PRIVACY NOTICE

June 2024

Purpose and scope

This privacy notice (the “Privacy Notice”) informs prospective clients, job applicants, and other persons (referred to herein as “you”), interacting with Celsion Finance AG about the treatment and processing of your personal data (i.e. data by which you may be directly or indirectly identified; referred to herein as “Personal Data”) by Celsion Finance AG, having its registered office in Vaduz, Liechtenstein and/or any of its affiliated entities (referred to herein as “Celsion”, “we” or “us”) and your rights in accordance with applicable Liechtenstein data protection laws (i.e. the Data Protection Act (“DPA”) as well as the EU General Data Protection Regulation 2016/679 (“GDPR”) (together the “Data Protection Legislation”).

This Privacy Notice provides information on our practices concerning the collection, use, processing, and disclosure of your Personal Data. The nature and utilization of Personal Data processed by Celsion are dependent on the nature of your interaction with Celsion. In adherence to our commitment to the protection of privacy and the maintenance of confidentiality, Celsion has implemented a range of technical and organizational measures dedicated to the secure processing of all Personal Data, in full compliance with applicable Data Protection Legislation.

This Privacy Notice specifically aims to inform you about the following points:

  • Why and how Celsion collects, uses, and stores Personal Data;
  • The lawful basis for the use of Personal Data; and
  • What your rights are in relation to such processing of Personal Data and how these rights can be exercised.

What Personal Data is collected and processed?

Depending on the type of interaction with you, Celsion may collect the following data (to the extent permitted by law):

  • Personal identification data such as name, e-mail address, postal address, telephone number, domicile, nationality, passport, identity card (incl. copies/images of identification documents), tax identification number, tax domicile, and other tax-related information and personal characteristics (e.g. date of birth, marital status, gender);
  • Employment and education data such as educational background, employer, function, title, place of work, professional network, work experience;
  • Banking and financial information such as financial situation (including loans, assets, expenses, liabilities, etc.);
  • Electronic identification data such as IP addresses, cookies, traffic data, digital ledger addresses, identification credentials to connect to Celsion services;
  • Communications (e.g. telephone recordings, exchange of emails); and
  • Advertisement and sales data (e.g. potential interesting products for you).

These types of Personal Data may include special categories of data.

What sources are used?

In the course of establishing and maintaining a relationship with you, and in accordance with Article 6 of the GDPR and the corresponding provisions in the DPA, we collect Personal Data that is essential for us. In this context, we receive data through various sources as outlined below:

  • Data from you: We process Personal Data that we receive from you (e.g. through any means of communications with you, electronic channels, telephone conversations, contact forms, e-mails, or meetings). In addition, information may be collected about you indirectly from monitoring or other means (e.g. recording of telephone calls and monitoring e-mails).
  • Data from other sources: We also process data about you that we obtain from publicly accessible sources (e.g. publicly available websites, press, sanction lists, etc.). Additionally, we process Personal Data that is legitimately transferred to us by third parties.
  • Personal Data relating to a third party: If you provide us with Personal Data relating to a third party, for example, your spouse, children, parents, or business partners, you represent and warrant that you have obtained the separate consent of such third party (when required) before providing us with such Personal Data. You must ensure that you make such third parties aware of our name, our contact information, and the scope of and purposes for which we will collect and process their Personal Data and how it will be processed as set out in this Privacy Notice.

For what purposes is personal data being processed?

The processing activities are grounded in the legal bases provided by the GDPR and DPA ensuring that our operations are in strict compliance with privacy and Data Protection Regulations. Celsion is committed to processing your Personal Data solely for legitimate business purposes. These include, but are not limited to the following:

  • For the fulfillment of contractual obligations: Personal Data is processed as part of the execution of our contracts or for the execution of pre-contractual measures in view of entering into or for our business relationship with you. The specific data processing purposes are determined in accordance with the particular product or services and the underlying contractual terms and conditions.
  • As a result of your consent: There may be circumstances where we ask for your consent to process your Personal Data. As long as you have granted us this consent, this processing is legal on the basis of that consent. You can withdraw your consent at any time by contacting the Data Protection Officer. Withdrawal of consent does not affect the legality of data processing carried out prior to withdrawal.
  • For purposes of legitimate interests: We may, if necessary, also process your Personal Data on the basis of our or a third party’s legitimate interest which is beyond the actual fulfillment of the contract:
    • Assertion of legal claims and defense in case of legal disputes;
    • General management and development of services, systems, and products;
    • Fulfillment of our internal requirements and those of our group companies, including credit and risk management, insurance, audit, and management purposes;
    • To assure the safety and continuity of IT services;
    • Advertisement and marketing research;
    • For the prevention and investigation of crime, as well as risk management and fraud prevention.

Our interest for the respective processing of data is based on the respective purposes and is otherwise of economic nature (efficient task fulfillment, sales, and avoidance of legal risks).

  • For compliance with legal and regulatory obligations: Celsion is subject to various legal and regulatory obligations and might collect Personal Data from you to comply with such legal and regulatory obligations.

