
Last Revised on August 1, 2024
Corcept Therapeutics Incorporated and its subsidiaries and affiliates (together, “Corcept,” “we”, “our”, “us”) are committed to protecting and respecting your privacy. The purpose of this Privacy Notice is to provide you with information on how we will collect, use, disclose, protect, and otherwise process personal information and explain the rights and choices available to individuals with respect to their personal information. We are a public company established in the United States (the “US”) with a registered office at 101 Redwood Shores Parkway, Redwood City, CA 94065, and, for the purposes of the General Data Protection Regulation (the “GDPR”) and the United Kingdom’s Data Protection Act 2018 (including the UK General Data Protection Regulation (“UK GDPR”)), we are the data controller.
This Privacy Notice sets out the basis on which we will process personal information or usage information we collect from you, or that you provide to us, in connection with your use of the following Corcept websites and related services or relationships described herein:
(together, the “Sites” and each a “Site”).
We may provide additional privacy notices to different categories of individuals at the time we collect their data, including as follows:
Please read this notice carefully so that you understand your rights in relation to your personal information, and how we will collect, use and process your personal information. If there is any conflict between this notice and a separate, more specific privacy notice provided to you by Corcept, you should rely on the more specific notice to determine your rights and how your data will be used and processed.
We do not “sell” your personal information in the traditional sense of the word “sale.” We may, however, share certain information about you with contracted third-parties to provide better services and advertising to you. You may opt out of sharing this information, by contacting us via the “How to Contact Us” section below.
Please note that if you consented to receiving text messages from us (e.g., as part of our Patient Advocate Support program), your telephone number will not be shared with third-parties for marketing purposes.
If you do not agree with this Privacy Notice in general or any part of it, you should not access the Sites.
INFORMATION WE COLLECT
Information you give us, or we collect about you.
We may obtain some or all the following information when you contact us via our Sites or email, telephone, or otherwise through your interaction with us or use of our Sites or where your information is made publicly available through other means;
Job applicants. Additionally, if you apply for a job via our Corcept.com Site, you may also provide us with the following information:
This includes information provided in resumes, emails, and cover letters we receive electronically or are uploaded directly to the Site by you.
Technical Usage Information. When you visit the Sites, we collect the information sent to us by your computer, mobile phone, or other access device. This information includes:
The above personal information is processed based on Concept’s legitimate business interest in providing our services to you and enhancing provision of such services. Where you provide health or ethnicity information to Corcept, such information is processed based on your explicit consent, which we will ask you to provide before providing any health or ethnicity information to us.
HOW WE USE INFORMATION ABOUT YOU
In order to be responsive to you and to maintain our relationship, as a matter of our legitimate interests, we may use your information to:
In addition, we will use some or all the information described in this notice to comply with any applicable legal obligations.
Technical Usage Information: we use technical usage information about you to:
Special Category/Sensitive Data: With your explicit consent, we will use your health-related information described in this Privacy Notice to:
HOW AND WHERE WE STORE, SHARE AND TRANSFER YOUR PERSONAL INFORMATION
Please note that the information that we collect from you may be stored/processed in the US. We will take all steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this notice. We may share your information with the following categories of recipients:
To the extent you are located in the EEA / UK, and your personal information is transferred to the above recipients in the US or to any other country not deemed to provide an adequate level of protection by the European Commission or UK government, such information will be transferred pursuant to the European Commission’s model contracts for the transfer of personal information to third-countries (i.e., the standard contractual clauses). Please contact us at corcept.dpo@mydata-trust.info if you wish to examine the data transfer safeguards entered by us.
We will share your information with law enforcement agencies, public authorities or other organizations if legally required to do so, or if we have a good faith belief that such use is reasonably necessary to:
We will also disclose your information to third-parties:
In the event any of the above situations apply, the buyer of our business or assets will be subject to the terms and conditions of this notice.
We may also provide third-parties with statistical information about our users (but those third-parties will not be able to identify any individual user from that information).
