top of page

Privacy Policy

Effective Date: January 15, 2001
Last Updated: October 4, 2026

​

xBxBio (“xBxBio,” “we,” “us,” or “our”) respects the privacy of individuals who visit, communicate with, or otherwise interact with www.xbxbio.com and related xBxBio digital services.

This Privacy Policy describes how xBxBio may collect, use, disclose, store, retain, protect, transfer, and otherwise process personal information through its public website, related communications, publications, business relationships, research activities, and digital services.

This Privacy Policy is intended to address applicable privacy and data-protection requirements in jurisdictions in which xBxBio operates, offers services, conducts research, engages with organizations, or receives website visitors, including, where applicable, the United States, European Union and European Economic Area, United Kingdom, Canada, Japan, and Republic of Korea (South Korea).

xBxBio operates in the healthcare, life-sciences, medical-technology, research, and software sectors. Information may therefore also be processed in connection with applicable healthcare, research, regulatory, cybersecurity, public-health, quality, contractual, and legal requirements, including interactions with governmental and regulatory organizations such as the U.S. Food and Drug Administration (FDA), National Institutes of Health (NIH), Centers for Disease Control and Prevention (CDC), U.S. Department of Health and Human Services (HHS), and comparable authorities in other jurisdictions.

FDA, NIH, CDC, and similar organizations are referenced because xBxBio may engage in research, regulatory, scientific, public-health, funding, or compliance activities involving such organizations. Their inclusion in this Policy does not mean that each organization is a general privacy regulator or that every regulatory framework administered by them applies to xBxBio.

This Policy also describes how xBxBio may interact with service providers, vendors, contractors, processors, subprocessors, professional advisers, business partners, website providers, hosting providers, social-media platforms, analytics providers, communications providers, and other third parties supporting xBxBio's activities.

The public xBxBio website is not a clinical-care portal and is not intended for the submission of protected health information (PHI), patient medical records, emergency medical information, genetic information, biometric information, or other sensitive patient-specific clinical information unless xBxBio expressly provides a designated secure mechanism for that purpose.

Visitors should not submit patient-specific medical information through general website forms, public email addresses, newsletter functions, social-media communications, or other ordinary website features.

1. Information We Collect

xBxBio may collect personal information in several ways depending on how an individual interacts with xBxBio, its website, personnel, publications, research activities, business operations, or third-party platforms.

Information You Provide Directly

We may collect information that you voluntarily provide, including:

  • Name

  • Professional title or occupation

  • Employer or organization

  • Business or professional email address

  • Telephone number

  • Mailing or business address

  • Country, state, province, region, or general location

  • Professional interests

  • Areas of expertise

  • Communication preferences

  • Information contained in correspondence

  • Information submitted through website forms

  • Briefing requests

  • Newsletter or publication requests

  • Employment inquiries

  • Partnership inquiries

  • Investor or business inquiries

  • Vendor and supplier communications

  • Research and scientific communications

  • Regulatory communications

  • Event or meeting communications

  • Other information you voluntarily provide

Website and Technical Information

When you access www.xbxbio.com, xBxBio or providers supporting the website may automatically receive certain technical and usage information, which may include:

  • Internet Protocol address

  • Browser type

  • Device type

  • Operating system

  • Language preferences

  • Approximate geographic location derived from IP address

  • Referring website or source

  • Pages viewed

  • Links selected

  • Date and time of access

  • Session information

  • Cookie or similar identifiers

  • Website performance information

  • Error and diagnostic information

  • General interaction and usage information

Information From Third Parties

Where permitted by applicable law, xBxBio may receive personal information from legitimate third-party sources.

These sources may include social-media platforms such as LinkedIn, professional networking services, website and hosting providers, analytics services, communications providers, vendors, contractors, professional advisers, business partners, research organizations, publicly available sources, professional directories, publications, and other organizations.

Business, Professional, Vendor, and Partner Information

xBxBio may collect information relating to representatives of healthcare organizations, research institutions, academic institutions, life-sciences companies, technology companies, vendors, suppliers, consultants, contractors, investors, advisers, collaborators, prospective customers, and other professional or business contacts.

This information may include organizational affiliation, professional role, business contact information, business communications, contractual information, due-diligence information, and information reasonably necessary to establish or administer a professional relationship.

