Comprehensive General Privacy Policy

Anspar Foundation
Version 1.0
Last Updated: November 27, 2025

Modular Policy Structure

This Comprehensive General Privacy Policy (Policy) establishes the foundational privacy framework for all Anspar Foundation activities. Project-specific privacy requirements are addressed in separate Project Privacy Addenda that supplement—but do not replace—this Policy.

Table of Contents

1. Introduction

1.1 About Anspar Foundation

Anspar Foundation ("Anspar," "we," "us," or "our") is a technology development organization that builds applications and systems for healthcare, research, and charitable purposes. We work with partner organizations, including patient advocacy foundations, research institutions, and healthcare providers, to develop technology solutions that advance health outcomes and scientific understanding.

1.2 Purpose of This Policy

This Comprehensive General Privacy Policy ("Policy") describes how Anspar Foundation collects, uses, shares, protects, and retains personal information across all our activities, projects, and services. This Policy applies to:

1.3 Modular Policy Structure

This Policy establishes our foundational privacy framework. Because we engage in diverse projects with varying data collection requirements, we use a modular structure:

Comprehensive General Privacy Policy (This Document): Establishes core principles, rights, security standards, and governance that apply to all Anspar activities.

Concise General Privacy Policy: A summary document containing the essential Policy information necessary to comply with GDPR and other regulations.

Project Privacy Addenda: Supplemental documents that specify project-specific data collection, use, sharing, and retention practices. Each addendum incorporates this Policy by reference.

When you use a specific Anspar project or service, both this Policy and any applicable Project Privacy Addendum govern your information. In the event of a conflict between this Policy and a Project Privacy Addendum, the Project Privacy Addendum controls for that specific project, except that a Project Privacy Addendum may not reduce the core protections and rights established in Sections 6 (Your Rights), 7 (Data Security), and 14 (Complaints) of this Policy.

1.4 Regulatory Compliance Framework

This Policy is designed to comply with applicable privacy and data protection laws, including:

Specific regulatory requirements for individual projects are detailed in the applicable Project Privacy Addenda.

1.5 Transferability and Successor Organizations

Anspar Foundation frequently develops technology in partnership with or under contract to other organizations. This Policy is designed to ensure continuity when:

Upon any such transfer, existing consents and authorizations remain valid, the successor organization assumes all applicable obligations, and users are notified but are not required to provide new consent for the transfer itself.

2. Definitions

The following definitions apply throughout this Policy and all Project Privacy Addenda:

"Personal Information" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This includes "Personal Data" as defined under GDPR.

"Protected Health Information (PHI)" means individually identifiable health information transmitted or maintained in any form or medium, as defined under HIPAA.

"Special Categories of Personal Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person's sex life or sexual orientation, as defined under GDPR Article 9.

"Sensitive Personal Information" means (under CCPA/CPRA) Personal Information that reveals social security number, driver's license number, financial account information, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of communications, genetic data, biometric information, health information, or sex life/sexual orientation information.

"Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

"Data Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller.

"Business Associate" means a person or entity that performs certain functions or activities involving the use or disclosure of Protected Health Information on behalf of, or provides services to, a Covered Entity, as defined under HIPAA.

"Project" means any application, service, research study, or other initiative undertaken by Anspar Foundation, whether independently or in partnership with other organizations.

"Project Privacy Addendum" means a supplemental privacy document that specifies data practices for a particular Project and incorporates this General Privacy Policy by reference.

3. Information We Collect

3.1 General Categories

Across our activities, Anspar Foundation may collect the following general categories of information. We endeavor to collect only the minimal information necessary to fulfill the service requested. Specific data elements collected for each Project are detailed in the applicable Project Privacy Addendum.

3.1.1 Identity and Contact Information

3.1.2 Health and Medical Information

For Projects involving health applications or research:

3.1.3 Technical and Device Information

3.1.4 Financial and Transactional Information

For donors, partners, or vendors:

3.1.5 Communications

3.2 Collection Methods

We collect information through:

3.3 Project-Specific Data Collection

The specific data elements collected for each Project are detailed in the applicable Project Privacy Addendum. Before using any Anspar Project, please review both this Policy and the Project-specific Addendum.

4. How We Use Your Information

4.1 General Purposes

We use Personal Information for the following general purposes across all Projects:

4.1.1 Service Delivery

4.1.2 Research and Development

4.1.3 Communications

4.1.4 Legal and Compliance

4.2 Legal Bases for Processing (GDPR)

Under the GDPR, we process Personal Data based on the following legal grounds:

For Special Categories of Personal Data (including health data), we rely on additional legal bases under Article 9, including explicit consent (Article 9(2)(a)) and scientific research purposes (Article 9(2)(j)) with appropriate safeguards.

4.3 Project-Specific Uses

Specific purposes for each Project are detailed in the applicable Project Privacy Addendum.

5. How We Share Your Information

5.1 Categories of Recipients

We may share your information with the following categories of recipients:

5.1.1 Partner Organizations (Opt-In Only)

We do not share your Personal Information with partner organizations by default. Data sharing with partner organizations occurs only when you affirmatively request a service that requires such sharing, and only after you provide explicit consent through a clear consent process.

Types of partner organizations we may work with include:

Consent Process: Before any data is shared with a partner organization, you will be presented with a specific consent request that identifies: (1) the partner organization, (2) the specific data to be shared, (3) the purpose of the sharing, and (4) any additional terms. You may decline without affecting your use of our core services.

