Last Updated on October 28, 2024
Arrowhead Pharmaceuticals, Inc. (“Arrowhead”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Notice for Healthcare Professionals (“HCPs”, “you”, or “your”) (“Privacy Notice”) describes our practices regarding the collection, use, and disclosure of your Personal Information (as defined below) when you visit our websites (including arrowheadpharma.com and lowertriglicerides.com) (collectively, the “Websites”), and interact with us offline. This Privacy Notice also describes your privacy rights in connection with Personal Information we collect about you, including the rights of California residents and individuals located in the European Economic Area (“EEA”) or the United Kingdom (“UK”).
This Privacy Notice will not apply to Personal Information collected and processed by us:
- should you participate in a clinical trial that we sponsor;
- if you are an individual other than a HCP;
- should you apply for a job with us; or
- in the course of your employment with us.
By accessing our Websites, you agree to our Terms of Use the collection and use of your Personal Information as described in this Privacy Notice. However, this does not equate to consent for the processing of your Personal Information for purposes of EEA and UK data protection laws.
For purposes of this Privacy Notice, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. The term does not include aggregated information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual.
Notice at Collection: Personal Information We Collect
We collect the following categories of Personal Information:
- Personal identifiers: name, residential and business address, home and business telephone number(s), email address(es), and National Provider Identifier (NPI), IP address;
- Characteristics of protected classes and demographic information: military or veteran status, age (over 40);
- Commercial and financial information: payment information, account information, and details of any financial relationship with us, information about prescriptions written, inquires or requests for assistance regarding our products or services;
- Professional or employment-related information: name of your practice, academic background, professional designation, medical specialty, licensing and disbarment status, publications and information about public speeches, and additional Personal Information you provide in your curriculum vitae or other similar documents or communications;
- Education information: academic background and credentials;
- Internet or electronic network information: your browser type, operating system, domain names visited, click activity, referring websites, the date and time and length of visit of your visit to our Websites or other websites or mobile applications;
- Audio and visual information: recordings of calls made to our information and support lines; audio and visual recordings of presentations given by you; and
- Inferences drawn from any above data to create profile reflecting an HCP’s interest as they relate to the types of products and educational offerings provided by Arrowhead.
We have collected the same categories of Personal Information in the 12 months prior to the date of this Privacy Notice.
Notice at Collection: Purposes for Collection of Personal Information
We collect and otherwise process your Personal Information, and may have previously processed your Personal Information for the following purposes:
- Facilitating your registration and attendance at events we sponsor
- Advertising and marketing, including providing you with promotional information about our products and events
- Providing you with scientific information about our research and products
- The administration of advisory boards and other committees that we convene
- Coordinating your participation as a speaker at events we sponsor, including any compensation or honorarium
- Responding to your inquiries about our products, policies and programs
- Processing patient requests to participate in programs we offer or administer
- Satisfaction of our reporting obligations under applicable law or by virtue of our membership in industry certification organizations
Notice at Collection: Categories of Personal Information We Sell or Share
When we engage in digital advertising in the United States, we may sell the following categories of Personal Information (according to the broad definition of “sell” under select state privacy laws) or share them for purposes of cross-context behavioral advertising: personal identifiers (including IP address, mobile advertising IDs), and internet or other electronic activity information.
These categories of Personal Information are sold to or shared for cross-context behavioral advertising with advertising networks, data brokers and other companies that facilitate or engage in digital advertising. We engage in such sales and sharing to engage in personalized advertising, such as providing you with information about products or developments we believe that are likely of interest to you. We do so by allowing third parties to place cookies or other tracking technologies on our Websites and in our advertisements which may collect information about your interactions with our Websites, advertisements, and your online activities over time and across different websites or applications. Please note that in some jurisdictions in which we operate, we do not engage in these practices. For more information about the use of cookies and other tracking technologies, see the Cookies and Other Technologies section below.
To opt out of such sales and sharing, email us at dpo@arrowheadpharma.com.
We do not sell or share for cross-context behavioral advertising any of the other categories of Personal Information we collect.
Notice at Collection: Retention Periods
We retain the categories of Personal Information we collect for as long as we need for a legitimate business purpose. The criteria used to determine the retention periods include: (i) how long the Personal Information is needed to provide / receive the services and operate the business; (ii) the type of Personal Information collected; and (iii) whether we are subject to a legal, contractual or similar obligation to retain the Personal Information (e.g., mandatory data retention laws, government orders to preserve data relevant to an investigation or data that must be retained for the purposes of litigation or disputes).
