Nuvaxovid XBB.1.5▼ dispersion for injection, COVID-19 Vaccine (recombinant, adjuvanted) (NVX-CoV2601)

Privacy Policy

Novavax company group

"Novavax", "we," and "us" refers to Novavax Inc. For the purpose of applicable data protection laws, we are the "Controller" for any Personal Data processing described in this privacy notice. This privacy notice covers how and why we collect and use Personal Data about you, through our provisions of Services. Note that this notice does not cover specific privacy practices for participants in research studies or clinical trials, which are governed by privacy notices provided as part of the particular study or trial. 

When we use the term “Personal Data,” we mean data that reasonably can be used to identify a person or that reasonably relates to a living person (a “Data Subject”). 

When we use the term “Services”, we mean to refer collectively to the website Novavax.com and any other website or mobile application that is owned and controlled by us that link to this privacy notice and in connection with the services we provide to you.

How we collect your Personal Data

  • Information you give to us. We collect relevant Personal Data when you voluntarily submit information, when you register with us to receive information about clinical trials or other research studies, when you register for events such as webinars, trainings, lectures, seminars, or workshops, when you submit a grant request, and/or when you request financial updates about Novavax’ business.
  • Information we collect automatically. We collect certain information in connection with the use of our website by visitors and the Services, which may include:
    • Device Data such as IP address (or proxy server), device and application identification numbers, geolocation data, browser type, Internet service provider and/or mobile carrier, and operating system and system configuration information.

Usage and Log Data such as, information about website visitors' activity on the Sites and Services, including but not limited to the pages viewed, actions taken, date/time stamps associated with usage, and other details about your use of and actions on our website./Information third parties provide us. Publicly Available Sources including from social media platforms such as Facebook, Twitter, Instagram, LinkedIn, and other publicly available databases may be used when relevant to the purpose for which the information was first shared through those platforms.

What personal data we collect

In connection with the Services, and only to the extent necessary for each specific purpose, we collect:

  • identification information including name, profession, email address, zip code and telephone number;
  • contact information including postal address and e-mail address, zip code and phone number;
  • research-specific information including information about patients (including health history, treatment outcomes, and other health information), caregivers, or Healthcare Professionals and their research activities;
  • health information including information about interest and participation in clinical trials, webinars community programs and interest groups;
  • adverse event information related to our products;
  • certain information in connection with the use of the Sites by visitors and the Services, which may include:
    • Device Data: information may include IP address (or proxy server), device and application identification numbers, geolocation data, browser type, Internet service provider and/or mobile carrier, and operating system and system configuration information; and
    • Usage and Log Data: information about website visitors' activity on the Sites and Services, including but not limited to the pages viewed, actions taken, date/time stamps associated with usage, and other details about your use of and actions on our website.
  • professional and employment information including CV/resume details, professional and academic history, credentials, designations, licenses and personnel files;
  • service data including information on requests made and interactions with our Services; and
  • other background data including information on criminal history/unlawful conduct.

Third-party collection of Personal Data

Third party analytics and advertising companies also collect personal information through our website and apps including identifiers and device information (such as cookie IDs, device IDs, and IP address), geolocation data, usage data, and inferences based on and associated with that data, as described in our Cookies Policy. These third-party vendors may combine this data across multiple sites to improve analytics for their own purpose and others. For example, we use Google Analytics on our website to help us understand how users interact with our website; you can learn how Google collects and uses information at www.google.com/policies/privacy/partners.

How do we use your Personal Data?

