Privacy Policy

Apellis Pharmaceuticals, Inc.
Dated: February 13, 2023

Apellis Pharmaceuticals Inc, based at 100 5th Avenue, Waltham, MA 02451, US, (“we”, “us” and “our”) as the data controller responsible for this website recognizes the importance of and is committed to respecting and protecting your privacy. This Privacy Policy applies to our collection and use of personal information through our website apellismedicalhub.com (the ”Site”).

We collect the following personal data about you:

  • When using our website, we collect data that your browser transmits to our server (so-called ‘’server log files’’). When you visit our website, we collect the following data that is technically necessary for us to display the website to you (date and time at the moment of access, amount of data sent in bytes, source/reference from which you came to the page, browser used, operating system used, IP address used).
  • Contact information: full name, email address, mailing address, street address, ZIP code, state, country, phone number
  • Professional credentials: Occupation, specialty, salutation, organization name, institution, HCP type
  • Health information: Disease state
  • Any personal information included by the HCP in the medical question area

Also, when you select the Compassionate Use Request in the ‘Resources’ (Early Access Program) area of our Site you should know that you will be redirected to an online form of a third-party Site ‘Smartsheet’ where the following data will be collected:

  • Treating Physician: full name, Institution, address, city, postal code, country, email
  • Patient: Date of birth, gender, disease/condition, medical history/current status, laboratory values and any other data shared via files and the area of rationale for request.

The linked websites are not under the control of Apellis, and Apellis is not responsible for the content available on any other website linked to this website. For more information check Apellis Terms and Conditions

We collect this data from:
You (HCPs)

We rely on the following legal basis according to GDPR:
The processing is carried out in accordance with i) Article 6 (1) point f GDPR on the basis of our legitimate interest in a) improving the stability and functionality of the website b) facilitating the communication with HCPs c) arranging a meeting with a MSL (Medical Science Liaison) and ii) Article 6 (1) point c GDPR to comply with our legal and regulatory obligations including those relating to providing a medical information service and to safety & quality reporting.

Purposes for which we collect personal data
We process your personal data for the following purposes:

  • To remain compliant with our legal and regulatory obligations
  • To create a scientific exchange with Healthcare Professionals answering their medical questions and providing them with the information they request via the online form
  • To arrange a meeting with a MSL (Medical Science Liaison)
  • To ensure the stability and upgrade the functionality of the website

We retain personal data:
For duration of service delivery

We share your personal data with:
Third party processors such as IT services and website hosting companies, (internet) connectivity providers

Your rights
You can access all your personally identifiable information that we collect online. You may also demand the deletion of your personal data unless the applicable laws and regulations oblige us to store your personal data.

You can request to be provided with information about data which we store/process about you. In addition, you have the right to have any personal data blocked or deleted, to object to the processing of your data, to have any incorrect data corrected and the right to have your data transferred to a third party.

You can correct factual errors in your personally identifiable information by sending us an email that credibly shows the error. You likewise have the right to request the correction of incorrect personal data.

To protect your privacy and security, we will also take reasonable steps to verify your identity before making corrections. Should you have other questions or concerns about this privacy policy or want to have your data deleted from our database, please send an email to privacy@apellis.com.

You also have the right to lodge a complaint with a supervisory authority, if applicable. A list of European Union supervisory authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en

We may update or amend this policy at any time by posting the amended version on the Site.

International data transfers
Apellis uses servers and other storage facilities in the United States and EU. Apellis may transfer personal information outside of its country of origin for the purposes, and in the manner, set out in this privacy policy, including for processing and storage by service providers and affiliates in connection with such purposes. In all situations, Apellis takes reasonable steps to ensure that your privacy is protected. Such steps include, but are not limited to, implementing privacy, security, and contractual controls, as well as steps noted in this privacy policy, as required by applicable law.

Apellis endeavors to obtain assurances from its service providers and affiliates that they will safeguard personal information consistent with this privacy policy. An example of appropriate assurances that may be provided by service providers and affiliates includes a contractual obligation that they provide at least the same level of protection as is required by Apellis’s privacy principles set out in this privacy policy. Where Apellis has knowledge that a service provider or affiliate is using or disclosing personal information in a manner contrary to this privacy policy, Apellis will take appropriate steps to prevent or stop the use or disclosure.

