Privacy Policy

IGM Biosciences, Inc.

Privacy Policy

IGM Biosciences, Inc. and its affiliates (“IGM Biosciences,” “we,” “our,” and/or “us”) value the privacy of individuals who use our website and related services (collectively, our “Services”). Our Services are not inclusive of the clinical activities that IGM Biosciences conducts. If you are a participant in a study, please contact your principal investigator or your doctor to obtain the relevant Privacy Policy for your study. This Privacy Policy (the “Privacy Policy”) explains how we collect, use, and share information from users of our Services (“Users”). By using our Services, you agree to the collection, use, disclosure, and procedures this Privacy Policy describes. Beyond the Privacy Policy, your use of our Services is also subject to our Terms of Use..

This Privacy Policy does not cover Personal Information we collect or receive in the context of a clinical trial. If you are a participant in one of our clinical trials, you will be informed about how we handle your Personal Information in connection with that trial through the documentation you received as part of your enrollment in that trial.

For the purposes of this Privacy Policy, “Personal Information” means any information relating to an identified or identifiable individual, such as an individual’s name, address, telephone number, or e-mail address.

Information We Collect

We may collect a variety of information from or about you or your devices from various sources, as described below.

A. Information You Provide to Us.

Registration and Profile Information. If you sign up for notifications, updates or to view a webcast, we may ask you for your name, email address, company affiliation, and the type of alert you want to receive.

Communications. If you contact us directly, we may receive additional information about you. For example, when you contact us through our “Investor Contact” page, we will receive your name, email address, the subject of your inquiry, and the contents of a message that you may send to us.

Careers. If you decide that you wish to apply for a job with us, you may submit your contact information, LinkedIn profile, current company, any links you choose to provide (e.g., LinkedIn, Twitter, GitHub, or other websites), work authorization status, your resume, and the contents of a message that you may send to us. We will collect the information you choose to provide on your resume, such as your education and employment experience. You may also apply through LinkedIn and Lever. If you do so, we will collect the information you make available to us on LinkedIn and Lever.

If you do not provide your personal information when requested, you may not be able to use our Services if that personal information is necessary to provide you with our Services or if we are legally required to collect it. Where required by applicable law, we indicate whether and why you must provide us with your personal information, as well as the consequences of failing to do so.

B.  Information We Collect When You Use Our Services.

Device Information. We receive information about the device and software you use to access our Services, including IP address (which may tell us your general location), web browser type, operating system version, phone carrier and manufacturer, and device identifiers.

Usage Information. To help us understand how you use our Services and to help us improve them, we automatically receive information about your interactions with our Services, like the pages or other content you view and the dates and times of your visits.

Information from Cookies and Similar Technologies.

We and our third-party partners collect information using cookies, pixel tags, or similar technologies. Our third-party partners, such as analytics partners, may use these technologies to collect information about your online activities over time and across different services. Cookies are small text files containing a string of alphanumeric characters. We may use both session cookies and persistent cookies. A session cookie disappears after you close your browser. A persistent cookie remains after you close your browser and may be used by your browser on subsequent visits to our Services.

The information collected via Cookies may include Personal Information, such as unique identifiers, system information, your IP address, web browser, device type, and the web pages that you visit just before or just after you use the Services, as well as information about your interactions with the Services, such as the date and time of your visit, and where you have clicked.

    • Strictly Necessary Cookies. Some Cookies are strictly necessary to make our Services available to you, for example, to provide login functionality. We cannot provide you with the Services without this type of Cookie.
    • Analytics Cookies. We also use Cookies for website and app analytics purposes in order to operate, maintain, and improve our Services. We may use our own analytics Cookies or use third-party analytics providers to collect and process certain analytics data on our behalf.

Please review your web browser’s “Help” file to learn the proper way to modify your cookie settings. Please note that if you delete or choose not to accept cookies from the Service, you may not be able to utilize the features of the Services to their fullest potential.

How We Process Your Personal Information

We use the information we collect for the purposes indicated below. If you are located in the European Economic Area, the United Kingdom, or Switzerland (“Europe”), we only process your Personal Information based on a valid legal ground. A “legal ground” is a reason that justifies our use of your Personal Information.

