Effective as of November 16, 2018.

This “Privacy Statement” describes the privacy practices of Merus N.V. and our subsidiary Merus US, Inc. (collectively, “Company”, “we”, “us”, or “our”) relating to our online practices, clinical research activities, and relationships with our suppliers, vendors, service providers and other persons and entities doing business with us. This Privacy Statement describes, under and in accordance with the requirements of applicable law, how we collect, use, disclose and otherwise process personal information in connection with our websites and other services and activities, and explains the rights and choices available to individuals with respect to their information. For convenience, our websites are collectively referred to as the “Sites,” and, together with our other services and activities, collectively referred to as the “Services.” This Privacy Statement governs any of the Services on which the Privacy Statement is posted.

In some situations, we may have a separate agreement or relationship with you with respect to a specific type of processing of your data, such as if you participate in a clinical trial. These situations will be governed by specific terms, privacy notices, or consent forms that provide additional information about how we will use your information. This type of an “in-time” notice or agreement will govern how we may process the information you provide at that time or in that context. To the extent that there is any conflict between the “in-time” privacy notice or agreement and this Privacy Statement, the “in-time” privacy notice or agreement shall prevail. This Privacy Statement also does not supersede or alter the terms of any contracts we enter into with persons or entities doing business with us.

Additional information related to European data protection legislation is provided here.

Personal Information We Collect

We collect personal information about the following types of individuals: clinical trial participants, clinical trial investigators, researchers, and other individuals who interact directly with us or our service providers or persons or entities doing business with us, including users of the Sites.  We collect personal information:

  • Directly from individuals
  • Through theSites
  • From contract research organizations and clinical trial investigators
  • From government agencies or public records
  • From third party service providers, data brokers or persons or entities doing business with us
  • From industry groups and associations

Types of Personal Information We Collect

The types of personal information we collect and share depend on the nature of the relationship you have with us and the requirements of applicable laws.  We may collect:

(i)   Information in the context of our clinical research

  • Health and medical information (such as medical insurance details, information about physical and mental health conditions and diagnoses, treatments for medical conditions, genetic information, family medical history, and medications an individual may take, including the dosage, timing, and frequency)
  • Personal and business contact information and preferences (such as name, job title and employer name, email address, mailing address, phone number, and emergency contact information)
  • Biographical and demographic information (such as date of birth, age, gender, marital status)
  • Professional credentials, educational and professional history,andinstitutional affiliations
  • Financial disclosure/transparency information
  • Other information you may provide to us (such as in emails, on phone calls,or in other correspondence with the Companyor its service providers or persons or entities doing business with us)

(ii)  Information you give us when visiting Sites

  • Personal and business contact information, such as your first name, last name, postal address, email address, telephone number, fax number, job title, and employer name, to the extent that you choose to submit it to us
  • Feedback and correspondence, such as information you provide when you request information for investors, report a problem with the Sites, or otherwise correspond with us
  • Usage information, such as information about how you use the Sites and interact with us
  • We ask that you not send us, and you not disclose, any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Site or otherwise to us in connection with your usage of the Sites.

(iii) Information we get from others

We may also get information about you from other sources, for example Google Analytics, and we may add this to information we get from our Site or the Services.See Cookies and Similar Technologies.

We may combine other publicly available information, such as information collected through publicly accessible sources and registers, such as public agencies or authorities, or information related to the organization for which you work, with the personal information that you provide to us through our Services.

(iv)Information automatically collected

We may automatically log information about you and your computer or mobile device when you access our Sites.  For example, we may log your internet protocol address, pages you viewed, access times, and the website you visited before visiting our Sites if you clicked on a hyperlink to visit our Sites.  We collect this information about you using technology similar to cookies.  Please refer to the Cookies and Similar Technologies section for more details.

(v) Information you provide to us if you conduct business with the Company

If you do business with the Company, we need to process certain personal data in the context of our relationship with you: contact information; financial information (for payment and billing purposes); personal information that may be gathered in relation to our partnership, transaction or interaction, such as through written communication, invitations and subscriptions to any events and publications, information gathered while facilitating your visits to our offices, including your access to a guest wireless internet network.  You are requested (insofar as applicable) to kindly communicate the information in this Privacy Statement to individuals working for or engaged by you or related to you whose personal data are or may be processed by us.

