Privacy Policy
Last Updated: April 30, 2026
Who We Are
Ataraxis AI, Inc. ("Ataraxis," "Company," "we," "our," or "us") values your privacy and the protection of your Personal Data. This Privacy Notice ("Notice") explains how we collect, store, use, share, transfer, delete, and process information collected from or about you, known as Personal Data (defined further below in this Notice). For individuals located in the European Union, United Kingdom, or European Economic Area, Ataraxis AI, Inc. acts as the data controller for Personal Data collected through our Products and Services.
Purpose and Reach of this Privacy Notice
This Notice describes the types of Personal Data that we may collect or process, how we may use and disclose that Personal Data, and how you may exercise any rights you may have regarding our processing of your Personal Data.
This Notice applies to Personal Data collected or processed by us:
- Through online activities and services we offer (through websites, web surveys, newsletters, applications, email, online messaging services/channels, and otherwise) ("Online Services");
- Related to activities we undertake in recruiting participants for clinical trials or identifying and contracting with study investigators and their staff;
- In connection with adverse events, complaints, and reports;
- When we provide products or services to you or your doctor, hospital, medical treatment or scanning facility, or other healthcare provider (collectively, "Healthcare Provider") or, if you are a Healthcare Provider, your patients;
- When you are applying to and/or enrolled in patient support programs, such as Access Solutions, patient foundations, or co-pay assistance programs;
- When we provide products and services directly to you and in other situations where you interact with us, including interactions through customer service centers, email, SMS/text, or visits to our sites and offices or events (collectively, the "Products and Services");
- When you interact with us in a professional capacity;
- When we undertake employment recruiting activities; or
- Anywhere this Notice is posted or referenced.
We may provide a different privacy notice in specific situations, which will govern the Personal Data collected or processed in that specific context, rather than this one.
If you provide us with Personal Data of anyone other than yourself, you are responsible for complying with all applicable privacy and data protection laws before sharing that information.
Information Collected
What is Personal Data?
"Personal Data" is any information—as electronically or otherwise recorded—that can be used to identify a person or that we can link to or associate with a specific individual.
Personal Data may include information considered sensitive in some jurisdictions, such as biometric information, genetic information, health information, financial account information, specific geolocation, ethnic or racial origin, information concerning your sex life or sexual orientation, social security number, driver's license, state identification card, passport number, and other similar information. Data that could be considered Sensitive Personal Data is highlighted with an asterisk (*) in the table below.
Where Personal Data constitutes Protected Health Information ("PHI") under HIPAA, it is handled in accordance with our HIPAA Notice of Privacy Practices, available upon request. Under the GDPR, health, biometric, and genetic data constitutes Special Category Data and is processed only where a specific legal condition under Article 9 applies.
We will process any Personal Data we collect in accordance with applicable law and as described in this Notice. In some circumstances, if you do not provide us with your Personal Data, certain Products and Services may be unavailable to you.
The below table is a high-level summary of the types of Personal Data we may collect from you. The types of Personal Data we collect and disclose depend on your relationship with us. Not all categories listed below may apply to you.
*Sensitive Personal Data / Special Category Data under GDPR / Protected Health Information under HIPAA. Processed only where a specific legal basis applies.
Note regarding De-identified Data: We will not attempt to re-identify you or anyone else from de-identified data, and if we disclose it to third parties, we require that they commit to the same. Please note that in the course of research, study doctors and authorized personnel may still have access to named subject records collected for such research.
Users of Online Services, Visitors to Our Websites and Physical Locations, and Senders of Inquiries
We may process your Personal Data when you visit our websites and physical locations; submit inquiries to us online or offline; sign up for newsletters or other informational or marketing materials; and/or register for, visit, or use our online Products and Services.
Patients Applying to or Enrolled In Patient Support Programs
We may process your Personal Data when you are applying to or enrolled in patient support programs.
Healthcare Providers
We may process your Personal Data when you are a Healthcare Provider who is a current or prospective customer, use Products and Services, or treat patients using our Products and Services, including our online portals.
Patients and Users of Medical Products
We may process your Personal Data when you are an existing or prospective patient of a Healthcare Provider who uses our products and/or services.
Business Partners and Their Employees, Agents, and Contractors
We may process your Personal Data if you are a current business partner, employee of a business partner, agent, or contractor.
Attendees and Participants at Events
We may process your Personal Data when you attend or participate in professional and educational events we sponsor or hold.
Clinical Investigators and Members of Investigator Teams
We may process your Personal Data if you are an existing or prospective clinical investigator or a member of an investigation team for a clinical study we manage on behalf of a customer.
Clinical Study Candidates
We may process your Personal Data when you have been identified as a potential candidate for clinical studies sponsored by us or conducted on behalf of a third party.
Employment and Apprenticeship Candidates
We may process your Personal Data when you apply or are a candidate for employment or apprenticeship.
Children
We do not knowingly collect, maintain, disclose, or process Personal Data from minors under the age of 18 without the permission of their parents or legal guardians.
Consumer Health Data
In some jurisdictions, specific requirements apply to the processing of Consumer Health Data. Where applicable, such data is handled in accordance with applicable law, including our HIPAA Notice of Privacy Practices where relevant.
How We Use Your Personal Data and Our Lawful Basis
We use your Personal Data to provide, maintain, and improve our Products and Services; manage patient support programs and clinical trials; communicate with healthcare providers and patients; send marketing and promotional communications where permitted by applicable law; comply with legal and regulatory obligations; conduct research and analysis; recruit and evaluate job candidates; and detect and prevent fraud.
For individuals in the EU, UK, and EEA, we process Personal Data on the basis of contract performance, legal obligation, legitimate interests, or consent, as applicable. For Special Category Data, we rely on additional conditions under Article 9 GDPR as applicable.
Marketing, Cookies, and Tracking
We may use your contact details for marketing purposes and display advertisements to you that we believe are relevant. You can opt out of such communications at any time by contacting us directly.
We use cookies and similar tracking technologies to track activity on our Online Services. Cookies are files with a small amount of data which may include an anonymous unique identifier, sent to your browser from a website and stored on your device. We also use beacons, tags, and scripts to collect and track information and to improve and analyze our Online Services.
Types of Cookies Used:
- Essential Cookies: Necessary for the website to function and cannot be switched off in our systems.
- Performance Cookies: Allow us to count visits and traffic sources so we can measure and improve the performance of our site.
- Functionality Cookies: Enable the website to provide enhanced functionality and personalization.
- Targeting Cookies: May be set through our site by our advertising partners to build a profile of your interests and show you relevant adverts on other sites.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Online Services.
Third Parties
We may share your Personal Data with third parties, such as service providers acting on our behalf. These service providers are contractually required to maintain confidentiality and process Personal Data only as necessary to perform their functions and in accordance with applicable law. Where required by applicable law, we enter into appropriate agreements with third parties that handle PHI on our behalf. We do not sell your Personal Data to third parties.
International Transfers of Personal Data
Ataraxis AI, Inc. is headquartered in the United States. If you are located in the EU, UK, or EEA, your Personal Data may be transferred to and processed in the United States or other countries that may not provide the same level of data protection as your home jurisdiction. Where such transfers occur, we implement appropriate safeguards in accordance with applicable law. You may request details of these safeguards by contacting us using the details provided on our website.
Your Rights Regarding Your Personal Data
Depending on the state or country in which you reside, you may have rights regarding your Personal Data, or opting out of certain processing activities, including:
- Right to Access: You can request a copy of your Personal Data.
- Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- Right to Erasure: You can ask us to delete or remove Personal Data where there is no good reason for us continuing to process it.
- Right to Restrict Processing: You can ask us to suspend the processing of your Personal Data.
- Right to Data Portability: You can request the transfer of your Personal Data to another party.
- Right to Object: You can object to the processing of your Personal Data where we are relying on a legitimate interest (or those of a third party).
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
EU, UK, and EEA residents additionally have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects (Article 22 GDPR). You also have the right to lodge a complaint with your local data protection supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in Ireland, the Data Protection Commission (dataprotection.ie); in France, the CNIL (cnil.fr). A full list of EU supervisory authorities is available at edpb.europa.eu.
Individuals whose Personal Data constitutes PHI under HIPAA have additional rights under our HIPAA Notice of Privacy Practices, available upon request.
To exercise any of these rights, please contact us using the details below. We may need to verify your identity before processing your request and will respond within the timeframe required by applicable law.
Safeguarding Information
We take reasonable steps to protect Personal Data from loss, misuse, alteration, unauthorized access, and unauthorized disclosure.
How Long Your Personal Data Will Be Retained
We generally retain Personal Data for as long as needed for the specific business purposes for which it was collected or obtained, and per legal obligations.
Changes to This Privacy Notice
We reserve the right to change this Notice from time to time. It is recommended that you periodically revisit this Notice to learn of any changes.
Contact Us
If you have questions or comments about this Notice or how your Personal Data is processed, please contact us by email or mail at the details provided on our website.