We rely on different legal bases to process your information for the purposes described in this Privacy Policy. Depending on the circumstances, we rely on different legal bases when processing your same information for different purposes. For each legal basis below, we describe why we may process your information.

You also have particular rights available to you depending on which legal basis we use, and we’ve explained these here. No matter what legal basis applies, you always have the right to request access to, rectification of and deletion of your information. To exercise your rights, see the “Your Rights and Choices” section.

Performance of a Contract – We process your information that is necessary to fulfil our contractual obligations with you.

Consent – We process your information if you give your consent for us to do so.

Legitimate Interests – We process your information as necessary for our or others’ legitimate interests. Our interests include providing innovative, personalized, safe and effective services for you while allowing IGM Biosciences to use your information to our benefit. We will not process your information if your interests, or your fundamental rights and freedoms, override ours.

Vital interests – We may process information if it will protect you or prevent harm, such as saving your life or someone else’s. Vital interests are intended to cover only interests that are essential for someone’s life. This condition is very limited in its scope, and generally only applies to matters of life and death.

Legal Obligations – We process information when necessary for us to comply with a legal obligation placed upon IGM Biosciences.

Public Interests – We process information as necessary for the public interest, such as conducting research or promoting safety, security and integrity.

Should we process sensitive personal data of yours such as genetic, biometric and health data, as well as personal data revealing racial and ethnic origin, political opinions, religious or ideological convictions or trade union membership we will always rely upon a legal basis identified above plus an additional legal basis as established by Article 9.2 of the GDPR.  If our processing of your sensitive data is deemed to be a high-risk processing activity, IGM Biosciences will perform a Data Protection Impact Assessment for that activity to ensure your rights are protected.

How We Share the Information We Collect

Vendors and Service Providers. We may share any information we receive with vendors and service providers retained in connection with the provision of our Services, such as to provide hosting, maintenance, and support services for our website.

Analytics Partners. We use analytics services such as Adobe Analytics to collect and process certain analytics data. These services may also collect information about your use of other websites, apps, and online resources. To help us understand how you use our Services and to help us improve them, we automatically receive information about your interactions with our Services, like the pages or other content you view and the dates and times of your visits.

As Required by Law and Similar Disclosures. We may access, preserve, and disclose your information if we believe doing so is required or appropriate to: (a) comply with law enforcement requests and legal process, such as a court order or subpoena; (b) respond to your requests; or (c) protect your, our, or others’ rights, property, or safety. For the avoidance of doubt, the disclosure of your information may occur if you post any objectionable content on or through the Services.

Merger, Sale, or Other Asset Transfers. We may transfer your information to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company, or we sell, liquidate, or transfer all or a portion of our assets. The use of your information following any of these events will be governed by the provisions of this Privacy Policy in effect at the time the applicable information was collected.

Consent. We may also disclose your information with your permission.

Your Rights and Choices

If you are located in Europe, you have certain rights. These rights are not absolute rights and cannot always be availed of and these rights will differ in their applicability due to the specific legal basis being used in relation to your Personal Information:

    • Access, Correction and Data Portability – You may ask for an overview of the Personal Information we process about you and to receive a copy of your Personal Information. You also have the right to request to correct incomplete, inaccurate or outdated Personal Information. To the extent required by applicable law, you may request us to provide your Personal Information to another company.
    • Objection – You may object to (this means “ask us to stop“) any use of your Personal Information that is not (i) processed to comply with a legal obligation, (ii) necessary to do what is provided in a contract between IGM Biosciences and you, or (iii) if we have a compelling reason to do so (such as, to ensure safety and security in our online community). If you do object, we will work with you to find a reasonable solution.
    • Deletion – You may also request the deletion of your Personal Information, as permitted under applicable law. This applies, for instance, where your Personal Information is outdated, or the processing is not necessary or is unlawful; where you withdraw your consent to our processing based on such consent; or where you have objected to our processing. In some situations, we may need to retain your Personal Information due to legal obligations or for litigation purposes.
    • Restriction Of Processing – You may request that we restrict processing of your Personal Information while we are processing a request relating to (i) the accuracy of your Personal Information, (ii) the lawfulness of the processing of your Personal Information, or (iii) our legitimate interests to process this Personal Information. You may also request that we restrict processing of your Personal Information if you wish to use the Personal Information for litigation purposes.
    • Withdrawal Of Consent – If we rely on consent for the processing of your Personal Information, you have the right to withdraw it at any time and free of charge. When you do so, we will apply your preferences going forward and this will not affect the lawfulness of the processing before your consent withdrawal.