Research, Scientific, Regulatory, and Government Information

Where applicable, xBxBio may process information associated with research activities, scientific communications, regulatory submissions or inquiries, public-health matters, funding or grant activities, quality or compliance programs, cybersecurity activities, and interactions with governmental or regulatory authorities.

Sensitive and Health Information

xBxBio does not intend its ordinary public website functions to collect patient medical records, PHI, genetic information, biometric information, precise clinical information, or comparable sensitive health information.

If xBxBio establishes a specific secure environment for regulated or sensitive information, additional notices, contracts, Business Associate Agreements, Data Processing Agreements, research documentation, consent or authorization requirements, access controls, or other safeguards may apply.

2. How We Use Personal Information

xBxBio may use personal information for purposes reasonably necessary to operate its website and business, support scientific and research activities, communicate with stakeholders, protect its systems, and satisfy applicable legal, contractual, regulatory, security, and organizational requirements.

Website Operation and Administration

We may use information to operate, maintain, secure, troubleshoot, administer, and improve www.xbxbio.com and related digital services.

Communications and Requests

We may process information to respond to:

  • Requests for information

  • Requests for briefings

  • Business inquiries

  • Partnership inquiries

  • Research communications

  • Employment inquiries

  • Vendor communications

  • Media inquiries

  • Investor communications

  • Professional correspondence

  • Newsletter requests

  • Publication inquiries

  • Regulatory communications

Research, Scientific, and Technical Activities

Where appropriate and legally permitted, information may be used to support scientific research, technical evaluation, product development, feasibility assessments, interoperability activities, validation planning, quality activities, publications, white papers, professional collaboration, and related research or development activities.

Regulatory, Quality, and Compliance Activities

xBxBio may process information where reasonably necessary to support regulatory, quality, safety, audit, documentation, governance, cybersecurity, risk-management, or compliance activities.

These activities may include communications with FDA, NIH, CDC, HHS, other U.S. governmental bodies, and corresponding authorities or institutions in other jurisdictions.

Business and Professional Relationships

We may use information to establish, manage, evaluate, or maintain relationships with healthcare organizations, research institutions, academic organizations, technology providers, vendors, suppliers, contractors, consultants, advisers, investors, collaborators, prospective customers, and other professional contacts.

Security and Fraud Prevention

Information may be processed to protect xBxBio, its website, personnel, intellectual property, systems, networks, confidential information, and business operations and to identify, investigate, prevent, or respond to suspected unauthorized access, misuse, fraud, cybersecurity incidents, or other harmful activities.

Legal Requirements

Information may be processed as reasonably necessary to comply with laws, regulations, court orders, subpoenas, governmental requests, regulatory obligations, contractual requirements, audits, investigations, litigation, claims, dispute resolution, or other lawful processes.

Analytics and Improvement

Subject to applicable consent and opt-out requirements, xBxBio may use website information to understand how the website is used, measure engagement, diagnose technical issues, improve content and navigation, and evaluate website performance.

Corporate Transactions

Information may be processed or disclosed as reasonably necessary in connection with an actual or proposed financing, investment, merger, acquisition, restructuring, corporate reorganization, asset transfer, due-diligence review, or similar business transaction, subject to applicable confidentiality and privacy requirements.

3. Legal Bases for Processing

Where the EU GDPR, UK GDPR, or another law requiring a specified legal basis applies, xBxBio will process personal information only when an appropriate legal basis exists.

Depending on the circumstances, that basis may include:

Consent

Processing may occur where an individual has provided valid consent. Where permitted by law, consent may be withdrawn at any time without affecting processing lawfully performed before withdrawal.

Contract

Processing may be necessary to enter into or perform an agreement with an individual or organization.

Legal Obligation

Processing may be necessary for xBxBio to comply with applicable legal or regulatory obligations.

Legitimate Interests

Processing may be based on legitimate interests pursued by xBxBio or a third party where those interests are not overridden by the rights and interests of the affected individual.

Such legitimate interests may include:

  • Operating and securing the website

  • Responding to professional inquiries

  • Protecting information and systems

  • Preventing fraud and misuse

  • Managing business relationships

  • Improving operations

  • Conducting appropriate research and development

  • Establishing, exercising, or defending legal claims

Other Lawful Grounds

Other lawful grounds may apply where authorized by applicable law.