  • We use the information that we collect to respond to your request, to fulfill our contracts with you (if applicable) and to carry out our legitimate business interests.  Some of these purposes are as follows:
  • Prospective research and employee application processes (“Application Activities”). While considering applications for employment, including evaluating and confirming your suitability for a position and the accuracy of any information submitted, we may make our own inquiries to verify or add to information you provide us during the course of Application Activities. We use this information to comply with applicable law, when it is necessary to comply with our responsibilities as an employee to hire the correct individuals or where the provision of the information is necessary for entry into your employment contract.
  • Our marketing and business development activities, including events we host (such as webinars) and social media properties we operate (“Marketing Activities”) in our legitimate interests for managing, operating, developing and growing our business, and administering the Services, including through the use of third party service providers and business partners.
  • Developing and maintaining relationships with health care professionals, investigators, researchers, patients and caregivers; for notifying related parties regarding Novavax financial information; for communicating with you to respond to your inquiries and to provide technical or administrative support in our legitimate interests; or for investigating and resolving disputes and security issues and enforcing our Terms and Conditions to comply with applicable law or in our legitimate interests.
  • Preventing, investigating or providing notice of fraud: unlawful or criminal activity; unauthorized access to our use of Personal Data, the website or our data systems; to meet legal, regulatory, judicial and company policy obligations; or for our legitimate purposes to keep our business safe.
  • The Data Subjects from whom we receive Personal Data from in providing the Services are:
  • Physicians and other healthcare professionals;
  • Clinical trial investigators;
  • Potential investors in Novavax;
  • Prospective and participating research participants;
  • Service providers, contractors and consultants;
  • Visitors to our Sites;
  • Job applicants; Volunteers; and
  • Other individuals who interact directly with Novavax or its business partners.
  • How your Personal Data may be shared
  • Within Novavax. Employees, consultants and agents of our Novavax affiliates may have access to your Personal Data to carry out legitimate business purposes.
  • Service providers. We share Personal Data with third-party service providers who complete transactions or perform services on our behalf, such as health care professionals, contract research organizations or other medical institutions conducting research on our behalf or in collaboration with us in our legitimate interests to conduct better research. We may also use data storage and analytics providers, recruiters, background check providers, event coordinators, market research providers, technology providers (including technology support providers, email communications providers and web developers) or those providers assisting with the Services in order to fulfil our contract with you.
  • Marketing and advertising partners. We may provide Personal Data to marketing and advertising partners. For example, we may disclose identifying information to an advertising partner in order to deliver personalized advertising to you or for the purpose of delivering advertisements to other people with similar interests to you. Where required by applicable law, we will obtain your consent prior to sharing this information.
  • Regulatory, legal process, safety and terms enforcement. We may disclose Personal Data to governmental regulatory authorities, including in connection with monitoring, review and approval of our studies: products and services: financial disclosure obligations: adverse event reporting: and in response to their requests for such information or to assist in investigations in order to comply with applicable law or in our legitimate interests to comply with a government authority. We may also disclose Personal Data to third parties in connection with claims, disputes, or litigation: when otherwise required by law: or if we determine its disclosure is necessary to protect your health and safety or ours, to protect against fraud or credit risk, or to enforce our legal rights. 

Business transfers. We may disclose Personal Data as part of a corporate business transaction, such as a merger, acquisition, partnership, joint venture, financing, or sale of company assets and may transfer Personal Data to a third party as one of the business assets in such a transaction in our legitimate interests or as required by law. Personal Data may also be disclosed in the event of insolvency, bankruptcy, or receivership.

What rights and control you have over our processing

Depending on where you reside and applicable law, you may have certain rights in relation to the personal information we hold about you, which we detail below. Certain rights only apply in specific circumstances. We also set out how to exercise those rights.

Your rights may include:

  • Right to access
    You may have the right to request information on our use of your Personal Data.
  • Right to rectification
    You may have the right to rectify Personal Data about you that is inaccurate, incomplete, or misleading.
  • Right to erasure
    You may have the right to request that we erase the Personal Data we have collected about you.
  • Right to restriction of processing
    We will temporarily restrict the processing of your Personal Data
  • Right to object to processing
    You may have the right to object to the processing of Personal Data that we base on our legitimate interests.
  • Right to data portability
    You may have the right to receive the Personal Data about you that Novavax processes and which you have provided to us, in a structured, commonly used, and machine-readable format.
  • Right to have your Personal Data corrected
    You have the right to correct any of your Personal Data we hold that is inaccurate.
  • Right to withdraw consent

    Where our processing of your Personal Data is based on your consent, you may have the right to withdraw such consent at any time by contacting us

  • Right to opt-out to selling and sharing for targeted advertising
    You may have the right to opt-out of the sharing of your personal information to third parties for advertising and marketing purposes. To exercise this right, please see the section below “U.S. Residents”. For additional information on opting out of interest based advertising or certain cookies provided by some of our key providers, please see the “Cookies, Web Beacons and other Technologies” section.

