exercise of other rights.

If you would like to contact us regarding any of these rights, please Contact Us as set out below. Please note that we may need to verify your identity before processing your request. Rights requests shall be reviewed to see if an exemption allows us to retain the information. We may deny your deletion request if an exemption applies and/or if retaining the information is necessary for us or our Service Provider(s), for example to detect fraudulent activity or comply with a legal obligation. We will delete, de-identify or limit the scope of personal information not subject to an exemption from our records and will direct our Service Providers to take similar action.

Other US Data Protection Legislation

If you are a US resident, we process your personal data in accordance with applicable privacy laws. Several US states have enacted comprehensive privacy statutes, including but not limited to Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. These laws include provisions aimed at safeguarding consumer rights and outlining business obligations. If you have relevant rights under these laws, you can exercise them by contacting us using the details provided in the Contact Us section as set out below.

Our practices are designed to adhere to the highest standards set forth by these laws, ensuring that we respect the privacy rights of all individuals. As the US privacy laws continue to evolve, we will monitor these changes, adjust our privacy practices, and update our Privacy Notice(s), accordingly.

We Do Not Sell Your Personal Information

You have the right to know whether your personal information is being sold. Your personal information is “sold” when it is provided to a third party for monetary or other valuable consideration for a purpose that is not a “business purpose” as set forth in the CCPA or other US state data privacy laws.

Please note a “sale” does not include when we disclose your personal information at your direction, or when otherwise permitted under law.

We May Share Your Personal Information

We may “share” your personal data, as defined under California and other applicable US state laws, for personalised advertising purposes and/or for any other purposes outlined in this Privacy Notice.

Do Not Track

Due to varying practices among browser providers and the lack of a market standard, we do not respond to Do Not Track signals at this time.

Non-Discrimination

US state privacy laws prohibit businesses from discriminating against you for exercising your rights under the law. Such discrimination may include denying goods or services, providing a different level or quality of service, or charging different prices.

The CCPA permits businesses to provide differing levels or quality or different prices where the business can demonstrate that the difference is reasonably related to the value to the business of the consumer’s personal information.

People’s Republic of China (mainland)

Under the Personal Information Protection Law (“PIPL”), you have the following rights in relation to your personal information:

Right to be informed

— to receive clear information about the processing of your personal information, including the identity and contact details of the organisation processing your personal information, the purposes and methods of processing, the categories of personal information processed, retention periods, how you may exercise your rights, and other matters required by law.

Right to consent (and to withhold or withdraw it)

— to decide whether to consent to the processing of your personal information where consent is required, and to withdraw consent at any time, including separate consent for certain processing activities such as the processing of sensitive personal information or cross-border transfers. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Right of access and copy

— to request access to and obtain a copy of your personal information held by an organisation, subject to limited legal exceptions.

Right to rectification

— to request correction or supplementation of inaccurate or incomplete personal information.

Right to erasure

— to request deletion of your personal information, except where retention is required by law.

Right to restrict or refuse processing

— to request to restrict or refuse the processing of your personal information, except where otherwise provided by applicable laws or administrative regulations.

Right to request an explanation of processing rules

— to request an explanation of the rules governing the processing of your personal information.

Right to data portability

— to request that we (as a data controller) transmit your personal data directly to another controller in certain circumstances.

Rights regarding automated decision-making

— to request an explanation of, and in certain cases to refuse, decisions made solely by fully automated systems that significantly affect you.

Right to be notified of cross-border transfers

— to be informed of overseas recipients, the purposes and methods of processing, the categories of personal information transferred, and the methods for exercising your rights before your personal information is transferred outside the People’s Republic of China, and to provide separate consent where required by law.

Right to designate a representative

— to exercise the above rights through a legal representative or duly authorised agent.

Right to lodge a complaint and seek judicial remedy

— to file a complaint with the relevant Chinese regulatory authorities, including the Cyberspace Administration of China (“CAC”), and to bring legal proceedings where your personal information rights and interests have been infringed.

Right of deceased persons’ close relatives

— in the event of your death, your close relatives may, for their lawful and legitimate interests, exercise rights to access, copy, correct, or delete your relevant personal information, unless otherwise arranged before your death.

Where applicable, you can exercise these rights by contacting us using the details provided in the Contact Us section as set out below.

People’s Republic of China (Hong Kong)

Under the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), you have the following rights in relation to your personal data:

Right to be informed

— to be told, on or before the collection of your personal data, of the purpose for which it is collected, the classes of persons to whom it may be transferred, whether the supply of data is obligatory or voluntary (and any consequences of failing to supply it), and your rights to request access to and correction of your data, together with the details of the individual to whom such requests may be made. You are also entitled to be informed, on request, of our policies and practices in relation to personal data and the kinds of data we hold.

Right of access

— to ascertain whether we hold your personal data and, if so, to be supplied with a copy, by making a data access request. We will ordinarily comply within 40 days of receiving the request, we may charge a fee that is not excessive, and we may only refuse in certain circumstances.

Right of correction

— to request correction of your personal data where you consider it inaccurate. Where the data is inaccurate, we must make the correction and supply a copy of the corrected data within 40 days; if we cannot comply within that period, we must inform you in writing and give reasons within the period, then comply as soon as reasonably practicable thereafter.

Right to opt out of direct marketing

— to be notified before your personal data is first used for direct marketing and to require us, without charge, to cease such use at any time.

Right in relation to retention and erasure

— to expect that your personal data is not kept longer than necessary for the purpose for which it is used. Please note that we will take all practicable steps to erase data no longer required, unless erasure is prohibited by law or is not in the public interest.

Right to make a complaint

— to lodge a complaint with the PCPD.

Right to compensation and judicial remedy

— to seek compensation through civil proceedings for damage, including injury to feelings, suffered by reason of a contravention of the PDPO; aggrieved individuals may also apply to the PCPD for assistance, including legal assistance, in such proceedings.

Right to act through a relevant person or agent

— to exercise the above rights, in defined circumstances, through a relevant person (for example, a person with parental responsibility for a minor, or a person appointed to manage the affairs of an individual unable to do so) or a duly authorised agent.

Where applicable, you can exercise these rights by contacting us using the details provided in the Contact Us section as set out below.

Other Data Protection Legislation

If you are located in another jurisdiction outside of the EU, EEA, UK, US and PRC (including Hong Kong), you may have data protection rights available to you under the applicable Data Protection Legislation of your jurisdiction, such as the right of access, rectification, and/or erasure. If you have relevant rights under these laws, you can exercise them by contacting us using the details provided in the Contact Us section as set out below.

Contact Us

If you would like to exercise one of your rights as set out above, or you have a question or a complaint about this Privacy Notice or the way your Personal Data is processed, please contact our Data Protection Officer (DPO) by emailing dpo@ascletis.com.

Our EU GDPR Representative is The DPO Centre Europe Limited, who can be contacted via emailing eurep@ascletis.com.

Our UK GDPR Representative is The DPO Centre Limited, who can be contacted via emailing ukrep@ascletis.com.

Changes to Our Privacy Notice

Thank you for taking the time to read our Privacy Notice.

We may change this Privacy Notice from time to time (for example, if the law changes). We recommend that you check this Privacy Notice regularly to keep up-to-date.