Healthcare Professional Privacy Notice
Last Updated: February 27, 2026
This Healthcare Professional (“HCP”) Privacy Notice sets forth the practices of Viridian Therapeutics, Inc. (“Viridian”, “we”, or “us”) regarding the collection, use, disclosure and other processing of information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a natural person or household, such as a name, postal address, e-mail address, telephone number (“Personal Information”), that you may provide or we may otherwise collect and process when you visit the Viridian website, www.viridiantherapeutics.com (the “Website”) or any other online service that links to this Privacy Notice, and interact with us offline. For purposes of European Economic Area (“EEA”) and United Kingdom (“UK”) data protection laws, we are the controller of Personal Information processed in the context of this Privacy Notice.
Please note that Personal Information does not include aggregated information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual. Viridian may create anonymized or aggregated data and use it for legitimate purposes (e.g. to improve products or research), ensuring it contains no identifiable information.
This Privacy Notice will not apply to Personal Information collected and processed by us:
- if you are an individual other than an HCP or an individual participating in a Viridian clinical study (e.g., study coordinator, research assistant, administrative staff);
- should you apply for a job with us; or
- in the course of your employment with us.
By accessing the Website, you agree to our Terms of Use, including the collection and use of your Personal Information as described in this Privacy Notice.
Notice at Collection: Personal Information we Collect
We may collect the following categories of Personal Information:
- Personal identifiers: name, address, telephone number, email address, and (electronic) signatures.
- Financial and reimbursement information: payment and account details (e.g., bank account information), insurance information (e.g., health insurer and policy number), and other financial information needed for reimbursement or compensation.
- Professional and employment-related information: name of your practice, professional designation, medical specialty, licensing and disbarment status (such as NPI), publications and information about public speeches, and additional Personal Information you provide in your curriculum vitae or other similar documents or communications.
- Education information: academic background and credentials.
- Clinical trial related information: information relating to your clinical trial involvement, such as quality / adverse event reports, clinical trial reports and previous clinical trial experience.
- Internet and other electronic activity information: your browser type, operating system, domain names visited, click activity, referring websites, the date and time and length of visit of your visit to our Website or other websites or mobile applications
- Publicly available information: such as content you post on public forums or social media, photographs, or other information about you available from public websites or public records.
- Audio and visual information: audio recordings (e.g., calls or interviews, voicemail messages), and photographs or video footage (e.g., at our events or on our premises, including security camera images).
We have collected the same categories of Personal Information in the 12 months prior to the date of this Privacy Notice.
Notice at Collection: Purposes for Collection of Personal Information / How We Use Your Personal Information
Set out below is a description of how we use your Personal Information (“Processing Purposes”), and, for individuals located in the EEA or the UK, the legal bases we rely on for each processing activity.
| Categories of Personal Information | Processing Purposes | Legal Basis (where you are in the EEA or the UK) |
|---|---|---|
| Where you register to attend and/or attend a sponsored event (e.g. medical conference, educational meeting, or similar event organized by Viridian): | ||
| Personal identifiers; Audio and visual information | Organizing and running the event, including registering you, providing event materials, and communicating with you about logistics or inquiries. (Note: Calls or virtual sessions may be recorded for training and quality purposes). | Where we have a legitimate interest to manage the event effectively and ensure you have all necessary information. |
| Personal identifiers; Audio and visual information | Creating and sharing event recordings or content (for example, distributing a recording of a conference talk or broadcasting a webinar session to a wider audience). | Where we have a legitimate interest to promote the event, to leverage the learnings from the event e.g., to educate others, and to more generally operate and improve our business. Where local law requires consent to record or use your image/voice for certain purposes, we will obtain consent. |
| Personal identifiers | Inviting you to events and sending relevant updates about our products or programs (only where permitted). You can opt out of these communications at any time. | If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent. In other instances, we will send marketing communications to you where we have a legitimate interest (i.e., keeping you informed about related events as part of our professional relationship). |
