Privacy Notice
Privacy Notice for the Protection of Personal information (PPI)
Last Update: April 22, 2025
1. Preamble and objectives
Ability Biotherapeutics recognizes the importance of protecting Personal Information, that is any information about an individual that directly or indirectly allows that individual to be identified, as defined hereunder.
The purpose of the present Privacy notice (the “Notice“) is to describe our privacy practices. It applies to all your interactions with Ability Biotherapeutics.
2. Definitions
“Person concerned” or “you” means any identified or identifiable individual about whom Ability Biotherapeutics collects Personal information. This Notice does not apply to Ability Biotherapeutics employees and other personnel.
“Personal information” (PI) means any information that relates to a natural person and allows, directly or indirectly, to identify that natural person.
3. Responsible for the protection of Personal information
Ability Biotherapeutics has appointed a Chief Privacy Officer, who ensures that staff are aware of their responsibilities in this area and that business practices are developed in accordance with applicable privacy laws.
The contact information for the office of the Chief Privacy Officer is as follows:
Name: Patrick Tremblay
Postal address: 3 Place Ville Marie, Suite 400, Montreal, Quebec H3B 2E3 Canada
4. Personal information that we collect
We make sure to collect only the Personal information that is necessary for the purposes of our activities, including information relating to the use of our website, information relating to applications you may submit to us (e.g. name, curriculum vitae, address and employment history) or feedback information (e.g. when you fill in forms that we may include on our website). Our website does not use cookies.
5. Purposes for which we collect Personal information
We only collect Personal information for purposes to which you have consented or as permitted by law. The purposes for which we collect your personal information are identified at the time of collection.
By way of example and without limitation, we collect Personal information for the following purposes:
- To answer your questions, queries, comments or complaints;
- To meet our business objectives, such as developing new products and services, improving or modifying our products and services;
- To send you administrative information, for example, information about our services and changes to our terms, conditions and policies;
- If you have consented to it, to send you marketing communications that we think may be of interest to you, such as newsletters, one-time promotional e-mails, direct mailings, business contacts or newsletters;
- For audit, surveillance and fraud prevention purposes;
- To comply with or act under any applicable law or regulation, including but not limited to: (i) respond to requests from public and governmental authorities, including public and governmental authorities outside your country of residence; (ii) to protect our operations and legitimate interests or those of our subsidiaries; (iii) to enable us to pursue available remedies or limit the damages we may suffer, etc.
- To manage the receipt of funds and payments;
- To manage the relationship with job applicants;
- To confirm your identity, verify the accuracy of your personal information and update it;
- For any other purpose to which you have consented.
6. Consent for the collection, use, and disclosure of Personal information
We collect, use and disclose your Personal information with your consent in accordance with applicable requirements, except as provided by law.
If we were to use or disclose your Personal information for purposes other than those to which you have consented, we will obtain your consent again, except in cases where other uses are permitted without the need for consent, or where exceptions are provided by law.
You may withdraw your consent to the use of your Personal information for purposes that are not essential to the provision of our services, as set out in Section 11 of this Notice.
7. Personal information collection methods
a) Directly from you
Most of the PI we collect is that which you provide directly to us, including when you:
- Contact us;
- Complete our surveys;
- Subscribe to our communication channels;
- Apply online for a job.
b) From third parties
We may also collect Personal information from third parties only with your consent or as permitted by law.
c) Through our web platforms
We may also collect information about your use of our website. These files allow us to recognize the user of our site when they access it and when they move from one page to another. Where required, we will seek your consent before collecting this information.
8. Limitation to the disclosure of Personal information
Personal information is accessible to our staff on a need-to-know basis, that is, on the condition that the Personal information is necessary for the performance of their duties.
The Personal information collected may be disclosed to partners or service providers in the context of the performance of service contracts, or to public authorities, for example:
a) Suppliers in connection with the performance of service contracts, such as providers for cloud data hosting, maintenance, analysis, fraud detection and development. In such cases, we implement reasonable contractual and technical safeguards to ensure that such third parties keep all Personal information they process strictly confidential.
b) Courts, regulators, officials or prosecutors or any other party investigating or enforcing laws (including, but not limited to, to assert or defend our rights and for the purpose of debt collection).
c) With potential purchasers of our business. We may need to share your Personal information without your consent in the event of a merger, acquisition or sale of all or part of the business, for example, as part of due diligence. In such cases, we limit sharing to what is necessary to assess the feasibility or advisability of the transaction.
9. Limitation to the retention of Personal information
We retain your Personal information only for as long as is reasonable to fulfill the purposes for which it was collected, including applicable legal and regulatory retention periods, which may sometimes justify longer retention periods. Generally, your Personal information is retained in Canada and our website is hosted there. However, it is possible that business partners to whom we disclose Personal information may retain it in other jurisdictions. We use systems and technology service providers to ensure the confidentiality and secure retention of your Personal information.
10. Security measures
The security of your Personal information is a priority for us. Your Personal Information is hosted by our service providers, who are committed to using reasonable security measures to preserve the integrity and confidentiality of your Personal information. Our employees and suppliers are informed of the confidential nature of the Personal information collected and are made aware of the appropriate security measures to prevent unauthorized access to Personal information. We maintain our service and all associated data with technical, administrative and physical safeguards to protect you against loss, unauthorized access, destruction, misuse, alteration and improper disclosure of your Personal information. These safeguards vary according to the sensitivity of the data in our possession, and are based on the best industry standards. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have any questions about the security of your interaction with us (if, for example, you feel that the security of any account you may have with us has been compromised), you can contact our Chief Privacy Officer.
11. Your rights and how to exercise them
We have procedures in place to process requests to exercise the following rights:
a) Access and rectification: You may review the Personal information we have collected about you, verify its accuracy, amend it if necessary and request a copy, subject to exceptions provided by law.
b) Withdrawal of consent: In certain circumstances, you may withdraw your consent to the use of your Personal information for purposes that are not essential to the provision of our services. If you wish to withdraw your consent for purposes that are essential to the provision of our services, this will usually lead to the termination of our contractual relationship.
c) Portability: You have the right to request that we provide you or any other person or entity authorized by law with a copy of your PI, in a structured, commonly used and readable format.
d) Question or complaint: Reading this Notice may not answer your questions with sufficient accuracy. In this case, we invite you to contact the Chief Privacy Officer, whose contact information appears in section 3. Similarly, any complaint arising from non-compliance with the principles set out in this Notice should be directed to the Chief Privacy Officer.
Any request in connection with this section must be directed to the Chief Privacy Officer at the contact information above. We will respond within 30 days of receipt. Where we cannot meet this deadline, or if additional time is required to comply with a request, we will notify the Person concerned in writing.
12. Update and revision
The present Notice is effective as of the above date and supersedes all prior versions. We may make changes from time to time in our sole discretion. If necessary, the changes will be the subject of a notice published on the home page of our web platforms and in our communication tools, for a certain period, in order to bring these new changes to your attention.