If xBxBio lawfully processes special-category or other highly sensitive personal information in a regulated environment, xBxBio will identify an additional lawful basis or applicable exception where required.

4. Health Information, HIPAA, and Regulated Clinical Data

xBxBio operates in a healthcare-technology environment, but that fact alone does not make every activity subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).

HIPAA applies to covered entities and to qualifying business associates and subcontractors in circumstances defined by U.S. law.

Where xBxBio acts as a business associate or subcontractor and creates, receives, maintains, or transmits PHI on behalf of a covered entity or another business associate, xBxBio will handle such PHI pursuant to applicable HIPAA requirements, contractual requirements, and any applicable Business Associate Agreement.

Such obligations may include appropriate administrative, technical, and physical safeguards and restrictions on permitted uses and disclosures.

PHI subject to a Business Associate Agreement or another regulated clinical environment is not governed solely by this public website Privacy Policy. Additional contractual or regulatory documentation may apply.

Visitors should not submit PHI through the public xbxbio.com website unless xBxBio expressly identifies a website feature as an authorized secure method for doing so.

5. Research and Scientific Information

xBxBio may conduct, support, participate in, or communicate about research, scientific evaluation, technical development, validation, and related activities.

Where personal information is processed for research purposes, xBxBio will apply protections appropriate to the nature of the research and applicable requirements.

Depending on the circumstances, protections may include:

  • Data minimization

  • Access restrictions

  • De-identification

  • Pseudonymization

  • Aggregation

  • Data-use agreements

  • Institutional or ethics review requirements where applicable

  • Research protocols

  • Consent or authorization where required

  • Contractual safeguards

  • Security controls

Where information has been effectively anonymized so that an individual cannot reasonably be identified and applicable law no longer treats the information as personal information, xBxBio may use such information for research, statistical, analytical, technical, or other lawful purposes.

6. Artificial Intelligence and Automated Processing

xBxBio develops and evaluates technologies that may involve artificial intelligence, machine learning, analytics, computational modeling, or automated processing.

The public xBxBio website is not intended to make solely automated clinical decisions about individual patients.

xBxBio may use automated systems for functions such as website operations, security, analytics, information organization, research, technical development, or other lawful purposes.

Where applicable law provides rights relating to decisions based solely on automated processing that produce legal or similarly significant effects, xBxBio will provide applicable protections, information, and means of exercising those rights.

Where AI or automated systems are used with regulated clinical information, additional clinical, contractual, ethical, quality, regulatory, or privacy requirements may apply.

7. Cookies and Similar Technologies

xBxBio and service providers supporting www.xbxbio.com may use cookies, pixels, local-storage technologies, tags, scripts, or comparable technologies.

Depending on the website configuration, these technologies may support:

  • Essential website operation

  • Security

  • Session management

  • User preferences

  • Accessibility

  • Performance measurement

  • Analytics

  • Content effectiveness

  • Website improvement

  • Integration with third-party services

Where legally required, non-essential cookies or similar technologies will be used only after appropriate consent or will be subject to available opt-out controls.

Visitors may also be able to manage cookies through their browser or device settings.

Disabling certain cookies may affect website functionality.

8. Global Privacy Control and Browser Signals

Some browsers and extensions communicate privacy-preference signals such as Global Privacy Control (“GPC”).

Where applicable law requires xBxBio to recognize a legally valid opt-out preference signal, xBxBio will endeavor to process that signal as required by law.

Because there is not a single universally applicable legal standard for all browser “Do Not Track” mechanisms, other signals may not have the same legal effect in every jurisdiction.

9. Vendors, Service Providers, Processors, and Sub-processors

xBxBio may engage third parties to support its website, communications, infrastructure, business operations, security, research, or professional activities.

These parties may include:

  • Website platform providers

  • Hosting and cloud providers

  • Security providers

  • Email and communications providers

  • Analytics providers

  • Professional advisers

  • Legal advisers

  • Accountants and auditors

  • Consultants

  • Contractors

  • Research partners

  • Software providers

  • Information-technology providers

  • Business-process providers

  • Social-media and professional-networking platforms

xBxBio may use Wix and related Wix services in connection with operation of www.xbxbio.com.

xBxBio also maintains a presence on LinkedIn and may use LinkedIn for company communications, newsletters, professional networking, publications, and related activities.