| Personal identifiers | Maintaining your contact details for future outreach, such as retaining your information in our HCP database to consider you for other events or opportunities that align with your interests and expertise. | Where we have a legitimate interest to manage our business and the conduct of future events / engagements. |
| All categories of Personal Information | Complying with legal and regulatory obligations related to the event, such as processing any payments or travel reimbursements to you and reporting transfers of value as required by law and industry trade associations. This includes fulfilling transparency reporting laws (e.g., U.S. Physician Payment Sunshine Act disclosures of physician payments) and other financial/ethical obligations. | To comply with a legal obligation (e.g., public transparency reports, financial record-keeping). Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
| Where you enter into a fee-for service, consultancy, ad board or other agreement with us: | ||
| Personal identifiers; Professional and employment information; Audio and visual information | Conducting a meeting at which you attend and participate, including inviting you, providing materials, facilitating discussions, and handling related communications or inquiries. (Calls/virtual meetings may be recorded to accurately capture input.) | Where we have a legitimate interest to ensure the effective administration and conduct of the meeting and accurately capture your valuable insights. |
| Personal identifiers; Audio and visual information | Utilizing meeting discussion recordings or outputs, for example to create internal summaries, training materials, or to inform our research and development strategies, or otherwise to share with attendees. | Where we have a legitimate interest to leverage knowledge gained from the meeting to improve our business and products or to educate others, to promote the event, and to more generally operate and improve our business. Where local law requires consent to record or use your image/voice for certain purposes, we will obtain consent. |
| Personal identifiers; Professional and employment information | Considering you for future advisory roles, by retaining your expertise profile in our HCP database. We may reach out about future expert engagements that match your specialty. | Where we have a legitimate interest to manage our business and the conduct of future advisory boards / collaborations / meetings etc. |
| All categories of Personal Information | Meeting legal and ethical obligations related to the meeting, such as safety reporting (if, for example, an adverse event is discussed), and financial transparency for any honoraria or expenses paid to you. | To comply with a legal obligation (e.g., safety data reporting obligations). Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States) for which there is no mandatory legal obligation. |
| Personal identifiers; Professional and employment information; Audio and visual information | Event management and communication: Use of your contact and professional info to organize the speaking engagement, ensure you have details, and answer questions. | Where we have a legitimate interest to ensure the effective administration and conduct of the relevant event. |
| Personal identifiers; Financial and reimbursement information; Professional and employment information | Honoring the speaker agreement: Use of your Personal Information to pay your honorarium and reimburse expenses, and to fulfill the speaker contract terms. | Where necessary for performance of a contract. |
| Personal identifiers; Professional and employment information | Future opportunities: Retaining your information to invite you for future speaking events if suitable. | Where we have a legitimate interest to manage our business and the conduct of future events. |
| All categories of Personal Information | Compliance reporting: Reporting your compensation as required by law (e.g. including it in transparency reports) or industry trade associations. | To comply with a legal obligation (e.g., public transparency reports, financial record-keeping). Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
| When you participate in or oversee a Viridian-sponsored clinical trial (i.e., as a clinical trial investigator or site staff, or member of an oversight entity): | ||
| Personal identifiers; Professional and employment information | Qualifications and onboarding: Using your identifiers and professional credentials to verify you are qualified (license check, training) and to fulfill any legal requirements for investigators. | To comply with a legal obligation (e.g. under clinical trials laws). Where we have a legitimate interest to ensure the effective administration and conduct of the clinical trial (e.g., with reference to conducting background checks to ensure trial integrity). |
| Personal identifiers; Professional and employment information; Clinical trial related information | Trial administration: Processing your information to set up and manage the trial – including site feasibility assessments, trial management, monitoring, data storage (in trial databases and records), and archiving of trial records. | Where we have a legitimate interest to ensure the efficient / effective administration and conduct of the clinical trial and to comply with our legal and regulatory obligations outside of the EEA/UK. To comply with a legal obligation (e.g., under the clinical trial laws). |
| Personal identifiers | Ongoing communication: Using your contact information to communicate with you throughout the clinical trial (updates, meetings, instructions). | Where we have a legitimate interest to ensure the effective administration and conduct of the clinical trial. |