You may submit a request to exercise any of these rights by emailing us at privacy@novavax.com. When you exercise your rights, we may need to request specific information from you to help us confirm your identity, such as your email address or phone number. We may also contact you to ask you for further information in relation to your request to speed up our response.

Please note that a number of these rights only apply in certain circumstances, and all of these rights may be limited by law. For example, where fulfilling your request would adversely affect other individuals or our trade secrets or intellectual property, where there are overriding public interests or where we are required by law to retain your personal data.

US Residents

This section applies if you are a resident of California, Colorado or another U.S. state that has passed a privacy law similar to the California Consumer Privacy Act (“CCPA”) and requires specific privacy notice disclosures. For purposes of this section, references to “personal information” also includes “sensitive personal information” as those terms are defined under such laws.

The table below sets out the categories of personal information (including sensitive information, denoted by *) we collect and disclose, including our collection and disclosure over the past 12 months.

Category of Personal InformationRecipient(s)
Identifiers such as name, profession, postal and email address, zip code, and telephone numberService providers, marketing and advertising partners, and affiliates
Personal information categories listed in the California Customer Records statute such as name, address, and telephone numberService providers and affiliates
Characteristics of protected classifications under California or federal law such as race, color, national origin or ancestry, sex, age, physical or mental disability, veteran status and citizenshipService providers and affiliates
Internet or other similar network activity such as information regarding your interaction with the ServicesService providers, marketing and advertising partners, and affiliates
Geolocation data such as IP addressService providers, marketing and advertising partners, and affiliates
Inferences drawn from other personal information such as a profile reflecting your preferencesService providers and affiliates
Professional and employment information including CV/resume details, professional and academic history, credentials, designations, licenses and personnel filesService providers and affiliates
Education information including academic historyService providers and affiliates
Sensitive personal information that reveals racial or ethnic origin, and information concerning your healthService providers and affiliates

For information regarding the specific purposes for which we collect and disclose your information, and the categories of sources from which we collect such information, please see “Collecting Information”, “Using Information” and “Disclosing Information” sections above. The criteria we use to determine how long to retain your information are described in the “Retaining Information” section. We only use and disclose sensitive personal information for the purposes specified in the CCPA or otherwise in line with your consent.

We do not have actual knowledge that we “sell” or “share” (as those terms are defined under the CCPA and used throughout this section) personal information of individuals under 16 years of age. However, we do disclose certain types of personal information and, in the preceding 12 months, we have shared the following categories of personal information with advertisers, ad servers, ad networks and social media platforms for advertising and marketing purposes, including to target and personalize advertising and content. For purposes of the CCPA, this may qualify as a “sale” / “sharing” of personal information.

CategoryCategories of Third Parties
Identifiers such as e-mail address, IP address, device identifiersMarketing and advertising partners
Internet or other similar network activity such as information regarding your interaction with the SitesMarketing and advertising partners
Geolocation data such as IP addressMarketing and advertising partners

Note that the CCPA defines “sell,” “share,” and “personal information” very broadly, and some of our data sharing described in this Privacy Policy may be considered a “sale” or “sharing” under those definitions. In particular, we let advertising and analytics providers collect identifiers (IP addresses, cookie IDs, and mobile IDs), activity data (browsing, clicks, app usage, non-product identifying transaction data), device data, and geolocation data through our sites and apps when you use our online services, but we do not “sell” or “share” any other types of personal information. If you do not wish for us or our partners to “sell” or “share” personal information relating to your visits to our sites for advertising purposes, you can request that we not do so by clicking the cookie settings icon to open the Privacy Preference Center at the bottom of our websites. We do not knowingly sell or share the personal information of minors under 16 years of age.

Some browsers include a “Do Not Track” (DNT) setting that can send a signal to the websites you visit indicating you do not wish to be tracked. Unlike the GPC described above, there is not a common understanding of how to interpret the DNT signal; therefore, our websites do not respond to browser DNT signals. Instead, you can use the range of other tools to control data collection and use, including the GPC, cookie controls, and advertising controls described above.

Emails: To opt out of receiving marketing communications via email, please click on the unsubscribe link at the bottom of the email that was sent to you or submit an opt-out request using the contact information set forth in the Contact Us section below. Please note that you may continue to receive certain transactional or account-related electronic messages from us.

