Privacy and security notice
Data Room Privacy Notice
This Notice explains how Maxwell Biosciences, Inc. collects and uses personal data when you access its password-protected diligence portal.
- Controller
- Maxwell Biosciences, Inc.
- Effective date
- August 25, 2026
- Notice version
- MXW-PN-2026-08-25-v1
1. Scope and consent
This Notice applies to dd.mxw.ai and the authentication, account, security, audit, and diligence activities connected with it (the “Data Room”). It supplements the User Agreement. Before signing in, you must affirmatively accept this Notice. Your acceptance and successful login authorize the collection and processing described here and are recorded with the version accepted. If you do not consent, do not log in.
2. Personal data we collect
We collect the following categories as reasonably available:
- Identity and account data: name, email address, telephone number, account role, verification and access status, credential hash, agreement status, and internal account identifiers. We do not store your plaintext password.
- Signature and consent evidence: the User Agreement and Privacy Notice versions, first and latest acceptance/login dates and times, authentication result, and related server records.
- Network and approximate location data: IP address and source header; continent, country, state or region, city, postal area, approximate latitude and longitude, time zone, host, and Vercel request or deployment-region identifiers.
- Browser, operating-system, and device data: user agent, inferred operating system, inferred browser, device type, platform, browser client hints, cookie capability, do-not-track signal, language and locale preferences.
- Display and performance data: screen and viewport dimensions, pixel ratio, color depth, touch capability, logical processor count, and approximate device-memory class when the browser exposes it.
- Portal activity and security data: login/logout events, session timing, pages and views accessed, searches, prompts, responses, downloads, error and diagnostic events, disclosure tier, audit events, and suspected misuse or incident records.
- Communications and investigation data: messages sent to Company, support requests, legal notices, audit responses, recipient information, and records provided during an authorized security or confidentiality investigation.
We do not intentionally collect Social Security numbers, payment-card data, consumer health data, biometric identifiers, passwords in readable form, private cookie contents, or page contents from outside Company-controlled systems through this login evidence process. Please do not submit unnecessary sensitive personal data.
3. Sources
Data comes from you and your browser; Company personnel who provision or administer your account; authentication, hosting, network, security, analytics, communications, and diligence providers; Vercel request headers; records created through Data Room use; and lawful audits, investigations, counterparties, or public sources. Approximate location is inferred from the public IP address and may be inaccurate.
4. Purposes and legal grounds
Company processes the data to:
- authenticate identity, provision access, enforce disclosure tiers, and operate the Data Room;
- document electronic signature, consent, contract version, consideration, and first and latest access;
- protect invaluable confidential information and trade secrets, attribute activity, deter misuse, detect fraud, and investigate suspected breaches;
- maintain audit trails, preserve evidence, respond to incidents, enforce agreements, establish or defend legal claims, and comply with law;
- support users, diagnose reliability or security problems, administer Company relationships, and improve authorized portal functionality; and
- complete a financing, reorganization, merger, acquisition, asset transfer, insolvency process, or other legitimate corporate transaction.
Depending on applicable law, the legal grounds are your express consent, performance of and steps relating to the User Agreement, Company's legitimate interests in securing a restricted business system and protecting legal rights, and compliance with legal obligations. Access cannot be provided without the security and signature evidence necessary for these purposes.
5. Disclosure and recipients
Company may disclose relevant data to its affiliates; directors, officers, employees, and authorized administrators; cloud hosting, authentication, cybersecurity, analytics, customer-relationship, communications, storage, professional, forensic, and legal service providers; auditors, insurers, financing sources, and advisers; prospective or actual transaction counterparties and successors; courts, arbitrators, regulators, law enforcement, or government bodies; and other persons when directed by you, necessary to protect rights or safety, or permitted by law. Recipients receive only data reasonably related to their role and are subject to applicable duties.
6. No sale, targeted advertising, or public profile
Company does not sell Data Room personal data for monetary consideration, use it for cross-context behavioral or targeted advertising, or publicly profile Data Room users. Company does not currently process this data for solely automated decisions producing legal or similarly significant effects. Disclosure to service providers or in a corporate transaction is not treated as a sale where applicable law excludes it.
7. Retention
Account, consent, agreement-version, authentication, security, audit, and legal evidence may be retained for the duration of access and afterward for as long as reasonably necessary to protect trade secrets and legal rights, administer continuing obligations, investigate incidents, resolve disputes, meet limitation periods, preserve records, and comply with law. Company may retain data longer during a legal hold, audit, investigation, or continuing confidentiality obligation. Data no longer required is deleted, deidentified, or archived under restricted access consistent with Company's retention practices and applicable law.
8. Security
Company uses administrative, technical, contractual, and physical safeguards designed for the nature of the Data Room, including password protection, hashed credentials, identity verification, access controls, disclosure tiers, session revocation, encryption in transit, logging, monitoring, and restricted administrative access. No system is perfectly secure, and this Notice is not a warranty against every event.
9. Your privacy choices and requests
Subject to applicable law and exemptions protecting trade secrets, security, privileged material, investigations, and legal claims, you may request confirmation, access, correction, deletion, or a portable copy of personal data; a list of relevant third-party categories; or review of a denied request. You may withdraw consent for future optional processing, but withdrawal does not invalidate prior processing and may require Company to terminate Data Room access. Company may authenticate requests and may deny or limit a request when law permits or retention is necessary.
Send a request titled “Data Room Privacy Request” to investor.relations@maxwellbiosciences.com or use the Company channel that issued your credentials. Include your account email, state or country, requested action, and enough information to verify identity. You may appeal a denial through the same channel with “Privacy Appeal” in the subject line.
10. Texas, Delaware, and Nevada residents
Where the Texas Data Privacy and Security Act, Delaware Personal Data Privacy Act, Nevada Revised Statutes Chapter 603A, or another state privacy law applies, Company will honor the rights, notice, security, appeal, opt-out, and non-discrimination requirements that cannot lawfully be waived. Business-contact, employment, investor, regulated, exempt, and threshold limitations may apply. Company does not discriminate for a valid privacy request, although access may be unavailable where requested deletion or noncollection prevents required authentication or security.
11. International processing
Company is based in the United States, and data may be processed in the United States and other countries where Company or its providers operate. Those locations may have different privacy laws. Company will use a lawful transfer mechanism and honor mandatory access, correction, deletion, restriction, objection, portability, complaint, and consent-withdrawal rights where applicable.
12. Children
The Data Room is a restricted business system and is not directed to anyone under eighteen. Company does not knowingly provide accounts to children or knowingly process their personal data through the Data Room. Notify Company if you believe a child has attempted access.
13. Changes and versioned consent
Company may update this Notice by posting a new effective date and version. A material change will be presented for renewed acceptance where required. Each successful login records the current Notice version alongside the current User Agreement version so Company can identify the terms associated with first and latest access.
14. Express privacy consent
BY SELECTING “I AGREE AND CONSENT” AND LOGGING IN, USER ACKNOWLEDGES THIS NOTICE AND EXPRESSLY CONSENTS TO THE COLLECTION, USE, DISCLOSURE, RETENTION, SECURITY MONITORING, AND VERSIONED SIGNATURE RECORD DESCRIBED ABOVE. IF USER DOES NOT AGREE, USER MUST NOT LOG IN.