| Personal identifiers; Clinical trial related information | Regulatory compliance: Processing of personal data necessary for safety reporting (pharmacovigilance), quality reporting, anti-corruption compliance (tracking any payments or benefits in the trial context), and responding to lawful requests or audits by authorities. | To comply with a legal obligation (e.g., under the clinical trial laws). Where we have a legitimate interest to ensure the effective administration and conduct of the clinical trial and to comply with our legal obligations outside of the EEA/UK. |
| Personal identifiers; Clinical trial related information | Public transparency: Publishing your name and role (e.g. as a trial investigator) in public registries or reports, such as on clinical trial registry websites or the Website, as required by law or industry practice. | Where we have a legitimate interest to ensure the effective administration and conduct of the clinical trial and to comply with our legal obligations outside of the EEA/UK. To comply with our legal obligations. |
| All categories of Personal Information | Collaboration and data sharing: Sharing your information with study partners (e.g. contract research organizations, co-sponsors, ethics committees) for the purposes of conducting the trial. | Where we have a legitimate interest to ensure the effective administration and conduct of the clinical trial and to comply with our legal obligations outside of the EEA/UK. To comply with our legal obligations. |
| Personal identifiers; Professional and employment information | Future research/consulting opportunities: Retaining your professional profile to identify you for future clinical trials or consulting engagements in your field of expertise. | If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent. In other instances, we will send marketing communications to you where this is in our legitimate interest (i.e., keeping you informed about related events as part of our professional relationship). |
| General communications and other interactions (e.g., when you contact Viridian with a question, request, or any interaction not covered above): | ||
| Personal identifiers; Audio and visual information | Responding to inquiries: If you reach out for medical information, support, grants, or any question, we use your contact info and any relevant details to respond and assist you. | Where we have a legitimate interest to manage our business, and to process and respond to your communications. |
| Audio and visual information | Call recordings for quality: If you call our medical information or support lines, the call may be recorded (and we will inform you at the start of the call). Recordings may be used to ensure we answered your questions correctly or to improve our services. | Where we have a legitimate interest to manage our business, and to process and respond to your communications including, to monitor quality and maintain a record of communications. |
| Personal identifiers; Financial and reimbursement information; Professional and employment information | General marketing or informational communications: This includes sending you newsletters, product updates, or event invitations (if not already covered above), as part of ongoing engagement with you as an HCP. | If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent. In other instances, we will send marketing communications to you where this is in our legitimate interest (i.e., keeping you informed about related events as part of our professional relationship). |
| All categories of Personal Information | Legal actions and risk management: If necessary, we will use your information to protect our rights or the rights of others – for example, in the case of a legal claim, regulatory investigation, or enforcement of an agreement. We will also use it if we need to take action to ensure safety (for instance, if someone’s activities pose a risk, we might use their data to intervene). | To comply with a legal obligation. Where we have a legitimate interest to protect our business and assets from threats or defending against legal claims. |
| All categories of Personal Information | Corporate transactions: To enable any due diligence and other appraisals or evaluations for any actual or proposed merger, acquisition, financing transaction or joint venture contemplated by us | To pursue our legitimate interests to efficiently administer and prepare for the management of our business affairs. |
If you are in the EEA or the UK, you have a right to object to the processing of your Personal Information where that processing is carried out for our legitimate interests. Please note however, that we may not be able to fulfil such requests in all instances.
Consequences of not Providing Personal Information
Where we require your Personal Information to comply with our legal obligations, failure to provide this Personal Information could make it impossible for you to interact with us.
Notice at Collection: Categories of Personal Information We Sell or Share for Behavioural Advertising
When we engage in digital advertising in the United States, we may sell the following categories of Personal Information (according to the broad definition of “sell” under select state privacy laws) or share them for purposes of cross-context behavioural advertising: personal identifiers (including IP address, mobile advertising IDs), and internet or other electronic activity information.