We do not use or disclose sensitive personal information (as defined by the CCPA) for restricted purposes that California residents have a right to limit under the CCPA. Additionally, we do not attempt to re-identify de-identified information that we derive from personal information, except for the purpose of testing whether our deidentification processes comply with applicable law.

How long will we store your Personal Data 

We retain your Personal Data for the period necessary to fulfill our legitimate business purposes. When determining the length of time to retain your Personal Data, we consider various criteria, including whether we need the information to continue to provide you with our Services, resolve disputes, comply with our legal obligations, enforce our contractual agreements, prevent harm, promote safety, security, and integrity, or protect ourselves, including our rights, property or products. [If you stop using our Services, we will store your information in an aggregated and anonymised format; we may use this information indefinitely without further notice to you.]

Where we store your Personal Data

The Personal Data that we collect from you will be transferred to, and stored at/processed in countries outside the European Economic Area (“EEA”) and the United Kingdom (“UK”). Your personal data is also processed by staff operating outside the EEA and the UK who work for us or one of our third party service providers or partners. We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this notice.

For any transfers of data from the EEA or the UK to a location outside of the EEA or the UK, the data transfer will be governed by the European Commission’s standard contractual clauses for the transfer of personal data to third countries or the UK Information Commissioner’s international data transfer addendum to the EU standard contractual clauses, as relevant, unless the data transfer is to a country that has been determined by the European Commission or the relevant UK authorities, as applicable, to provide an adequate level of protection for individuals’ rights and freedoms for their personal data. Please contact us using the details below should you wish to examine a copy of the EU standard contractual clauses or UK international data transfer addendum. 

Contact us

If you have any questions about this privacy notice or concerns about the way Novavax processes your Personal Data, or require assistance in managing your privacy choices, please get in touch with us at:

Novavax, Inc.
21 Firstfield Road
Gaithersburg, MD 20878

Phone: 1-844-NOVAVAX (668-2829)
privacy@novavax.com

Ask our Data Protection Officer

You can contact the Novavax Data Protection Officer at privacy@novavax.com with any questions about this notice.

EU/UK supervisory authorities

How to lodge a complaint:

If you wish to raise a concern about our data processing practices, you have the right to do so with your local supervisory authority, found here: https://edpb.europa.eu/csc/about-csc/members-coordinated-supervision-committee_en, or Novavax's lead supervisory authority, the Czech Republic, using the contact details listed on their website.

Managing communication preferences

If you have signed up to receive information from us (or where permitted by law, if you have provided your consent to us), we may send you email messages, direct mail information, push notifications, or other communications regarding our Services. You may ask us not to do so when you access our Services, and you may change your preferences by updating any accounts you have with us. At any time, you may elect to discontinue receiving commercial messages from us by following the unsubscribe instructions in the form of the communication you received or by submitting an opt-out request using the contact information set forth in the Contact Us section above.

Printed Materials: To opt out of receiving printed marketing materials at your postal address, such as advertisements, flyers, or postcards, please submit an opt-out request using the contact information set forth in the Contact Us section above. Please be sure to include your name and mailing address exactly as they appear on the printed marketing materials you received.

Children’s privacy

The Sites are not intended for, or directed to, children under the age of 18. We do not knowingly receive Personal Data from children under the age of 18. If you are under the age of 18, do not provide us with any Personal Data either directly, through any website forms, or by any other means. If you become aware that your child has provided us with Personal Data, please contact us at privacy@novavax.com.

Links to other sites and/or mobile applications

Our sites contain links to other sites or mobile applications that are owned by third parties and are not controlled by Novavax. In addition, research participants may be asked to use third-party websites or mobile applications to provide data or feedback during or following their participation in such research. Please be aware that we are not responsible for the privacy policies of such other sites or mobile applications or how these sites or mobile applications operate or treat your Personal Data. We encourage you to be aware of this when you leave our Sites, or participate in research using these applications, and to read the privacy policies and terms and conditions associated with each of these third-party sites that collect personally identifiable information. 

Updates to our privacy notice

Novavax is continually improving and adding new functionality and features to the Services. Because of these ongoing improvements, changes in the law and the changing nature of technology, Novavax’ data practices will change from time to time. Accordingly, this privacy notice is subject to occasional revisions. We will notify you of changes in accordance with, and to the extent required by, law and we will post any new or revised privacy notice on the Sites and update its effective date. Such changes to the privacy notice will become effective when posted.