Neos Therapeutics, Inc. and its subsidiaries and affiliates (collectively “Neos” “our,” “we” or “us”) are committed to respecting your privacy. This Privacy Policy describes how we collect, use, disclose, store and otherwise process information when you use our websites and other online products and services. We urge you to read this Privacy Statement so that you understand our commitment to you and your privacy, and how you can participate in that commitment.

Neos may provide additional privacy notices to individuals at the time we collect their data. For example, we provide a specific privacy notice to clinical trial participants that describe our privacy practices in connection with conducting clinical trials. This type of an “in-time” notice will govern how we may process the information you provide at that time.

Personal Information We Collect

Definition of Personal Data
Personal data refers to any information relating to an identified or identifiable natural person, such as an identification number, physical, physiological, mental, economic, cultural, or social identifiers.

Whose Personal Information We Collect
We collect personal information about the following types of individuals: clinical trial participants, patients, patient family members, caregivers or advocates, physicians and other health care professionals, clinical trial investigators, researchers, pharmacists, and other individuals who interact directly with Neos or its service providers or business partners, including users of websites and mobile applications.

How We Collect Personal Information
We collect personal information:

  • Directly from individuals
  • Through our websites and mobile apps
  • From healthcare professionals
  • From contract research organizations and clinical trial investigators
  • From government agencies or public records
  • From third party service providers, data brokers or business partners
  • From industry and patient groups and associations
  • From social media or other public forums (including adverse event information or product quality complaints)

Types of Personal Information We Collect
The types of personal information we collect and share depend on the nature of the relationship you have with Neos and the requirements of applicable laws. We may collect:

  • Health and medical information (such as medical insurance details, information about physical and mental health conditions and diagnoses, treatments for medical conditions, genetic information, family medical history, and medications an individual may take, including the dosage, timing, and frequency) we collect in connection with managing clinical trials, conducting research, providing patient support programs, managing compassionate use and expanded access programs, and tracking adverse event reports
  • Personal and business contact information and preferences (such as name, job title and employer name, email address, mailing address, phone number, and emergency contact information)
  • Biographical and demographic information (such as date of birth, age, gender, marital status, and information regarding any parents or legal guardians)
  • Professional credentials, educational and professional history, and institutional affiliations
  • Payment-related information we need to pay for professional services, such as consulting, that individuals may provide to us (such as tax identification number and financial account information)
  • If you are a health care professional, we collect information about the programs and activities in which you have participated, your prescribing of our products and the agreements you have executed with us
  • Your photograph, social media handle or digital or electronic signature
  • Publicly available information (such as comments describing support for and experience with Neos products)
  • Other information you provide to us (such as in emails, on phone calls, in market research surveys, or in other correspondence with Neos or its service providers or business partners)

We may combine other publicly available information, such as information related to the organization for which you work, with the personal information that you provide to us through our Services.

Information automatically collected
We may automatically log information about you and your computer or mobile device when you access our Sites. For example, we may log your computer or mobile device operating system name and version, manufacturer and model, browser type, browser language, screen resolution, the website you visited before browsing to our Sites, pages you viewed, how long you spent on a page, access times and information about your use of and actions on our Sites. We collect this information about you using cookies. Please refer to the Cookies and Similar Technologies section below for more details.

Changes to your personal information
It is important that the personal information we hold about you is accurate and current. Please let us know if your personal information changes during your relationship with us by emailing us at info@neostx.com.

Cookies and Similar Technologies

We may collect information about your use of the websites through cookies and similar technology. A “cookie” is a unique numeric code that we transfer to your computer so that we can keep track of your interests and/or preferences and recognize you as a return visitor to the websites. For example, we may use these technologies to collect information about the ways visitors use our websites, to support the features and functionality of our websites, and to personalize your experience when you use our websites.

Disabling cookies
You can typically remove or reject cookies via your browser settings. To do this, follow the instructions provided by your browser (usually located within the “settings,” “help” “tools” or “edit” facility). Many browsers are set to accept cookies until you change your settings.

Further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org.

If you do not accept our cookies, you may experience some inconvenience in your use of our Site. For example, we may not be able to recognize your computer or mobile device and you may need to log in every time you visit our Site.

Do Not Track Signals
Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not currently respond to do not track signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.

