Privacy Notice

Effective Date: February 15, 2024

Iovance Biotherapeutics, Inc., its affiliates, and subsidiaries (collectively “Iovance”, “we” or “us”), value your privacy. This privacy notice (“Notice”) describes how we may collect, share, use, and process personal information about you, your household, or your device (collectively “you”), and how you can exercise your privacy rights. It applies to personal information we collect through your interactions with any Iovance websites where this Notice is linked, applications, in-person events, communications with us, or by using our services, including using the IovanceClinical Portal, IovanceCares Hospital Portal, and the IovanceCares Patient Support eConsent Portal.

This Notice does not apply to job applicants, employees, clinical trial site personnel, and clinical trial participants, who receive separate privacy notices through other means. This Notice also does not apply to information collected through third-party websites or links provided to social media sites.

We may update this Notice from time to time. The effective date of the Notice is noted at the top of this page. If we make material changes to the way we collect, use, share or process the personal information that may adversely impact you, we will notify you. Any modifications to this Notice will be effective upon our posting the modified version. In all cases, your interaction with Iovance indicates that you acknowledge the modified content of this Notice.

TABLE OF CONTENTS

You can jump to a particular section by clicking on the headings below:

PERSONAL INFORMATION WE COLLECT

Some information we collect can directly or indirectly identify you (“Personal Information”). The types of Personal Information we collect are based on the specific function of the services that you use or program that you participate in and might include the following:

Information you voluntarily provide us: 

  • contact information (such as first and last name, mailing address, email address, telephone number, professional affiliation) and that of your caregiver if you are a patient;
  • demographic or geographic information (such as gender, date of birth, age, zip code);
  • information about your health and/or medical condition(s);
  • your photograph, video, voice recording, or digital electronic signature; 
  • your social media handle;
  • for services we provide to patients who receive AMTAGVI™ as treatment, and their family members or caregivers who will accompany them to the treatment facility, travel and lodging information, and health insurance information for patient who use the patient assistance program;
  • other information you choose to provide to us.

Information that may be collected automatically:

  • website usage information about your interaction with online services that you may access or use (such as IP address, pages visited, frequency of access, time spent on each page, browser used, internet address of the site that directed you to our website and referring website details).
  • information about your location, which may be determined through your IP address. You can adjust your consent to providing location information in the browser settings.
  • information about the device you use to access the website, such as hardware model, operating system, browser, and device preferences.

Information from Other Sources: We may also receive information about you from other sources, including third parties, such as our business partners, affiliates, publicly available sources, or social networks in which you participate.

  • For healthcare professionals: information obtained from a W-9, public sources or databases, publications (including contact information, education and professional history, and medical license number), professional affiliations, credentials, information from a resume.
  • For patients who are treated with AMTAGVI™: testing, manufacturing, and delivery of our products require coordination between Iovance and the hospital or center, where you will be treated, your physicians and other health care professionals (collectively, “healthcare providers”). This requires the healthcare providers to share certain Personal Information about you, including your name, date of birth, gender, address, medical condition, and sometimes insurance information.

HOW WE COLLECT YOUR PERSONAL INFORMATION

Iovance limits the collection and use of Personal Information to what is reasonably necessary to fulfill the purpose for which it was collected. Examples of when we may collect your Personal Information include: 

  • signing up for newsletter; 
  • registering for an event or program;
  • signing up for informational or marketing material; 
  • directly contacting us or providing us your information; 
  • making an inquiry about participation or eligibility for a clinical trial;
  • signing into the IovanceCares or IovanceClinical portals (healthcare professionals only);
  • reporting an adverse event;
  • visiting our websites or offices;
  • registering to use our programs or services;
  • providing a testimonial;
  • receiving AMTAGVI™;
  • interacting with us on social media or via email;
  • responding to inquiries;
  • other means.

If you submit Personal Information in relation to other individuals, you represent to Iovance that you have the authority to do so and permit us to use the information in accordance with this Notice.

