Last Updated: 11/07/2022
Welcome to www.durect.com. DURECT Corporation (“DURECT“, “we“, “our“, or “us“) is a biopharmaceutical company which provides transformational treatment of acute organ injury and chronic liver diseases by advancing new and potentially lifesaving therapies based on its endogenous epigenetic regulator program. We provide information about our therapies, technologies, pipeline, and clinical trials through our website www.durect.com (the “DURECT Website”) which we make available to our users.
We may choose or be required by law to provide additional disclosures relating to the processing of personal information in certain countries, regions, or states. Please refer below to disclosures that may be applicable to you.
THE INFORMATION WE COLLECT
We collect information about you when you voluntarily provide it to us, when you access the DURECT Website. When we use the term “personal information,” we mean any information that can be used to identify you, directly or indirectly, as an individual person.
- Information You Provide to Us
Like many websites, the DURECT Website actively collects information from its visitors both by asking you specific questions and by permitting you to communicate directly with us via e-mail. Some of the information that you submit may be personally identifiable information (that is, information that can be uniquely identified with you, such as your full name, address, e-mail address, phone number and so on).
Some areas of the DURECT Website may require you to submit information in order for you to benefit from the specified features (such as email alerts, requests for information packages or webcast attendance forms through the investor relations site). You will be informed at each information collection point what information is required and what information is optional.
The types of data we collect directly from you may include, without limitation:
- Contact information, including first name, last name, date of birth, email address, postal address or telephone number; and
- Professional information and credentials, such as educational and professional history, institutional and government affiliations, and information of the type included on a resume or curriculum vitae education and work history (such as work experience, education, salary, and languages spoken).
- Information We Collect Through Automated Means
As you navigate through the DURECT Website, certain information can be passively collected (that is, gathered without you actively providing the information) using various technologies and means, such as Internet Protocol addresses, cookies, Internet tags, and navigational data collection. The DURECT Website may use Internet Protocol (IP) addresses. An IP Address is a number assigned to your computer by your Internet service provider so you can access the Internet and is generally considered to be non-personally identifiable information, because in most cases an IP address is dynamic (changing each time you connect to the Internet), rather than static (unique to a particular user’s computer). We use your IP address to diagnose problems with our server, report aggregate information, determine the fastest route for your computer to use in connecting to our site, and administer and improve the site.
- Cookies are bits of information that a Web site sends to your Web browser that helps the site remember information about you and your preferences.
- Session cookies are temporary bits of information that are erased once you exit your Web browsers window or otherwise turn your computer off. Session cookies are used to improve navigation on Web sites and to collect aggregate statistical information. The DURECT Website uses session cookies.
- Persistent cookies are more permanent bits of information that are placed on the hard drive of your computer and stay there unless you delete the cookie. Persistent cookies store information on your computer for a number of purposes, such as retrieving certain information you may have previously provided (e.g. passwords) and helping to determine what areas of the Web site visitors find most valuable. The DURECT Website uses persistent cookies.
- Navigational data (“log files,” and “server logs”) are used for system management to improve the content of the site, market research purposes, and to communicate information to visitors. The DURECT Website uses navigational data.
- Information We Collect from Third Parties
- Social Media and Other Content Platforms. When you “like” or “follow” us on LinkedIn, Twitter or other social media sites, as applicable, we may collect some information about you including your name, email address, and any comments or content you post that is relevant to us. We also collect your information if you submit information to us through social media sites. The data we receive is dependent upon an individual’s privacy settings with the network. Individuals should always review and, if necessary, adjust their privacy settings on third-party websites and networks before sharing information with us or the social media platform.
- Information from Service Providers. Our service providers that perform services solely on our behalf, such as web hosting providers, analytics providers and user authentication service providers collect personal information and often share some or all of this information with us.
HOW WE USE YOUR INFORMATION
If you provide personally identifiable information to the DURECT Website, we may combine such information with other actively collected information unless we specify otherwise at the point of collection. We will take reasonable measures to prevent personally identifiable information from being combined with passively collected information, unless you consent otherwise.
In addition, we will make full use of all information acquired through the DURECT Website that is not in personally identifiable form.
HOW WE SHARE AND DISCLOSE YOUR INFORMATION
- Service Providers. In addition, we may disclose your personal information to third parties located in the United States and/or any other country
- such as to contractors we use to support our business (e.g., fulfillment services, technical support, delivery services, and financial institutions),
- where required by applicable laws, court order, or government regulations.
- Business Transfers. As we continue to develop our business, we may buy, merge, or partner with other companies. In such transactions, (including in contemplation of such transactions) user information may be among the transferred assets. If a portion or all of our assets are sold or transferred to a third-party, customer information (including your email address) would likely be one of the transferred business assets. If such transfer is subject to additional mandatory restrictions under applicable laws, we will comply with such restrictions.