Where an xBxBio website function is integrated with a third-party platform, the third party may process information under its own privacy policy and terms.

Where required, xBxBio will use contracts or other legally appropriate mechanisms governing processing performed on xBxBio's behalf.

xBxBio expects vendors handling personal information on its behalf to use appropriate safeguards and to process information in accordance with applicable contractual and legal requirements.

10. LinkedIn, Newsletters, and Social Media

xBxBio publishes or may publish company information, newsletters, articles, announcements, and other materials through LinkedIn and other social-media or professional-networking services.

Links on xbxbio.com may direct visitors to LinkedIn or another external service.

When a visitor leaves xbxbio.com for a third-party platform, that platform's privacy practices and terms generally govern its independent processing.

Where xBxBio implements an authorized integration between LinkedIn and xbxbio.com, including an API-based integration for displaying xBxBio publications or newsletter information, xBxBio may receive or process information made available through that integration in accordance with applicable permissions, platform requirements, and law.

xBxBio does not control the independent privacy practices of LinkedIn or other third-party social-media platforms.

11. Third-Party Websites and Services

The xBxBio website may contain links to websites, services, publications, repositories, social-media platforms, or resources operated by third parties.

A link does not mean that xBxBio controls the third party's privacy practices.

Visitors should review the privacy policies of third-party services before providing information to them.

12. When We May Disclose Personal Information

xBxBio may disclose personal information where reasonably necessary and legally permitted, including to:

  • Service providers

  • Vendors

  • Processors and subprocessors

  • Professional advisers

  • Contractors

  • Research collaborators

  • Business partners

  • Government authorities

  • Regulatory bodies

  • Courts and law-enforcement authorities

  • Auditors

  • Potential or actual investors or transaction counterparties

  • Other parties where authorized by the individual or permitted by law

xBxBio seeks to disclose only information reasonably appropriate to the relevant purpose.

13. Government, Regulatory, and Public-Health Disclosures

xBxBio may disclose information when reasonably necessary to comply with an applicable law, regulation, subpoena, court order, governmental inquiry, regulatory request, lawful investigation, public-health requirement, or other legally binding process.

Depending on the circumstances, interactions may involve FDA, NIH, CDC, HHS, courts, law-enforcement bodies, data-protection authorities, research organizations, ethics bodies, or comparable authorities in other jurisdictions.

Where legally permitted and appropriate, xBxBio may evaluate requests for information to determine whether they are lawful, proportionate, and properly authorized.

14. International Data Transfers

xBxBio is based in the United States and may interact with individuals and organizations in multiple countries.

Personal information may therefore be transferred to, stored in, or processed in countries other than the country in which the information was originally collected.

Privacy laws may differ between jurisdictions.

Where required, xBxBio will use an appropriate legal mechanism for international transfers.

Such mechanisms may include, as applicable:

  • Adequacy decisions

  • European Commission Standard Contractual Clauses

  • UK International Data Transfer Agreement

  • UK Addendum to Standard Contractual Clauses

  • Contractual safeguards

  • Consent where legally permissible

  • Other transfer mechanisms authorized by applicable law

Additional technical, organizational, and contractual safeguards may be used where appropriate.

15. European Union and European Economic Area — GDPR

To the extent the General Data Protection Regulation applies to xBxBio's processing of personal data relating to individuals in the European Union or European Economic Area, individuals may have rights that include:

  • The right to be informed

  • The right of access

  • The right to rectification

  • The right to erasure in applicable circumstances

  • The right to restriction of processing

  • The right to data portability where applicable

  • The right to object to certain processing

  • The right to withdraw consent where processing is based on consent

  • Rights relating to qualifying automated decision-making and profiling

  • The right to lodge a complaint with an appropriate supervisory authority

These rights are subject to applicable legal limitations and exceptions.

Where processing is based on legitimate interests, an individual may object to processing on grounds relating to their particular situation. Where personal data is processed for direct marketing, an individual may object to that processing as provided by applicable law.

If xBxBio is legally required to appoint an EU representative or Data Protection Officer, applicable contact information will be made available.