Cookies and Similar Technologies

What are cookies?

Information about you and your computer may be collected by using “cookies.”  Cookies are small data files stored on the hard drive of your computer or mobile device by a website.
We use third-party cookies which are provided by external parties.  These third-party cookies are used by us to track unique visitors across our Sites, and by external parties to track views for videos or other media.

Cookies we use

Our Sites use the following types of cookies for the purposes set out below:

Type of cookie Purpose
Analytics and Performance Cookies These cookies are used to collect information about traffic to our Site and how users use our Site.  The information gathered may include the number of visitors to our Site, the websites that hyperlinked them to our Site, the pages they visited on our Site, what time of day they visited our Site, whether they have visited our Site before, and other similar information. We use this information to help operate our Site more efficiently, to gather broad demographic information and to monitor the level of activity on our Site.

We use Google Analytics for this purpose.  Google Analytics uses its own cookies.  It is used to improve how our Site works.  You can find out more information about Google Analytics cookies here and about how Google protects your data here.  You can prevent the use of Google Analytics relating to your use of our Site by downloading and installing the browser plugin available here.

For any videos on our Sites, Vimeo Analytics uses its own cookies to track views of videos and other media.  You can find out more information about Vimeo Analytics cookies here.

Disabling cookies

You can typically remove or reject cookies via your browser settings.  In order to do this, follow the instructions provided by your browser (usually located within the “settings,” “help” “tools” or “edit” facility).  Many browsers are set to accept cookies until you change your settings.

For further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org.

Do Not Track Signals

Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit.  We do not track unique users of our Sites, except as described above in the Cookies we use section.  We currently do not respond to do not track signals.

How We Use Your Personal Information

To provide our Services

If you use our Sites, we use your personal information to:

  • Operate, maintain, administer and improve the Sites;
  • Provide support and maintenance for the Sites and our services;
  • Respond to your requests, questions and feedback; and
  • If you request information from us or otherwise communicate with us, we may send you Company-related communications as permitted by law. You will have the ability to opt out of such communications by emailing us at privacy@merus.nl.

To perform and administer clinical trials and research activities

We may use personal information of clinical trial participants, investigators, researchers, and other individuals when necessary to facilitate our clinical trials, research, studies, and related activities, including to:

  • Staff and manage clinical trials, including by recruiting investigators and participants;
  • Support symposia, conferences, and scientific, educational and volunteer events;
  • Identify and engage thought leaders and external experts;
  • Attribute authorship to academic materials
  • Comply with regulatory monitoring and reporting obligations, such as those related to adverse events and financial disclosures.

To conduct our business activities

If you or your employer does business with us, we may use your personal information to:

  • Negotiate, manage, and/or perform our contractual relationship with you (or the entity you work for);
  • Manage and administer our relationship with you, including with respect to invoicing and payment;
  • Provide access to our offices and/or certain information technology systems.

To comply with law

We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests and legal process, such as to respond to subpoenas or other requests from government authorities.

With your consent

We may use or share your personal information with your consent, such as when you instruct us to take a specific action with respect to your personal information.

For compliance, fraud prevention and safety

We use your personal information as we believe necessary or appropriate to (a) enforce the terms and conditions that govern the Services; (b) protect our rights, privacy, safety or property, and/or that of you or others; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

How We Share Your Personal Information

Except as described in this Privacy Statement or in any other contracts or privacy notices that govern our relationship with you, we do not share the personal information that you provide to us with other organizations. We disclose personal information to third parties under the following circumstances:

  • Affiliates.  We may disclose your personal information to any of our corporate affiliates for purposes consistent with this Privacy Statement.
  • Service Providers.  We may employ third-party companies and individuals to administer and provide the Services on our behalf, including:
    • Contract research organizations that conduct clinical trials;
    • Data storage and analytics
    • Technology services and support (such as training, customer support, hosting, email delivery and database management services)

    These third parties may use your information only as directed by the Company and in a manner consistent with this Privacy Statement, and are prohibited from using or disclosing your information for any other purpose.