We will retain your information as follows:
We will also retain and use your information in identifiable form to the extent necessary to comply with our legal obligations, resolve disputes and enforce our terms and conditions, other applicable terms of service, and our policies. Following this period, we will store your information in an aggregated and anonymised format; we may use this information indefinitely without further notice to you.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third-parties.
APPLICABLE REGULATIONS
We collect and use your personal information in compliance with applicable privacy and data protection regulations, including the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”)), the Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications, “ePrivacy”), The California Consumer Privacy Act (“CCPA”), The Californian Online Privacy Protection Act (“COPPA”) and any applicable law.
CCPA NOTICE FOR CALIFORNIA RESIDENTS
The California Consumer Privacy Act (“CCPA”) regulates how businesses handle “personal information” (as such term is defined in the CCPA) of California residents and gives California residents certain rights with respect to their personal information. If you are a resident of California, we are required to inform you of how we use and disclose your personal information and certain rights you may have under the CCPA.
In the chart below, we have described the categories of personal information that we have collected and shared over the past twelve (12) months, the purposes for such collection and the types of entities with whom we have shared such information.
| CATEGORY OF PERSONAL INFORMATION | SOURCES OF INFORMATION | PURPOSE OF COLLECTION | WHOM WE SHARE PERSONAL INFORMATION WITH |
|---|---|---|---|
| Identifiers / Categories of Personal Information described in Cal. Civil Code § 1798.80(e), such as your name, username, email address, IP address, health-related information. | We collect this information directly from you. | We collect this information to communicate with you, provide, personalize and improve the Sites, and to perform other business purposes. | Certain professional service providers that help us provide the Sites and services. |
| Internet or other electronic network activity information, such as cookies, web logs, IP address, and information about how you use our Sites. | We collect this information from your computer or your device. | We collect this information to personalize and improve the Sites and to perform other business purposes. | Advertising networks, internet service providers, professional services providers (incl. data analytics providers), operating systems and platforms, social networks. |
| Professional or employment-related information, such as your company name and address and any information that you provide in your job application you provide to us. | We collect this information directly from you as well as from third-party sources, such as recruiters and employment websites; and from publicly available sources, like government records, or from information you have made public, including by posting or publishing it online. | To consider you for employment and otherwise provide employee-related services. | Service providers and government agencies. |
| Sensitive personal information under California or federal law (e.g., race, religion, sexual orientation, gender identity, gender expression, health, citizenship, etc.). | Directly from you and from third-parties, including those to whom you have previously provided data. | For our everyday business purposes such as to process your requests, inquiries, or other communications with us.To conduct research related to our current or prospective products or services.
To respond to law enforcement requests as required by applicable law, court order, or government regulation. |
Service providers and government agencies. |
| Education information, such as your college records. | We collect this information directly from you as well as from third-party sources, such as recruiters and employment websites. | To consider your application for employment. | Service providers and government agencies. |
| Inferences drawn from any of the information identified above, such as your preferences, interests, and other information used to personalize your experience. | This information is derived from the categories above. | We collect this information to personalize and improve the Sites and to perform other business purposes. | Service providers |
You can turn off tracking and sharing of your personal information in the Cookie Notice section below.
MHMDA NOTICE FOR WASHINGTON RESIDENTS
If you are a resident of Washington, please read this notice carefully. It explains Corcept’s collection, use and sharing of Consumer Health Data as that term is used in the Washington My Health My Data Act (“Washington Health Act”), as well as the rights you may have.
Consumer Health Data We Collect
The types of Consumer Health Data that we may collect include:
Sources of Consumer Health Data
We may collect Consumer Health Data about you:
How We Use Consumer Health Data About You
We may use Consumer Health Data about you to manage our Corcept Patient Programs and for the purposes listed under the “How We Use Information About You” tab in our Privacy Notice.
How We Share Consumer Health Data About You
We may share the categories of Consumer Health Data with service providers and third parties as described above and as listed under the “How and Where We Store, Share and Transfer Your Personal Information” tab in our Privacy Notice.