16. United Kingdom Privacy Rights

Where UK data-protection law applies, including the UK GDPR and applicable UK legislation as amended from time to time, individuals may have rights concerning:

  • Information about processing

  • Access

  • Rectification

  • Erasure

  • Restriction

  • Data portability

  • Objection

  • Withdrawal of consent

  • Certain automated decision-making

  • Complaints to the UK Information Commissioner's Office

The availability and scope of particular rights depend on the circumstances and lawful basis for processing.

Where legally required, xBxBio will implement appropriate mechanisms for international transfers of UK personal data.

If xBxBio is required to appoint a UK representative or Data Protection Officer, relevant contact information will be made available.

17. Canada Privacy Rights

Where Canadian privacy law applies, xBxBio will process personal information in accordance with applicable requirements, which may include Canada's Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation.

Applicable principles may include:

  • Accountability

  • Identifying purposes

  • Appropriate consent

  • Limiting collection

  • Limiting use, disclosure, and retention

  • Accuracy

  • Safeguards

  • Openness and transparency

  • Individual access

  • Ability to challenge compliance

Where applicable, individuals may request information about personal information xBxBio holds about them and may request corrections to inaccurate information.

Additional rights or requirements may apply under provincial privacy legislation, including legislation in Québec, Alberta, and British Columbia where applicable.

18. Japan — APPI

Where Japan's Act on the Protection of Personal Information (“APPI”) applies, xBxBio will process personal information in accordance with applicable APPI requirements.

Depending on the circumstances and applicable provisions, individuals may have rights concerning disclosure, correction, addition, deletion, cessation of use, erasure, or cessation of third-party provision of retained personal data.

Where required in connection with transfers of personal data to third parties outside Japan, xBxBio will use an appropriate lawful mechanism and provide information or safeguards required under applicable law.

xBxBio will identify and use personal information consistently with applicable purposes of use and legal requirements.

19. Republic of Korea — PIPA

Where the Republic of Korea's Personal Information Protection Act (“PIPA”) applies, xBxBio will process personal information in accordance with applicable requirements.

Depending on the circumstances, individuals may have rights relating to:

  • Access

  • Correction

  • Deletion

  • Suspension of processing

  • Withdrawal of consent where applicable

  • Certain automated decisions where provided by law

  • Cross-border transfers

  • Complaints concerning processing

Where consent or another specified legal basis is required for collection, use, disclosure, or overseas transfer, xBxBio will seek or rely upon an appropriate lawful basis.

If Korean law requires appointment of a local representative or other contact, xBxBio will make the appropriate information available.

20. United States Privacy Rights

Privacy rights in the United States may arise under federal or state law depending on an individual's location, the nature of information, and whether the relevant law applies to xBxBio.

Where applicable, rights may include the ability to request:

  • Confirmation of processing

  • Access to personal information

  • Correction

  • Deletion

  • A portable copy of certain information

  • Information regarding categories of processing

  • Opt-out of certain sales, sharing, targeted advertising, or profiling

  • Limitation of certain uses of sensitive information

  • Appeal of certain decisions concerning privacy requests

  • Non-discriminatory treatment for exercising applicable privacy rights

These rights vary by jurisdiction and are subject to statutory exceptions.

21. California Privacy Rights

To the extent xBxBio is subject to the California Consumer Privacy Act, as amended (“CCPA”), California residents may have rights that include:

  • The right to know the categories of personal information collected

  • The right to know the sources from which information is collected

  • The right to know purposes for collection, use, sale, or sharing

  • The right to know categories of recipients

  • The right to request specific pieces of personal information, subject to law

  • The right to request deletion

  • The right to request correction

  • The right to opt out of qualifying sale or sharing

  • The right to limit certain uses and disclosures of sensitive personal information where applicable

  • The right to non-discrimination for exercising CCPA rights

xBxBio's policy and intention is not to sell personal information for monetary consideration.

Certain uses of third-party website technologies may be legally defined as “sharing” or “sale” in particular jurisdictions even where no money changes hands. If xBxBio uses technology that triggers such requirements, xBxBio will provide the legally required notice and opt-out mechanism.

Where legally required, xBxBio will recognize qualifying Global Privacy Control signals.

xBxBio does not knowingly sell or share personal information of individuals under the age at which applicable law prohibits such activity without required authorization.