  • Professional Advisors.  We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.
  • Compliance with Laws and Law Enforcement; Protection and Safety.  We may disclose information about you to government or law enforcement officials or private parties as required by law, and disclose and use such information as we believe necessary or appropriate to: (a) comply with applicable laws and lawful requests and legal process, such as to respond to subpoenas or requests from government authorities; (b) enforce the terms and conditions that govern the Services; (d) protect our rights, privacy, safety or property, and/or that of you or others; and (e) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
  • Business Transfers.  We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business deal (or potential business deal) such as a merger, consolidation, acquisition, reorganization or sale of assets or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Statement.
  • Employees/Consultants.We may disclose your personal information to our employees, consultants and other people working for us, who need to have access to your information or have a legitimate interest in having access to your information.  All these persons are bound by confidentiality obligations.

Your Choices

Access, Update, Correct or Delete Your Information

You may review, update, correct or request the deletion of your personal information by contacting us at privacy@merus.nl or if you have additional requests or questions.

Choosing not to share your personal information

Where we are required by law to collect your personal information, or where we need your personal information in order to provide the Services to you, if you do not provide this information when requested (or you later ask to delete it), we may not be able to provide you with the Services.  We will tell you what information you must provide to receive the Services by designating it as required in the Services or through other appropriate means.

Security

The security of your personal information is important to us.  We take appropriate and commercially reasonable organizational, technical and physical measures designed to protect the personal information we collect, both during transmission and once we receive it, in accordance with requirements under law. However, no security safeguards are 100% secure and we cannot guarantee the security of your information.

Children

At this time, we do not knowingly collect personal information from children under 16.  If a parent or guardian becomes aware that his or her child has provided us with information without parental or guardian consent, he or she should contact us at privacy@merus.nl.  We will delete such information from our files as soon as reasonably practicable.

International Data Transfer

Merus N.V. is headquartered in the Netherlands and has affiliates and service providers in other countries, and your personal information may be transferred to the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.

Whenever we transfer your personal information out of the EEA to countries not deemed by the European Commission to provide an adequate level of personal information protection, the transfer will be based on safeguards that allow us to conduct the transfer in accordance with the EU’s data protection laws, such as the specific contracts approved by the European Commission as providing adequate protection for personal information.  For details, see the European Commission’s website for model contracts for the transfer of personal information to third countries.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal information out of the EEA.

Other Sites and Services

The Sites may contain links to other websites and services.  These links are not an endorsement, authorization or representation that we are affiliated with that third party.  We do not exercise control over third-party websites or services, and are not responsible for their actions.  Other websites and services follow different rules regarding the use or disclosure of the personal information you submit to them.  We encourage you to read the privacy policies of the other websites you visit and services you use.

Additional Information Related to European Data Protection Legislation

Personal information

References to “personal information” in this Privacy Statement are equivalent to “personal data” governed by European data protection legislation.

Controller and Data Protection Officer

The Company is the controller of your personal information for purposes of European data protection legislation. See the Contact Us section below for contact details.

Purposes and Legal Grounds of Processing Personal Information

Purposes of processing

We process your personal information for the following purposes:

  • Identificationof the individual involved, e.g., entity or person transacting business with the Company;
  • Contract administration and collaboration (e.g., negotiation of the agreement, exchangesin the context of the execution of the agreement and the termination of the agreement);
  • To perform our contractual relationship with you (or the companyyou work for) and/or to provide and improve our Services;
  • To manage and administer our relationship with you, including the monitoring and payment of invoices;
  • To comply with applicable laws and regulations and our obligations thereunder (e.g., financial accounting obligations, regulatory monitoring and reporting obligations);
  • To keep our internal records updated with correct information and to prepare internal management reporting;
  • To give and administer access to our IT services or applications, as well as to maintain and protect them;
  • To provide and improve our Sites (e.g., by generating statistics regarding the use of the Sites);
  • To perform statistical and other research;
  • Granting physical access rights, such as providing access to buildings and / or parking locations;
  • Security, surveillance and protection of buildings, businesses and natural persons;
  • For the establishment, exercise or defense of legal claims;
  • To provide our Services;
  • To perform and administer clinical trials and research activities;
  • To operate our Sites;
  • To communicate with you;
  • For fraud prevention and safety;
  • Any other specific purposes for which we have obtained your consent (or, if required, explicit consent).
Legal grounds of processing