- Consent. We may also disclose your information in other ways you direct us to and when we have your consent.
- Aggregate/De-Identified Information. We reserve the right to share aggregate/de-identified data at our discretion.
YOUR MARKETING CHOICES
THIRD PARTY SERVICES
HOW WE PROTECT YOUR INFORMATION
We take reasonable technical and organizational security measures to protect your personally identifiable information as you transmit your information from your computer to our site and to protect such information from loss, misuse, and unauthorized access, disclosure, alteration or destruction. You should keep in mind that no Internet transmission is ever 100% secure or error-free. In particular, e-mail sent to or from this site may not be secure, and you should therefore take special care in deciding what information you send to us via e-mail.
10260 Bubb Road
Cupertino, CA 95014-4166
European Privacy Notice
DURECT is the data controller of the personal information we hold about you. This means that we determine and are responsible for how your personal information is used.
INFORMATION WE COLLECT
If you are in the UK or European Economic Area, the table at ANNEX 1 sets out in detail the categories of personal information we collect about you and how we use that information when you use the DURECT Website as well as the legal basis which we rely on to process the personal information and recipients of that personal information.
If you are in the UK or European Economic Area, the table at ANNEX 2 sets out in detail the categories of personal information we collect about you automatically and how we use that information. The table also lists the legal basis which we rely on to process the personal information and recipients of that personal information.
HOW LONG WE KEEP YOUR PERSONAL INFORMATION
We will store the personal information we collect for our own purposes for no longer than necessary for the purposes set out and in accordance with our legal obligations and legitimate business interests. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and the applicable legal requirements.
As required in accordance with how we use your personal information, we may share your personal information as set forth in the section above titled HOW WE SHARE AND DISCLOSE YOUR INFORMATION.
COOKIES AND SIMILAR TECHNOLOGIES
We use the following types of cookies:
- Strictly necessary cookies. These are cookies that are required for the operation of our Website and without, the Website would not work.
- Analytical/performance cookies. They allow us to recognize and count the number of visitors, to see how visitors move around the DURECT Website when they are using it and to monitor the performance of certain features on the DURECT Website. This helps us to improve the way the DURECT Website works, for example, by ensuring that users are finding what they are looking for easily and to test the rollout of new features.
- Functionality cookies. These are used to recognize you as you move around the DURECT Website and to remember information that you enter when you use the DURECT Website, such as when you fill in a form.
ANNEX 3 contains more information about the cookies we use and how long they remain on your device.
Other than cookies that are required to operate the DURECT Website, we will only place cookies on your device with your consent. You can also change your preferences in relation to the cookies you consent by clicking Manage Cookies and opening your cookie settings.
- Cookie settings in Edge
- Cookie settings in Firefox
- Cookie settings in Chrome
- Cookie settings in Safari web and iOS.
If you only want to limit third party advertising cookies and similar technologies, you can opt out of receiving certain targeted advertising by visiting the following links (please bear in mind that there are many more companies listed on these sites than those that drop cookies via our website):
- Your Online Choices (https://www.youronlinechoices.eu)
- Network Advertising Initiative (https://www.thenai.org/)
- Digital Advertising Alliance (https://www.youradchoices.com/control)
STORING AND TRANSFERRING YOUR PERSONAL INFORMATION
- We implement appropriate technical and organizational measures to protect your personal information against accidental or unlawful destruction, loss, change or damage. All personal information we collect will be stored on our secure servers. We will never send you unsolicited emails or contact you by phone requesting your credit or debit card information or national identification numbers.
- International Transfers of your personal information. The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third-party service providers have operations. If you are located in the UK or European Economic Area (“EEA”), your personal information may be processed outside of the UK or EEA; these international transfers of your personal information will be made pursuant to appropriate safeguards, including:
(a) ensuring that the personal data is transferred to countries recognized by the European Commission or the UK Secretary of State (as applicable) as offering an equivalent level of protection; or
(b) implementing appropriate contractual safeguards, including Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner’s Office.
YOUR RIGHTS IN RESPECT OF YOUR PERSONAL INFORMATION
In accordance with applicable privacy law you may have the following rights in respect of your personal information that we hold:
- Right of access. The right to obtain:
(i) confirmation of whether, and where, we are processing your personal information;
(ii) information about the categories of personal information we are processing, the purposes for which we process your personal information and information as to how we determine applicable retention periods;
(iii) information about the categories of recipients with whom we may share your personal information; and
(iv) a copy of the personal information we hold about you.
- Right of portability. The right, in certain circumstances, to receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal data to another person.
- Right to rectification. The right to obtain rectification of any inaccurate or incomplete personal information we hold about you without undue delay.
