WEBSITE PRIVACY POLICY

Version March 2022

AC Immune SA and/or its affiliated companies (“AC Immune”, “we” or “our”) is committed to protecting and respecting the privacy of individuals visiting our website. In this Privacy Policy, we describe how AC Immune processes personal information, by providing the relevant information regarding the processing, the rights of the data subjects and the safeguards we implement to protect personal data.

1. Compliance with Data Protection Laws

AC Immune complies with the European General Data Protection Regulation (GDPR), as well as the Swiss Federal Data Protection Act (FDPA) for the processing of personal data (together “Data Protection Rules”).

2. Contact Information

The company responsible for data processing is:

AC Immune SA
EPFL Innovation Park, Building B,
1015 Lausanne
Switzerland
Phone: +41 21 345 91 21
Fax: +41 21 345 91 20

Our Data Protection Officer may be contacted via email at: dpo@acimmune.com

You can access a copy of this Privacy Policy via the following link:
https://www.acimmune.com/privacy-policy/

3. Data Subject Rights

You have the right to the preservation of your privacy. This includes the right to information, access, correction, deletion, limitation of data processing, objection to data processing and the right to withdraw your consent when a process is based on it.

4. Collection and Use of Personal Data

When visiting AC Immune’s website, some of your personal data is collected and processed, on the basis of your consent, the law or our legitimate interest.

4.1. Personal data collected

  • Personal data such as, but not limited to:
    • Contact information (name and e-mail address);
    • Documents related to job applications;
    • Other information.
  • Non-personal information such as, but not limited to:
    • Browser type and operating system;
    • IP address;
    • Unique identifiers;
    • Pages you view;
    • Sites you visited;
    • Information collected through cookies (see hereunder section about Cookies (5.) and Google Analytics (6.))

4.2. Purpose for the processing

Your personal data is used to provide you with services, such as but not limited to:

  • Sending you newsletters or information you requested;
  • Contact you via email;
  • Perform analyses regarding the administration and use of our website;
  • Process job applications or related activities;
  • Personalize or customize your use of the website;
  • Any other purpose pursuant to your consent.

4.3. Storage of your personal data

Your data is stored for as long as necessary for the purpose. In certain instances, we may have to store data for longer, when required by the law.

4.4. Transfer of your personal data

4.4.1. Third Parties

AC Immune may use third parties for the processing of your personal data. Those follow the same principles and rules required by Data Protection Rules.

4.4.2. Third Parties in a country without adequate level of protection

AC Immune may use third parties based outside of the European Union or Switzerland, in a country without data protection laws with the same level of protection as applicable to AC Immune. In such cases, we provide appropriate safeguards to ensure that your personal data is protected, and your privacy maintained.

5. Cookies

Our website uses cookies for technical purposes as well as to allow the personalization of your experience on our website. Data may also be collected for analytical and website administration purposes.

6. Use of Google Analytics

Google Analytics is a web analytics service provided by Google LLC. The service uses cookies to collect information about your use of our website, which may include your IP address. This data may be sent to Google’s servers in the U.S.

The following cookies are activated on our website:

  • _ga (cookie used to distinguish individual users on your domain, expires after 2 years).
  • _gid (cookie used to distinguish individual users on your domain, expires after 24 hours).
  • _gat (cookie used to limit the number of user requests to maintain the performance of your website, expires after 1 minute)
  • AMP_TOKEN (cookie containing a unique identifier assigned to each user of your domain, expires between 30 seconds and 1 year)
  • gac_<property-id> (cookie containing a unique identifier that allows Google Analytics and ads to work together, expires after 90 days).

You have the right to disable non-necessary cookies and opt-out of having your data used by Google Analytics.

7. Use of Google Fonts

Our website uses Google fonts. Similarly, to Google Analytics, your IP address may be collected and sent to Google’s servers in the U.S.