How We Use Your Personal Information

To operate our websites and mobile apps
If you use our websites or mobile apps, we use your personal information to:

  • Operate, maintain, administer and improve the websites and mobile apps
  • Better understand your needs and interests, and personalize your experience with the websites and mobile apps
  • Provide support and maintenance for our websites and mobile apps
  • Respond to your service-related requests, questions and feedback

To perform and administer clinical trials, research and product-improvement activities
We may use your personal information when necessary to facilitate our clinical trials, research, studies, and related activities that support product improvement, including to:

  • Staff and manage clinical trials, including by recruiting investigators and participants
  • Track and respond to safety and product quality concerns (including product recalls)
  • Support public health initiatives, symposia, conferences, and scientific, educational and volunteer events
  • Define and manage appropriate patient engagement activities, and patient support programs (including to provide co-pay and other financial assistance where available)
  • Identify and engage thought leaders and external experts
  • Award scholarships and grants
  • Attribute authorship to academic and promotional materials

To provide our products and services
We use your personal information as necessary to provide Neos products and services, including to:

  • Manage access to our products, including where access is limited by law to licensed physicians
  • Pay for services that physicians, researchers and other individuals may provide to us

To communicate with you
If you request information from us or participate in our surveys, promotions or events, we may send you Neos-related marketing communications as permitted by law. We may also use your personal information to engage in direct marketing activities as permitted by law. You will have the ability to opt out of such communications.

To comply with law
We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or requests from government authorities.

To comply with regulatory monitoring and reporting obligations
We use your personal information as we believe necessary or appropriate to comply with regulatory monitoring and reporting obligations, such as those related to adverse events, product complaints, patient safety, and financial disclosures.

With your consent
We will request your consent to use your personal data where required by law, such as where we use certain cookies or similar technologies or would like to send you certain marketing messages. If we request your consent to use your personal data, you have the right to withdraw your consent any time in the manner indicated when we requested the consent or by contacting us.

To create anonymous data for analytics
We may create anonymous data from your personal information and other individuals whose personal information we collect. We make personal information into anonymous data by excluding information that makes the data personally identifiable to you and use that anonymous data for our lawful business purposes.

For compliance, fraud prevention and safety
We use your personal information as we believe necessary or appropriate to (a) enforce the terms and conditions that govern our websites, mobile apps, products and services; (b) protect our rights, privacy, safety or property, and/or that of you or others; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Compliance with Applicable Regulations
Neos regularly reviews this Privacy Policy and ensures that we process your information in a manner that in compliance with applicable regulations.

How We Share your Personal Information

Subsidiaries and Affiliates
We may disclose your personal information to our subsidiaries and corporate affiliates for purposes consistent with this Privacy Policy.

Service Providers
We may employ third party companies and individuals to perform services on our behalf, including:

  • Contract research organizations that conduct clinical trials
  • Data storage and analytics
  • Customer service (including our medical information line) and patient support providers (including for product quality and adverse event reporting, patient co-pay assistance, medicine intake adherence programs, etc.)
  • Product recall administration
  • Technology services and support (including email and web hosting providers, marketing and advertising technology providers, email and text communications providers, mobile app developers)
  • Event planning and travel organizations that help facilitate Neos programs
  • Payment, shipping and fulfillment service providers

These third parties may use your information only as directed by Neos and in a manner consistent with this Privacy Policy and are prohibited from using or disclosing your information for any other purpose.

Business Partners and Other Professionals and Organizations
We may disclose your personal information to partners with whom we jointly develop products or services, in connection with the development and promotion of such products or services. We will ask for your consent before disclosing your information with our business partners where required by applicable law. We may also share your personal information with health care professionals, researchers, academics, public health organizations, and publishers for purposes consistent with this Privacy Policy.

Internal Professional Advisors
We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.

Compliance with Laws and Law Enforcement; Protection and Safety
We may disclose information about you to government or law enforcement officials or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to (a) comply with applicable laws and lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern our websites, mobile apps, products and services; (d) protect our rights, privacy, safety or property, and/or that of you or others; and (e) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Business Transfers
We may sell, transfer or otherwise share some or all of its business or assets, including your personal information, in connection with a business deal (or potential business deal) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Policy.

Additional Program Terms
In some situations, we may have a separate agreement or relationship with you with respect to a specific type of processing of your data, such as if you participate in a special program, activity, event, or clinical trial. These situations will be governed by specific terms, privacy notices, or consent forms that provide additional information about how we will use your information. We will honor these additional terms with respect to your information and thus, strongly recommend you review the additional terms prior to participating in any programs.

Your Choices

Access, Review, Update Your Information
If you become aware that the personal information we maintain about you is inaccurate, incomplete, misleading, irrelevant or out of date, or if you would like to access or review your information, you may contact us at privacy@neostx.com.

Marketing communications
You may opt out of marketing-related emails by clicking the “Unsubscribe” link at the bottom of each such email, or by sending an email with the subject line “Unsubscribe” to privacy@neostx.com. You may continue to receive service-related and other non-marketing emails.

