Effective Date: August 20, 2024

Tenaya Therapeutics, Inc. (”Tenaya,” “we,” “us,” or “our”) provides this privacy policy (the “Privacy Policy”) to explain how we collect, use, and disclose Personal Information, including on our website (www.tenayatherapeutics.com) (the “Site”), social media, from business contacts, when you visit our offices or other facilities, or as otherwise described herein.  This Privacy Policy also tells you about rights and choices you may have when it comes to your Personal Information. Employees and participants in our preclinical studies and ongoing or planned clinical trials may receive a supplementary privacy notice, and, in the event of any conflict with this Privacy Policy, the terms of those supplementary notices will control.

As used in this Privacy Policy, “Personal Information” means any information that: (i) can reasonably be used to identify an individual or information relating to an identified or reasonably identifiable individual and (ii) is collected by us or on our behalf.  By using the Site, you agree to the collection, use, and disclosure of your Personal Information as described in this Privacy Policy.  Beyond this Privacy Policy, your use of the Site is also subject to our Terms of Service.

Information We Collect

A. Categories of Personal Information

In the course of regular business, we may collect the following categories and examples of Personal Information when you interact with us in various ways, as described under “Sources of Personal Information”:

  • Identifiers: such as a real name, alias, postal address, email address, account name, social security number, driver’s license number, passport number, and other similar identifiers.
  • Professional or employment-related information: such as job title and place of work and other information you provide when you complete an application.
  • Internet or other electronic network activity information: such as your internet protocol (IP) address, unique device identifiers, browser type and version, operating system and platform, and information about your interaction with the Site.
  • Audio or visual information: such as CCTV footage if you visit our office, audio recordings, photographs, and other information obtained through electronic means.
  • Other personal information: such health or genetic data you may provide in your communications with us or that you post publicly such as with patient advocacy groups.

B. Sources of Personal Information

Information You Provide to Us

  • Communications. If you contact us directly, we may receive additional Personal Information about you. For example, if you apply to participate in a preclinical study or ongoing or planned clinical trial, we may receive your name, email address, phone number, and any additional information you choose to provide. If you subscribe to our newsletter, we will receive your email address.  Additionally, when you post a comment, question or otherwise communicate us, we may request additional information to respond to you.  This can information contact information like name, email address, phone number, demographic information like data of birth, and health or genetic information, depending on your communication and the nature of your request.
  • Social Media. If you engage with us on social media, we collect your posts and comments and other identifying information.
  • Feedback and Polls. From time to time, we conduct polls or solicit other feedback to better understand the community we serve and to develop programs or education to meet its needs.  When we do so, we collect information about individuals’ preferences and other interests and the content of any additional comments or feedback provided.
  • Investor Portal. If you fill out information on the Site via the investor portal (the “Investor Portal”), we may receive additional Personal Information about you. For example, if you request to receive alerts for business updates or make a partnering or media request through the Investor Portal, we may receive your name, email address, phone, company, postal address, the content of your message, date and time of your message, and other information you may directly provide to us.
  • Careers. If you decide to apply for a job with us, you may submit your contact information and your resume online. We will collect the information you choose to provide us as part of your job application, such as your contact information, current employment information, and other information you choose to submit with your application and on your resume. If you apply for a job with us through a third-party platform, we will collect the information you make available to us through such third-party platforms.

Information We Collect When You Use the Site

  • Usage Information. To help us understand how you use the Site and to help us improve it, we automatically receive information about your interactions with the Site, such as the pages or other content you view, referring sites, the searches you conduct, and the dates and times of your visits.  We may also collect information about how you interact with our ads or newsletters.
  • Device information. We may collect information about the device and software you use to access the Site, including IP address, web browser type, operating system version, and device identifiers (including unique device identifiers and MAC addresses).
  • Location Information. When you use the Site, we may infer your general location information. For example, your IP address may indicate your general geographic region.  We do not collect precise geolocation information, defined as information that identifies the specific location of an individual with precision and accuracy within a radius of 1,750 feet.
  • Cookies and Related Technologies. We use cookies, beacons, invisible tags, and similar technologies (collectively, “Cookies”) to collect information about your browsing activities, including the information described in this section, and to distinguish you from other users of the Site. You can find more information about our use of Cookies in our Cookie Policy.