Sources From Which We Collect Personal Information
We collect Personal Information from you when you: (i) attend or register to attend an event sponsored by us; (ii) participate in one of our advisory boards or speak at an event on our behalf; (iii) request information from us about our products or services; (iv) apply for a grant, donation or sponsorship; (v) respond to one of our surveys; or (vi) otherwise interact with us including, via the Website. We may also collect your Personal Information from patients, other HCPs or medical professionals, dispensing entities, from data brokers specializing in HCP data, and from publicly available sources. We will continue to collect Personal Information from these same types of sources.
Sensitive Personal Information
We do not use or disclose sensitive Personal Information under this Privacy Notice to create profiles about or infer characteristics about individuals.
Automated Decision-Making / Profiling
We do not process your Personal Information on the basis of any automated decision-making including profiling.
Cookies and Other Technologies
We collect some of the Personal Information above through “cookies” and other similar technologies. Cookies are small, sometimes encrypted text files that are stored on computer hard drives by websites that you visit. They are used to help users navigate websites efficiently as well as to provide information to the owner of the website, and for digital advertising. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie Policy.
Additionally, we use Google Analytics to evaluate the use of our Websites. Google Analytics uses cookies and other identifiers to collect information, such as how often users visit a website, what pages they visit when they do so, and what other websites they visited prior to visiting a website. To learn more about how Google Analytics collects Personal Information, review Google’s Privacy Policy.
How We Use The Personal Information We Collect
We have set out below, a description of the ways we use your Personal Information (referred to as “processing purposes” below), and, for HCPs located in the EEA or the UK, we explain which of the legal bases we rely on.
Categories of Personal Information | Processing Purposes | Legal Basis (where you are located in the EEA or the UK) |
Where you register to attend and/or attend a sponsored event: | ||
Personal identifiers; Audio and visual information; travel and accommodation information | The administration and conduct of the relevant event, including to respond to your enquiries and communicate with you about the event which may involve the recording of calls. | Where we have a legitimate interest to ensure the effective administration and conduct of the relevant event. |
Personal identifiers; Audio and visual information | Enabling the creation, distribution, broadcast or other use of any recordings made during the event | Where we have a legitimate interest to promote the event, to leverage the learnings from the event, and to more generally operate and improve our business |
Personal identifiers | To invite you to future events and to send you other promotional information about our products (where permitted by law). If you wish to stop receiving marketing or market research communications from us you can unsubscribe via the link at the bottom of the relevant e-mail or contact us using the contact details below. | If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent. In other instances, we will send marketing communications to you where this is in our legitimate interest. |
Personal identifiers | The storage of your Personal Information in databases for use when sending invites to future events. | Where we have a legitimate interest to manage our business and the conduct of future events. |
All categories of Personal Information | Compliance with and satisfaction of legal obligations and regulatory requirements for purposes of financial reporting / public disclosure obligations in relation to agreements with and/or payments and benefits to HCPs and healthcare organizations. | To comply with a legal obligation. Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
Where you participate in an Arrowhead advisory board: | ||
Personal identifiers; Professional or employment information; Education information; Audio and visual information | The administration and conduct of the relevant advisory board, including to respond to your enquiries and communicate with you about the advisory board which may involve the recording of calls. | Where we have a legitimate interest to ensure the effective administration and conduct of the advisory board. |
Personal identifiers; Audio and visual information | Enabling the creation, distribution, broadcast or other use of any recordings made during the advisory board | Where we have a legitimate interest to leverage the learnings from the advisory board, and to more generally operate and improve our business |
Personal identifiers; Professional or employment information; Education information | The storage of your Personal Information in databases for use when selecting HCPs for future advisory boards. | Where we have a legitimate interest to manage our business and the conduct of future advisory boards. |
All categories of Personal Information | Compliance with and satisfaction of legal obligations and regulatory requirements in the context of safety data reporting activities, and for purposes of financial reporting / public disclosure obligations in relation to agreements with and/or payments and benefits to HCPs and healthcare organizations. | To comply with a legal obligation. Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
Where you are engaged to speak on our behalf: | ||
Personal identifiers; Professional or employment information; Education information; Audio and visual information | The administration and conduct of the relevant event, including to respond to your enquiries and communicate with you about the event which may involve the recording of calls or the event. | Where we have a legitimate interest to ensure the effective administration and conduct of the relevant event. |
Personal identifiers; Audio and visual information | Enabling the creation, distribution, broadcast or other use of any recordings made during the event. | Where we have a legitimate interest to promote the event, to leverage the learnings from the event, and to more generally operate and improve our business. |
Personal identifiers; Commercial and financial information; Professional or employment information; Education information | Meeting our contractual obligations under the speaker agreement with you including, to pay you for your speaking services. | Where necessary for performance of a contract. |
Personal identifiers; Professional or employment information; Education information | The storage of your Personal Information in databases for use when selecting speakers for future events. | Where we have a legitimate interest to manage our business and the conduct of future events. |
All categories of Personal Information | Compliance with and satisfaction of legal obligations and regulatory requirements for purposes of financial reporting / public disclosure obligations in relation to agreements with and/or payments and benefits to HCPs and healthcare organizations. | To comply with a legal obligation. Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
When you contact us or we communicate with you: | ||
Personal identifiers; Audio and visual information | To respond to your enquiries and communicate with you including, where these relate to, for example, requests for funding, grants, early access programs. | Where we have a legitimate interest to manage our business, and to process and respond to your communications. |
Audio and visual information | To make and use recordings of calls made to our information and support lines. | Where we have a legitimate interest to manage our business, and to process and respond to your communications. |
Personal identifiers; Commercial and financial information; Professional or employment information | To send you promotional information about our products or otherwise engage in advertising and marketing (where permitted by law). If you wish to stop receiving marketing or market research communications from us you can unsubscribe via the link at the bottom of the relevant e-mail or contact us using the contact details below. | If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent. In other instances, we will send marketing communications to you where this is in our legitimate interest. |
If you are located in the EEA or the UK: You have a right to object to the processing of your Personal Information where that processing is carried out for our legitimate interests. Please note however, that we may not be able to fulfil such requests in all instances.
Disclosure of Your Personal Information For Business Purposes
The following chart describes the categories of Personal Information we disclosed to entities for a business purpose in the 12 months prior to the date of this Privacy Notice:
Categories of Personal Information | Categories of Third Parties to Which We Disclosed Personal Information for Business Purposes |
Personal identifiers:name, residential and business address, home and business telephone number(s), email address(es), National Provider Identifier (NPI), IP address. | Service providers that manage customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Websites and assist with other IT-related functions, advertise and market our products and services, provide analytics information, and provide legal and accounting services. |
Protected class information: military or veteran status; age (over 40). | Service providers that manage customer information and provide patient support services. |
Commercial and financial information: payment information, account information, and details of any financial relationship with us, information about prescriptions written, inquires or requests for assistance regarding our products or services. | Service providers that manage customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Website and assist with other IT-related functions, advertise and market our products and services, provide market research and analytics information, and provide legal and accounting services. |
Professional or employment-related information: name of your practice, academic background, professional designation, medical specialty, licensing and disbarment status, publications and information about public speeches, and additional Personal Information you provide in your curriculum vitae or other similar documents or communications. | Service providers that manage customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Websites and assist with other IT-related functions, advertise and market our products and services, provide market research and analytics information. |
Education information: academic background and credentials. | Service providers that manage customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Websites and assist with other IT-related functions, advertise and market our products and services, provide market research and analytics information. |
Internet or electronic network information: your browser type, operating system, domain names visited, click activity, referring website and the date and time and length of your visit to our Websites or other websites or mobile applications. | Service providers that manager customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Websites and assist with other IT-related functions, advertise and market our products and services, provide market research and analytics information. |
Audio and visual information: recordings of calls made to our information and support lines; audio and visual recordings of presentations. | Service providers that manage customer information and provide patient support services, provide access to audio or video recordings. |
Inferences drawn from any above data to create profile reflecting a health care professional’s interests as they relate to the types of products and educational offerings provided by Arrowhead. | Service providers that manage customer information and provide patient support services, advertise and market our products and services, provide market research and analytics information. |
Internet or electronic network information: your browser type, operating system, domain names visited, click activity, referring website and the date and time and length of your visit to our Websites or other websites or mobile applications. | Service providers that manager customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Websites and assist with other IT-related functions, advertise and market our products and services, provide market research and analytics information. |
Audio and visual information: recordings of calls made to our information and support lines; audio and visual recordings of presentations. | Service providers that manage customer information and provide patient support services, provide access to audio or video recordings. |
Inferences drawn from any above data to create profile reflecting a health care professional’s interests as they relate to the types of products and educational offerings provided by Arrowhead. | Service providers that manage customer information and provide patient support services, advertise and market our products and services, provide market research and analytics information. |
Business Purposes for Such Disclosures
We disclosed the aforementioned categories of Personal Information to the categories of third parties identified above for the following purposes: to manage customer information and provide patient support services, to facilitate email communications, provide copies of recorded presentations, manage contacts, work with vendors and suppliers, manage our Websites and secure our systems, prevent fraud and other illegal activities and for marketing and analytics.
