Privacy policy
Last updated: 1/6/2026
OVERVIEW
This Privacy Policy is designed to provide information about how Elion Therapeutics, Inc. (“Elion,” “we,” “us,” or “our”) collects, uses, maintains, protects, and discloses information which could identify a natural person (“Personal Data”), and information about your rights and choices regarding our processing of your Personal Data.
This Privacy Policy applies to:
- all visitors to our website (eliontx.com, referred to herein as the “Website”);
- to Personal Data which we receive from our service providers in connection with performance of a contract; or
- to Personal Data which we receive from our business partners, including, but not limited to, our corporate partners or employees/personnel/contractors/representatives of our corporate partners, or any other party that we engage with for the purposes of establishing, developing, maintaining, facilitating, managing, or otherwise furthering a business relationship.
- Our website uses Google Analytics, a web analytics service provided by Google, Inc. Google Analytics may collect information about your use of the site. Google Analytics uses cookies to provide information about visits to our pages, including number of visitors, the websites from which visitors have navigated to our site, and the pages on our site to which visitors navigate. More information on Google Analytics can be found in the “Privacy & Terms” section of the Google website.
This Privacy Policy does not cover or apply to:
- information collected from participants in clinical trials or other research endeavors that Elion participates in, sponsors, or is affiliated with. For information about collection or processing of participant Personal Data in the context of a clinical trial, refer to the Informed Consent Form for that trial;
- information collected from healthcare professionals taking part in our trials. For information about collection or processing of healthcare professionals Personal Data, refer to the Privacy Notice for Healthcare Professionals;
- Personal Data relating to job applicants, our employees, consultants, directors, officers, and other staff of Elion who will be provided a separate privacy notice where required by applicable law; and/or
- information that does not constitute Personal Data. If we do not maintain information in a manner that identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular individual, such information is not considered Personal Data, and this Privacy Policy will not apply to our processing of that information.
Please review the following to understand how we process Personal Data about you. By accessing or using this Website, or by otherwise voluntarily providing Personal Data to us, you acknowledge that you have read and understand the disclosures contained in this Privacy Policy, and you agree that we may collect, use, share and/or disclose Personal Data in accordance with the terms of this Privacy Policy subject to your rights and our obligations under applicable law. This Privacy Policy may be revised from time to time (see “Modifications and Updates” below). Your continued use of our Website after we make changes is deemed to be an acceptance of those changes, so please ensure that you check this Privacy Policy periodically to remain fully informed.
CONTROLLERSHIP
Within the scope of this Privacy Policy, Elion generally acts as a data controller for the Personal Data processed. This means that we alone determine the purpose and means of the processing of your Personal Data.
TYPES OF PERSONAL DATA WE COLLECT
Personal Data you provide to us
- Contact data, such as your first and last name, email address, mailing address, zip/postal codes, professional title and company name, and phone number.
- Communications that we exchange with you, including when you contact us through the Website, email, social media, or otherwise, including the contents of messages you may send us.
- Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
- Other data not specifically listed here, which we will use as described in this Privacy Policy.
Elion gathers Personal Data when voluntarily submitted by you. We collect Personal Data from you through registrations, applications, surveys, support or information requests, filling in a form on our Website, business engagements, or other data capturing processes. Elion does not require you to register in order to view our Website. If you submit any Personal Data relating to other people to us, you represent that you have the authority to do so and to permit us to use that Personal Data in accordance with this Privacy Policy.
Third-party sources
We may combine information we have about you with information obtained from other sources, such as:
- automatically through logging and analytics tools, cookies, and as a result of your use of and access to the Website;
- from third-party sources, including service providers; and
- from publicly available information.
Other Information Collected
Elion may utilize data collection technologies that automatically collect and temporarily store certain information about your visit to our Website, including (i) the pages of our Website that you visited; (ii) the time and date of your visit; (iii) the address of the website that you came from when you entered our Website. This information would be aggregated and anonymized, and we use it to help diagnose problems with our server and to improve our Website’s content. We may also utilize, directly or indirectly through a third-party service provider, technical methods in HTML emails that we may send to determine whether you have opened those emails or clicked on links in the emails.
