Legal
Privacy Policy
Last updated: April 9, 2026
This Privacy Policy explains how BioThera Solutions Inc. ("BioThera Solutions", "we", "us", "our") collects, uses, discloses, and protects your personal information when you use our website, purchase our Products, or otherwise interact with us (collectively, the "Services"). By using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, you must discontinue use of the Services.
1. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. We will post the updated policy on our website with a revised "Last updated" date. Where required by law, we will provide additional notice of material changes. Your continued use of the Services after an update constitutes your acceptance of the revised Privacy Policy.
2. Personal Information We Collect
We collect personal information that you provide directly, information collected automatically through your use of the Services, and information from third-party sources.
Information you provide directly may include: name and contact details; billing and shipping address; order details and purchase history; payment information (processed by third-party processors); account credentials (such as email and password); communications with us, including customer support inquiries; and reviews, testimonials, and other user-generated content.
If you submit an inquiry through our Contact page, we collect: your first and last name; email address; the reason for contact (selected from a predefined category: General Inquiry, Partnership & Collaboration, Product & Clinical Interest, Media & Press, or Investor Relations); and the content of your message. This information is collected with your explicit consent and is used solely to respond to your inquiry and route it to the appropriate team.
If you submit an expression of interest through our Careers page, we additionally collect: your first and last name; email address; telephone number (optional); LinkedIn profile URL; area of interest or desired role; and a short personal statement about your interest in joining BioThera Solutions. This information is collected with your explicit consent and is used solely for recruitment and talent evaluation purposes.
If you join our product waitlist or submit a Certificate of Analysis (CoA) request, we collect: your first and last name; email address; professional role; clinic type; and geographic information (country, province/state, city). This information is used to manage our pre-launch pipeline and fulfill CoA requests.
Information collected automatically may include: IP address and approximate location; device identifiers, browser type, and operating system; pages visited, links clicked, and other usage information; and information collected through cookies, pixels, and similar technologies.
Information from third parties may include: payment processors, for payment confirmation and fraud prevention; shipping and logistics providers, for delivery and tracking; and analytics and marketing partners, to help us understand site usage and improve our Services.
3. How We Use Your Personal Information
We use personal information for the following purposes: processing and fulfilling your orders and transactions; managing your account and providing customer support; shipping Products and handling returns and refunds; communicating with you about your orders, account, and the Services; providing, operating, maintaining, and improving our website and Services; personalizing your experience and tailoring content and offers; evaluating expressions of interest submitted through our Careers page and contacting suitable candidates; conducting analytics, research, and business operations; detecting and preventing fraud, security incidents, and misuse; complying with legal and regulatory obligations; and sending marketing communications where we have your consent or a lawful basis.
We process personal information only for purposes that a reasonable person would consider appropriate in the circumstances and as permitted by applicable privacy laws.
4. Cookies and Similar Technologies
We use cookies and similar technologies to: enable core site functionality; remember your preferences and settings; understand how visitors use our site through analytics; improve performance and user experience; and support marketing and advertising activities, where applicable.
Analytics cookies — Google Analytics 4: We use Google Analytics 4 (Google LLC, United States) to understand how visitors navigate and use our website. Google Analytics may collect data such as pages visited, session duration, device type, browser, and approximate location derived from IP address. We have implemented Google Consent Mode v2: Google Analytics is blocked from collecting or processing any personal data unless and until you explicitly grant analytics consent through our cookie consent banner. You can change or withdraw your consent at any time via the "Cookie Settings" link in our footer.
Bot protection — Google reCAPTCHA Enterprise: We use Google reCAPTCHA Enterprise (Google LLC, United States) on all website forms to protect against automated abuse, spam, and fraudulent submissions. reCAPTCHA analyzes hardware and software information, including device and application data, and sends it to Google for risk assessment. This processing is based on our legitimate interest in protecting the integrity of our Services. The reCAPTCHA assessment runs invisibly in the background and does not require any action from users. For more information, see Google's Privacy Policy at policies.google.com/privacy.
Necessary cookies: Certain cookies are strictly necessary for the website to function and cannot be disabled. These include session identifiers, security tokens, and language preference storage. No consent is required for strictly necessary cookies.
You can manage all non-essential cookie preferences at any time through the Cookie Settings link in our website footer, or by configuring your browser settings. Disabling certain cookies may affect site functionality.
5. How We Share Personal Information
We may share personal information with: service providers and partners who assist in operating our business, including payment processors, hosting providers, analytics services, marketing services, and shipping companies; professional advisers, such as lawyers, accountants, and auditors, where necessary; government authorities or law enforcement, where required by law or to protect our legal rights; and another organization in connection with a corporate transaction such as a merger, acquisition, or sale of assets.
