Paradigm Biopharmaceuticals Ltd. is committed to protecting the privacy of all persons with whom it communicates whether through its site or otherwise.

This statement sets out our policies on managing personal information including health information and ensuring the privacy of that information.

PURPOSE

Paradigm Biopharmaceuticals Limited (ASX: PAR) is an ASX-listed Australian biotechnology company. We may collect and hold personal information necessary for us to carry out our business. We are committed to safeguarding the privacy of the personal information that we gather. You understand and agree that we collect, use and disclose your personal information in accordance with this policy (the “Policy”).

This Policy prescribes the principles by which we protect your personal information.

SCOPE

This Policy applies to personal information regarding patients, healthcare professionals, potential future customers, other third party business associates, employees and others and to the management of that personal information.
POLICY

1.1 TYPES OF INFORMATION

The term “personal information” under this Policy refers to information about an identifiable individual. The types of personal information that we may process and which may vary depending on your relationship with us as well as by jurisdiction based on applicable law, may include contact information (such as name, postal or e-mail address, and phone number), or other information (such as language preference, date of birth, gender and family status).

Paradigm may collect personal information directly from individuals when necessary to provide our services and conduct our business, including as part of responding to queries from individuals or health professionals, our recruitment processes, ongoing employment activities, conducting clinical trials, conducting IR activities, and receiving medical enquiries.

There may be instances in which the personal information that we collect, use, and process is considered “sensitive personal information” under the privacy laws of some countries. The definition of “sensitive personal information” under these privacy laws may, for instance, include personal information such as your medical condition or symptoms.

We collect, use, and process “sensitive personal information” only to the extent permitted or required by applicable law.
Where you prefer that we do not collect your personal information, we may not be able to assist you or provide services or undertake activities that we would otherwise provide or undertake.

Where reasonably possible, we seek to work with information and records from which personal information has been removed.

1.2 USE OF PERSONAL INFORMATION

Paradigm Biopharmaceuticals currently uses personal information only to the extent necessary for our activities and business, and in our efforts to expand and improve our business including to respond to enquiries from members of the public, employees and investors. Subject to applicable laws, we may collect, use, process and disclose relevant portions of your personal information in order to

• administer, operate, facilitate and manage your relationship with Paradigm. This may include sharing such information internally as well as disclosing it to third parties, as described in Section 1.3;
• provide you with information or contact you by post, telephone, email etc. in connection with your relationship;
• facilitate our internal business operations, including fulfilling our legal and regulatory requirements.

1.3 DISCLOSURE OF PERSONAL INFORMATION

In order to best handle your enquiries, more than one entity within Paradigm Biopharmaceuticals may be given, or given access to, your personal information. When we share your personal information, we adhere to applicable legal requirements regarding the protection of personal information.

We may outsource the processing of certain functions and/or information to third parties (including, but not limited to, mail-out companies, agencies engaged to organize conferences and database managers who maintain and update contract information and who may contact you independently to verify that information or your contact preferences).

When we contract with other companies to provide services to Paradigm and then provide or allow access to personal information to such third party service providers for that purpose, we take steps to ensure that personal information is treated in the same way that we would treat it and we require those companies to protect the information and adhere to applicable data privacy standards. We do our best to keep records of personal information up to date and accurate and not to keep personal information that is no longer needed.

We reserve the right to disclose any personal information if we are compelled to do so by a court of law or requested to do so by governmental authorities or if we determine it is necessary or desirable to comply with the law or to protect or defend our rights or property in accordance with applicable laws. We also reserve the right to retain personal information collected and to process such personal information to comply with applicable regulations and any specific record retention laws.

Circumstances may arise where, whether for strategic or other business reasons, Paradigm decides to sell, buy, merge or otherwise reorganize businesses. Such a transaction may involve the disclosure of personal information to prospective or actual purchasers, or the receipt of it from sellers.

1.4 INTERNATIONAL DATA PROCESSING

Like most international businesses, certain aspects of our data processing activities will result in the transfer of your personal information from one country to another. The jurisdictions where that information will be processed may or may not have laws that seek to preserve the privacy of personal information. Nevertheless, whenever your personal information is transferred within Paradigm, your personal information will be processed in accordance with the terms and conditions of this Policy and all applicable laws.

1.5 CHOICE

You may always choose what personal information (if any) you wish to provide to us. If you provide us with your contact details (e.g., postal or email address, telephone number or fax number), we may contact you in order to resolve your enquiry or provide further information.

In some jurisdictions, data privacy laws may require us to obtain your consent before we, for instance, send you information that you have not specifically requested. In certain circumstances, your consent may be implied (e.g., where communications are required in order to fulfil your requests and/or where you have volunteered information for use by us). In other cases, we may seek your consent expressly in accordance with applicable laws (e.g., where the information collected is regarded to be of a sensitive nature under local regulations).

1.6 OTHER APPLICABLE TERMS; CHANGES TO THIS POLICY

This Policy provides a general statement of the ways in which Paradigm protects your personal information. This Policy does not modify or alter any applicable agreement you have or may have with Paradigm. This Policy may be changed from time to time to reflect changes in our practices concerning the collection and use of personal information. To assist you, this Policy has an effective date.