PRIVACY POLICY
Last Updated: June 25, 2026
INTRODUCTION
This Privacy Policy for Frezent Biological Solutions Inc. ("Frezent," "Company," "we," "us," or "our") describes how and why we collect, use, and share your personal information when you use our services ("Service"), including when you:
• Visit our website at http://www.frezent.com
• Engage with us in other related ways, including marketing, employment, or events.
Frezent is the data controller responsible for your personal information under applicable laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. state and federal privacy laws.
If you share with us Personal Data concerning another individual, such as a patient, family member, or other third party, you are responsible for ensuring compliance with all applicable privacy and data protection laws before sharing such information, including obtaining any required consents or authorizations and by your sharing Personal Data, you confirm such compliance by you with such laws.
Please review this Privacy Policy carefully. IF YOU DO NOT AGREE WITH OUR POLICIES AND PRATICIES, PLEASE DO NOT USE ANY OF OUR SERVICES. Your use of our Services confirms your agreement, acceptance of and consent to our policies. Questions or concerns can be directed to us at the contact information at the end of this Policy.
1. INFORMATION WE COLLECT
1.1 Personal Data
While using our Service, we may ask you to provide, or accept, personally identifiable information or identifiers, including but not limited to:
• Email address
• First name and last name
• Cookies and Usage Data
1.2 Usage Data
We may collect information about how the Service is accessed and used ("Usage Data"), including your IP address, browser type, device type, pages visited, and other diagnostic data.
1.3 Location Data
We may process approximate geographic information derived from your IP address or device settings for purposes such as, including, server diagnostics and service optimization. You can enable or disable location services at any time through your device settings.
1.4 Cookies and Similar Tracking Technologies
We use cookies and similar tracking technologies (including beacons, tags, scripts) to track activity and hold certain information. Types of cookies we use:
• Necessary cookies: Required for site functionality and user preference storage.
• Performance and Analytics cookies: Optional cookies that provide quantitative measures of website visitors.
• Advertising cookies: Optional cookies used to serve ads relevant to your interests.
You can instruct your browser to refuse all cookies, other than the Necessary cookies. However, some portions of our Service may not function properly without cookies.
2. LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, we process your personal data only where we have a valid legal basis under applicable law, including:
Contractual Necessity (Article 6(1)(b) GDPR):
We process your data to provide, maintain, and improve our Services as part of our contractual relationship with you, including fulfilling service requests and inquiries.
Legitimate Interests (Article 6(1)(f) GDPR):
We process your data for our legitimate business interests, such as analyzing usage trends, improving our website, detecting fraud or security threats, and sending relevant business communications. We have balanced these interests against your rights and determined that our processing does not override your fundamental rights and freedoms.
Legal Obligation (Article 6(1)(c) GDPR):
We may process your data where necessary to comply with applicable legal requirements, court orders, or governmental regulations.
Consent (Article 6(1)(a) GDPR):
Where we rely on consent as our legal basis (e.g., for optional analytics or advertising cookies, or for certain marketing communications), you have the right to withdraw your consent at any time. Withdrawal of consent does not affect or negate the lawfulness of processing carried out prior to withdrawal. See Section 10 for details on how to withdraw your consent.
3. HOW WE USE YOUR INFORMATION
Frezent uses the collected information for the following purposes:
• To provide and maintain our Service
• To allow you to participate in interactive features of our Service
• To provide general inquiry support and share Company information
• To gather analysis and improve our Service
• To monitor usage and detect, prevent, and address technical issues
• To fulfill employment-related purposes
• To provide you with news and general information about our updates and promotional materials (where permitted or unless opted out by you)
• To comply with legal obligations
• For any other purpose with your consent, which is given by you by your use of our Services unless you have opted out.
4. RETENTION OF YOUR PERSONAL DATA
Frezent retains your Personal Data only for as long as necessary for the purposes set out in this Privacy Policy, or as required to comply with legal obligations, resolve disputes, and enforce agreements. Usage Data is generally retained for a shorter period unless needed for security or legal compliance purposes.
5. TRANSFER OF YOUR PERSONAL DATA
Your information, including Personal Data, may be transferred to and processed on computers located outside your state, province, country, or other governmental jurisdiction where data protection laws may differ. If you are located outside the United States and choose to provide information to us, please note that we transfer and process data in and to the United States.
5.1 International Data Transfers
Our website is operated and hosted using Squarespace, Inc. ("Squarespace"), a third-party service provider based in the United States. As a result, your Personal Data may be transferred to, stored in, and processed in the United States or outside the European Economic Area ("EEA"), the European Union ("EU"), or the United Kingdom ("UK"), any or all of which may have data protection laws that differ from those in your country of residence.