We process your personal information based on one or more of the following legal grounds:

  • To perform our obligations under an agreement or to take steps at your request prior to entering into such agreement;
  • To comply with legal obligations we are subject to, such as regulatory monitoring and reporting obligations, or complying with requests from governmental authorities;
  • To protect your, or another person’s, vital interests;
  • For scientific or historical research purposes or statistical purposes;
  • When we have legitimate interests to process your personal information, e.g.:
    • management and administration of our relationships with you;
    • our commercial interest, including in relation to the improvement of our Services and for statistical purposes;
    • for internal communications;
    • when providing information to auditors;
    • in relation to lawful requests and legal process, such as to respond to claims, subpoenas or other requests from government authorities;
    • for compliance , fraud prevention and safety;
    • in the course of a (potential) sale or transfer or some or all of our business or assets, in connection with a (potential) business deal;

    except where such interest is overridden by your interests or the protection of your fundamental rights and freedoms as data subject (unless we have your consent or are otherwise required or permitted to by law); and;

  • When you have given your consent, or, where applicable, your explicit consent, for the processing of personal information for a specific purpose. Where we rely on your consent you have the right to withdraw it to any further processing in the manner indicated in the Services or by contacting us at privacy@merus.nl.
Use for new purposes

We may use your personal information for reasons not described in this Privacy Statement where permitted by law and the reason is compatible with the purpose for which we collected it.  If we need to use your personal information for an unrelated purpose, we will notify you and provide the applicable legal basis.

Retention

We will retain your personal information for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we will consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.

In some circumstances we may anonymize your personal information (so that it can no longer be associated with you) in which case we may use this information indefinitely without further notice to you.

Your rights

European data protection laws may give you certain rights regarding your personal information.  You may ask us to take the following actions in relation to your personal information that we hold:

  • Opt-out. Stop sending you direct communications.  You may continue to receive service-related emails, if applicable.
  • Access. Provide you with information about our processing of your personal information and give you access to your personal information.
  • Correct. Update or correct inaccuracies in your personal information.
  • Delete. Delete your personal information.
  • Transfer. Transfer a machine-readable copy of your personal information to you or a third party of your choice.
  • Restrict. Restrict the processing of your personal information.
  • Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.
  • Withdraw consent.  If our processing of your personal information is based upon your consent for an explicit purpose you may withdraw your consent to any further processing, subject to applicable law

You can submit these requests by email to privacy@merus.nlor our postal address provided below.  We may request specific information from you to help us confirm your identity and process your request.  Applicable law may require or permit us to decline your request.  If we decline your request, we will tell you why, subject to legal restrictions.  If you would like to submit a complaint about our use of your personal information or response to your requests regarding your personal information, you may contact us as described below or submit a complaint to the data protection regulator in your jurisdiction.  You can find your data protection regulator here.

Changes to this Privacy Statement

We reserve the right to modify this Privacy Statement at any time in our sole discretion.  We encourage you to periodically review this page for the latest information on our privacy practices within the scope of this Privacy Statement.  If we make material changes to this Privacy Statement you will be notified through the Services in a manner that we believe reasonably likely to reach you (which may include posting a new privacy statement on our Sites, or a specific announcement on this page or elsewhere on our Sites).

Any modifications to this Privacy Statement will be effective upon our posting of the new terms and/or upon implementation of the changes on the Services (or as otherwise indicated at the time of posting).  In all cases, your continued use of the Services after the posting of any modified Privacy Statement indicates your acceptance of the terms of the modified Privacy Statement.

Contact Us

If you have any questions or concerns at all about our Privacy Statement, please feel free to email us at privacy@merus.nl, or write to us at:

Data Protection Officer
Merus N.V.
Yalelaan 62
3584 CM Utrecht
The Netherlands