California Privacy Policy

Rhythm Pharmaceuticals, Inc. and its affiliates (collectively, “Rhythm,” “we,” “our,” or “us”) have created this California privacy statement (“CA Privacy Policy”) to supplement our Privacy Policy with additional information specific to residents of the State of California.

The California Consumer Privacy Act (“CCPA”) provides certain additional rights to residents of California. This CA Privacy Policy describes how we collect, use, and disclose personal information about California residents.

Unless otherwise expressly stated, all terms in the CA Privacy Policy have the same meaning as defined in our Privacy Policy or as otherwise defined in the CCPA.

NOTE ABOUT RESEARCH DATA

Rhythm engages in clinical research that is subject to the Common Rule and similar global ethical standards that apply to research. When we collect personal information in this context, it is exempt from the CCPA, including the privacy rights described below. If you are a research participant residing in California and have a question about your personal information, please contact us at [email protected].

COLLECTION AND USE OF PERSONAL INFORMATION

We collect personal information from and about California residents for a variety of purposes. To learn more about the types of personal information we collect, the sources from which we collect or receive personal information, and the purposes for which we use this information, please refer to our Privacy Policy.

Specifically, in the last 12 months, we have collected the following categories of personal information:

  • Identifiers, such as your name, phone number, email address, physical address;
  • Protected class and demographic information, such as age (including birthdates) and gender.
  • Internet or other electronic network activity, such as certain technical information we and our authorized service providers may automatically over time and across different websites about your use of the Online Services; including your Internet Protocol address or other device identifier, browser type, operating system, the pages you view on the Online Services, the pages you view immediately before and after you access the Online Services, your movement between different Rhythm websites, and the search terms you enter on the Online Services;
  • Non-precise geolocation data, such as your location as derived from your IP address.
  • Professional or employment-related information, such as that contained on a resume or a curriculum vitae, in connection with a job application or inquiry; and
  • Sensitive Personal Information, such as your medical symptoms, diagnoses, and other health-related information relating to certain medical conditions that you have, and/or your eligibility, or that of someone for whom you provide care, for participation in a study or research initiative.

SOURCES OF PERSONAL INFORMATION

We collect this information from a variety of sources, including but not limited to:

  • Directly from you;
  • Automatically from your browser or device; and
  • Third parties, such as public databases, providers of demographic information, joint marketing partners, social media platforms, and other third parties.

USE AND DISCLOSURES OF PERSONAL INFORMATION

As noted in our Privacy Policy, we use your personal information for a variety of business purposes, including to administer our patient support programs, deliver education and promotional materials, and customize our services for you. We also disclose your personal information in specific contexts, including to our service providers and for certain legal purposes. We do not currently disclose information with non-affiliated third parties for those third parties’ direct marketing purposes. Please see the “Use of Collected Information” and “Disclosure of Collected Information” sections in our Privacy Policy for more information.

Specifically, in the last 12 months, we have not sold or shared your personal information for targeted advertising purposes. We may have disclosed your personal information, as defined by the CCPA and the appropriate regulations, as follows:

Category of InformationRecipients To Whom Data is Disclosed for a Business or Commercial Purpose
IdentifiersService Providers; Our Business Partners; Third Parties Pursuant to Law or a Legal Process
Protected class and demographic informationService Providers; Our Business Partners; Third Parties Pursuant to Law or a Legal Process
Internet or other electronic network activity informationService Providers; Our Business Partners; Third Parties Pursuant to Law or a Legal Process
Non-precise geolocation informationService Providers; Our Business Partners; Third Parties Pursuant to Law or a Legal Process
Professional or employment-related informationService Providers; Our Business Partners; Third Parties Pursuant to Law or a Legal Process
Sensitive Personal InformationService Providers; Our Business Partners; Third Parties Pursuant to Law or a Legal Process

Sensitive Personal Information

We only use and disclose your Sensitive Personal Information for the following purposes: (i) performing services or providing goods reasonably expected by an average consumer; (ii) detecting security incidents; (iii) resisting malicious, deceptive, or illegal actions; (iv) ensuring the physical safety of individuals; (v) for short-term, transient use, including non-personalized advertising; (vi) performing or providing internal business services; or (vii) verifying or maintaining the quality or safety of a service or device.

CALIFORNIA PRIVACY CHOICES

California residents have the following rights under the CCPA:

  • Right to access and portability: You may have the right to obtain access to the personal information we have collected about you and, where required by law, the right to obtain a copy of the personal information in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.
  • Right to correct: You may have the right to request that we correct inaccurate information that we maintain about you.
  • Right to delete: You may have the right to request that we delete the information that we have collected or maintain about you. We may deny your request under certain circumstances, such as if we need to comply with our legal obligations or complete a transaction for which your information was collected. If we deny your request for deletion, we will let you know the reason why.
  • Right to opt out of sale/sharing: You may have the right to opt out of the sale of your personal information or sharing of your personal information for targeted advertising purposes. We do not currently sell or share your personal information for targeted advertising purposes.
  • Right to nondiscrimination: You have the right to not be discriminated against for exercising these rights.

As a California resident, you may also request certain information regarding our disclosure of certain categories of information to third parties for those third parties’ direct marketing purposes. To make such a request, please contact us at [email protected]. This request may be made no more than once per calendar year, and we reserve our right not to respond to requests submitted other than to the email address specified herein.

EXERCISING YOUR PRIVACY CHOICES

To exercise your rights, contact us at [email protected] or (866) 515-9466.

We will take steps to verify your identity before processing your request. We will not fulfill your request unless you have provided sufficient information for us to reasonably verify you are the individual about whom we collected Information. We will only use the information provided in the verification process to verify your identity or authority to make a request and to track and document request responses unless you initially provided the information for another purpose.

You may use an authorized agent to submit a request. When we verify your agent’s request, we may verify your identity and request a signed document from your agent that authorizes your agent to make the request on your behalf. To protect your information, we reserve the right to deny a request from an agent that does not submit proof that they have been authorized by you to act on their behalf.

CONTACTING US

If you have any questions about this CA Privacy Policy, our Privacy Policy, or our use of your personal information, you can contact [email protected].

Last Updated: January 2024