Information We Receive from Third Parties

You may post photos, comments, or reviews on our pages available through third-party platforms, such as social media or through patient advocacy groups. If you do so, we and other users on those third-party platforms may be able to view Personal Information you make available through these third-party platforms. We may also obtain Personal Information from third parties and sources other than the Site, such as third-party service providers who host and build the Site, and combine it with other Personal Information we have about you.

How We Use Your Information

We use the Personal Information we collect:

  • To provide, update, maintain, and enhance the Site;
  • To test and develop new products, services, and features;
  • To understand stakeholder needs and to develop programs or education;
  • To operate our preclinical studies and ongoing or planned clinical trials;
  • For marketing and advertising purposes, such as developing and providing promotional and advertising materials that may be relevant, valuable, or otherwise of interest to you, including through our third-party providers;
  • To communicate with you, provide you with updates and other information, provide information that you request, respond to comments and questions, and otherwise provide support;
  • To find and prevent fraud, and respond to trust and safety issues that may arise;
  • To detect security risks, protect against malicious or illegal activity, and to investigate and pursue those responsible for such activity
  • To conduct benchmarking, analytics, and industry analysis;
  • To de-identify and aggregate information collected through the Site and use it for our business purposes;
  • For compliance purposes, including enforcing our Terms of Service or other legal rights, or as may be required by applicable laws and regulations or requested by any judicial process or governmental agency;
  • To process job applications; and
  • For other purposes for which we provide specific notice at the time the Personal Information is collected.

Legal Bases For Processing European Information

If you are located in the European Economic Area (“EEA”) or the United Kingdom (“UK”), we only process your Personal Information when we have a valid “legal basis,” including as set forth below.

  • We may process your Personal Information where you have consented to certain processing of your Personal Information. For example, we may process your Personal Information to send you marketing communications or to use Cookies where you have consented to such use.
  • Contractual Necessity. We may process your Personal Information where required to provide you with the Site or other services. For example, we may need to process your Personal Information to respond to your inquiries or requests.
  • Compliance with a Legal Obligation. We may process your Personal Information where we have a legal obligation to do so. For example, we may process your Personal Information to comply with tax, labor, and accounting obligations.
  • Legitimate Interests. We may process your Personal Information where we or a third party have a legitimate interest in processing your Personal Information. Specifically, we have a legitimate interest in using your Personal Information for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of the Site.

How We Disclose The Information We Collect

We do not disclose the Personal Information we collect from you except as described below or otherwise disclosed to you at the time of the collection.

  • Vendors and Service Providers. We may disclose any information we receive to our vendors and service providers.
  • Partners and Affiliates. We may disclose any information with our partners, corporate affiliates, parents, or subsidiaries for any purpose described in this Privacy Policy.
  • Social Media. Where you choose to interact with us through social media, your interaction with these programs typically allows the third party to collect some information about you through digital cookies they place on your device and other tracking mechanisms. In some cases, the third party may recognize you through its digital cookies even when you do not interact with their application. Please visit the third parties’ respective privacy policies to better understand their data collection practices and controls they make available to you.
  • We do not rent, sell, or share information about you with nonaffiliated companies for their direct marketing purposes unless we have your permission.  We do not sell Personal Information or share Personal Information for purposes of cross-context behavioral advertising, and we have not done so in the past, including within the last 12 months.
  • Advertising Partners. We work with third-party advertising partners to show you ads that we think may interest you. These advertising partners may set and access their own Cookies on the Site and they may otherwise collect or have access to information about you which they may collect over time and across different online services. Some of our advertising partners are members of the Network Advertising Initiative or Digital Advertising Alliance. If you do not wish to receive personalized ads, please visit their opt-out pages to learn about how you may opt out of receiving web-based personalized ads from member companies.
  • Analytics Partners. We use analytics services such as Google Analytics to collect and process certain analytics data. These services may also collect information about your use of other websites, apps, and online resources. You can learn about Google’s practices here and opt out of them by downloading the Google Analytics opt-out browser add-on available here.
  • Aggregated or Anonymized Data. We may disclose or use aggregated or anonymized data for our business purposes.
  • As Required by Law and Similar Disclosures. We may access, preserve, and disclose your Personal Information if we believe doing so is required or appropriate to: (i) comply with law enforcement requests and legal process, such as a court order or subpoena; (ii) respond to your requests; or (iii) protect your, our, or others’ rights, property, or safety. For the avoidance of doubt, the disclosure of your Personal Information may occur if you post any objectionable content on or through the Site.
  • Merger, Sale, or Other Asset Transfers. We may disclose and transfer your Personal Information to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or sell, liquidate, or transfer all or a portion of our business or assets.
  • We may also disclose Personal Information from or about you or your devices with your permission.