COOKIES AND OTHER TRACKING TECHNOLOGIES
Cookies are small pieces of information that are stored by your browser on your computer’s hard drive. We use cookies to enhance your experience on our Website. Cookies may collect such information as your IP address to identify the device that you use. Users may have the opportunity to set their computers to accept all cookies, to notify them when a cookie is issued or not to receive cookies at any time. If you set your browser not to accept cookies, you may not be able to take advantage of the full features of the Website. Cookies may be served by the entity that operates the website you are visiting (“first-party cookies”) or by other companies (“third-party cookies”). If you access our Website using a mobile device, the device ID or IP address may be recorded and used for purposes similar to those of cookies. For more information about cookies and how to manage them, please see our Cookie Policy.
PURPOSES AND BASIS FOR PROCESSING PERSONAL DATA
This section describes the purposes for which we use the Personal Data we collect about you or you provide to us, and the basis for processing Personal Data. Please note that there may be other uses, which we would describe to you when we collect the Personal Data.
To contract with you
We may use the Personal Data you provide us to help us fulfill a contract with you, when you use our Website or for other contractual purposes. We may also use this information to enforce our rights arising from such contracts.
Our legitimate business interests
We process your Personal Data to pursue our legitimate business interests, including to:
- understand you and your preferences to enhance your experience and enjoyment using our Website;
- operate, maintain, and improve the content, design and navigation of our Website;
- respond to comments and questions, provide requested services and information, and otherwise communicate with you;
- develop and deliver our products and services;
- fulfill any other purpose for which you provide Personal Data;
- comply with regulatory monitoring and reporting obligations;
- analyze and enhance our communications and strategies (including by identifying when emails sent to you have been received and read); and
- study Website traffic patterns, detect and correct technical errors, protect against, identify, investigate and respond to fraudulent, unauthorized, or illegal activity (such as incidents of hacking or misuse of our Website) and claims and other liabilities.
To the extent permitted by applicable law, we may combine the various types of data we collect. We may use aggregate and/or de-identified data about visitors to our Website for various business purposes, including development and improvement activities.
Where we process Personal Data on the basis of our legitimate interests, we will do so after a careful assessment which requires balancing your right to privacy and our legitimate interests.
Consent
We may use your Personal Data when we have your consent to do so, when required or permitted under applicable law. If we are using your Personal Data on the basis of consent, you may withdraw your consent at any time (which will not affect the lawfulness of the processing before consent was withdrawn, or as otherwise agreed in writing) by contacting us at [email protected].
Compliance with Legal Obligations
We reserve the right to use your Personal Data (i) as required by law, court order, legal process or government or regulatory requirement; (ii) to respond to a request from public or government authorities; or (iii) to protect the safety, rights, or property of the public or our company.
SHARING OF YOUR PERSONAL DATA
We may share Personal Data that we collect, or you provide as described in this Privacy Policy:
- with certain affiliates, partners, prospective partners, and service providers in order to provide us and/or our affiliates and partners with information about the use of the Website, our products and services and levels of engagement with the Website, and to allow us to enter into new business relationships;
- with service providers, including marketing partners, software and Web developers, commercial email providers, security consultants, and other vendors we engage so that they may provide services to us or on our behalf; and
- with a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets pursuant to the terms of the transaction, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by us is among the assets transferred.
Elion may also share Personal Data, with affiliated and non-affiliated third parties as follows:
- as necessary to provide you with information or materials you request;
- to respond to a subpoena or court order, judicial process or regulatory inquiry;
- when required by applicable law, including laws outside your country of residence;
- to protect or defend against fraud, lawsuits, claims or other liabilities;
- to protect the security of our systems, or to protect the rights or property of Elion, our business partners, or the public;
- to otherwise assist Elion in offering products and services;
- for any other purpose disclosed by us when you provide the Personal Data; and/or
- upon your request, or with your consent.
The Personal Data you provide may also be available to third-party application service providers that we have engaged to operate this Website.
We may also disclose aggregate or de-identified data that is not personally identifiable to third parties for any purpose.
INTERNATIONAL DATA TRANSFERS
Elion is headquartered in the United States (US) and any information that we collect will be transferred to our servers in the US. If you engage with us or access our Website from another country, you understand that your Personal Data will be transferred to the US. However, we will handle Personal Data in accordance with this Privacy Policy, and in compliance with applicable law. We have undertaken reasonable safeguards to require that your Personal Data will remain protected, and we require our third-party service providers to provide appropriate safeguards as well. To the extent you have questions or concerns with regard to your rights regarding our collection and processing of your Personal Data, please contact us at [email protected].