We may also disclose HCP Personal Information with third parties we consult and engage as part of our clinical research and compliance activities, such as research partners, ethics committees, and professional advisors, and clinical research monitors and research organizations.
We may also disclose Personal Information as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property or the rights, property or safety of others, including to law enforcement agencies, and judicial and regulatory authorities. We may also disclose your Personal Information to third parties to help detect and protect against fraud or data security vulnerabilities. And we may transfer your Personal Information to a third party in the event of an actual or contemplated sale, merger, reorganization of our entity or other restructuring.
Security
We take reasonable steps, consistent with generally accepted industry standards, including technical, administrative and physical safeguards to protect Personal Information we process from loss, misuse and unauthorized access, disclosure, alteration and destruction. However, no system is fully secure and we cannot guarantee the security of your Personal Information.
International Transfers of Personal Information
We are located in the U.S. All Personal Information collected via the Websites will in turn, be processed in the U.S. Where we disclose Personal Information originating in the EEA/UK to a third party (e.g., a service provider) located outside of the EEA/UK we will as deemed necessary, enter into a data transfer agreement (e.g., standard contractual clauses) with that third party, seek to rely on the third party’s Binding Corporate Rules or otherwise make the transfer in reliance on a derogation under EEA/UK data protection laws (e.g., where the transfer is necessary for the defense of legal claims). If you would like further information in relation to, or a copy of, the relevant safeguards, you can contact us using the details set out below.
Children’s Privacy
The Websites and other HCP-related data processing activities are not directed to minors under the age of 16. We do not have actual knowledge that we collect Personal Information from minors, including those under the age of 16.
Third Party Links
Our Websites may contain social media buttons or links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the activities and practices that take place on those social media platforms or third-party websites.
Your Data Privacy Rights
1. EEA/UK Data Privacy Rights
If you are located in the EEA or the UK, you have the following data privacy rights which may be subject to limitations / restrictions:
- The right to request access to your Personal Information;
- The right to request that your Personal Information be corrected or deleted;
- The right to request that we restrict our processing of your Personal Information;
- The right to object to the processing of your Personal Information where it is carried out (i) for our legitimate interests – unless we can demonstrate compelling legitimate grounds for the processing; and/or (ii) for direct marketing purposes;
- The right to withdraw consent to the processing of your Personal Information; and
- The right to request that Personal Information be provided to you or a third-party in a machine-readable format.
Please contact us using the details set out below in case you wish to exercise any of the above rights.
You also have the right to file a complaint with the competent data protection authority if you have any reason to believe we have not properly handled your Personal Information or have not respected your rights.
2. California Data Privacy Rights
If you are a California resident, you may have specific rights regarding your Personal Information, in accordance with California law.
California Consumer Privacy Act
The California Consumer Privacy Act (“CCPA”) gives California residents rights described below with respect to their Personal Information.
Your Right To Request Disclosure of Information We Collect and Share About You
We are committed to ensuring that you know what Personal Information we collect. To that end, you can ask us for any or all of following types of information regarding the Personal Information we have collected about you since January 1, 2022.
- Specific pieces of Personal Information we have collected about you;
- Categories of Personal Information we have collected about you;
- Categories of sources from which such Personal Information was collected;
- Categories of Personal Information that the business sold or disclosed for a business purpose about the consumer;
- Categories of third parties to whom the Personal Information was sold or disclosed for a business purpose; and
- The business or commercial purpose for collecting or selling your Personal Information.
Your Right To Request Deletion of Personal Information We Have Collected About You
You have the right to ask us to delete Personal Information we have collected from you. We will do so, subject to the exceptions in the CCPA and other applicable laws.
Your Right to Request to Correct Personal Information We Hold About You
You have the right to request that we correct Personal Information we hold that you believe is not accurate. We will take steps to determine the accuracy of the Personal Information that is the subject of your request to correct, and in doing so will consider the totality of the circumstances relating to the Personal Information you have identified as being incorrect. We may ask that you provide documentation regarding your request to correct to assist us in evaluating the request.
