Atara complies with the requirements of the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework (collectively “Privacy Shield”), as set forth by the U.S. Department of Commerce and the Federal Trade Commission (“FTC”), regarding the collection, use, and retention of Personal Information transferred from the European Economic Area and Switzerland to the United States. Atara has certified to the Department of Commerce that it adheres to the Privacy Shield Principles and Supplemental Principles. If there is any conflict between the terms in this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view Atara’s certification, please visit https:// www.privacyshield.gov. Additionally, Atara may protect information through other legally valid methods, including international data transfer agreements.
This Policy applies to all Atara operating divisions, subsidiaries, affiliates, and branches, including its U.S. affiliates certified under the Privacy Shield and any additional subsidiary, affiliate, or branch of Atara that we may subsequently form.
2.0 Transparency/Notice–What Personal Information We Collect and How We Use It
The types of Personal Information we may collect (directly from you or from Third Party-sources) and our privacy practices depend on the nature of the relationship you have with Atara and the requirements of applicable law. We endeavor to collect information only relevant for the purposes of Processing. Below are the legal bases and some of the ways we collect information and how we use it.
Atara collects Personal Information regarding its current, prospective and former clients, Employees, customers, patients, visitors and guests (collectively “Individuals”).
2.2 Information Atara Collects
The data we collect from or about Individuals includes information that may be deemed Personal Information, such as title, name, address, phone number, email address, user name, government identification (e.g., driver’s license, passport), photo or image and Internet Protocol address, professional experience, educational background, nationality, ethnic origin, gender, interests, preferences and favorites. We may also collect other information that is not Personal information, such as demographic information you choose to provide (e.g., your business, company or institutional information) and answers to a security question and password.
In addition, if you participate in certain Atara programs or services, we may collect information regarding your medications, medical state and history and other healthcare-related information, including, without limitation, Protected Health Information (collectively, “Health Information”), from Individuals or indirectly from a Third Party. For example, we may indirectly collect information about your health condition, diagnosis, and treatment from your healthcare professional, but only where your healthcare professional has obtained your consent to disclose that information to us, as required by law. Any Health Information that is tied to an Individual’s Personal Information will be treated as Personal Information and will be protected in accordance with the applicable laws in North America, Europe, APAC, and other jurisdictions. Protected Health Information will be also protected in accordance with the requirements of HIPAA.
2.3 How Atara Collects Personal Information
Some of the ways that Atara may collect your Personal Information include:
- Atara may, to the extent permitted by law, collect Personal Information from you through various channels, including the Websites, in surveys, during business or marketing events, and when delivering programs and services to you.
- When you use the Websites, Atara may provide you with opportunities to sign up to receive specific information or services and may ask for your contact information (e.g. name, home/contact address, home/contact phone number or personal/contact email address), so that we can send you specific information about our products, services and specific health conditions, with your consent.
- When you enroll in a program that Atara offers, we may obtain your contact information, details of your health condition, and prescribing information relating to our products.
- Atara is also obligated to collect certain Personal Information to comply with regulatory requirements, including information relating to adverse effects you have experienced when using our products.
- Atara may indirectly collect information about your health condition, diagnosis, and treatment from your healthcare professional, but only where your healthcare professional has obtained your consent to disclose that information to us, as required by law.
- Atara may, to the extent permitted by law, collect various information from healthcare professionals as part of marketing or educational activities to healthcare professionals, including first name, last name, age, gender, home/contact address, home/contact phone number, medical specialization, professional qualifications, license number and scientific society membership number.
- As you navigate the Websites, certain passive information may also be collected, including Internet Protocol addresses, cookies, navigational data, the name of the domain and host from which you access the Internet, the browser software you use and your operating system, the date and time you access our Websites, and the Internet address of the website from which you linked directly to our Websites. This type of information is used for the purposes of gathering data to provide improved administration of our Websites, and to improve the quality of your experience when interacting with our Websites.
2.4 Information from Third-Party Sources
Atara may collect information about you from Third-Party sources to supplement information provided by you. This supplemental information allows us to verify information that you have provided to Atara and to enhance our ability to provide you with information about our business, products and services. Atara’s agreements with these Third Party-sources typically limit how the Company may use this supplemental information.