Where your Personal Data is protected by European or UK privacy laws, before transferring your Personal Data to third parties, we will require the third party to comply with privacy and security requirements to provide a level of protection equivalent to the level of protection we provide. We will only transfer your Personal Data to third parties in countries not recognized by the European Commission or the UK Information Commissioner’s Office as providing an adequate level of protection where there are appropriate safeguards in place, including for example Standard Contractual Clauses as approved by the European Commission with relevant adjustment for the UK.
SECURITY OF PERSONAL DATA
Elion takes steps intended to secure the Personal Data provided to us. For example, Personal Data you provide is accessible only by designated personnel. We employ reasonable physical, technical and organizational safeguards to promote the security of our systems and protect the confidentiality, integrity, availability and resilience of your Personal Data.
Please note, however, that no data transmission over the Internet can be guaranteed to be totally secure. While we use these measures to protect your Personal Data, we cannot guarantee that our safeguards will always be effective or sufficient. Additionally, please be aware that since Internet data submissions are not always secure, we cannot warrant that information you transmit utilizing the Website is or will be secure. Elion assumes no responsibility for interception of confidential information or Personal Data (including in a sign-up form) that you send in an unsecured (unencrypted) email message or other Internet transmission to and from this Website. Therefore, you should take special care in deciding what information you send to us via e-mail, in a website form or via other Internet transmission. DO NOT SEND INFORMATION RELATING TO YOUR MEDICAL CONDITIONS OR THOSE OF A FAMILY MEMBER OR ANY OTHER PERSONAL HEALTH INFORMATION VIA OUR WEBSITE.
RETENTION OF YOUR PERSONAL DATA
We retain Personal Data for as long as needed or permitted in light of the purpose(s) for which it was obtained and as described in this Privacy Policy. The criteria used to determine our retention periods include: (i) the length of time we have an ongoing relationship with you; (ii) whether there is an applicable legal obligation; and/or (iii) whether retention is advisable to enforce our agreements, satisfy applicable statutes of limitations, resolve disputes, or manage litigation or regulatory investigations.
EXTERNAL LINKS
In order to provide certain services and materials, our Website may allow you to “click” over to other websites. This Privacy Policy only applies to this Website and does not apply to any third-party sites. Elion is not responsible for the privacy practices or content of such other third-party sites, even if our name and logo appear on such websites. We recommend that you review the privacy policies on third-party sites to understand their privacy practices.
INFORMATION FROM CHILDREN UNDER AGE 18
Elion does not knowingly solicit or collect Personal Data from anyone under the age of 18. Visitors under the age of 18 should ask their parent or legal guardian for assistance when using this Website. We do not knowingly collect, maintain or process children’s Personal Data unless the child’s parent or guardian consents and provides the information. In the event we learn that we have collected Personal Data from a child under age 18 from a source other than the child’s consenting parent/guardian, we will delete that information.
YOUR PRIVACY RIGHTS
Where provided for under applicable data privacy laws, you may have certain rights to know about, access, update, correct, delete, port, and restrict processing of your Personal Data.
For security purposes, we will verify your identity when you request to exercise your data privacy rights. For certain types of requests, we may also need to ask you for additional information to verify your identity. Once we have verified your identity (or your authorized agent, as applicable), we will respond to your request as appropriate.
Your rights relating to your Personal Data depends on the data privacy law applicable to where you reside. You may have the following rights:
- Right of Access and Review: If you are a data subject about whom we store Personal Data, you may have a right to request access to such Personal Data.
- Right to Correct: This is called the right to rectification; in other words, the right to ask us to correct anything that you think is wrong with the Personal Data we have on file about you and to complete any incomplete Personal Data.
- Right to Delete: This is called the right to erasure, right to deletion or the “right to be forgotten”. This right means you can ask for your Personal Data to be deleted. Sometimes we can delete your information, but other times it may not be possible, such as when the law tells us we cannot do so. If that is the case, we will consider if we can limit how we use it. There may also be circumstances where we deny your request to delete your information under applicable law, such as if we or our service providers need to retain the Personal Data.
