Zai Lab Limited Global Privacy Notice

Effective Sept. 12, 2023

Zai Lab’s Privacy Policy describes our practices regarding the collection, use and disclosure of information that Zai Lab may collect about you through our websites, mobile sites, and mobile applications (collectively, the “Sites”). Except as specifically provided below, this Privacy Policy does not apply to any other information collected by Zai Lab by or through any other means, such as information collected offline. When we refer to ourselves as “we” or “Zai Lab,” we mean Zai Lab Limited and all of its subsidiary companies. To the extent our Sites contain links to third party websites/content/services that are not owned or controlled by Zai Lab. Zai Lab is not responsible for how these properties operate or treat your personal data so we recommend that you read the privacy policies and terms associated with these third party properties carefully.

Individuals in the EU/EEA/UK or Switzerland: For additional information for individuals in the EU, EEA, UK or Switzerland, please see the applicable section below.

California Residents: For information relating to California residents, please see the applicable section below.

INFORMATION ZAI LAB MAY COLLECT

We collect personal information online through the Sites. There are three methods that Zai Lab uses to collect personal information online:

  • Information that you provide: We collect personal information and other data that you may enter into forms or data fields on our Sites. Such information may include, but is not limited to, contact information (such as your name, postal address, e-mail address, telephone number, user ID and password), date of birth, professional credentials, experiences, activities, skills, preferences, hobbies and interests. We may also collect, when relevant for the processing purpose, health information about you that you provide by responding to our questions and surveys or through your use of online and downloadable health-related tools we provide.
  • Information from public or third-party information sources: We may collect personal information about health care professionals from public or third-party information sources to verify their professional credentials and identity. In some cases, we may augment our existing user databases with information from third parties. Some of this information may be personal information, such as change of postal address information.

We may also collect personal information about you from other sources, including data companies, publicly accessible databases, joint marketing partners, social media platforms and other third parties.

  • Information collected from your computer or other electronic device: We may collect information about your computer or other electronic device when you visit our Sites. This information may include your Internet Protocol (IP) address, Internet Service Provider (ISP), domain name, browser type, date and time of your request and information provided by tracking technologies, such as cookies, single-pixel tags, local share objects (Flash), local storage, Etags and scripts. If you use a mobile device to access our web sites and online resources or to download our mobile apps or services, we also may collect information about your device, such as your device ID and device type, as well as usage information about your device and your use of our mobile web sites and other mobile resources.

HOW WE MAY USE YOUR PERSONAL DATA

Generally, Zai Lab collects personal information from the Sites as necessary to enable individuals to register for, customize and personalize certain of our resources and communications. We use personal information collected from the Sites to provide products, services and features and other resources that individuals have requested; for example, educational literature and related information about our business, e-mail programs, tools, questionnaires, and surveys. We analyze personal information collected online to identify and offer additional services and promotions that we believe you might find interesting. We may aggregate and/or de-identify data about visitors to our Sites and use it for any purpose, including product and service development and improvement activities.

The personal information that is collected in connection with the Sites may be used in any of the following ways:

  • To respond to your requests for information, products, or services;
  • To provide you with general health information (such as information on certain health conditions) as well as information about our products and services;
  • To provide you with marketing communications whether about a particular Zai Lab product or concerning general disease information;
  • To determine if you are eligible for certain products, services, or programs (such as patient assistance programs);
  • To manage or develop our business relationship with you (e.g., to respond to questions, invite you to events, comply with regulatory obligations, or determine eligibility for Zai Lab programs);
  • To recruit and/or consider you for employment;
  • For our research, development, and collaboration efforts;
  • For regulatory reporting, such as adverse event or pharmaceutical transparency reporting; and
  • For other everyday business purposes, such as payment processing and financial account management, product development, contract management, Site administration, fulfillment, analytics, fraud prevention, corporate governance, reporting, and legal compliance.

The information we collect from your device is used to better design our Sites. We analyze this information to enhance Site security and to track the popularity of certain pages of the Sites, the success of our email notifications, traffic levels on the Sites, and other usage data, all of which helps us to provide content tailored to your interests and improve the Sites and related Services.