2.5 Research/Survey Solicitations
From time to time, Atara may perform research (online and offline) via surveys. We may engage Third Party-service providers to conduct such surveys on our behalf. All survey responses are voluntary, and the information collected will be used for research and reporting purposes to help us better serve Individuals by learning more about their needs and the quality of the products and services we provide. The survey responses may be utilized to determine the effectiveness of our Websites, various types of communications, advertising campaigns and/or promotional activities. If an Individual participates in a survey, the information given will be used along with that of other study participants. We may share anonymous individual and aggregate data for research and analysis purposes.
2.6 How Atara Uses Your Personal Information
Depending on how you interact with Atara, we and our Third Party-service providers may also use Personal Information in a variety of ways, including:
- Providing Information and Services You Requested. Atara may use the Personal Information about you to provide you information that you may request, e.g. information about a product or program we are offering. Atara may also use your Personal Information to deliver a specific program or service to you, when you enroll to receive the program or service. Such use may include: (a) generally managing your information and accounts; (b) responding to questions, comments and requests; (c) providing access to certain areas and features of the Atara Websites; and (d) permitting you to register for events or participate in webinars or other events.
- Marketing Products and Services. Atara may use the Personal Information about you to provide you with materials about offers, products and services offered by us, including new content or services on Atara Websites. Atara may provide you with these materials by phone, postal mail, facsimile or email, as permitted by applicable law. If you do not wish us to use your Personal Information for marketing purposes, you may contact us at any time to opt out of the use of your Personal Information for such purposes, as further described below.
- Research and Development. Atara may use your Personal Information to create non-identifiable information that we may use alone or in the aggregate with information obtained from other sources, in order to help us to optimally deliver our existing products and services or develop new products, processes and services.
- Information Submitted Via Websites. You agree that Atara is free to use the content of any communications or other information submitted by you via the Websites, including any narratives, images, ideas, inventions, concepts, techniques, or know-how disclosed therein, for any purpose including developing, manufacturing, and/or marketing goods or services. However, Atara does not release your name or otherwise publicize the fact that you submitted materials or other information to us unless: (a) you grant us permission to do so; (b) we first send notice to you that the materials or other information you submit to a particular part of a site will be published or otherwise used with your name on it; or (c) we are required to do so by law.
- Other Uses. Atara may use Personal Information for which we have a legitimate interest, such as direct marketing, individual or market research, anti-fraud protection, or any other purpose disclosed to you at the time you provide Personal Information or with your consent.
2.7 Human Resources Data
Atara collects Personal Information from current, prospective and former Employees, their contact points in case of a medical emergency, and beneficiaries under any insurance policy (“Human Resources Data”). The Human Resources Data we collect may include title, name, address, phone number, email address, date of birth, passport number, driver’s license number, Social Security number or other government-issued identification number, financial information related to credit checks, bank details for payroll, information that may be recorded on a CV or application form, language abilities, contact information of third parties in case of an emergency and beneficiaries under any insurance policy. We may also collect Sensitive Human Resources Data such as details of health and disability, including mental health, medical leave, and maternity leave.
We acquire, hold, use and Process Human Resources-related Personal Information for a variety of business purposes including:
- workflow management, assigning, managing and administering projects;
- Human Resources administration and communication;
- payroll and the provision of benefits;
- compensation, including bonuses and long-term incentive administration, stock plan administration, compensation analysis, including monitoring overtime and compliance with labor laws, and company recognition programs;
- job grading activities;
- performance and employee development management;
- organizational development and succession planning;
- benefits and personnel administration;
- absence management;
- helpdesk and IT support services;
- regulatory compliance;
- internal and/or external or governmental compliance investigations;
- internal or external audits;
- litigation evaluation, prosecution and defense;
- diversity and inclusion initiatives;
- restructuring and relocation;
- emergency contacts and services;
- Employee safety;
- Security of corporate data and messaging
- compliance with statutory requirements;
- Processing of Employee expenses and travel charges; and
- acquisitions, divestitures and integrations.
2.8 Social Media
Atara may collect Personal Information to enable Data Subjects to use online social media resources offered either by Atara or a Third Party. We may also enable you to use these social media resources to post or share Personal Information with others. When using social media resources, you should take into careful consideration what Personal Information you share with others.
2.9 Direct Mail, Email and Outbound Telemarketing
Individuals who provide us with Personal Information, or whose Personal Information we obtain from Third Parties, may receive periodic emails, newsletters, mailings or phone calls from us with information on Atara or our business partners’ products and services or upcoming special offers/events we believe may be of interest. We offer the option to decline these communications at no cost to the individual by following the instructions in Section 3 below.
2.10 All Internet Users – Cookies, Pixel Tags/Web Beacons, Analytics Information, and Interest-Based Advertising
- Cookies. Cookies are small text files placed in visitors’ computer browsers to store their preferences. Most browsers allow you to block and delete cookies. However, if you do that, the Site may not work properly.
- Pixel Tags/Web Beacons. A pixel tag (also known as a web beacon) is a piece of code embedded on the Site that collects information about users’ engagement on that web page. The use of a pixel allows us to record, for example, that a user has visited a particular web page or clicked on a particular advertisement.
- Analytics. We may also use Google Analytics and Google Analytics Demographics and Interest Reporting to collect information regarding visitor behavior and visitor demographics on some of our Services, and to develop website content. This analytics data is not tied to any Personal Information. For more information about Google Analytics, please visit google.com/policies/privacy/partners/. You can opt out of Google’s collection and Processing of data generated by your use of the Services by going to http://tools.google.com/dlpage/gaoptout.
Our uses of such Technologies fall into the following general categories:
- Advertising or Targeting Related.We may use first-party or third-party cookies and web beacons to deliver content, including ads relevant to your interests, on our sites or on third party sites. This includes using technologies to understand the usefulness to you of the advertisements and content that has been delivered to you, such as whether you have clicked on an advertisement.
If you would like to opt out of the Technologies we employ on our sites, services, applications, or tools, you may do so by blocking, deleting, or disabling them as your browser or device permits.
2.11 Mobile Devices
Atara may provide websites and online resources that are specifically designed to be compatible and used on mobile devices. Atara will collect certain information that your mobile device sends when you use such websites or online resources, like a device identifier, user settings and the operating system of your device.
2.12 Anonymous and Aggregated Information
Atara may use your Personal Information and other information about you to create anonymized and aggregated information, such as de-identified demographic information, de-identified location information, information about the computer or device from which you access the Atara Website or other online services, or other analyses we create. Anonymized and aggregated information is used for a variety of functions, including the measurement of visitors’ interest in and use of various portions or features of the Websites. Anonymized or aggregated information is not Personal Information, and Atara may use such information in a number of ways, including research, internal analysis, analytics and any other legally permissible purposes. We may share this information within Atara and with Third Parties for our or their purposes in an anonymized or aggregated form that is designed to prevent anyone from identifying you.
3.0 Choice/Modalities to Opt Out
Where you have consented to Atara’s Processing of your Personal Information or Sensitive Personal Information, you may withdraw that consent at any time and opt out by following the instructions in this Section 3. Additionally, before we use Personal Information for any new purpose not originally authorized by you, we will provide information regarding the new purpose and give you the opportunity to opt in.
Prior to disclosing Sensitive Data to a Third Party or Processing Sensitive Data for a purpose other than its original purpose or the purpose authorized subsequently by the Data Subject, Atara will endeavor to obtain each Data Subject’s explicit consent (opt-in). Where consent of the Data Subject for the Processing of Personal Information is otherwise required by law or contract, Atara will comply with the law or contract.
3.2 Email and Telephone Communications
We maintain telephone “do not call” lists and “do not mail” lists as mandated by law. We process requests to be placed on do not mail, do not phone and do not contact lists within 60 days after receipt, or such shorter time as may be required by law.
3.3 Human Resources Data
With regard to Personal Information that Atara receives in connection with the employment relationship, Atara will use such Personal Information only for employment-related purposes as more fully described in section 2.3 above. If Atara intends to use this Personal Information for any other purpose, the Company will provide the Individual with an opportunity to consent to such new purposed and to opt in.
