Avedro, Inc. (“us”, “we”, or “our”) operates http://www.livingwithkeratoconus.com (the “Site”). This Privacy Policy describes the way in which we collect, use and disclose the personally identifiable information (“Personal Information”) we receive from users of the Site and any other websites that link to this Privacy Policy (the “Online Services”). When we refer to ourselves as “us”, “we” or “our” in this Privacy Policy we mean our entire company, including our affiliates such as subsidiaries.

By using the Online Services, you consent to the processing, collection and use of your Personal Information in accordance with this Privacy Policy now and as amended by us from time to time. If you do not agree to this Privacy Policy, you may not use the Site. This Privacy Policy is subject to change without notice from time to time in our sole discretion. You acknowledge that by accessing the Site after we have posted changes to this Privacy Policy, you are agreeing to this Privacy Policy as amended.

You should carefully read this Privacy Policy before using and/or submitting information through the Online Services. Please note that this Privacy Policy is not an exclusive statement of our privacy principles across all of our products and services. Other privacy principles or policies may apply depending on the products or services you obtain from us, or the jurisdiction in which you transact with us.

Information Collection and Use

Below are the types of Personal Information that we might collect from you.

A. Information you provide

We and our Service Providers (defined below) collect information that you choose to provide when you use the Online Services, including when you register to access the Online Services, sign up to receive emails or other communications, apply for a job, report a safety-related event related to one of our products (e.g., an adverse event, use during pregnancy or lactation, suspected interaction with other products, treatment errors such as overdose, usage outside the conditions in the label), or otherwise contact us with a question, comment, or request. This can include, but is not limited to: (a) your name, contact information, sex, and other registration information; (b) health information; (c) information you provide when submitting an employment application form; and (d) information you provide us when you contact us. If you report an experience or reaction involving one of our products, we may ask you for additional information, for example, to help us meet our reporting obligations under existing federal law. Any information collected about you from the Site can, from time to time, be associated with other identifying information we have about you.

If you are a medical professional and are using the Online Services for reasons other than reporting a product experience, you should make sure that you do not disclose identifiable information about your patients where not authorized by law.

B. Information automatically collected from you

We and our Service Providers (defined below) automatically collect certain technical information from your computer when you use the Online Services, such as your Internet Protocol address, your browser type, your operating system, the pages you view through the Online Services, the pages you view immediately before and after you access the Online Services, the length of time that you spend using the Online Services, and the search terms you enter through the Online Services. This information allows us to recognize you and personalize your experience if you return to the Online Services using the same computer, and to improve the Online Services and the services we provide. We and our Service Providers (defined below) may collect this information using “cookies,” which are small text files that the Online Services save on your computer using your web browser and access when you return, web beacons, tracking pixels, or other technologies. From time to time, we may use or augment this information with information obtained by third parties.

C. Information from outside sources

In certain instances, we collect information about you from other sources, such as information about physicians or other health care professionals who register with the Online Services in order to verify their licensure status and identity.

Use of Data

We use the information we collect for a number of purposes, including, but not limited to:

  • providing you with products, services, or information you request, such as sending you investor information or processing your employment application;
  • creating customized offers, information, and services tailored to your interests and preferences;
  • sending you emails containing newsletters or other information that may be of interest to you;
  • providing you with information about the Online Services or required notices;
  • investigating safety-related events arising from the use of our products, provided that if you report to us a safety-related event through our forms set up for this purpose for patients or healthcare professionals, we will only use the data you provide through the forms to
  • contact you and to comply with the applicable laws regarding this type of information;
  • customizing your experience when using the Online Services, such as by providing interactive or personalized elements through the Online Services and providing you with content based on your interests;
  • allowing us to improve the Online Services and the products and services we provide, such as by better tailoring our content to our users’ needs and preferences;
  • generating and analyzing statistics about your use of the Online Services; and
  • detecting, preventing, and responding to fraud, intellectual property infringement, violations of any terms of us, violations of law, or other misuse of the Online Services.

We also may combine or aggregate any of the information we collect through the Online Services or elsewhere for any of these purposes.

Disclosure of Personal Information

We will not sell or otherwise disclose any Personal Information, including your name, contact information, government identifier, or any other information associated with those data elements, we collect about or from you through the Online Services to any third parties without your consent, except as follows:

• to our affiliates and companies and individuals that provide services to us and on our behalf (“Service Providers”) including, but not limited to, service providers such as background check vendors that evaluate your eligibility for employment opportunities to which you apply, data analysis firms, email and SMS vendors, web-hosting and development companies, and our webmasters, attorneys, auditors, and others who are hired to analyze the data collected through the Online Services, provided that such Service Providers shall only use the information to carry out the function being provided for us or on our behalf;
• as required by law including, but not limited to, to comply with a subpoena or other legal process, regulatory requirement, judicial proceeding, or court order served on us, to comply with government reporting obligations such as disclosing information you submit about your personal experiences with one of our pharmaceutical products (investigational or marketed) to the Federal Food and Drug Administration pursuant to federal regulations;
• when we believe in good faith that disclosure is necessary (a) to protect our rights, the integrity of the Online Services, or your safety or the safety of others, (b) to detect, prevent, or respond to fraud, intellectual property infringement, violations of any terms of use, violations of law, or other misuse of the Online Services, or (c) for corporate audits or to investigate or respond to a complaint or security threat; and
• to affiliates, Service Providers, advisors, and other third parties in connection with the negotiation or completion of a merger, acquisition, or sale of all or a portion of our assets.