Your Rights And Choices

  • Opt-Out. You can unsubscribe from our promotional emails via the link provided in the emails. Even if you opt out of receiving promotional messages from us, you will continue to receive administrative messages from us.
  • Do Not Track. Your browser may allow you to transmit a “Do Not Track” signal to online services. However, there is no accepted standard on what a “Do Not Track” signal means or how to respond to them, and like many other online services, we do not alter any of our online practices when such signals are received.
  • Withhold Information. You may choose not to provide us with your Personal Information when requested. However, if you choose not to do so, some features of the Site may not work as intended, you may not be able to use the Site, and we may be unable to provide you with our services if that information is necessary to provide you with our services or if we are legally required to collect it.
  • Your European Privacy Rights. If you are located in the EEA or the UK, you have the rights described below.
    • You may request access to the Personal Information we maintain about you, update and correct inaccuracies in your Personal Information, restrict or object to the processing of your Personal Information, have your Personal Information anonymized or deleted, as appropriate, or exercise your right to data portability to easily transfer your Personal Information to another company. You also have the right to lodge a complaint with a supervisory authority, including in your country of residence, place of work or where an incident took place.
    • You may withdraw consent you previously provided to us regarding the processing of your Personal Information at any time and free of charge. We will apply your preferences going forward, and this will not affect the lawfulness of the processing before you withdrew your consent.

You may exercise these rights by contacting us using the contact details at the end of this Privacy Policy. Before fulfilling your request, we may ask you to provide reasonable information to verify your identity. Please note that there are exceptions and limitations to each of these rights, and that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain Personal Information for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so in compliance with applicable law.

Third Parties

The Site may contain links to other websites, products, or services that we do not own or operate (“Third-Party Services”). We are not responsible for the privacy practices, policies, or other content of these Third-Party Services. Please be aware that this Privacy Policy does not apply to your activities on these Third-Party Services or any information you disclose to these Third-Party Services. If you have any questions about how these other sites use your Personal Information, you should contact them directly. We encourage you to read their privacy policies before providing any information to them.

Retention

We take measures to delete your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it unless we are required by law to keep this information for a longer period. When we process Personal Information for our own purposes, we determine the retention period taking into account various criteria, such as the type of services provided to you, the nature and length of our relationship with you, the impact on the services we provide to you if we delete some information from or about you, and mandatory retention periods provided by law and the statute of limitations.

Security

We make reasonable efforts to protect your Personal Information by using physical and electronic safeguards designed to improve the security of the Personal Information we maintain. However, as no electronic transmission or storage of information can be entirely secure, we can make no guarantees as to the security or privacy of your Personal Information.

International Visitors

The Site is hosted in the United States (“U.S.”) and intended for visitors located within the U.S. If you choose to use the Site or otherwise provide information to us from the European Union or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your Personal Information outside of those regions to the U.S. for storage and processing. We may transfer Personal Information from the EEA or the UK to the U.S. and other third countries based on European Commission-approved Standard Contractual Clauses, as needed to perform our services that you have requested from us, or with your consent. Also, we may transfer your Personal Information from the U.S. to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the Site. By providing us with any information, including Personal Information, you consent to such transfer, storage, and processing.

Children’s Privacy

We do not knowingly collect, maintain, or use Personal Information from children under 16 years of age, and no part of the Site is directed to children. If you learn that a child has provided us with Personal Information in violation of this Privacy Policy, please alert us at privacy@tenayathera.com.

Changes To This Privacy Policy

We will post any adjustments to the Privacy Policy on this page, and the revised version will be effective when it is posted. If we materially change the ways in which we use or disclose Personal Information, we will attempt to notify you through the Site, by email, or by other means.

How To Contact Us

For question or complaints regarding our use of your information or this Privacy Policy, please contact us via email at privacy@tenayathera.com or via post at:

Tenaya Therapeutics, Inc
171 Oyster Point Blvd., Suite 500
South San Francisco, CA 94080