Privacy Notice for Healthcare Professionals

Last Updated: April 2024
We want you to understand what personal information Freeline Therapeutics Limited and its group of companies (“Freeline,” “we,” “us”, “our”) may collect about you, and how we use that personal information in connection with our activities, communications, products, services, applications and websites. This Privacy Notice applies to all personal information collected and otherwise processed by Freeline.

Freeline Therapeutics Limited and its group companies (“Freeline”,“we”, “us”, or “our”) are committed to safeguarding your personal information (or personal data) in line with all applicable laws, including the UK Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR). This Privacy Notice provides a global privacy baseline for Healthcare Professionals (HCPs) who may interact with Freeline. Some jurisdictions will have different and perhaps more restrictive local implementation of data protection laws. Where such variations exist, these will be set out in country-specific notices.
Freeline is a ‘controller’ of your personal data for the purposes of data protection laws. This means that Freeline is responsible for deciding how we hold and use personal information about you, as described below. Privacy contact details are supplied at the end of this Privacy Notice.

This Privacy Notice does not form part of any agreement to provide services. We may update this Privacy Notice at any time. If any significant changes are made, we will provide you with an updated copy or notify you of such change as soon as reasonably practical.

It is important that you read and retain this Privacy Notice, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information and what your rights are under applicable laws.

This Privacy Notice explains:

What information Freeline collects about you

How does Freeline use your personal information?

How do we use sensitive personal information?

What are our lawful bases for using your personal information?

With whom we may share your personal information and where we may transfer it internationally

How do we protect your personal information?

How long do we keep your personal information?

What are your rights regarding your personal information?

What information Freeline collects about you
Freeline collects and processes information about you that is necessary for managing our relationship with you and for the performance of any services you may provide to Freeline. This will vary depending on the way in which you are engaged with Freeline and the nature of your relationship with us. This includes:

Your name, address and contact details, including mailing address, email address, telephone number, date of birth, gender and nationality.

Employment history, employment status and entitlement to work (as applicable).

Details of your professional qualifications, skills, education, academic information and your interests, work experience and professional licenses.

Details of your professional activities, such as prescribing history, networks and affiliations, programs and activities participated in, publications authored or co-authored, awards, board memberships, professional conferences and events and influence rankings.

Due diligence information about your practice or other information that may be publicly available from sources such as public databases, social media platforms and other third parties, which we may combine with personal information that we already hold.

Details related to previous interactions with Freeline.

The terms and conditions of your consultancy arrangements with Freeline.

Information about the payments and services that you may provide to Freeline, invoices and tax-related information, travel and expenses information, and other monetary and non-monetary transfers of value.

Details of your bank account and government-issued identification, such as a Social Security Number, National Insurance Number, tax identification number, driving license or passport number.

Information about any background vetting, where necessary.

Information about medical or health conditions, including health and safety related incidents and accidents, dietary preferences and requirements, and whether you have a disability for which Freeline needs to make reasonable adjustments.

CCTV footage and other information obtained through electronic means such as swipe card records.

Information about your use of our information and communications systems.

Photographs, digital imagery and sound recordings.
Freeline may collect this information in a variety of ways. For example, information might be collected through your professional bio or curriculum vitae (CV); obtained from your passport or other identity documents (such as your driving license); from correspondence with you; through interviews, business card, meetings or other assessments; or obtained when you attend a scientific or congress event; and if you provide consultancy services to us, in the course of consultancy-related activities throughout the period that you provide such services.
When you access our website via links in any marketing emails we send you (such as newsletters or information relating to upcoming events), we will collect certain technical and activity information related to your usage of our website, such as your IP address, pages visited, time spent, links clicked, and this data will be linked with your email address. Sometimes this involves the use of cookies. For more information on cookies see our Cookie Policy.
In some cases, Freeline may collect personal information about you from third parties, such as information from:

Background check providers, information from credit reference agencies, and information from criminal records checks permitted by law;

Data companies that provide information services in the healthcare sector and related fields, and healthcare provider directories;

Publicly accessible sources;

When you interact with us online, such as via social media channels.
Information and data will be stored in a range of different IT systems, including in the Company’s finance system, email systems and databases.

How does Freeline use your personal information?

Freeline uses your personal information for the purposes set out in this Privacy Notice, or for such other purposes, which are reasonably compatible to those described.
Freeline needs to process data to enter into any consultancy agreement it may have with you and to meet its obligations under that agreement. For example, we need to process your personal information to formalize our agreement with you and to pay you in accordance with the terms of our agreement with you. Freeline also needs to process your personal information to ensure compliance with our legal obligations.
In other cases, Freeline has a legitimate interest in processing personal information before, during and after the end of the relationship with you. This may be where it is necessary for legitimate interests pursued by us or a third party and your interests and fundamental rights do not override those interests. We may also use your personal
information where we need to protect your interests (or someone else’s interests), or where it is needed in the public interest.
Processing personal data under the above lawful bases allows Freeline to:

Conduct background vetting processes.

Maintain accurate and up-to-date consultancy records and contact details and records of your contractual and statutory rights.

Obtain occupational health advice, to ensure that it complies with duties in relation to individuals with disabilities and meets obligations under health and safety law.

Manage data related to business travel that is required for consultancy arrangements.

Report on interactions with HCPs/consultants for payment transparency purposes.

Ensure effective general business administration.

Identify you as a key opinion leader or expert, influencer or advisor for scientific or medical engagement.

Conduct and improve our business operations, including collecting information to store in our databases and systems, and keep records related to our relationship with you.

Manage our interactions with you, including to respond to any inquiries and requests.

Organise meetings and events online or face to face.

Collaborate with you on our research and development activities.

Perform market research and analysis.

Provide you with information that may be of interest to you.

Respond to and defend against legal claims.

If you fail to provide certain information when requested, it may restrict our relationship with you. For example, we may not be able to provide you with the services you have requested; we may not be able to give you access to an online event, we may not be able to perform the agreement we have entered into with you (such as paying you); or we may be prevented from complying with our legal obligations.

How do we use sensitive personal information?

Special categories of particularly sensitive personal information include information about your health, racial or ethnic origin, sexual orientation, trade union membership or criminal history, and require higher levels of protection. We need to have further
justification for collecting, storing and using this type of personal information. We may process special categories of personal information in the following circumstances:

In limited circumstances, with your explicit written consent.

Where we need to carry out our legal obligations or exercise rights (for example, in connection with any consultancy arrangement).

Where it is needed in the public interest.

Where it is necessary to protect you or another person from harm.

Less commonly, we may process this type of information where it is needed in relation to legal claims or where it is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent, or where you have already made the information public.

What are our lawful bases for using your personal information?

We operate under a global privacy framework, most notably the UK GDPR which requires us to demonstrate a lawful basis when processing your personal information.
As further described above, Freeline uses your personal information for the following reasons:

Legitimate business purposes: where we have a legitimate business interest to perform processing on your personal information provided your interests and fundamental rights do not override those interests.

Contractual: to which you are a party; we may need to process your personal information to provide a product or service you request or hire you to work as a consultant or contractor.

Legal obligations: there is a legal and/or regulatory obligation to process your personal information and we must comply.

Consent: in limited circumstances, we may ask you to provide your consent for us to process your personal information and where this is provided you have a right to withdraw this at any time.

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making unless we have a lawful basis for doing so and we have notified you.