3.4 “Do Not Track”
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Atara does not recognize or respond to browser-initiated DNT signals. For information about “do-not-track”, visit http://www.allaboutdnt.org.
3.5 Advertising Choices
For more information regarding the collection and use of such information by Facebook, please see the Facebook Data Policy, available at: https://www.facebook.com/policy.php.
You can opt out of the collection and use of your information for interest-based advertising by going to http://optout.aboutads.info or http://www.youronlinechoices.eu/ to limit collection through the Website or by configuring the settings on your mobile device to limit ad tracking through the mobile applications.
Even if you opt-out, we may still collect and use non-Personal Information regarding your activities on our Websites and/or information from the advertisements on Third-Party websites for non-interest based advertising purposes, such as to determine the effectiveness of the advertisements.
4.0 Onward Transfer
4.1 Information We Share
4.1.1 Service Providers
Atara may share Personal Information with our service providers that we have retained to perform services on our behalf including (i) provision of IT and related services; (ii) provision of information and services you have requested; (iii) payment processing; and (iv) customer service activities. Payment information will be used and shared only to effectuate your order and may be stored by a service provider for purposes of future orders.
Atara has executed appropriate contracts with the service providers that prohibit them from using or sharing your Personal Information except as necessary to perform the contracted services on our behalf or to comply with applicable legal requirements.
4.1.2 Business Partners
Atara may share Personal Information with our business partners, and affiliates for our and our affiliates’ internal business purposes or to provide you with a product or service that you have requested Atara may also provide Personal Information to business partners with whom we may jointly offer products or services, or whose products or services we believe may be of interest to you. In such cases, our business partner’s name will appear, along with Atara’s. Atara requires our affiliates and business partners to agree in writing to maintain the confidentiality and security of Personal Information they maintain on our behalf and not to use it for any purpose other than the purpose for which it was provided.
4.1.3 Privacy Shield
4.1.4 Information Disclosed for Our Protection and the Protection of Others
We may disclose Personal Information about you: (i) if we are required to do so by law, court order or legal process; (ii) in response to lawful requests by public authorities, including to meet national security or law enforcement requirements; (iii) under the discovery process in litigation; (iv) to enforce Atara policies or contracts; (v) to collect amounts owed to Atara; (vi) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation or prosecution of suspected or actual illegal activity; or (vii) if we, in good faith, believe that disclosure is otherwise necessary or advisable.
In addition, from time to time, server logs may be reviewed for security purposes – e.g., to detect unauthorized activity on the Websites. In such cases, server log data containing IP addresses may be shared with law enforcement bodies in order that they may identify users in connection with their investigation of the unauthorized activities.
4.1.5 Information Disclosed in Connection with Business Transactions
4.2 Data Transfers
All Personal Information sent or collected via or by Atara may be stored anywhere in the world, including but not limited to, in the United States, in the cloud, our servers, the servers of our affiliates or the servers of our service providers. Your Personal Information may be accessible to law enforcement or other authorities pursuant to a lawful request. By providing information to Atara, you consent to the storage of your Personal Information in these locations.
5.0 Rights of Access, Rectification, Erasure and Restriction
Although Atara makes good faith efforts to provide Individuals with access to their Personal Information, there may be circumstances in which Atara is unable to and would not, to the extent permitted by law, to provide access, including but not limited to: where the information contains legal privilege, would compromise others’ privacy or other legitimate rights, where the burden or expense of providing access would be disproportionate to the risks to the Individual’s privacy in the case in question or where it is commercially proprietary. If Atara determines that access should be restricted in any particular instance, we will provide you with an explanation of why that determination has been made and a contact point for any further inquiries. To protect your privacy, Atara will take commercially reasonable steps to verify your identity before granting access to or making any changes to your Personal Information.
The security of all Personal Information provided to Atara is important to us, and Atara takes reasonable steps designed to protect your Personal Information. Unfortunately, no data transmission over the Internet or storage of information can be guaranteed to be 100% secure. As a result, while Atara strives to protect your Personal Information, we cannot ensure or warrant the security of any information you transmit to Atara, and you do so at your own risk. You are responsible for maintaining the secrecy of your own passwords. If you have reason to believe that your passwords or Personal Information is no longer secure, please promptly notify Company at email@example.com.