22. Other U.S. State Privacy Laws

Residents of other U.S. states may possess privacy rights under applicable comprehensive state privacy laws.

Where such a law applies to xBxBio, xBxBio will provide and honor rights required by that law, subject to applicable exceptions and verification requirements.

xBxBio may update this Policy or provide supplemental state-specific notices as laws evolve.

23. Children's Privacy

www.xbxbio.com is intended primarily for professional, scientific, healthcare, research, business, and general informational audiences and is not directed to young children.

xBxBio does not knowingly seek to collect personal information from children under 13 through the public website in circumstances subject to the U.S. Children's Online Privacy Protection Act (“COPPA”) without the legally required parental consent.

Where another jurisdiction establishes a different age threshold for valid consent to online processing, xBxBio will apply applicable requirements where relevant.

If xBxBio learns that information has been collected from a child contrary to applicable law, xBxBio will take appropriate steps to address the information.

24. Marketing and Communications

Where permitted by law, xBxBio may communicate with individuals regarding company news, publications, research, newsletters, events, business developments, or other information that may be relevant to their professional relationship with xBxBio.

Where consent is legally required, such communications will be sent pursuant to appropriate consent.

Individuals may unsubscribe from optional marketing communications using available unsubscribe mechanisms or by contacting xBxBio.

Withdrawal from marketing communications does not prevent xBxBio from sending necessary administrative, contractual, legal, security, or transactional communications.

25. Data Minimization

xBxBio seeks to collect and retain personal information that is reasonably necessary and proportionate to the purpose for which it is processed.

Where appropriate, xBxBio may use techniques such as aggregation, de-identification, pseudonymization, restricted access, or minimization to reduce privacy risk.

26. Data Accuracy

xBxBio seeks to maintain personal information that is reasonably accurate, complete, and current for the purposes for which it is used.

Individuals may contact xBxBio to request correction of inaccurate personal information where applicable.

27. Data Retention

xBxBio retains personal information for no longer than reasonably necessary for the purposes for which it was collected or for another lawful purpose.

Retention periods may depend on factors including:

  • Nature and sensitivity of the information

  • Purpose of processing

  • Business needs

  • Contractual obligations

  • Research requirements

  • Regulatory requirements

  • Quality requirements

  • Security requirements

  • Statutory limitation periods

  • Litigation or investigation holds

  • Recordkeeping obligations

  • Applicable privacy or healthcare law

When information is no longer reasonably required, xBxBio may delete, destroy, anonymize, or otherwise dispose of it in accordance with applicable requirements.

28. Information Security

xBxBio recognizes the importance of protecting personal and potentially sensitive information.

xBxBio seeks to employ administrative, technical, organizational, and physical safeguards appropriate to the nature of the information and associated risks.

Depending on the system and circumstances, safeguards may include:

  • Access controls

  • Authentication controls

  • Role-based permissions

  • Least-privilege principles

  • Encryption where appropriate

  • Secure transmission mechanisms

  • Logging and monitoring

  • Backup and recovery controls

  • Vulnerability management

  • Security testing

  • Vendor-risk management

  • Incident-response procedures

  • Workforce confidentiality requirements

  • Policies and procedures

  • System validation and documentation where applicable

No website, network, storage system, transmission method, or security program can be guaranteed to be completely secure.

Accordingly, xBxBio cannot guarantee absolute security.

29. Data Breaches and Security Incidents

If xBxBio discovers a security incident involving personal information, xBxBio will assess and respond to the incident in accordance with applicable legal, regulatory, contractual, and security requirements.

Where legally required, xBxBio may notify affected individuals, customers, regulators, law-enforcement authorities, contractual counterparties, or other appropriate entities.

Where applicable to particular health-related products or information, requirements such as the HIPAA Breach Notification Rule or FTC Health Breach Notification Rule may also apply.

30. Privacy by Design and Data Protection

Where appropriate to the nature and risk of processing, xBxBio seeks to incorporate privacy and data-protection considerations into the design, development, evaluation, and operation of systems and processes.

Relevant considerations may include:

  • Purpose limitation

  • Data minimization

  • Access controls

  • Data segregation

  • Security

  • Retention

  • Transparency

  • Accountability

  • Vendor management

  • Risk assessment

  • De-identification

  • User rights

  • International transfers

Where required by applicable law, xBxBio may conduct privacy, security, data-protection, or other risk assessments before implementing higher-risk processing.