However, there are exceptions and limitations to each of these rights. We may, for example, refuse to act on a request if the request is manifestly unfounded or excessive, or if the request is likely to adversely affect the rights and freedoms of others, prejudice the execution or enforcement of the law, interfere with pending or future litigation, or infringe applicable law. To submit a request to exercise your rights, please contact igmbiosciences.dpo@mydata-trust.info for assistance.

In addition to the above-mentioned rights, you also have the right to lodge a complaint with a competent supervisory authority including in your country of residence, place of work or where an incident took place subject to applicable law. You can find the contact details of the EU Data protection Authorities at: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.

Third Parties

Our Services may contain links to other websites, products, or services that we do not own or operate.  We are not responsible for the privacy practices of these third parties. Please be aware that this Privacy Policy does not apply to your activities on these third-party services or any information you disclose to these third parties. We encourage you to read their privacy policies before providing any information to them.

Security

We make reasonable efforts to protect your information by using physical and electronic safeguards designed to improve the security of the information we maintain. However, as no electronic transmission or storage of information can be entirely secure, we can make no guarantees as to the security or privacy of your information.

 Children’s Privacy

We do not knowingly collect, maintain, or use Personal Information from children under 16 years of age, and no part of our Services is directed to children. If you learn that a child has provided us with Personal Information in violation of this Privacy Policy, then you may alert us at igmbiosciences.dpo@mydata-trust.info.

International Visitors

Our Services are hosted in the United States (U.S.) and are intended for visitors located within the United States. If you choose to use the Services from the European Union or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your Personal Information outside of those regions to the United States for storage and processing. Also, we may transfer your data from the U.S. to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the Services.

If you are located in Europe, we will comply with applicable data protection laws when transferring your Personal Information outside of your jurisdiction. We may transfer your Personal Information to countries that have been found to provide adequate protection by the European Commission or other competent authorities (e.g., see list of countries for which the European Commission has issued an adequacy decision here), If this is not the case we will use  the appropriate safeguards like EU Standard Contractual Clauses (SCCs) and the International Data Transfer Agreement (“IDTA”); contractual protections for the transfer of Personal Information, or transfer to recipients who have adopted Binding Corporate Rules.

You can contact our Data Protection Officer, hereinafter DPO, igmbiosciences.dpo@mydata-trust.info, if you want to have more details about the mechanism supporting data transfer or a copy of such mechanism.

In accordance with Article 27 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (Data Protection Legislation), IGM Biosciences, Inc. named its Data Protection Representative (DPR) as follows:

MyData-TRUST France Valpark – rue Louis Duvant, 1 – 59220 Rouvignies (FRANCE)  igmbiosciences.dpr.eu@mydata-trust.info

MyData-T Ltd, Belmont Building, Belmont Road, London, UK igmbiosciences.dpr.eu@mydata-trust.info

Data Retention

The retention period of the personal data we collect is determined in accordance with the purpose and legal basis for each processing activity. This means that we only retain your personal data for as long as the legal basis is applicable and once the legal basis expires your information will be deleted.

Performance of a Contract – your information will be stored for the duration of the contractual period plus the applicable limitation period for any claims which may arise out of the contract.

Consent – your information will be retained as long as your consent has not been withdrawn.

Legitimate Interests – your information will be retained in line with IGM Biosciences’ Legitimate Interests, and the period of time identified in the related Legitimate Interests Assessment for the processing activity.

Vital interests – your information will be processed for the duration of the legal basis should it arise.

Legal Obligations – IGM Bioscience is subject to certain varied legal obligations such as, but not limited to, the retention of personal data for compliance under Tax Law, Social Security Law, Employment Law and/or Health and Safety.

Public Interests – your information will be processed for the duration of the legal basis should it arise.