We occasionally disclose aggregate or de-identified data that is not personally identifiable with third parties.

Where Information Is Stored

Information collected through the Online Services will be processed in and subject to the laws of the United States, which may not provide the same level protection for your information as your home country, and may be available to the United States government or its agencies under a lawful order made in United States. In addition, we may transfer your information outside of the United States to our affiliates, business partners, and Service Providers located in other countries. By using the Online Services, you consent to such transfer to, and processing in, the United States and these other countries.

Links to Other Websites

The Online Services may contain tools, technology or links to websites provided by third parties. You acknowledge and agree that we are not responsible for the collection and use of your information by such third parties. We encourage you to review the privacy policies of each website you visit.

Cookies

We often collect information about you by using cookies, tracking pixels and other technologies. We use this information to better understand, customize and improve user experience with our websites, services and offerings, as well as to manage our advertising. For example, we use web analytics services that use these technologies to gather information to help us understand how visitors engage with and navigate our Website, e.g., how and when pages in a site are visited and by how many visitors. We are also able to offer our visitors a more customized, relevant experience on our sites using these technologies by delivering content and functionality based on your preferences and interests. Cookies are files with small amount of data, which may include an anonymous unique identifier.

Depending on their purpose, some cookies will only operate for the length of a single browsing session, while others have a longer life span to ensure that they fulfill their longer-term purposes. Your web browser can be set to allow you to control whether you will accept cookies or reject cookies, to notify you each time a cookie is sent to your browser, or to delete cookies that have already been set. If your browser is set to reject cookies, certain aspects of the Site that are cookie-enabled will not recognize you when you return to the website, and some Site functionality may be lost. The “Help” section of your browser may tell you how to prevent your browser from accepting cookies. To find out more about cookies you may visit http://www.aboutcookies.org.

Do Not Track Disclosures

Do Not Track (“DNT”) is a privacy preference that users can set in their web browsers. When a user turns on DNT, the browser sends a message to websites requesting that they don’t track the user. At this time, we ignore these signals. We do not change our practices, described elsewhere in this Privacy Policy, in response to DNT browser settings or signals. In particular, even if you have turned on DNT, we and others will continue to collect information about you and your activity through the use of cookies, tracking pixels and other technologies. For information about DNT, visit http://www.allaboutdnt.org.

Notice to California Residents

Under California law, California residents may request a list of all third parties to whom we have disclosed certain personal information (as defined by California law) during the preceding year for those third parties’ direct marketing purposes. If you are a California resident and would like to receive such a list, please contact us at info@avedro.com. For any such request, include the statement “Your California Privacy Rights” in the body of your request, as well as your name, street address, city, state and zip code. Please provide enough information for us to determine if this applies to you. You must also attest to the fact that you are a California resident and provide a current California address for our response. Please note that we will not accept requests via the telephone, email, or by facsimile, and we are not responsible for notices that are not labeled or sent properly or that do not have complete information.

Your Choices

If you no longer wish to receive emails from us, you can do so at any time by clicking on the relevant link included along with the emails you receive from us or by letting us know at the contact information provided below.

Children’s Policy

The Site is not directed to, nor do we knowingly collect information from, children under the age of 13. If you become aware that your child or any child under your care has provided us with information without your consent, please contact us at the contact information listed below.

Security

The security of your Personal Information is important to us, but remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security. Moreover, we are not responsible for the security of information you transmit to the Online Services over networks that we do not control, including the Internet and wireless networks.

Keep in mind that any passwords, ID numbers, or other special access numbers you might use to access any part of the Online Services are your responsibility, so you should safeguard them carefully. You should take steps to ensure that the computer you are using is adequately secured and protected against malicious software. Without adequate security measures (e.g., secure web browser configuration, up-to-date antivirus software, personal firewall software, no usage of software from dubious sources) there is a risk that the data and passwords you use to protect access to your data on the Online Services could be disclosed to unauthorized third parties.

Changes to This Privacy Policy

This Privacy Policy is effective as of (add date) and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page. If you believe any credentials you use to access the Online Services have been compromised, please change them and let us know as soon as possible.

Contact Us

If you have any questions about this Privacy Policy your personal information or require assistance in managing your choices, please contact us here or at:

Avedro, Inc.
Marketing Department
201 Jones Road
Waltham, MA 02451
(844) 528-3376

Last updated: February 14, 2019

Disclaimer

Where the Site contains links to third-party websites/content/services that are not owned or controlled by us, we are not responsible for how these properties operate or treat your Personal Information so we recommend that you read the privacy policies and terms associated with these third party properties carefully.