How to Exercise Your Rights
Depending on where you reside, you may have certain rights under the Washington Health Act, such as:
To exercise the rights described above, please submit a verifiable consumer request to us by:
The Washington Health Act also allows you to contact the Washington State Attorney General if you are not satisfied with the outcome of a rights request made to us – visit www.atg.wa.gov/ for contact information.
SOCIAL FEATURES
Certain features of the Sites permit you to initiate interactions between the Site and third-party services or platforms, such as social networks (“Social Features”). Social Features include features that allow you to click and access Corcept’s pages on certain third-party platforms, such as Facebook and Twitter, and from there to “like” or “share” our content on those platforms. Use of Social Features may entail a third-party’s collection and/or use of your data. If you use Social Features or similar third-party services, information you post or otherwise make accessible may be publicly displayed by the third-party service you are using. Both Corcept and the third-party may have access to information about you and your use of both the Site and the third-party service. See below for more information on third-party websites and links.
THIRD-PARTY WEBSITES AND LINKS
Our Site may contain links to other online platforms operated by third-parties. We do not control such other online platforms and are not responsible for their content, their privacy policies, or their use of your information. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms (such as Facebook or Twitter) may also be viewable by other users of the Site and/or users of those third-party online platforms without limitation as to its use by us or by a third-party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators except as disclosed on the Site. We expressly disclaim any and all liability for the actions of third-parties, including but without limitation to actions relating to the use and/or disclosure of personal information by third-parties. Any information submitted by you directly to these third-parties is subject to that third-party’s privacy policy.
THE SECURITY OF YOUR PERSONAL INFORMATION
Unfortunately, the transmission of information via the internet or email is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your information transmitted through the Sites or over email; any transmission is at your own risk. Once we have received your information, we will take appropriate technical and organizational measures to safeguard your personal information against loss, theft and unauthorized use, access or modification.
YOUR RIGHTS AND HOW TO CONTACT US
Depending on which Data Protection Laws are applicable to you, you may have rights in relation to the personal information we hold about you. Below is an outline of those rights and how to exercise them. Please note that we will require you to verify your identity before responding to any requests to exercise your rights. Please also note that these rights are not absolute and will be assessed on a case-by-case basis by Corcept’s Data Protection Officer. In case of denial of a request, we will let you know the reasons for such denial.
If you would like to exercise your rights, please let us know by:
You also have the right to lodge a complaint with the respective authorities of your place of residence if you consider that your personal information is not processed in accordance with Data Protection Laws.
CHILDREN
We do not knowingly collect or solicit personal information from anyone under the age of 18. If we learn that we have collected personal information from a child under age 18, we will delete that information. If you believe that we might have any such information from or about a child under 18, please contact us at dataprotectionofficer@corcept.com.
CHANGES
Any changes we will make to this Notice in the future will be posted on this page. Please check back frequently to see any updates or changes to this Notice.
COOKIE NOTICE
COOKIES AND OTHER TRACKING TECHNOLOGIES
We and certain third-parties, use cookies and other technologies (“Tracking Technologies”) to collect personal data and to store information or gain access to information stored on your device, when you use our Sites. This notice tells you more about Tracking Technologies and how we use them in our Sites. When you enter our Sites, you can accept our cookies, or you can manage your cookie preferences through your browser settings. In some cases, when you disable certain cookies, some functions of the Sites may not work.
WHAT ARE TRACKING TECHNOLOGIES?
Tracking Technologies can remain on your device for different periods of time. Some Tracking Technologies exist only while your browser is open. These are deleted automatically once you close your browser. Other Tracking Technologies are “permanent”, meaning that they survive after your browser is closed. They can be used to recognise your device when you open your browser and browse the internet again.
HOW DO WE USE TRACKING TECHNOLOGIES?
We use first-party and third-party Tracking Technologies. First-party Tracking Technologies are set directly by us whereas third-party Tracking Technologies are set by a third-party (such as analytics providers, our advertisers and business partners).
We use Tracking Technologies that perform the following functions: