Privacy Policy

1. INTRODUCTION

We take your privacy seriously and are committed to being transparent with how we use your Personal Information. This Privacy Policy describes how Foghorn Therapeutics, Inc. and its affiliates (“Foghorn,” “we,” “us,” and/or “our”) collect, use, disclose, and process Personal Information we collect online (e.g., through our website at foghorntx.com and other websites, the “Sites”) and does not apply to our clinical trials or to our data collection from employees or contractors.

This Privacy Policy forms a part of the Terms governing your use of the Site.

2. TYPES OF PERSONAL INFORMATION WE COLLECT

Within the context of this Privacy Policy, “Personal Information” means information that enables the identification, directly or indirectly, of a specific person or household.

The types of Personal Information we collect depend on the nature of the relationship you have with Foghorn and the requirements of applicable laws. The types of Personal Information we collect include:

  • Contact and demographic information, such as your name, phone number, email and postal address;
  • Information we obtain from your use of our Services, such as device information (e.g., IP address, browser information), and login information;
  • Other information you provide to us, such as information provided in optional forms and email correspondence.
3. INFORMATION COLLECTED AUTOMATICALLY

We may automatically collect certain information about the devices you use to access our Sites, as well as information on how you interact with our Sites, through cookies, web server logs, web beacons and other similar technologies. The information we collect automatically may include:

  • URLs that refer visitors to our Sites;
  • Search terms used to reach our Sites;
  • Details about the devices that are used to access our Sites (such as IP address, browser information, device information, and operating system information);
  • Details about your interaction with our Sites (such as the date, time, length of stay, and specific pages accessed during your visits to our Sites, and which emails you may have opened); and
  • Usage information (such as the number and frequency of visitors to our Sites).

We may associate this information with the device you use to connect to our Services.

4. COOKIES AND OTHER SIMILAR TECHNOLOGIES

Foghorn and its service providers may collect information using cookies, tags and other technologies. A “cookie” is a text file that websites send to a visitor’s computer or other internet-connected device to uniquely identify the visitor’s browser or to store information or settings in the browser. A “web beacon,” also known as a pixel tag or clear GIF, is used to transmit information back to a web server. We may use third-party web analytics services (such as those of Google Analytics) and other technologies on our Services to collect and analyze usage information through cookies and similar tools; engage in activities such as auditing, research, or reporting; and provide certain features to you. To prevent Google Analytics from using your information for analytics, you may install the Google Analytics Opt-out Browser Add-on by clicking here.

Please be aware that some analytics providers may set and access their own cookies, pixel tags and similar technologies on the Site and may also collect or have access to information about you collected over a period of time and/or across a variety of website. Any such information is collected by the applicable third parties and not by Foghorn.

If you do not want the Site to collect information through the use of cookies, your browser may permit you to be notified of or disable certain cookies. This functionality varies by browser. Please note that if you disable or reject cookies, some functionality of the Site may not work correctly.

Please also note that our Sites do not presently respond to or modify its practices in response to browser Do Not Track (“DNT”) signals.

5. HOW WE USE YOUR PERSONAL INFORMATION

We use the information we collect for the following purposes:

  • Managing, operating and growing our business, and administering the Services, including through the use of third-party service providers;
  • Complying with legal or regulatory obligations;
  • Developing new resources and services;
  • Processing and considering applications for employment, including evaluating and confirming your suitability for a position and accuracy of any information submitted;
  • Monitoring and auditing compliance with internal policies and procedures, legal obligations and to meet requirements and orders of regulatory authorities;
  • Communicating with you to respond to your inquiries and to provide technical or administrative support;
  • Conducting marketing activities, communicating updates, invitations and other information that we believe may be of interest to you;
  • Investigating and resolving disputes and security issues and enforcing our Terms and Conditions;
  • Preventing, investigating and providing notice of fraud, unlawful or criminal activity, unauthorized access to or use of Personal Data, the website or our data systems, and to meet legal, regulatory, judicial and company policy obligations; and
  • For any other lawful, legitimate business purposes.
6. EMPLOYMENT APPLICATIONS

If you apply for employment with Foghorn, we will use the information you provide to process your application, to monitor recruitment statistics, and to comply with government reporting requirements. We may retain de-identified statistical information about applicants to help inform our recruitment activities. Foghorn is headquartered in the United States and employee and recruitment data is held there. If an applicant becomes a Foghorn employee, Foghorn will maintain a record relating to that person’s employment (including information collected via the employment application) and provide additional information about our data practices in connection with employee data to the extent required by law.