31. Vendor and Third-Party Governance

Where third parties process personal information on behalf of xBxBio, xBxBio may use appropriate contractual and due-diligence measures proportionate to the nature of the relationship and information involved.

Such measures may address:

  • Confidentiality

  • Authorized purposes of processing

  • Information security

  • Subprocessor requirements

  • Incident notification

  • Data retention and deletion

  • International data transfers

  • Audit or assurance requirements

  • Compliance with applicable law

A third party acting independently rather than as a processor for xBxBio may be responsible for its own privacy practices.

32. Sale, Sharing, and Commercialization of Personal Information

xBxBio does not intend to operate the public website as a business for the commercial sale of visitor personal information.

xBxBio's policy is not to sell personal information for monetary consideration.

Because certain privacy laws define “sale” or “sharing” more broadly than ordinary commercial usage, some transfers involving advertising or tracking technologies could potentially fall within statutory definitions even without payment.

If xBxBio engages in processing that legally constitutes sale or sharing and an applicable law provides an opt-out right, xBxBio will provide the required mechanism.

33. De-Identified and Aggregate Information

Where legally permitted, xBxBio may create or use aggregated, anonymized, or de-identified information for purposes such as:

  • Research

  • Statistical analysis

  • Product development

  • Technical evaluation

  • Performance analysis

  • Security

  • Quality improvement

  • Scientific communication

  • Business planning

Where xBxBio maintains information as de-identified information subject to a legal requirement not to attempt re-identification, xBxBio will treat it consistently with that requirement.

34. Professional and Employment Information

Individuals applying for employment, consulting, advisory, scientific, professional, or other roles with xBxBio may provide additional information such as:

  • Curriculum vitae or résumé

  • Employment history

  • Education

  • Certifications

  • Professional licenses

  • Publications

  • References

  • Professional qualifications

  • Contact information

  • Other application information

Such information may be used to evaluate qualifications, communicate with applicants, administer recruitment, perform legally permitted verification, maintain records, and satisfy legal obligations.

Additional employment or workforce privacy notices may apply where required.

35. Intellectual Property, Legal Claims, and Investigations

xBxBio may process information as reasonably necessary to protect or enforce intellectual property, confidential information, contractual rights, legal rights, cybersecurity interests, or other legitimate interests.

Information may also be retained or disclosed in connection with investigations, disputes, litigation, regulatory matters, audits, insurance matters, or legal claims where lawful.

36. Changes in Corporate Ownership

If xBxBio undergoes or considers a merger, financing, investment, acquisition, sale, restructuring, reorganization, insolvency event, transfer of assets, or similar corporate transaction, personal information may be reviewed or transferred as part of that process subject to appropriate legal and confidentiality safeguards.

A successor entity may assume applicable privacy obligations relating to transferred information.

37. Exercising Privacy Rights

Where applicable law grants an individual privacy rights, a request may be submitted to xBxBio using the contact mechanisms available at:

www.xbxbio.com

When contacting xBxBio, please identify the communication as:

Privacy Request

and describe the right you wish to exercise.

Depending on applicable law and the nature of the request, xBxBio may need to verify identity or authority before acting on the request.

xBxBio will use information submitted for verification only as permitted by applicable law.

Authorized agents may submit requests where applicable law permits them, subject to appropriate verification of authorization.

xBxBio will respond within the period required by applicable law where the law applies.

Some requests may be subject to lawful exceptions, limitations, or retention obligations.

38. Appeals and Complaints

Where applicable law gives individuals a right to appeal a decision concerning a privacy request, xBxBio will provide or follow an applicable appeal process.

Individuals may also have the right to lodge a complaint with an appropriate privacy or data-protection regulator.

Depending on location, this may include:

  • An EU national data-protection supervisory authority

  • The United Kingdom Information Commissioner's Office

  • The Office of the Privacy Commissioner of Canada or applicable provincial authority

  • Japan's Personal Information Protection Commission

  • The Republic of Korea Personal Information Protection Commission

  • A U.S. state attorney general or privacy regulator

  • Another competent authority

Individuals are encouraged to contact xBxBio first so that xBxBio has an opportunity to address the concern.