Security of your personal information
The security of your personal information is important to us. We take reasonable steps, including technical, administrative and physical safeguards, designed to protect the personal information submitted to us from loss, misuse and unauthorized access, disclosure, alteration and destruction. Such measures may include but are not limited to: the encryption of communications via SSL, encryption of information while it is in storage, firewalls, access controls, separation of duties, and similar security protocols. However, no method of security or method of transmission over the Internet is entirely secure. You should always use caution when transmitting personal information over the Internet.

US State Supplemental Privacy Notice to Residents of California, Colorado, Connecticut, Virginia, and Utah
If you are a resident of California, Colorado, Connecticut, Virginia, or Utah, this notice applies to you and supplements Apellis’s Website Privacy Policy. This notice is intended to provide certain information to you as required by the California Consumer Privacy Act of 2018, as amended (“CCPA”), the Colorado Privacy Act of 2021 (the “CPA”), the Virginia Consumer Data Protection Act of 2021 (the “VCDPA”), the Utah Consumer Privacy Act of 2022 (the “UCPA”), and the Connecticut Data Privacy Act of 2022 (“CDPA”).

Categories of Personal Information We Collect, and How We Use and Share that Information
The section, above, entitled “We collect the following personal data about you” outlines the categories of personal information we may have collected during the 12-month period prior to the effective date of this Privacy Policy as well as how we use and share that information.

Sensitive Personal Information
When we collect medical information or financial details, we are deemed to be collecting data that is “sensitive” under state privacy laws. Where legally required, we will obtain your consent to collect this information. For our California users, we do not use or disclose sensitive personal information for any purpose other than as permitted by law, such as to provide our service to you, to detect security incidents, and protect against malicious or fraudulent actions, nor do we use or disclose such information to build a profile about you.

Your rights
Subject to certain limitations, you have the following rights with respect to the personal information that we collect about you:

  1. Right to Know

You have the right to request that we disclose certain information to you about our collection of your personal information. Upon our receipt of your verified request, we will provide you with:

  • The categories of personal information we have collected about you.
  • The categories of sources from which we have collected your personal information.
  • Our business or commercial purpose for collecting your personal information.
  • The categories of third parties with whom we have shared your personal information.
  • The specific pieces of personal information we have collected about you.

You have the right to request that we disclose certain information to you about our disclosures and sales of your personal information; however, Apellis does not sell personal information. Upon our receipt of your verified request, we will provide you with:

  • The categories of personal information we have collected about you; and
  • The categories of personal information that we disclosed about you for a business purpose.
  1. Right to Opt-Out of Targeted Advertising or Sale

You have the right to opt-out of the sale of your personal information; however, Apellis does not sell Personal Information.

  1. Right to Delete

You have the right at any time to request that we delete your personal information.

  1. Right to Correct.

You can ask us to correct inaccurate personal information that we have about you.

  1. Right to Nondiscrimination

We will not discriminate against you for exercising your rights. This generally means we will not deny you goods or services, charge different prices or rates, provide a different level of service or quality of goods, or suggest that you might receive a different price or level of quality for goods.

To request access to or deletion of personal information:

Depending on the nature of your request, we may have to verify your identity when you contact us. We do this by attempting to match the identifying information that you provide to the personal information maintained by Apellis, if any.

We endeavor to respond to your request as soon as we can. If we are not able to respond to your request within 45 days, we will let you know that we may require additional time (up to 90 total days).

You may also use an authorized agent to exercise your rights on your behalf. If you wish to use an authorized agent, we require that your authorized agent provides written proof to us that they are authorized to act on your behalf, and we may also require your authorized agent to verify their own identity.

Appeals
Residents of Colorado, Connecticut, and Virginia can appeal a refusal to take action on a request by contacting us by email at privacy@apellis.com

Contact Us
Before sending an e-mail, please be aware of the following:

If you have any questions about this Privacy Policy or concerns about the way Apellis processes your personal information, or require assistance in managing your privacy choices, please get in touch with us at:

Apellis Pharmaceuticals Inc
100 5th Avenue, Waltham, MA 02451, US
Email: info@apellis.com

Our data protection officer can be contacted as follows:
E-mail: privacy@apellis.com

Our EU Data Privacy Representative can be contacted as follows:
ALG Manousakis Law Firm,
16, Laodikias Str., Athens,
P.O. 11528, Greece
Email: dataprivacy@alg.gr