These categories of Personal Information are sold to or shared for cross-context behavioural advertising with advertising networks, data brokers and other companies that facilitate or engage in digital advertising. We engage in such sales and sharing to engage in personalized advertising, such as providing you with information about products or developments we believe that are likely of interest to you. We do so by allowing third parties to place cookies or other tracking technologies on our Website and in our advertisements which may collect information about your interactions with our Website, advertisements, and your online activities over time and across different websites or applications. Please note that in some jurisdictions in which we operate, we do not engage in these practices. For more information about the use of cookies and other tracking technologies, see the Cookies and Other Technologies section below.
To opt out of such sales and sharing, click here.
We do not sell or share for cross-context behavioural advertising any of the other categories of Personal Information we collect.
Notice at Collection: Retention Periods
We retain the categories of Personal Information we collect for as long as we need for a legitimate purpose. The criteria used to determine the retention periods include: (i) how long the Personal Information is needed to provide / receive the services and operate the business; (ii) the type of Personal Information collected; and (iii) whether we are subject to a legal, contractual or similar obligation to retain the Personal Information (e.g., mandatory data retention laws, government orders to preserve data relevant to an investigation or data that must be retained for the purposes of court orders, regulatory investigations, or legal proceedings).
Sources From Which We Collect Personal Information
We collect Personal Information from you when you: (i) attend or register to attend an event sponsored by us; (ii) participate in one of our advisory boards or speak at an event on our behalf; (iii) request information from us about our products or services; (iv) apply for a grant, donation or sponsorship; (v) respond to one of our surveys; (vi) participate in one of our clinical trials; or (vii) otherwise interact with us including, via the Website. We may also collect your Personal Information from patients, other HCPs or medical professionals, dispensing entities, from data brokers specializing in HCP data, and from publicly available sources. We will continue to collect Personal Information from these same types of sources.
Sensitive Personal Information
We do not use or disclose sensitive Personal Information (also known as special category personal data) under this Privacy Notice to create profiles about or infer characteristics about individuals.
Automated Decision-Making / Profiling
We do not process your Personal Information based on any automated decision-making including profiling.
Cookies and Other Technologies
We use “cookies” and other similar technologies, some of which are essential for our Website to function. Cookies are small, sometimes encrypted, text files that are stored on computer hard drives by websites that you visit. They are used to help users navigate websites efficiently as well as to provide information to the owner of the website, and for digital advertising.
If you are in the EEA or the UK, we will only use non-essential cookies if you provide your opt-in consent through our cookie banner or preference tool. For information on the cookies that we use on the Website and the purposes for which we use them in the EEA or the UK, please see our Cookie Policy.
We use Google Analytics to evaluate the use and performance of our Website (in some jurisdictions, only with your consent). Google Analytics uses cookies and other identifiers to collect information, such as how often users visit a website, what webpages they visit on a website, and what other websites they visited prior to visiting a website. To learn more about how Google Analytics collects Personal Information, please see Google’s Privacy Policy.
Disclosure of Your Personal Information for Business Purposes – Categories of Personal Information
We have disclosed the following categories of Personal Information to service providers for a business purpose:
- Personal identifiers: name, residential and business address, home and business telephone number(s), email address(es), National Provider Identifier (“NPI”), IP address.
- Commercial and financial information: payment information, account information, and details of any financial relationship with us, information about prescriptions written, inquires or requests for assistance regarding our products or services.
- Professional or employment-related information: name of your practice, academic background, professional designation, medical specialty, licensing and disbarment status, publications and information about public speeches, and additional Personal Information you provide in your curriculum vitae or other similar documents or communications.
- Education information: academic background and credentials.
- Internet or electronic network information: your browser type, operating system, domain names visited, click activity, referring website and the date and time and length of your visit to our Website or other websites or mobile applications.
- Audio and visual information: recordings of calls made to our information and support lines; audio and visual recordings of presentations.
Inferences drawn from any above data to create profile reflecting an HCP’s interests as they relate to the types of products and educational offerings provided by Viridian.