Key third-party service providers we currently use include: Brevo (Sendinblue SAS, France) — our email delivery and contact relationship management platform, which stores and processes personal information submitted through website forms including name, email address, and form-specific fields under a Data Processing Agreement; Google LLC (United States) — for Google Analytics 4 (website analytics, subject to your consent) and Google reCAPTCHA Enterprise (bot protection, based on legitimate interest); and Vercel Inc. (United States) — our website hosting provider, which processes request data including IP addresses in the course of delivering the Services.
Service providers are given access to personal information only as needed to perform their functions and are required to protect the information and handle it in accordance with applicable privacy laws.
We do not sell or rent your personal information to third parties.
6. International Transfers
Your personal information may be transferred to and processed in jurisdictions outside your province or country of residence, including other provinces in Canada and countries where our service providers are located. These jurisdictions may have different data protection laws than your home jurisdiction.
Where personal information is transferred to the United States — for example, through our use of Google Analytics 4 (Google LLC) — we rely on applicable transfer mechanisms, including Standard Contractual Clauses (SCCs) approved by the European Commission, Google's Data Processing Terms under the EU General Data Protection Regulation (GDPR), and other appropriate contractual safeguards.
When transferring personal information to any third party, we take steps to ensure that appropriate safeguards are in place in accordance with applicable privacy laws.
7. Children and Minors
Our Services are not intended for minors under the age of 18. We do not knowingly collect personal information from children under 18.
8. Security
We use reasonable physical, technical, and administrative safeguards designed to protect personal information from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction.
However, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee the absolute security of your personal information.
9. Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, to meet legal and regulatory requirements, and to resolve disputes.
We typically retain order and transaction records for at least the period required by tax and accounting laws. We retain marketing preferences until you withdraw your consent or until we determine that the information is no longer needed.
Contact form inquiry data submitted through our Contact page is retained for as long as necessary to respond to and follow up on your inquiry, and for a minimum of 12 months thereafter. After this period, data is reviewed and securely deleted if no longer needed.
Waitlist and CoA request data is retained for the duration of our pre-launch and commercial pipeline, and for a minimum of 24 months from submission. After this period, data is reviewed and either retained where a legitimate interest continues to exist, or securely deleted.
Career application data submitted through our Careers page is retained for a minimum of 24 months from the date of submission, in accordance with industry standards for recruitment. After this period, data is reviewed and either retained where a legitimate interest continues to exist, or securely deleted.
When personal information is no longer required, we will securely delete, anonymize, or otherwise dispose of it in accordance with our policies and applicable law.
10. Your Rights
Subject to applicable law, you may have the right to: request access to the personal information we hold about you; request correction of inaccurate or incomplete personal information; request deletion of your personal information, in certain circumstances; request restriction of processing in certain circumstances; withdraw consent to processing where we rely on your consent; object to certain types of processing, including direct marketing; and request information about how your personal information has been used and disclosed.
To exercise these rights, please contact us using the contact information below. We may need to verify your identity before responding to your request.
We will not discriminate against you for exercising your privacy rights.
11. Commercial Electronic Messages (CASL)
We comply with Canada's Anti-Spam Legislation (CASL).
We send marketing and promotional emails only where we have your express or implied consent.
You can withdraw your consent to receive marketing emails at any time by clicking the unsubscribe link in any marketing email, or by contacting us at the email address provided below.
Even if you opt out of marketing messages, we may still send transactional or service-related communications relating to your orders, account, or our ongoing business relationship, as permitted by law.
12. Residents Outside Canada
If you access the Services from outside Canada, you acknowledge that your personal information may be transferred to and processed in Canada and other jurisdictions where our service providers operate.
European Economic Area (EEA) and United Kingdom: If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR, including: the right to lodge a complaint with your local data protection supervisory authority; the right to data portability; and the right not to be subject to solely automated decision-making. The lawful basis for processing your personal information is: consent (for analytics cookies and marketing communications); performance of a contract (for order fulfillment and customer support); and legitimate interests (for security, fraud prevention, and improving our Services).
California (USA): If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including: the right to know what personal information we collect, use, and disclose; the right to request deletion of your personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (we do not sell or share your personal information for advertising purposes); and the right to non-discrimination for exercising your privacy rights.
To exercise any of these rights, please use our contact page at biotherasolutions.com/contact. We will respond in accordance with applicable law.
13. Changes to This Policy
You can review the most current version of this Privacy Policy at any time on this page. We reserve the right, at our sole discretion and subject to applicable law, to update, change, or replace any part of this Policy by posting updates and changes to our website. Where required by law, or where changes are material, we will provide you with reasonable advance notice. Your continued use of the website or Services following the posting of any changes constitutes acceptance of those changes.
14. Governing Language
This Privacy Policy is made available in multiple languages for accessibility. In the event of any inconsistency or conflict between the English version and any translation, the English version shall govern and take precedence.
15. Contacting Us and Complaints
If you have questions about this Privacy Policy, our data practices, or wish to exercise any of your privacy rights, please reach out through our contact page at biotherasolutions.com/contact.
BioThera Solutions Inc., Ottawa, Ontario, Canada.
If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
Questions? Contact us here.