Your Right to Request to Opt-Out of the Sale of Your Personal Information or Sharing of Your Personal Information for Cross-Context Behavioral Advertising
You have the right to request that we stop selling your Personal Information or sharing it for purposes of cross-context behavioral advertising.
Exercising Your Rights and How We Will Respond
Rights to Access, Delete, Correct
To exercise any of the rights above, or to ask a question, email us at dpo@arrowheadpharma.com or use the contact details set out at the end of this Privacy Notice.
For requests for access, deletion, or correction we will first acknowledge receipt of your request within 10 business days of receipt of your request. We will provide a substantive response to your request as soon as we can, generally within 45 days from when we receive your request, although we may be allowed to take longer to process your request under certain circumstances. If we expect your request is going to take us longer than normal to fulfill, we will let you know.
Opt-Out Rights
To exercise your right to opt out of the sale or sharing (for cross-context behavioral advertising) of your Personal Information, submit your request by emailing us at dpo@arrowheadpharma.com.
Opt-out Preference Signals and Do Not Track
An opt-out preference signal is sent by a platform, technology, or mechanism on behalf of consumers and communicates a consumer’s choice to opt out of the sale and sharing of Personal Information for cross-context behavioral advertising with all businesses that recognize the signal, without having to make individualized requests. The signal can be set on certain browsers or through opt-out plug-in tools.
We recognize the Global Privacy Control signal for California and Connecticut residents based on IP address and do so at the browser level; it does not apply to Personal Information we may collect offline or that we may associate only with your name or email address. This means that if the signal is sent through a specific browser, we will recognize it for that browser only, and only with respect to the identifiers for that browser. If you would like more information about opt-out preference signals, including how to use them, the Global Privacy Control website has such information (https://globalprivacycontrol.org/).
We do not respond to the DNT or “Do Not Track” signal.
Our Commitment to Allowing You to Exercise Your Rights – Non-Discrimination
If you exercise any of the rights explained in this Privacy Notice, we will continue to treat you fairly. If you exercise your rights under this Privacy Notice, you will not be treated differently than others.
Verification of Identity – Access, Deletion or Correction Requests
We will ask you for identifying information and attempt to match it to information that we maintain about you.
If we are unable to verify your identity with the degree of certainty required, we will not be able to respond to your request. We will notify you to explain the basis of the denial.
Authorized Agents
You may designate an agent to submit requests on your behalf. If the agent submits an opt-out request on your behalf, the agent will need to provide us with your signed permission indicating the agent has been authorized to submit the opt-out request on your behalf. Agents can submit opt-out requests by emailing dpo@arrowheadpharma.com.
If you would like to designate an agent to exercise access, deletion, or correction requests on your behalf, the agent will need to provide us with your signed permission indicating the agent has been authorized to submit the request on your behalf. We will also require that you verify your identity directly with us or confirm with us that you provided the agent with permission to submit the request.
Please note that this subsection does not apply when an agent is authorized to act on your behalf pursuant to a valid power of attorney. Any such requests will be processed in accordance with California law pertaining to powers of attorney.
California Shine the Light
With reference to California Civil Code Section 1798.83, also known as the “Shine the Light” law, we allow California residents to opt out of the disclosure of Personal Information to third parties for those third parties’ direct marketing purposes. To exercise that opt-out option, please email us at dpo@arrowheadpharma.com.
Accessibility
We are committed to ensuring that our communications are accessible to people with disabilities. To make accessibility-related requests or report barriers, please contact us at peopleservices@arrowheadpharma.com.
Changes to Our Privacy Notice
We may change this Privacy Notice from time to time. You will be informed about any material changes through a notice on our Websites.
Contact Us
Questions, comments and requests regarding this Privacy Notice are welcomed, including requests relating to exercising any of your data privacy rights.
If you reside in the EEA, please contact our EEA Data Protection Representative using the following contact details:
Kaleidoscope Data Privacy Consultants Limited
The Black Church, St Mary’s Place, Dublin DO7 P4AX
Call: +353 (0) 153 14430
Email: contact@kdpc.ie
If you reside in the UK, please contact our UK Data Protection Representative using the following contact details:
Kaleidoscope Consultants Limited
East Side, Kings Cross, London N1C 4AX
Call: +44 (0)20 3637 1111
Email: general@kdpc.uk
If you reside in the U.S., please contact Arrowhead Pharmaceuticals using the following contact details:
Arrowhead Pharmaceuticals, Inc.
177 East Colorado Boulevard, Suite 700, Pasadena, CA 91105
Email: dpo@arrowheadpharma.com