Safeguards for Transfers from the EEA, EU and the UK
If we, via Squarespace, transfer your Personal Data outside the EEA, EU, or the UK, we use European Commission or the UK Information Commissioner’s Office (ICO) - approved safeguards such as Standard data protection clauses (SCCs), as applicable, to ensure equivalent data protection. We rely on Squarespace’s data transfer contracts in place via Squarespace's data transfer policy and the safeguards they maintain. Please refer to Squarespace's Privacy Policy and their Data Processing Addendum for more information.
6. DISCLOSURE OF YOUR PERSONAL DATA
Business Transactions
If Frezent is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. To the extent required by law, we will provide an online notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
Disclosure for Law Enforcement
Under certain circumstances, Frezent may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
Legal Requirements
Frezent may disclose your Personal Data in the good faith belief that such action is necessary, among other matters, to:
• Comply with a legal obligation
• Protect and defend the rights or property of Frezent
• Prevent or investigate possible wrongdoing in connection with the Service
• Protect the personal safety of users or the public
• Protect against legal liability.
7. THIRD-PARTY SERVICE PROVIDERS
We may engage third-party companies and individuals ("Service Providers") to facilitate our Service, provide services on our behalf, or assist in analyzing how our Service is used. These third parties have access to your Personal Data to perform these tasks and are obligated not to disclose or use it for any other purpose. Service Providers we currently engage include, among others;
Cloud Hosting and Infrastructure:We presently use cloud hosting service provider, Squarespace, Inc., to host our website and store data securely. Squarespace, as a third-party service provider, processes your data on our behalf and complies with necessary security measures and data protection laws and regulations.
Analytics:
Google Analytics — a web analytics service by Google LLC that tracks and reports website traffic. Google may use the data collected to contextualize and personalize ads within its advertising network. You can opt out via the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout. For more information: https://policies.google.com/privacy.
Advertising:
We may use Google advertising products to serve relevant advertisements. Google uses cookies to deliver ads based on visits to our Service or other websites. You may opt out of interest-based advertising via Google Ads Settings: https://adssettings.google.com. For more information: https://policies.google.com/privacy.
Email Communications:
We use email service providers to send transactional and marketing communications. These providers process your email address for communication delivery. We will periodically update this list as or if our Service Provider relationships change. For an up-to-date list of Service Providers, please contact us.
8. SECURITY OF YOUR PERSONAL DATA
The security of your Personal Data is important to us. We implement a combination of administrative, technical, and physical safeguards designed to protect your information, including:
• Encryption of data in transit using industry-standard TLS/SSL protocols
• Access controls and role-based permissions limiting access to Personal Data to authorized personnel
• Regular security assessments and monitoring of our systems
• Data minimization practices — we collect what is necessary for the stated purposes
However, please note that no method of transmission over the internet or method of electronic storage is entirely or fully secure. We cannot guarantee absolute security and encourage you to be cautious when sharing information over the internet.
9. DATA BREACH NOTIFICATION
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Frezent will:
• Notify the relevant supervisory authority (e.g., the applicable Data Protection Authority) without undue delay, and, to the extent applicable, where feasible within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR if and to the extent applicable or other applicable law.
• Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms in accordance with Article 34 of the GDPR if and, to the extent applicable under applicable law.
• Comply with applicable U.S. federal and state data breach notification laws, including the New York SHIELD Act and other relevant state statutes, within the timeframes prescribed by such laws.
Breach notifications will include, to the extent known at the time: the nature of the breach, the categories and approximate number of individuals concerned, the likely consequences of the breach, and the measures taken or proposed to address the breach.
10. CHILDREN’S PRIVACY
Our Service is not directed to anyone under the age of 16 (or 13 where required by applicable U.S. federal and state law). We do not knowingly collect Personal Data from children under 16. If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us immediately. If we become aware of such collection without appropriate parental consent, we will take steps to delete that information from our servers.
11. YOUR DATA PROTECTION RIGHTS
11.1 General Rights
Regardless of your location, you may request:
• Access: A copy of the personal information we hold about you in a commonly used machine-readable format.
• Deletion: That we delete your personal information, subject to legal retention requirements and to the extent technologically and reasonably feasible.
We will respond to requests within 30 days or as soon as reasonably feasible. We may need to verify your identity before processing your request.
11.2 GDPR Rights (EEA, UK, and Switzerland Residents)
If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR or equivalent legislation:
• Right to be informed: To receive clear and transparent information about how we process your data (this Policy fulfills that obligation).
• Right of access (Article 15): To obtain confirmation of whether we process your data and to receive a copy of it.