SHARING YOUR PERSONAL INFORMATION

We may share your information amongst and between our family of companies or our business partners for the purposes set forth in this Policy. We will require the recipients to use your personal information only for appropriate purposes and take appropriate measures to protect your personal information.

If we sell or transfer all or a portion of our business or assets to a third party, such as in the event of a corporate sale, merger, reorganization, dissolution or similar event, we may transfer information that we have collected to such third party. We will require such a third party to continue to comply with this Privacy Policy.

We reserve the right to disclose your personal data as required by law, when we believe disclosure is necessary or appropriate to comply with a regulatory requirement, judicial proceeding, court order, government request, or legal process served on us, or to protect the safety, rights, or property of our customers, the public, Zai Lab or others. Zai Lab may disclose aggregate or de-identified data that is not personally identifiable to third parties for any purpose.

GLOBAL ACCESS

This site is owned and operated by Zai Lab in the People’s Republic of China. However, your personal information may be accessible or transferred to our affiliates, vendors, and suppliers who are located in other countries. If you are visiting this site from a country other than the People’s Republic of China, your communication with us will necessarily result in the transfer of information across international borders. Therefore, by using the Sites, you hereby expressly consent to the transfer of your personal information outside your country or region.

OUR COMMITMENT TO DATA SECURITY AND DATA RETENTION

Zai Lab uses technical, administrative, and procedural measures in an attempt to safeguard your personal data from unauthorized access or use. No such measure is ever 100% effective though, so we do not guarantee that your personal data will be secure from theft, loss, or unauthorized access or use, and we make no representation as to the reasonableness, efficacy, or appropriateness of the measures we use to safeguard such data. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately notify us by contacting us at privacy.inquiries@zailaboratory.com.

CHILDREN’S PRIVACY

The Site is not directed to individuals under the age of thirteen (13), and we do not knowingly collect personal data from children under the age of 13.

YOUR ABILITY TO CORRECT OR DELETE PERSONAL INFORMATION

If you would like to request to review, correct, or update your personal data that Zai Lab maintains, you may contact us as indicated in the Contact section below. We will respond to your request consistent with applicable law.

You may update your personal data and your preferences provided through the Sites. Different programs and services may offer different phone numbers, links or preference managers that allow you to inform us of your updates and choices, including opting out of particular communications. These contact options are typically available on the Sites, but you may always contact us for assistance at privacy.inquiries@zailaboratory.com if you have any difficulty finding these tools or otherwise updating your data or preferences.

You may choose not to provide any personal information to us; however, in doing so, you may not be able to use certain Services. Please note that we may need to retain certain personal data for record keeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion.

ACCESSING INFORMATION & CONTACTING US

You may contact us at any time if you have questions about this Privacy Policy. If you would like to exercise any individual rights related to your personal data, please contact us by sending an email to privacy.inquiries@zailaboratory.com. Additionally, residents of California, USA, may obtain certain information regarding Zai Lab’s disclosure of personal information to third parties for third-party direct marketing.
We will respond to your request consistent with applicable law.

HOW LONG WILL WE RETAIN PERSONAL INFORMATION

We retain your personal data for as long as needed or permitted in light of the purpose(s) for which it was obtained. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you and operate the Sites; (ii) whether there is a legal obligation to which we are subject; or (iii) whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).

CHANGES TO OUR PRIVACY POLICY

From time to time, we may update this Privacy Policy. Any changes will be effective when we post the revised Privacy Policy. This Privacy Policy was last updated as of the effective date listed above. We encourage you to periodically review this page for the latest information on our privacy practices.

ADDITIONAL INFORMATION FOR INDIVIDUALS IN THE EU/EEA/UK OR SWITZERLAND

We are required to comply with the European Union’s and the United Kingdom’s General Data Protection Regulations(“GDPR”), Switzerland’s Federal Act on Data Protection (FADP) and similar applicable local laws with regards to certain personal information we collect. The data controllers of your personal information are the Zai entities referenced when we collect your personal information. Please contact us at privacy.inquiries@zailaboratory.com if you have any questions about the controller or controllers of your personal information.