- Right to Ask Us to Change How We Process Your Personal Data. This is called the right to restrict processing. It is the right to ask us to only use or store your Personal Data for certain purposes. You may have this right in certain occasions, such as where you believe the data is inaccurate or the processing activity is unlawful. This right enables you to ask us to suspend the usage of Personal Data about you, for example if you want us to establish its accuracy or the reason for processing it.
- Right to Ask Us to Stop Using Your Personal Data. This is called the right to object. This is the right to tell us to stop using your Personal Data. You may have this right where we rely on a legitimate interest of ours (or of a third party). Also, you have the right to object at any time to the processing of your Personal Data for direct marketing purposes. We will stop processing the relevant Personal Data unless: (i) we have compelling legitimate grounds for the processing that override your interests, rights, or freedoms; or (ii) we need to continue processing your Personal Data to establish, exercise, or defend a legal claim.
- Right to Data Portability: This is the right to request/claim that your Personal Data be provided to you in a structured, commonly-used and machine-readable format and to transfer that data to another party e.g. service provider. This applies to Personal Data for which processing is based on your consent and the processing carried out by automated means. Where feasible and applicable, you may request/claim that the Personal Data be transferred directly from our systems to those of another provider.
- Right to Withdraw Consent: This is the right to withdraw consent to processing your Personal Data. Withdrawing consent does not affect the lawfulness of processing based on consent prior to the withdrawal.
- Right to Lodge a Complaint with a Supervisory Authority: If the EU or UK General Data Protection Regulation (GDPR) applies to our processing of your Personal Data, you have the right to lodge a complaint with a supervisory authority in the Member State of your habitual residence, place of work, or of the alleged infringement of the GDPR. A list of the European Union data protection regulatory authorities can be accessed here: https://edpb.europa.eu/about-edpb/board/members_en. In the UK, you can lodge a complaint with the UK Information Commissioner’s Office, which can be reached via the following link: https://ico.org.uk. The Swiss data protection authority can be reached at: https://www.edoeb.admin.ch/edoeb/en/home.html.
If you wish to exercise these data privacy rights, or if you have questions or concerns about how we use your Personal Data, please contact us at [email protected] or any of the contact methods provided below and we will make efforts to respond to your questions and/or resolve any issues consistent with applicable law.
CONTACT US
If you have any questions about this Privacy Policy or our processing of your Personal Data, please contact us as follows:
Elion Therapeutics, Inc.
Attn: Privacy
1 Lincoln Street
Suite 30-120
Boston, MA, 02111, USA
Telephone Number: 443-423-1785
Email address: [email protected]
Data Protection Officer
We have appointed VeraSafe as our Data Protection Officer (DPO). While you may contact us directly, VeraSafe can also be contacted on matters related to the processing of Personal Data. VeraSafe’s contact details are:
VeraSafe
100 M Street S.E., Suite 600
Washington, D.C. 20003 USA
+1 (617) 398-7067
[email protected]
Web: https://www.verasafe.com/about-verasafe/contact-us/
Toll-free: 1-888-376-1079
Our Data Protection Representative for purposes of compliance with European Privacy Law is VeraSafe. If you want to raise a question or concern relating to data privacy with Elion, or otherwise exercise your rights with respect to your Personal Data, you may contact them as follows:
EU Data Protection Representative
VeraSafe
Plaza de la Solidaridad 12, Floor 5
29006 Malaga
Spain
Phone: +420 228 881 031
Email: [email protected]
Contact form: www.verasafe.com/privacy-services/contact-article-27-representative
UK Data Protection Representative
VeraSafe United Kingdom Ltd.
Address: 37 Albert Embankment
London SE1 7TL
United Kingdom
Phone: +44 (20) 4532 2003
Email: [email protected]
Contact form: www.verasafe.com/privacy-services/contact-article-27-representative
MODIFICATIONS AND UPDATES
This Privacy Policy replaces all previous disclosures we may have provided to you about our Personal Data processing. Unless stated otherwise, our current Privacy Policy applies to all Personal Data that we have about you. We reserve the right, at any time, to modify, alter, and/or update this Privacy Policy without advance notice, and any such modifications, alterations, or updates will be effective upon our posting of the revised Privacy Policy. When we post a revised version of this Privacy Policy, we will update the effective date at the top of this webpage.