8.0 Redress/Compliance and Accountability
Danielle Graves, Esq. at firstname.lastname@example.org
In addition, Atara has agreed to refer unresolved complaints related to Personal Information to JAMS Privacy Shield Dispute Resolution Program and, with respect to Employee and human resources data, has committed to cooperate with the panel established by local data protection authorities and comply with the advice given by the panel for EU citizens and with the Swiss Federal Data Protection and Information Commissioner’s authority and advice for such data of Swiss citizens. For more information and to submit a complaint regarding Individual data to JAMS, a dispute resolution provider which has locations in the United States and EU, visit https://www.jamsadr.com/file-an-eu-us-privacy-shield-or-safe-harbor-claim.
Such independent dispute resolution mechanisms are available to citizens free of charge. If any request remains unresolved, you may contact the national data protection authority for your EU Member State.
You may also have a right, under certain conditions, to invoke binding arbitration under Privacy Shield; for additional information, see https://www.privacyshield.gov/article?id=ANNEX-I-introduction. The FTC has jurisdiction over Atara’s compliance with the Privacy Shield.
9.0 Other Rights and Important Information
9.1 Information Regarding Children
Due to the nature of Atara’s business, services and benefits are not marketed to minors. Atara does not knowingly solicit or collect Personal Information from children under the age of 13 (and in certain jurisdictions under the age of 16). If we learn that we have collected Personal Information from a child under the age of 13 (and in certain jurisdictions under the age of 16), we will promptly delete that information.
9.2 California Privacy Rights
California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the Third Parties to whom we have disclosed their Personal Information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of Personal Information disclosed to those parties. Atara does not share Personal Information with any third parties for their own marketing purposes.
9.3 Links to Third-Party Websites
“Agent” means any third party that processes Personal Information pursuant to the instructions of, and solely for, Atara or to which Atara discloses Personal Information for use on its behalf.
“Data Subject” or “Individual” is an identified or identifiable natural person. A Data Subject may be an Employee, an Individual or any other natural person.
“Employee” refers to any current, temporary, permanent, prospective or former employee, director, contractor, worker or retiree of Atara or its subsidiaries worldwide.
“Personal Information” is any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Privacy Shield” means the seven (7) principles of the Privacy Shield Framework: (1) notice, (2), choice, (3) accountability for onward transfer, (4) security, (5) data integrity and purpose limitation, (6) access, and (7) recourse, enforcement, and liability. Additionally, it includes the sixteen (16) supplemental principles described in the Privacy Shield: (1) sensitive data, (2) journalistic exceptions, (3) secondary liability, (4) performing due diligence and conducting audits, (5) the role of the data protection authorities, (6) self-certification, (7) verification, (8) access, (9) human resources data, (10) obligatory contracts for onward transfers, (11) dispute resolution and enforcement, (12) choice – timing of opt-out, (13) travel information, (14) pharmaceutical and medical products, (15) public record and publicly available information, and (16) access requests by public authorities.
“Process” or “Processing” means any operation which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Protected Health Information” is a subset of Personal Information and has the meaning set out in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), and in particular at 45 C.F.R. § 160.103, as it may be amended from time to time.
“Sensitive Data” or “Sensitive Personal Information” is a subset of Personal Information which, due to its nature, has been classified by law or by policy as deserving additional privacy and security protections. Sensitive Personal Information includes Personal Information regarding EU-residents that is classified as a “Special Category of Personal Data” under EU law, which consists of the following data elements: (1) race or ethnic origin; (2) political opinions; (3) religious or philosophical beliefs; (4) trade union membership; (5) genetic data; (6) biometric data where Processed to uniquely identify a person; (6) health information; (7) sexual orientation or information about the individual’s sex life; or (8) information relating to the commission of a criminal offense.
“Third Party” is any natural or legal person, public authority, agency or body other than the Data Subject, Atara or Atara’s agents.