39. Non-Discrimination

Where required by applicable law, xBxBio will not unlawfully discriminate against an individual for exercising a protected privacy right.

40. Verification of Requests

To protect personal information from unauthorized disclosure, xBxBio may verify the identity of a person requesting access, deletion, correction, portability, or another privacy right.

The amount of verification requested will be proportionate to the nature and sensitivity of the information and applicable legal requirements.

If identity cannot reasonably be verified, xBxBio may be unable to fulfill certain requests.

41. Authorized Representatives

Where permitted by applicable law, an individual may authorize another person to submit a privacy request on their behalf.

xBxBio may request evidence of that authority and may independently verify the individual's identity where permitted or required.

42. Regulators, Research Organizations, and Institutional Requirements

xBxBio's healthcare, scientific, and research activities may be subject to requirements that are separate from general website privacy laws.

Depending on the activity, these may involve:

  • FDA requirements

  • HHS requirements

  • NIH grant or research requirements

  • CDC or public-health requirements

  • Research agreements

  • Institutional Review Board or ethics requirements

  • Clinical research requirements

  • Quality-system requirements

  • Medical-device requirements

  • Cybersecurity requirements

  • Records-retention requirements

  • International regulatory obligations

Where such requirements apply, they may supplement this Privacy Policy.

43. No Medical Advice or Emergency Services

The public xBxBio website is provided for company, scientific, research, educational, professional, and informational purposes.

It is not intended to replace professional medical judgment, diagnosis, treatment, emergency services, or direct clinical care.

Do not submit an emergency medical request through xbxbio.com.

Individuals experiencing a medical emergency should contact the appropriate local emergency service or qualified healthcare provider.

44. Research-Stage Technology

Certain xBxBio technologies, capabilities, models, demonstrations, publications, or concepts described on the website may relate to research-stage, developmental, investigational, or pre-commercial work.

Nothing in this Privacy Policy should be interpreted as representing that a particular product, clinical function, regulatory authorization, certification, privacy designation, or security certification has been obtained unless xBxBio expressly states that it has been obtained.

45. Changes to This Privacy Policy

xBxBio may modify this Privacy Policy from time to time to reflect changes in:

  • Legal requirements

  • Regulatory requirements

  • Website functionality

  • Business practices

  • Technology

  • Security practices

  • Vendor relationships

  • Research activities

  • International operations

  • Privacy practices

When material changes are made, xBxBio will update the Last Updated date at the top of this Policy and may provide additional notice where required by law.

The version published at www.xbxbio.com/privacy-policy is the current website Privacy Policy unless otherwise stated.

46. Contact xBxBio

Questions, concerns, complaints, or requests concerning this Privacy Policy or xBxBio's handling of personal information may be submitted through the contact mechanisms provided at:

xBxBio
Website: www.xbxbio.com

For privacy-related communications, please clearly identify the request as:

PRIVACY REQUEST

If xBxBio designates a Data Protection Officer, Privacy Officer, EU representative, UK representative, Korean representative, or other legally required privacy contact, the relevant contact information will be published or otherwise made available as required.

47. Relationship to Other Notices and Agreements

This Privacy Policy applies to the public website and related interactions described above.

Additional agreements, notices, policies, authorizations, or privacy terms may govern specific services or relationships, including:

  • Business Associate Agreements

  • Data Processing Agreements

  • Clinical or research agreements

  • Data-use agreements

  • Employment notices

  • Vendor agreements

  • Customer agreements

  • Research consents

  • Institutional requirements

  • Product-specific privacy notices

  • Security terms

  • Contractual confidentiality obligations

Where a specific legally binding agreement governs the processing of particular information, that agreement may supplement this Policy and may control to the extent provided by applicable law and contract.

48. Questions About Applicability

Privacy and healthcare laws differ by jurisdiction, data type, processing activity, organization, relationship, and purpose.

A reference in this Privacy Policy to HIPAA, GDPR, UK GDPR, CCPA, PIPEDA, APPI, PIPA, FDA, NIH, CDC, HHS, or another law, regulator, agency, or framework does not by itself represent that the law or framework applies to every xBxBio activity.

xBxBio will determine applicable requirements based on the relevant circumstances and will implement additional protections where legally required.

END OF PRIVACY POLICY

bottom of page