HOW WE USE YOUR PERSONAL INFORMATION

Iovance may use your Personal Information in the following ways: 

  • to respond to your requests;
  • to provide customer support;
  • to improve our level of service;
  • to provide our websites, products, and services;
  • to provide you with information about our products, services, and programs;
  • to register visitors;
  • to record phone calls for training, quality assurance, and administration purposes;
  • to invite you to provide your views on our products and services, participate in research or attend events;
  • to administer speaker programs, training and scheduling speakers, coordinating events and travel, processing honoraria and expenses;
  • to complete transactions;
  • to report any product adverse events;
  • to perform analytics;
  • to provide access where required to our sites and facilities;
  • to manufacture AMTAGVI™ therapy for you;
  • to communicate with your healthcare providers relating to your treatment;
  • to assist you with travel and lodging arrangements, billing and payment, coordinating with healthcare providers and payors for understanding coverage for Iovance products, or determining your eligibility for alternative forms of coverage and sources of funding for Iovance products at your request;
  • in accordance with your written consent;
  • for Iovance’s quality and operations such as maintaining chain of custody and chain of identity, delivering the product, performing quality checks on the product, internal audits, or developing regulatory data for our therapies;
  • for administration, billing or other purposes as may be permitted by law;
  • for our own administrative and quality assurance purposes; and
  • for other purposes that may be detailed on our website which will be described at the time the information is collected, and as permitted by applicable law.

HOW WE SHARE YOUR PERSONAL INFORMATION

The Personal Information we collect from and about you may be shared: 

  • with our subsidiaries and affiliates to exchange information, provide services, and maintain databases;
  • with third-parties that provide services to us or with whom we collaborate. Iovance requires them to not use your Personal Information for independent purposes not authorized by Iovance and to protect it using substantially similar standards to those outlined in this Notice;
  • with healthcare providers, to communicate and coordinate your care and the manufacturing and delivery of your therapy;
  • to third parties, advisors, and other entities for development of or to proceed with the negotiation or completion of a corporate or commercial transaction, including a corporate reorganization, merger, acquisition, joint venture, sale or other disposition of all or a portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings);
  • as required to prevent harm, where necessary to detect, investigate, prevent, or take action against illegal activities, fraud, or situations involving potential threats to the rights, property, or personal safety of any person, as well as the security and integrity of our systems;
  • as required by law, such as to law enforcement, health authorities to report possible adverse events, during government inspections or audits, in response to court or administrative orders, to comply with a subpoena or other legal process, as part of quality, safety, and regulatory reporting requirements, to establish, protect, or exercise our legal rights, as required to enforce our terms of use or other contracts, to defend against legal claims or demands, or to comply with the requirements of any applicable law;
  • Iovance does not sell your Personal Information in exchange for monetary or other valuable consideration, nor do we share your Personal Information for purposes of targeted or cross-context behavioral advertising.

HOW LONG WE KEEP YOUR PERSONAL INFORMATION

Iovance will only store Personal Information for as long as reasonably necessary to fulfill the purposes for which it was collected, subject to applicable data retention periods imposed upon Iovance by applicable law. This may mean that your Personal Information is stored by Iovance for a number of years, depending on the purpose and the need for that data to be processed. For more information about Iovance’s retention periods of Personal Information, please refer to “How to Contact Us” section below.