Choosing not to share your personal information
Where we are required by law to collect your personal information, or where we need your personal information in order to provide you with our products or services, if you do not provide this information when requested (or you later ask to delete it), we may not be able to provide you with our products or services and may need to terminate our relationship with you. We will tell you what information you must provide to us by designating it as required when we request the information or through other appropriate means.

Security
Security of all information is of the utmost importance for Neos. Neos uses organizational, technical and physical safeguards to protect the security of your personal data from unauthorized disclosure and to keep all information secure. We also make all attempts to ensure that only necessary people and third parties have access to Personal Data. Nevertheless, such security measures cannot prevent all loss, misuse or alteration of Personal Data and we are not responsible for any damages or liabilities relating to any such incidents to the fullest extent permitted by law. Where required under law, we will notify you of any such loss, misuse or alteration of Personal Data that may affect you so that you can take the appropriate actions for the due protection of your rights. Neos also reviews its security procedures periodically to consider appropriate new technology and updated methods.

Children
The Company recognizes the importance of protecting the privacy and safety of children. Our website and services are directed towards the general audience and are not directed towards children. We do not knowingly collect information about children under the age of 13 or minors otherwise defined in local law or regulation without verifiable parental consent. If we learn that someone under 13 has provided Personal Data through one of our websites, we will use reasonable efforts to remove that information from our databases.

Data Subject Access Requests
You have the right to access and limit the use and disclosure of your personal data. If you would like to express your point of view, challenge an explanation of data use, or otherwise obtain further information, contact info@neostx.com. If at any time after registering for information, your personal information changes, notify us and we will update your contact information. Please note, at any time, if you desire to obtain or transfer your information, we will provide you with your personal data in a structured and commonly used electronic format.

Additional Information for California Residents

IF YOU ARE NOT A CALIFORNIA RESIDENT THIS SECTION DOES NOT APPLY TO YOU.

California law grants its residents certain rights regarding the collection and use of their personal information. Subject to certain limitations, California residents have the following rights:

  • Right to Notice. You have the right to receive notice about the categories of personal information we have collected about you within the last 12 months, as well as the categories of sources from which such information is collected, the purpose for collecting such information and the categories of third parties with whom we share such information. You also have the right to know if we have sold or disclosed your personal information.
  • Right to Access. You have the right to request that we disclose or provide you with access to the specific pieces of personal information we have collected about you in the preceding 12 months.
  • Right to delete. You have the right to request the deletion of your personal information, subject to certain exceptions.
  • Right to non-discrimination. You have the right to not be discriminated against for exercising any of the above-listed rights. We may, however, provide a different level of service or charge a different rate reasonably relating to the value of your personal information.

If you are a California resident and would like to exercise your rights, please submit your request at privacy@neostx.com. Please note that we may require additional information from you in order to honor your request, and there may be circumstances where we will not be able to honor your request. For example, if you request deletion, we may need to retain certain personal information to comply with our legal obligations or other permitted purposes.

When submitting your request, please indicate your relationship with us as well as your specific request with enough information to allow us to understand and respond appropriately. We may request additional personal information from you in order to verify your identity. We will only use personal information provided in connection with a rights request under California law to review and comply with the request. If we are unable to verify your identity, we may decline a request to exercise rights under California law.

International Data Transfers
Neos is headquartered in the United States and has service providers in other countries, and your personal information may be transferred to the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.

Other Sites and Services
For your convenience and information, we may provide links to websites and other third-party content that is not owned or operated by Neos. These links are not an endorsement, authorization or representation that we are affiliated with that third party. We do not exercise control over third party websites or services and are not responsible for their actions. Other websites and services follow different rules regarding the use or disclosure of the personal information you submit to them. We encourage you to read the privacy policies of the other websites you visit and services you use.

Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. We encourage you to periodically review this page for the latest information on our privacy practices. If we make material changes to this Privacy Policy you will be notified via email (if we have your email address) or another manner that we believe reasonably likely to reach you (which may include posting a new privacy policy on our websites, or a specific announcement on this page).

Any modifications to this Privacy Policy will be effective upon our posting of the new terms and/or upon implementation of the changes (or as otherwise indicated at the time of posting). In all cases, your continued use of our websites, mobile apps, products and services after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.

Contact Us
Customers may contact Neos with any questions, concern, or inquiries about this Privacy Policy or company data. If you would like to make an inquiry or formal complaint, please contact Neos at the following mailing address or email.

Neos Therapeutics, Inc.
Attention: Chief Compliance Officer
1787 Sentry Parkway W
Veva 16, Suite 130
Blue Bell, PA 19422
privacy@neostx.com

All complaints will be evaluated and a reply will be sent as soon as appropriate. In some instances, Neos may have to cease services to you if necessary to satisfy your request.

Effective as of January 1, 2020.