Disclosure of Your Personal Information for Business Purposes – Purposes for Disclosure
We may disclose or make available HCP Personal Information to service providers or data processors for the following business purposes: to manage HCP information and provide patient support services; facilitate email communications, provide security services and cloud-based data storage, host our Website and assist with other IT-related functions, advertise and market our products and services (including educational offerings), provide analytics information, and provide legal and accounting services, and provide access to audio or video recordings. We may also disclose HCP Personal Information with third parties we consult and engage as part of our clinical research and compliance activities, such as research partners, ethics committees, and professional advisors, and clinical research monitors and research organizations.
We may also disclose Personal Information as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property or the rights, property or safety of others, including to law enforcement agencies, and judicial and regulatory authorities. We may also disclose your Personal Information to third parties to help detect and protect against fraud or data security vulnerabilities. And we may transfer your Personal Information to a third party in the event of an actual or contemplated sale, merger, reorganization of our entity or other restructuring.
Security and Confidentiality
Viridian is committed to protecting the security and privacy of your information stored by implementing standard security safeguards. However, no company, including Viridian, can fully eliminate security risks associated with Personal Information. Thus, while Viridian uses reasonable efforts to protect your Personal Information, we cannot guarantee its absolute security.
International Transfers of Personal Information
Your Personal Information may be transferred internationally as described in the Viridian Privacy Policy (available here).
Personal Information of Children
The Website and other HCP-related data processing activities are not directed to minors under the age of 16. We do not have actual knowledge that we collect Personal Information from minors, including those under the age of 16.
Third Party Links
Our Website may contain social media buttons or links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the activities and practices that take place on those social media platforms or third-party websites.
Your Data Privacy Rights
If you are in the EEA or the UK, details of your privacy rights are as described in the Viridian Privacy Policy (available here).
If you are a resident of California, we provide the following rights with respect to the Personal Information we collect about them.
Right to Know: The right to request the following additional information collected since January 1, 2022: categories of Personal Information we have collected about them; categories of sources from which such Personal Information was collected; categories of Personal Information that the business sold or disclosed for a business purpose about the consumer; categories of third parties to whom the Personal Information was sold or disclosed for a business purpose; and the business or commercial purpose for collecting or selling your Personal Information.
Right to Access / Copy: The right to access or request a copy of the Personal Information we have collected from the resident, subject to certain exceptions.
Right to Delete: The right to request deletion of their Personal Information that we have collected from or about the resident and to have such information deleted, subject to certain exceptions.
Right to Correct: The right to request that we correct inaccuracies in the resident’s Personal Information, taking into account the nature of personal data and purposes of processing such information.
Rights to Opt Out: Various rights to request that we stop using the resident’s Personal Information for one or more of the following purposes:
- Sale of Personal Information: The right to request that we stop selling of their Personal Information, consistent with the definition of “sale” in each law.
- Sharing for Cross-Context Behavioural Advertising: California’s law provides the right to request that we stop sharing Personal Information for cross-context behavioural advertising.
Exercising Your Rights and How We Will Respond
To exercise rights to know, access/copy, delete, correct, or to ask a question, email us at privacy@nullviridiantherapeutics.com or use the contact details set out at the end of this Privacy Notice.
To exercise rights to opt out, please click here.
When you exercise any of your privacy rights, we will continue to treat you fairly.
Changes to Our Privacy Notice
Viridian reserves the right to make additions, deletions or modifications to this Privacy Notice from time to time. If we make any material changes in the way we use or share your Personal Information, we will notify you by posting a notice on our Website prior to the change becoming effective. We encourage you to refer to this Privacy Notice on an ongoing basis, so you understand our current privacy practices.
Contact Us
Please contact us at privacy@nullviridiantherapeutics.com or the address or phone number provided below if you have any questions about this Privacy Notice, including requests relating to exercising any of your data privacy rights.
Viridian Therapeutics, Inc.
Attn: Data Protection Officer
221 Crescent Street
Suite 103A
Waltham, MA 02453
T: +1 617 272 4600
Please note that communications to this email address will not constitute legal notice to us or any of our officers, employees, agents or representatives in any situation where notice to us is required by contract or any law or regulation.