With whom may Personal Data be shared?

Your Personal Data may be disclosed to and processed by internal departments within Celsion, external service providers, legal and regulatory bodies, and, under certain conditions, entities in third countries, ensuring an adequate level of data protection is maintained at all times. Such transfers are conducted in compliance with legal requirements and are limited to purposes where it is necessary for the provision of our services, the fulfillment of legal obligations, or the execution of your instructions.

Where is Personal Data transferred to?

Transfers of Personal Data may be made to countries located in or outside the EEA. Certain countries in which recipients and data processors may be located and to which Personal Data may be transferred may not have the same level of protection of Personal Data as in the EEA/Liechtenstein. You understand that the data protection legislation in such other countries may not give you as much protection as the data protection legislation in the country where you are located. Personal Data transferred to countries outside of the EEA and Switzerland will be protected by appropriate safeguards such as approved data transfer agreements.

Cookies

Our website may use cookies. Cookies are intended to personalize the website for your visit and to improve the use of the website. Cookies are small text files that the website transmits to the cookie file of the internet browser on your device and stores it there for later retrieval so that you are recognized when the website is re-visited. If Celsion uses cookies and through this collects and processes your Personal Data, this is based on Article 6 (1) (f) GDPR as the processing is necessary for Celsion to pursue the legitimate interests to personalize the website to your visit and to facilitate the use of the website.

Automated Decision-Making and Profiling

Celsion does not generally rely on automated Decision-Making and Profiling of Personal Data. Regardless of this, however, Celsion reserves the right to employ automated decision-making processes, including profiling, which are necessary for entering into or performing a contract with you, based on your explicit consent, or where legally permissible. These processes are designed to ensure fairness and transparency in the decisions affecting you, with mechanisms in place for you to request human intervention or challenge decisions made about you. We process your Personal Data automatically in certain instances, to evaluate certain personal aspects of you (profiling).

Retention of Personal Data

We will retain the Personal Data for as long as required to perform the purposes for which such Personal Data was collected, depending on the legal basis on which that Personal Data is processed and/or whether additional legal/regulatory obligations such as document retention duties according to the applicable data protection laws or other applicable regulations, mandate that we retain the Personal Data. In certain circumstances, Personal Data may need to be retained for a longer period of time (for example in the context of litigation or as required by authorities).

Your rights

Under the GDPR, you are afforded several rights in relation to your Personal Data. Celsion respects these rights and facilitates the exercise of these rights. In accordance with Article 7 and 15 to 21 GDPR, you have the following rights:

  • Right of access: Data subjects have the right to obtain confirmation as to whether or not their personal data is being processed and the right to obtain a copy of their Personal Data.
  • Right to rectification: Data subjects have the right to request the rectification of inaccurate or incomplete Personal Data.
  • Right to erasure: Data subjects have the right to request the erasure of their Personal Data under certain circumstances ("right to be forgotten").
  • Right to restriction of processing: Data subjects have the right to request the restriction of the processing of their Personal Data under certain circumstances.
  • Right to data portability: Data subjects have the right to receive their Personal Data in a structured, commonly used, and machine-readable format and to transmit those data to another controller.
  • Right to object: Data subjects have the right to object to the processing of their Personal Data in certain situations, including direct marketing.

In the event that you wish to exercise these rights or make a complaint about how we process your Personal Data, please contact us in the first instance at the email address indicated below and we will endeavour to deal with your request as soon as possible. This is without prejudice to your right to file a complaint with the Liechtenstein data protection authority as outlined below.

Data Protection Officer/Contact information

Any Personal Data provided to or collected by us will be processed by us in our capacity as a controller or by our subcontractors and service providers in their capacity as processors in accordance with this Privacy Notice. For the purposes of this Privacy Notice, “processing” refers to any operation or set of operations performed on Personal Data, such as the collection, storage, use, alteration, disclosure, or deletion thereof. We have appointed a Data Protection Officer (“DPO”). You can contact our DPO under:

Celsion Finance AG Data Protection Officer c/o BEATADOMUS ANSTALT Austrasse 15 9495 Triesen Liechtenstein legal@celsion-finance.com

Data Protection Office Liechtenstein and Right of complaint

You have the right to file a complaint with the Data Protection Office in Liechtenstein (“Datenschutzstelle”). You can also contact another supervisory authority in an EU or EEA member state, e.g. at your place of residence or work or at the place where the cause of the complaint is suspected. The file a complaint, the Data Protection Office in Liechtenstein can be contacted as follows:

Data Protection Office (Datenschutzstelle) Liechtenstein Städle 38 Postfach 684 FL-9490 Vaduz Phone: +423 236 60 90 E-Mail: info.dss@llv.li Website: www.datenschutzstelle.li

Amendment of Privacy Notice

Celsion reserves the right to amend this Privacy Notice from time to time to ensure that you are fully informed about all processing activities and our compliance with applicable Data Protection Legislation. Please therefore make sure to regularly consult the current Privacy Notice, available on the Celsion website.

By clicking “Accept All”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.