COOKIE NOTICE

We use technologies like internet tags and cookies to automatically gather information about the use of our websites and how people interact with our emails. We use technologies such as local storage and cookies to store an access token on your browser which enables us to recognize you and your preferences the next time that you log in. We do this specifically to (i) ensure the website functions properly; (ii) learn how you use the website; (iii) enhance user experience; (iv) conduct analytics to improve the website; (v) prevent fraudulent use of the website; and (vi) diagnose and repair technical errors within the website and, in cases of abuse, track and mitigate the abuse. Iovance uses three types of cookies:

  • Essential Cookies. These are necessary for basic website functionality, including session cookies, authentication cookies, and security cookies. These cookies are placed on your computer to let our website function as intended, by allowing the pages to display correctly. Without these, our website would be prevented from working and would be unusable.
  • Preferences & Functionality Cookies: These cookies enhance functionality, performance, and services on the website, allowing the site to remember how it looks based on your preferences (e.g. your preferred language or the region you are in). These cookies can also assist you in changing text size, font, and allow you to personalize the pages based on your preferences. While disabling these cookies would not prevent our website from working, it may make it less functional.
  • Third-Party Cookies: We use third-party cookies for analytics, to improve the website and enhance user experience. The analytics cookies allow us to recognize and count the number of users to the website, see when users are using the website, see how users interact with the website, which page are viewed most frequently viewed, and help us record any difficulties you may have with the website. We use Google Analytics, with restricted data processing enabled, so this use is not considered a sale under the California Consumer Privacy Act. Google Analytics may also receive information about you from applications you have downloaded that partner with Google. Iovance does not combine the information collected through Google Analytics with personally identifiable information. The Google Analytics terms describe how Google may use and share the information collected by Google Analytics. To prevent your data from being used by Google Analytics. To prevent your data from being used by Google Analytics, you can download the Google Analytics opt-out browser add-on here.

How to restrict cookies: You may restrict or block web browser cookies on your device through the Privacy Preference Center which can be accessed by clicking Cookie Settings in the banner that appears at the bottom of our website. Alternatively, you may wish to visit www.aboutcookies.org, which contains comprehensive information on how to change settings for a variety of desktop browsers.

Do Not Track Disclosure: Some internet browsers allow you to limit or disable the use of tracking technologies that collect this data. We currently do not support Do Not Track signals.

DATA INTEGRITY AND SECURITY

Iovance has implemented reasonable technical, administrative, and physical safeguards to protect your Personal Information (and requires its vendors and service providers to do the same) from unauthorized access, disclosure, alteration, or destruction. However, we cannot guarantee the absolute security of your Personal Information, especially when transmitted over the internet or electronically stored. Therefore, when submitting Personal Information to Iovance, you must weigh both the benefits and the risks.

UPDATING AND ACCESSING YOUR DATA

We encourage you to update the Personal Information you provide Iovance periodically so that we have the most up-to-date information. Additionally, if specific laws or regulations apply, subject to certain exceptions, you may have rights to access, correct or delete your Personal Information. Please see Supplemental Provisions for Specific Geographic Areas below, as it may include important information about exercising privacy rights. We will respond to requests consistent with applicable laws. For your protection, all requests will be subject to verification of your identity first.

You may unsubscribe from our marketing emails at any time by following the instructions included in those emails. Any requests to opt-out of future communications from Iovance or to opt-out of a particular Iovance program should be directed to Iovance using the contact method indicated in the marketing email.

CHILDREN’S ONLINE PRIVACY

Iovance does not knowingly collect Personal information from children under 13 without obtaining prior parental consent. If we learn that we have collected or received Personal Information from a child under 13 without parental consent, or if you become aware that we may have collected such information from our websites, alert us immediately at privacy@iovance.com. For more information about protecting the privacy of children online in the United States under the Children’s Online Privacy Protection Act (“COPPA”), please visit: http://www.ftc.gov/ogc/coppa1.htm.

LINKS AND THIRD-PARTY SITES

Our website may contain links or references to third-party websites that are not under Iovance’s control. This Notice does not apply to third-party operated or controlled websites. Iovance may have some social media (e.g., Facebook) “widgets” on Iovance’s website, which may track you across several websites. For example, if you are logged in to Facebook, if you land on a webpage that has a Facebook widget, the widget will signal to Facebook about the particular page you are on. Iovance does not control the privacy practices of these third parties. If you do not wish to enter another website, do not click on such links.