7. HOW WE SHARE PERSONAL INFORMATION

We share personal information with:

  • Foghorn affiliates;
  • Service providers such as those who provide us with technology services;
  • Regulators;
  • Health care professionals, researchers, academics, and public health organizations;
  • Partners with whom we jointly develop clinical trials;
  • Law enforcement and other third parties where necessary to protect against fraud, illegal activity, and claims and other liabilities;
  • In connection with due diligence or a transaction process relating to a sale by Foghorn of all or part of its business, or transfer of assets, or transaction involving a merger, restructuring or business transfer.
8. DATA SUBJECT RIGHTS

Individuals in Andorra, Argentina, Australia, California, Canada, Europe, Faroe Islands, Guernsey, Hong Kong, Israel, Isle of Man, Japan, Jersey, Mexico, New Zealand, Singapore, South Korea, Switzerland, the United Kingdom, Uruguay, and certain other jurisdictions may have certain data subject rights. These rights vary, but they may include the right to: (i) request access to and rectification or erasure of their personal information; (ii) restrict or object to the processing of their personal information; (iii) obtain a copy of their personal information in a portable format; and (iv) object to certain personal information processing activities. Individuals may also have the right to lodge a complaint about the processing of personal information with a data protection authority.

If you wish to exercise any of these rights please contact us using the information in the “How to Contact Us” section below. The rights described herein are not absolute and we reserve all of our rights available to us at law in this regard. Additionally, if we retain your Personal Information only in de-identified form, we will not attempt to re-identify your data in response to a data subject rights request.

The California Consumer Privacy Act (“CCPA”) prohibits covered businesses from discriminating against you for exercising applicable CCPA rights.

If you make a request related to personal information about you, we will need to verify your identity. To do so, we will request that you match specific pieces of information you have provided to us previously. If it is necessary to collect additional information from you, we will use the information only for verification purposes and will delete it as soon as practicable after complying with the request. For requests related to particularly sensitive information, we may require additional proof of identification. If you make a request through an authorized agent, we will require written proof that the agent is authorized to act on your behalf. We will process your request within the time provided by applicable law.

9. INTERNATIONAL DATA TRANSFERS

We operate our information technology systems, including the website, from the United States, where we are headquartered.  Any information you provide to us may be stored and processed, transferred between and accessed from the United States, and other countries which may not guarantee the same level of protection of personal information as the one in which you reside.  However, we will handle your personal information in accordance with this Privacy Policy regardless of where your personal information is stored/accessed.

We take reasonable steps to ensure that the overseas recipients of your personal information do not breach the privacy obligations relating to your personal information.  Where required by certain jurisdictions, we will transfer your information subject to jurisdiction-approved safeguards, such as standard contractual clauses.

10. INFORMATION SECURITY

We use technical, administrative and procedural measures in an attempt to safeguard your personal information from unauthorized access or use. No such measure is ever 100% effective though, so we do not guarantee that your personal information will be secure from theft, loss, or unauthorized access or use, and we make no representation as to the reasonableness, efficacy, or appropriateness of the measures we use to safeguard such data.

11. THIRD-PARTY SITES

We may provide links to websites and other third-party content that is not owned or operated by Foghorn. Our Privacy Policy does not apply to services offered by other companies or individuals, including products or sites that may be displayed to you on this site. We also do not control the privacy policies and your privacy settings on third-party sites, including social networks.

12. CHILDREN’S PRIVACY

Our site is not directed toward children under the age of thirteen (13) and we will not knowingly collect information for any child under the age of thirteen (13). If you are the parent of a child under the age of thirteen (13) and have a concern regarding your child’s information on our website, please contact us using the information in the section “How to Contact Us.”

13. DATA RETENTION

We retain personal information for as long as is necessary for the processing purpose(s) for which the information was collected, and any other permissible, related purpose. When we no longer need the personal information we collect, we either anonymize the information or securely destroy the data.

14. UPDATES

We may update our Privacy Policy from time to time. We will post updates to the Privacy Policy on this page and, if the changes are material, we may also provide a more prominent notice on our Sites.

15. HOW TO CONTACT US

You may contact us with questions, comments, or complaints about this Privacy Policy using the contact information below:

privacy@foghorntx.com