• Right to rectification (Article 16): To have inaccurate or incomplete personal data corrected.
• Right to erasure / ‘right to be forgotten’ (Article 17): To request deletion of your personal data where there is no compelling reason for its continued processing.
• Right to restrict processing (Article 18): To request that we limit how we use your data in certain circumstances.
• Right to data portability (Article 20): To receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
• Right to object (Article 21): To object to processing based on legitimate interests or for direct marketing purposes.
• Rights related to automated decision-making (Article 22): To not be subject to solely automated decisions that produce significant legal or similar effects. See Section 13.
To exercise any of these rights, please contact us. We will respond within 30 days (extendable by further 60 days in complex cases, with notice to you).
You also have the right to lodge a complaint with your local data protection supervisory authority. In the EU, this is your national Data Protection Authority (DPA). In the UK, this is the Information Commissioner’s Office (ICO): https://ico.org.uk/. We encourage you to contact us first so we can try to resolve your concern.
11.3 CCPA / CPRA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA, effective January 1, 2023), grants you the following rights:
• Right to Know: You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purpose for collection, and the categories of third parties with whom we share it.
• Right to Delete: You may request deletion of your Personal Information, subject to certain exceptions (e.g., legal obligations, completing transactions).
• Right to Correct: You may request correction of inaccurate Personal Information we maintain about you.
• Right to Opt-Out of Sale/Sharing: We do not sell your Personal Information for monetary consideration. However, under the CPRA, sharing data through certain targeted advertising may constitute “sharing” of Personal Information. You may opt out of such sharing by contacting us or using any opt-out mechanism we make available.
• Right to Limit Use of Sensitive Personal Information: You may direct us to limit our use and disclosure of sensitive Personal Information to only what is necessary to perform the services.
• Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
We will respond to verified requests within 45 days. We may extend this period by an additional 45 days (total 90 days) where reasonably necessary, and will inform you of the extension in writing. For more information, visit the California Privacy Protection Agency (CPPA) website: https://cppa.ca.gov.
12. CONSENT WITHDRAWAL AND OPT-OUT MECHANISMS
Where we process your Personal Data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing we carried out prior to your withdrawal.
12.1 Marketing Communications
You may opt out of receiving promotional emails from us at any time by:
• Clicking the “Unsubscribe” link in any marketing email we send you; or
• Sending a written opt-out request to us by filling out the contact us form.
Please note that even if you opt out of marketing communications, we may still send you transactional or service-related messages (e.g., responses to your inquiries, legal notices).
12.2 Cookies and Tracking Technologies
You can manage your cookie preferences at any time by:
• Adjusting your browser settings to refuse all or some cookies. Most browsers allow you to block or delete cookies in their privacy or security settings.
• For performance/analytics cookies: Installing the Google Analytics opt-out browser add-on at https://tools.google.com/dlpage/gaoptout.
• For advertising cookies: Opting out via Google Ads Settings at https://adssettings.google.com or via the Network Advertising Initiative opt-out tool at https://optout.networkadvertising.org.Please note that disabling certain cookies may affect the functionality of our Service.
12.3 Do Not Track Signals
Some browsers include a “Do Not Track” (DNT) feature that signals your preference not to be tracked across websites. Our website does not currently respond to DNT signals. However, you can use the cookie controls described above to limit tracking.
13. AUTOMATED DECISION-MAKING AND PROFILING
We may use automated tools and technologies to analyze usage data and improve our Services (for example, analytics platforms that automatically segment users by behavior or geography for optimization purposes).
We do not currently make decisions that produce significant legal or similarly significant effects on individuals solely through automated processing without human involvement.
If this changes in the future, we will update this Policy on our website and, where required by applicable law (including Article 22 of the GDPR), we will:
• Inform you about the logic involved in any such automated decision-making;
• Explain the significance and likely consequences for you; and
• Provide you with the right to request human review of the decision, express your point of view, and contest the decision.
If you have concerns about any automated processing that may affect you, please contact us.
14. LINKS TO OTHER SITES
Our Service may contain links to third-party sites not operated by us. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility or liability for the content, privacy policies, or practices of any third-party sites or services.
15. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. For material changes, we may notify you by email (if we hold your email address) and by posting a prominent notice on our website at least 15 days prior to the change becoming effective. The “Last Updated” date at the top of this Policy will always reflect the most recent revision.
We encourage you to review this Privacy Policy periodically. Continued use of our Services after changes become effective constitutes your acceptance of and agreement to the updated Policy.
16. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us.
We aim to respond to all privacy-related inquiries within 30 days. For GDPR-related requests, we will respond within 30 days to the extent required by law.