Some of Iovance’s service providers (e.g., website providers), may use their cookies on Iovance’s website. Although Iovance may not have direct access to or control over such cookies, this Notice governs the use of cookies by Iovance and such service providers on Iovance’s website.

SUPPLEMENTAL PROVISIONS FOR SPECIFIC GEOGRAPHIC AREAS

Depending on your state or country of residence, you may be entitled to further information about our practices and your privacy rights. Your Personal Information may be collected, transferred to, and stored by us and third parties shown in How We Share Your Personal Information above outside of your state or country of residence. The Personal Information will be subject to the laws of the country in which it is held (likely the USA), and may be subject to disclosure to governments, courts, or law enforcement or regulatory agencies of such other country. The supplemental provisions apply to persons from the geographic areas specifically named below and are in addition to general statements made above and supersede any conflicting general statements.

EUROPEAN ECONOMIC AREA (EEA), SWITZERLAND AND THE UNITED KINGDOM (UK)

To the extent Iovance receives or processes Personal Information about an individual located in the EEA, Switzerland, or the UK, the following additional principles and disclosures shall apply:

  • For this processing of Personal Information, Iovance has assigned a data protection officer (DPO) and a data protection representative (DPR) responsible for overseeing our compliance with EU and UK data protection laws.
CountriesDPODPR
EEAJelmer Pietersj.pieters@dpoconsultancy.nlDPO Consultancy B.V.dpr@dpoconsultancy.nl
Reitscheweg 37, 5232 BC’s-Hertogenbosch, The Netherlands
UKJelmer Pietersj.pieters@dpoconsultancy.nlDPO Consultancy Ltd.info@dpoconsultancy.co.uk
19 The Square, Retford
Nottinghamshire, DN 22 6DQ
  • The processing of your Personal Information is intended for the following purposes: for legitimate interest or the performance of a contract in accordance with Art. 6 (1) (b) and (f) the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”);
  • The categories of recipients of your Personal Information are: Iovance affiliates, employees, consultants, health authorities, and third-party service providers;
  • You have the following rights to request about your Personal Information:
  • Right to Access the Personal Information you provided us;
  • Right to Deletion of your Personal Information that you provided us, subject to certain exceptions.
  • Right to Rectification of inaccuracies about the Personal Information you provided us;
  • Right to Restrict processing concerning your Personal Information;
  • Right to be Informed about what Personal Information is collected about you, why, who is collecting it, how long it will be kept, how it is shared and how to file a complaint;
  • Right to Object to the processing of your Personal Information;
  • Right to Portability to receive your Personal Information in a manner that is structured and in a standard format that can potentially be transmitted to another party; and/or
  • Withdrawal of Consent. If consent was obtained, you have the right to withdraw your consent for the processing of Personal Information.

You may exercise these rights free of charge unless the request is unfounded, excessive, or otherwise unreasonable, for instance, because it is repetitive. In some situations, we may refuse to act or may impose limitations on your rights, as permitted by law.

You must provide us with sufficient information that allows us to reasonably verify your identity and describe your request with sufficient detail to allow us to properly evaluate and respond to it. If we are unable to verify your identity with the information you provided, we may ask you for additional pieces of information.

For questions or complaints concerning the processing of your Personal Information, you can email our DPO at j.pieters@dpoconsultancy.nl. If you are dissatisfied with the outcome of the complaint or the way in which the complaint was handled, you may lodge a complaint with the appropriate data protection authority in your country. You can find the relevant name and contact details under http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm, and for the UK under https://ico.org.uk/make-a-complaint/.

Transfers of your Personal Information may be made to entities located outside the European Economic Area, including entities located in the United States, for processing consistent with the purposes above. Pursuant to Article 46 of the GDPR, Iovance will implement appropriate contractual measures (including standard data protection clauses, a copy of which you can obtain by contacting us) to ensure that the relevant Iovance companies and third parties outside the EEA provide an adequate level of protection to your Personal Information as set out in this Notice and as required by applicable law.