Changes to this Privacy Policy

We will post any adjustments to the Privacy Policy on this page, and the revised version will be effective when it is posted. If we materially change the ways in which we use or share Personal Information previously collected from you through the Services, we will notify you through the Services, by email, or other communication.

Contact Information

IGM Biosciences is the entity responsible for the processing of your Personal Information or the “data controller”. If you have any questions, comments, or concerns about our processing activities, please email us at igmbiosciences.dpo@mydata-trust.info or write to us at IGM Biosciences, Inc., Legal Department, 325 E Middlefield Road, Mountain View, CA 94043.

Last Updated: September 18, 2024

Additional Information for California Residents

Depending on your residency, you may have certain additional information and certain rights. In the United States, these rights vary by States.

If you are a California resident, additional information is provided as follows:

Do Not Track (“DNT”) requests. DNT is an optional browser setting that allows you to express your preferences regarding tracking by advertisers or other third parties. Some web browsers may allow you to transmit a “Do Not Track” signal to online services and websites. If a website receives such signal, the web browser can block that website from collecting certain Personal Information about you. We will try our best to respond to global privacy controls, including DNT signals. However, we do not assume liability for failure to comply with DNT signal by our partners and / or providers.

Children’s Online Data. It is not our intention to collect personal information from children under the age of 13 through our website. If you are under 13, please do not give us any personal information through our website. We encourage parents and legal guardians to monitor their children’s internet usage and to help enforce our notice by instructing their children never to provide us personal information. If you have reason to believe that a child under age 13 has provided personal information to us through our website, please contact us and we will endeavor to delete that personal information from our records, unless other applicable law requires us to retain that information

If you are a California resident, you have the following rights with respect to your Personal Information:

“Shine the Light “and “Eraser” Laws.  You may request a list of all third parties to which we have disclosed certain information for those third parties’ direct marketing purposes. 

The right to know. You may have the right to request that we disclose to you the personal information we have collected or sold about you and how it is used and shared. Here is the information you may have access to:

    • the categories of personal information collected;
    • the categories of sensitive personal information collected;
    • the categories of sources from which the personal information or sensitive personal information is collected;
    • the business purpose for such collection, sharing, or selling;
    • the categories of third parties to whom to personal information or sensitive personal information is disclosed to;
    • the specific pieces of personal information collected;
    • the length of time that the business intends to retain each category of personal information and sensitive personal information.

The right to access. You may have the right to access personal information which we may collect or retain about you free of charge (for which we have 45 days to respond). If requested, we shall provide you with a copy of your personal information which we collect. You also have the right to receive your personal information in a structured and commonly used format so that it can be transferred to another entity (“data portability”).

The right to opt-out of sale/share of my personal information. You have the right to opt-out from the selling of your personal information, which means that any third party who has received your personal information as part of their ‘sale’ may only further sell that personal information if you have provided “explicit notice” and the opportunity to opt-out of that subsequent sale. This right to opt-out of the sale is absolute. Further, you have the right to opt-out of sharing your personal information. This right can be exercised through igmbiosciences.dpo@mydata-trust.info and cannot be re-solicited before a period of 12 months for additional purposes.

The right to limit use of sensitive personal information. You have the right to direct us to limit the use of your sensitive personal information to what’s necessary or reasonably expected to perform the service or provide the goods. This right can be exercise through igmbiosciences.dpo@mydata-trust.info.

The right to correct inaccurate personal information. You have the right to require rectification of inaccurate personal information about you. Upon verifying the validity of a verifiable consumer correction request, we will use commercially reasonable efforts to correct your personal information as directed within 45 days (with the possibility to extend the period once), taking into account the nature of the personal information and the purposes of maintaining your personal information.

The right to request deletion of personal information. You have the right to request the deletion of your personal information collected, or maintained by us, subject to certain exceptions permitted by law. In the event of a request for deletion, we will acknowledge receipt of your request within ten (10) business days and will endeavor to respond substantially within forty-five (45) days.

The right to not be subject to discrimination (“right to equal service and price”). You have the right not to be denied goods or services, to be charged for different prices or rates for goods or services or provided a different level or quality of goods or services.

Last Updated: September 18, 2024