SENSITIVE DATA
We process special categories of information (e.g., sensitive information that reveals racial or ethnic origin or genetic, biometric and health information) only where you give us your explicit consent, or when our processing is for scientific research purposes, necessary to meet a legal or regulatory obligation, in connection with the establishment, exercise or defense of legal claims, or is otherwise expressly permitted by law.

If we need to collect your personal information by law or under the terms of a contract we have with you and you do not provide the requested information, we may not be able to perform the contract we have, or are trying to enter into, with you.

DATA TRANSFERS
Zai Laboratory is a multi-national company with offices in the United States and China. As such, Zai Laboratory may transfer or provide access to your personal information to affiliates, service providers or collaborators in these countries and others that do not provide the same level of protection as your own country. When we do so, in the absence of an adequacy decision concerning the recipient country, we rely on safeguards such as approved model contracts (for example the EU’s standard contractual clauses), after having carried out an assessment of the level of protection of your rights on the territory of the third country where the recipient of your personal information is established.

YOUR RIGHTS UNDER THE GDPR
Rights you may have under the GDPR with regards to the personal information we collect and maintain about you are described in the section YOUR ABILITY TO CORRECT OR DELETE PERSONAL INFORMATION. Please note that residents of the EU/EEA/UK/Switzerland also have the right to file a complaint with the supervisory authority of their member state/country.

ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS

CALIFORNIA JOB APPLICANTS
This notice informs you of the personal information we collect and how we use such information as part of our employment application process, pursuant to the California Consumer Privacy Act of 2018.

In connection with your creating a profile and submitting your application, Zai Lab will collect the following categories of personal information:

  • direct identifiers, such as your name and contact information;
  • professional information, such as your previous employment and education background; and
  • other information you include in your resume and cover letter.

We also may collect information from your social media profile if you create a profile using a social media account, as well as any other personal information you voluntarily provide to us in connection with the application process.

If you accept an offer of employment and subject to your authorization, we will conduct a background check which may include access to additional employment and educational background information as well as criminal record information.

We use the information you provide to evaluate your candidacy for the job opening(s) you apply to and other job openings at Zai Lab that we think may interest you, to conduct background and reference checks and to communicate with you about such matters. Zai Lab will generally delete personal information of unsuccessful candidates, but may retain personal information in certain cases, i.e., for consideration for future positions or as necessary to defend against potential legal claims.

We may update this Notice at any time to reflect changes to the personal information we collect and how we use it. If you have questions about this notice, please contact Zai Lab at privacy.inquiries@zailaboratory.com.

CALIFORNIA CONSULTANTS AND CONTRACTORS
In accordance with the California Consumer Privacy Act of 2018, this California Privacy Notice for Consultants and Contractors (“Notice”) describes the categories of personal information that Zai Lab collects about you in the context of your relationship with Zai Lab and the purposes for which we collect your personal information. In certain circumstances, vendors such as placement agencies may collect this information on our behalf.

We collect the following categories of personal information about you in the context of your relationship with us:

  • Direct identifiers: We collect information that directly identifies you, such as your name, address, phone numbers, photograph, government-issued IDs (such as your social security numbers or passport information), and Zai Lab issued access cards and IT credentials.
  • Professional or employment-related information: We may collect your professional and employment-related information, including your work experience and education and reference information.
  • Financial information: We may collect your financial information, such as your bank account and W9 information.
  • Information about your use of the internet, our networks, and our devices: We collect information about your use of Zai Lab email accounts, the internet, and our computers, phones, and other devices to which you have access. We may also collect your information through security cameras if they exist in your workplace.

In addition to the categories listed above, we will collect any other personal information you voluntarily provide to us in the context of your relationship with Zai Lab.

We use the personal information we collect about you to manage our relationship with you. Uses include:

  • Onboarding and access to our administrative and IT systems;
  • Payment administration;
  • Monitoring the use of IT and other equipment and property for security purposes, to protect against fraud, and to ensure compliance with applicable policies and procedures;
  • Complying with our legal obligations under federal and state laws; and
  • Our own internal business purposes, including performing analytics and applying algorithms to discover ways to improve our business, identify trends in our workforce, and enhance our service offerings.

We may update this Notice at any time to reflect changes to the personal information we collect and how we use it. If you have questions about this notice, please contact Zai Lab at privacy.inquiries@zailaboratory.com.