CALIFORNIA RESIDENTS

To the extent Iovance receives or processes Personal Information about an individual who is a resident of California, and if the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations, collectively CCPA, applies, this section’s additional terms apply. This section does not address or apply to our handling of Personal Information that is exempt from the CCPA.

In addition to the categories of Personal Information We Collect listed above, for patients who receive AMTAGVI™ as treatment, the testing, manufacturing and delivery of our products require coordination between Iovance and the hospital or center where you will be treated and with your physicians and other health care professionals (collectively, “healthcare providers”). This requires the healthcare providers to share certain sensitive Personal Information about you, including your health information, your racial origin and race, and sometimes your insurance information. We only use and disclose sensitive Personal Information as reasonability necessary to perform our services requested by you;

Purpose. For the purpose of the collection of Personal Information, please reference How We Use Your Personal Information.

Sharing Personal Information. For information about which categories of third parties we share your Personal Information with, please reference How We Share Your Personal Information.

Sale/ Sharing. Iovance does not sell your Personal Information in exchange for monetary or other valuable consideration, nor do we share your Personal Information for purposes of targeted or cross-context behavioral advertising.

Retention. For the retention period of your Personal Information, please reference How Long We Keep Your Personal Information.

CCPA Rights of California Residents. You are entitled to the following rights, subject to certain limitations and exceptions:

  • Right to Access the Personal Information we have collected, used, disclosed, and sold about you;
  • Right to Deletion of your personal information, subject to certain exceptions;
  • Right to Correct Personal Information about you that is incorrect;
  • Right to Non-Discrimination. You have the right to not receive discriminatory treatment if and when you exercise your rights under the CCPA.

If you are a California resident and want to exercise your rights to access, delete or correct, please email privacy@iovance.com, or call us at 1.866.565.4410 (toll free), or by mail at: 825 Industrial Road, Suite 400, San Carlos, California. You must provide us with sufficient information to verify your identity and describe your request in detail to allow us to properly evaluate and respond to it. If we are unable to verify your identity with the information you provide, we may ask you for additional information. Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a request related to your Personal Information. If you are an authorized agent making a request on behalf of another individual, you must provide us with a signed document that shows that you are authorized to act on behalf of that individual. Please note that we are not obligated to respond to more than two access requests for the same individual’s Personal Information within a 12-month period.

California law also permits California residents to request certain information about the disclosure of Personal Information to third parties for their own direct marketing purposes during the preceding calendar year. We do not share the Personal Information of California residents with third parties for their own direct marketing purposes. However, if you have further questions about our privacy practices and compliance with California law, please contact us.

AUSTRALIA

To the extent Iovance receives or processes Personal Information about an individual who is located in Australia, the following additional principles and disclosures apply, subject to certain limitations:

  • The Right to Access Personal Information that we hold about you; and/or
  • The Right to Correct your Personal Information if it is inaccurate, outdated, incomplete, irrelevant, or misleading.

You can ask to access or correct your Personal Information by contacting us using the details below. We will endeavour to respond to your request within 30 days. We will ask you to verify your identity before we give you access to your information or correct it, and we will try to make the process as simple as possible. If we refuse to give you access to, or correct, your Personal Information, we must notify you in writing setting out the reasons.

If you have any questions or complaints about this Notice or consider there has been any breach of the APPs, please contact us in writing. If you are dissatisfied with the outcome of the complaint or the way in which the complaint was handled, you may contact the Office of the Australian Information Commissioner (“OAIC”).

HOW TO CONTACT US

If you have questions or comments about our privacy practices or this Notice or to request this Notice in another form, contact us at:

 

Iovance Biotherapeutics, Inc.
Attn: Privacy Office
825 Industrial Road, Suite 400, San Carlos, California
Phone: +1.650.260.7120 or toll free: 1.866.565.4410
privacy@iovance.com