5.1.2 Service Providers

We engage trusted service providers who assist in our operations:

All service providers are bound by contractual obligations (including Business Associate Agreements under HIPAA and Data Processing Agreements under GDPR) that require them to protect your information and limit its use.

5.1.3 Regulatory and Legal Authorities

We may disclose information when required by law or to:

5.1.4 Successor Organizations

In the event of a merger, acquisition, reorganization, or transfer of assets, your information may be transferred to a successor entity that agrees to be bound by the terms of this Policy.

5.2 No Sale of Personal Information

Anspar Foundation does not sell Personal Information. We do not share data for third-party advertising purposes. Any data sharing is conducted solely for the purposes described in this Policy and applicable Project Privacy Addenda.

5.3 Project-Specific Sharing

Specific data sharing arrangements for each Project are detailed in the applicable Project Privacy Addendum. All partner organization sharing remains opt-in and requires your explicit consent before any data is shared.

6. Your Rights

CORE PROTECTION: The rights in this Section represent core protections that apply to all Anspar activities and cannot be reduced by any Project Privacy Addendum.

6.1 Universal Rights

Regardless of your location, you have the right to:

6.2 Rights Under HIPAA (U.S. Residents)

If you are a U.S. resident and we maintain your Protected Health Information:

6.3 Rights Under GDPR (EEA Residents)

If you are in the European Economic Area:

6.4 Rights Under California Law

California residents have the following rights under CCPA/CPRA:

6.5 Exercising Your Rights

To exercise any rights, contact us using the information in Section 13. We will respond within applicable timeframes:

6.6 Limitations on Rights

Certain rights may be limited where permitted by law, including for clinical trial data integrity, regulatory compliance, or legal obligations. Any limitations are specified in the applicable Project Privacy Addendum.

7. Data Security

CORE PROTECTION: The security standards in this Section represent core protections that apply to all Anspar activities and cannot be reduced by any Project Privacy Addendum.

7.1 Security Safeguards

We implement comprehensive safeguards to protect your information:

7.1.1 Technical Safeguards

7.1.2 Administrative Safeguards

7.1.3 Physical Safeguards

7.2 Breach Notification

In the event of a security breach:

8. Data Retention

8.1 General Retention Principles

We retain Personal Information only as long as necessary for the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce agreements.

8.2 Standard Retention Periods

8.3 Extended Retention for Regulatory Compliance

Certain data is subject to extended retention as required by regulation, including clinical trial data (up to 25 years under EU Clinical Trial Regulation) and FDA-regulated records. Extended retention requirements are specified in applicable Project Privacy Addenda.

8.4 Deletion and Anonymization

When data is no longer required, we securely delete or anonymize it. Anonymized data that cannot be linked to individuals may be retained indefinitely for research and statistical purposes.

9. International Data Transfers

9.1 Data Location

Anspar Foundation is based in the United States. Your data may be processed and stored in the United States and potentially other countries where our service providers operate.

9.2 Transfer Mechanisms

For transfers from the EEA, UK, or Switzerland to countries without adequate data protection, we use:

10. Cookies and Tracking Technologies

10.1 Types of Cookies

Our websites and applications may use:

10.2 Your Choices

You can manage cookies through your browser settings. Note that disabling certain cookies may affect functionality. We honor Global Privacy Control (GPC) signals.

11. Children's Privacy

Our general services are not intended for children under 13 (or 16 in certain EU jurisdictions). We do not knowingly collect Personal Information from children without appropriate parental consent.

For Projects involving pediatric participants (such as clinical research), appropriate consent mechanisms are implemented as required by applicable law and specified in the Project Privacy Addendum.

12. Changes to This Policy

We may update this Policy periodically. When we make material changes:

Your continued use of our services after notice constitutes acceptance of the updated Policy.

13. Contact Information

General Privacy Inquiries:

Anspar Foundation
Attention: Privacy Officer
Email: privacy@anspar.org

Data Protection Officer:
Email: dpo@anspar.org

EU Representative (for GDPR):
[To be designated when applicable]

14. Complaints

CORE PROTECTION: Your right to complain about our data practices cannot be limited by any Project Privacy Addendum.

If you have concerns about how we handle your data:

We will not retaliate against you for filing a complaint.

Appendix A: Project Privacy Addendum Framework

Each Project Privacy Addendum should address the following elements:

A.1 Required Addendum Elements

A.2 Incorporation Clause

Each Project Privacy Addendum must include the following incorporation clause:

This Project Privacy Addendum supplements and incorporates by reference the Anspar Foundation General Privacy Policy (Version [X], Effective [Date]). In the event of conflict between this Addendum and the General Privacy Policy, this Addendum controls for this Project, except that this Addendum may not reduce the core protections established in Sections 6 (Your Rights), 7 (Data Security), and 14 (Complaints) of the General Privacy Policy.

Appendix B: Regulatory Glossary

21 CFR Part 11: FDA regulations on electronic records and signatures.

CCPA/CPRA: California Consumer Privacy Act as amended by California Privacy Rights Act.

Clinical Trial Regulation (EU) No 536/2014: EU regulation on clinical trials for medicinal products.

EU Annex 11: EU GMP guidelines for computerized systems.

GDPR: General Data Protection Regulation (EU) 2016/679.

HIPAA: Health Insurance Portability and Accountability Act of 1996.

HITECH Act: Health Information Technology for Economic and Clinical Health Act.

ICH-GCP: International Council for Harmonisation Good Clinical Practice.

Appendix C: Document Control

Version History:

Version 1.0 – November 27, 2025 – Initial Release

Review Schedule:

This Policy shall be reviewed at least annually and updated as necessary.