- Right to erasure. The right, in some circumstances, to require us to erase your personal information without undue delay if the continued processing of that personal information is not justified.
- Right to restriction. The right, in some circumstances, to require us to limit the purposes for which we process your personal information if the continued processing of the personal information in this way is not justified, such as where the accuracy of the personal information is contested by you.
You also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal information, and we will assess and inform you if that is the case.
If you wish to enquire further about the safeguards we use, please contact us using the details set out in the Contacting Us section above.
You may also have the right to lodge a complaint to your local data protection authority. If you are based in the European Union, information about how to contact your local data protection authority is available here. If you are based in the UK, information about how to contact your local data protection authority is available here.
ANNEX 1 – PERSONAL INFORMATION YOU PROVIDE TO US
Category of personal information
How we may use it
Legal basis for the processing
Recipients of personal information
Contact Information when you make an information request, such as your first name, last name, phone number, company name, and e-mail address and any other personal information you may disclose in the comments box.
We may use this information to provide you with the information you have specifically requested or to deal with enquiries and complaints made by or about you relating to the DURECT Website.
The processing is necessary for our legitimate interests namely to respond to specific information requests made via the DURECT Website, and for communicating with our users effectively to respond to any queries or complaints.
We may share this information with service providers such as those who provide hosting services.
Contact and employment information when you submit an employment application or resume.
We may use this information to consider your application for employment.
The processing is necessary for our legitimate interests namely to consider your employment application.
We may share this information with service providers such as those who provide hosting services.
Contact Information such as your email address when you sign up for e-mail alerts.
We use this information to provide notifications, send news, alerts to users.
The processing is necessary for our legitimate interest, namely ensuring the user receives email alerts (as requested).
We may share this information with service providers such as those who provide hosting services.
All personal information set out above.
We may use all the personal information we collect to monitor and improve the DURECT Website and to help us develop new products and services.
The processing is necessary for our legitimate interests, namely to administer and improve the DURECT Website.
|Category of personal information||How we may use it||Legal basis for the processing||Recipients of Personal Data|
|Information about how you access and use the DURECT Website. For example, how frequently you access the DURECT Website, the time you access the DURECT Website and how long you use it for, the approximate location that you access the DURECT Website from, the site from which you came and the site to which you are going when you leave DURECT Website, the pages you visit, the links you click, and other actions you take on the DURECT Website.||We may use information about how you use the DURECT Website to present the DURECT Website to you on your device.||The processing is necessary for our legitimate interests, namely to tailor the DURECT Website to the user.||We may share this information with service providers such as those who provide hosting services.|
|We may use this information to monitor and improve the DURECT Website, resolve issues and to inform the development of new products and services.||The processing is necessary for our legitimate interests, namely to improve the DURECT Website.|
|Log files and information about your device. We also collect information about the tablet, smartphone or other electronic device you use to connect to the DURECT Website. This information can include details about the type of device, unique device identifying numbers, operating systems, browsers and applications connected to the DURECT Website through the device, your mobile network, your IP address and your device’s telephone number (if it has one).||We may use information about how you use and connect to the DURECT Website to present the DURECT Website to you on your device.||The processing is necessary for our legitimate interests, namely to tailor the DURECT Website to the user.|
|We may use this information to monitor and improve the DURECT Website, resolve issues and to inform the development of new products and services.||The processing is necessary for our legitimate interests, namely to monitor and resolve issues with the DURECT Website and to improve the DURECT Website generally.|
ANNEX 3 – COOKIES
|Cookie Name||Type of cookie||When is the cookie set?||How long does the cookie stay on my device?||Purposes / Additional information|
|cookielawinfo-checkbox-necessary||Necessary||when the user first visits the DURECT Website||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Necessary”.|
|cookielawinfo-checkbox-functional||Necessary||when the user first visits the DURECT Website||11 months||The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category “Functional”.|
|cookielawinfo-checkbox-performance||Necessary||when the user first visits the DURECT Website||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Performance”.|
|cookielawinfo-checkbox-analytics||Necessary||when the user first visits the DURECT Website||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Analytics”.|
|cookielawinfo-checkbox-others||Necessary||when the user first visits the DURECT Website||11 months||This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Other”.|
|CookieLawInfoConsent||Necessary||when the user first visits the DURECT Website||1 year||Records the default button state of the corresponding category. It works only in coordination with the primary cookie.|
|cookielawinfo-checkbox-advertisement||Necessary||when the user first visits the DURECT Website||1 year||Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the “Advertisement” category.|
|elementor||Necessary||when the user first visits the DURECT Website||Never||This cookie is used by the website’s WordPress theme. It allows the website owner to implement or change the website’s content in real-time.|
|__cf_bm||Functional||when the user first visits the DURECT Website||30 minutes||This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.|