For People Living With FA and Their Caregivers

Privacy Policy

Effective Date: October 9, 2025

Larimar Therapeutics, Inc. (“Larimar”, “we”, “our”, or “us”) respects your privacy and is committed to protecting the privacy of your personal information. When you access and use this Website, we will collect certain personal information about you that may be used to identify you, sometimes referred to as “personal data” or “personally identifiable information” (collectively, “Personal Information”).

Larimar is the “Data Controller” of the Personal Information that we collect about you. This means that we are responsible for making decisions regarding the collection and use of your Personal Information. It also means that we are responsible for ensuring the protection and security of the Personal Information that we hold about you. This Privacy Policy (this “Policy”) explains how we collect, use, process, share, protect, and store your Personal Information when you use this Website (this “Website”), which has been created as part of an unbranded, non-promotional disease awareness campaign relating to Friedreich's ataxia (“FA”). Also, where applicable privacy laws and/or regulations require that we handle your Personal Information in a manner that is different from that which is described herein, we shall comply with those laws and/or regulations as applicable.

IMPORTANT NOTICE: Certain subsets of Personal information, such as information about a person’s health or medical status (pursuant to all applicable laws) and “Location Data” (meaning information that identifies or allows inference of the geographic location of a person or device), are characterized as “Sensitive Personal Information” and may be subject to stricter regulation and consent requirements than other Personal Information. Before providing any Sensitive Personal Information to us through this Website, we urge you to carefully consider whether you are certain that you wish to disclose such Sensitive Personal Information about you to us. If, in using this Website, you do provide Sensitive Personal Information to us, you consent to our collection and use of it for the purposes and in the manner described in this Policy (hereinafter, any reference to “Personal Information” is to be considered inclusive of “Sensitive Personal Information”).

By using this Website, you agree to the terms of this Policy. If you do not agree to all of the terms of this Policy, please do not use this Website.

1. Personal Information We Collect

When you interact with this Website, we may collect the following Personal Information about you:

  • Personal Information that you provide to us directly when you “sign up” to receive educational information, materials, updates, and other content related to this Website from Larimar via email, mail, or text message.
    • Your first and last name
    • Your email address
    • Your phone number
    • Your state or ZIP Code
    • If you are a US healthcare professional, your specialty
    • Depending upon which form you use to sign up, the fact that you are either:
      • A person who has been diagnosed with FA;
      • A caregiver for a person who has been diagnosed with FA; or
      • A healthcare professional practicing in the United States of America (“US”).
  • Personal information collected automatically when you access or use this Website:
    • The IP address of the device that you use to visit this Website
  • Other Information collected automatically when you access or use this Website either by this Website itself or through this Website’s use of cookies:
    • Information about your activity on this Website known as “Usage Data”.
      • Since your Usage Data, by itself, usually cannot be used to identify you personally, we do not consider it to be your Personal Information. However, if your Usage Data and any of the Personal Information that we collect about you are linked together and, once linked, can be used to identify you, in such limited scenarios your Usage Data may be considered as your Personal Information.
    • This Website uses cookies to enhance your experience on this Website and to help us understand this Website’s usage as well as to measure campaign effectiveness. When you first visit this Website, this Website’s Cookie Consent Banner will pop up, prompting you to select between either "Accept all", by which you agree to our use of cookies, or "Reject all", by which you agree to a single strictly necessary cookie to prevent the use of data analytics cookies. We do not use cookies to sell or share your Personal Information.

2. How We Use Your Personal Information

We may use the Personal Information that we collect to:

  • Provide educational information, materials, updates, and other content related to the disease awareness campaign;
  • Communicate with you by email, text message, or mail (with your consent);
  • Improve this Website and its content;
  • Comply with legal and regulatory requirements; and
  • Protect against fraud, security threats, or misuse of this Website.

3. How We Share Your Personal Information

We may share your Personal Information only as follows:

  • With service providers who help us operate this Website and deliver communications (e.g., email service providers, mailing vendors, SMS text messaging platforms).
  • With affiliates and partners working with us on the disease awareness campaign, subject to confidentiality obligations.
  • For legal reasons, if required by law, regulation, legal process, or government request, or to protect our rights, safety, and/or property.
  • In aggregated or de-identified form that cannot reasonably be used to identify you.

WE DO NOT SELL YOUR PERSONAL INFORMATION.

4. Your Choices

  • Email communications: You may unsubscribe at any time by clicking the “Unsubscribe” link located at the bottom of our emails.
  • Text messages: You may unsubscribe at any time by texting “UNSUBSCRIBE” in reply to our messages.
  • Cookies: You can disable cookies in your browser settings, however, if you do, some or all of the features on this Website may not function properly or become disabled.

5. Security

We have implemented reasonable and appropriate technical and organizational security measures to protect and safeguard your Personal Information from loss, misuse and unauthorized access, disclosure, alteration, and destruction, considering the risks involved and the nature of your Personal Information. We have also taken measures to maintain the ongoing confidentiality, integrity, and availability of the systems and services that process your Personal Information and will restore the availability and access to your Personal Information in a timely manner in the event of a physical or technical incident. Still, as no method of transmission over the Internet or electronic storage system is completely secure, we cannot guarantee absolute security. If you have questions about the security of your Personal Information, or if you have reason to believe the Personal Information that we hold about you is no longer secure, please contact us immediately at privacyinfo@larimartx.com.

6. Retention

We will retain your Personal Information only for as long as is reasonably deemed necessary in order to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

7. Children’s Privacy

This Website is not directed to or intended for use by children. If you are under the age of majority in your place of residence, you may use this Website only with the consent of or under the supervision of your parent or legal guardian. Consistent with the requirements of the Children’s Online Privacy Protection Act (“COPPA”), if we learn that a child under the age of 13 has provided his/her Personal Information to us through this Website without first receiving his or her parent’s or legal guardian’s verified consent, we will use that Personal Information only to respond directly to that child (or his or her parent or legal guardian) to inform the child (or his or her parent or legal guardian) that he or she cannot use this Website, and subsequently, we will dispose of such Personal Information in accordance with this Policy.

If you believe Larimar may have received any Personal Information from or about a child under the age of 13, please contact us at legaldept@larimartx.com.

8. International Visitors to this Website

The information and materials provided on and offered through this Website are intended for and currently available for use only by:

  • Individuals located in the United States of America (“US”) who are either living with FA or caring for someone with FA; and
  • Healthcare professionals practicing in the US.

However, we recognize that individuals from outside the US may visit this Website. If you are visiting from outside the US, please note that any Personal Information you provide through this Website will be processed in accordance with applicable US data privacy/protection laws and regulations, which may or may not require the same level of protection and security as those in the country where you are located.

9. Changes to This Policy

We may update this Policy from time to time. When we do, we will post the updated version on this page with a new “Effective Date”. Your continued use of this Website after changes are posted constitutes your acceptance of those changes.

10. Your California Privacy Rights (if applicable)

If you are a California resident, you may have rights under the California Consumer Privacy Act (“CCPA”) and its amendments. These may include the right to request information about how we collect and use your Personal Information, and to request deletion of your Personal Information, subject to legal exceptions. To exercise these rights, please contact us as at legaldept@larimartx.com.

11. Contact Us

If you have questions about this Policy or our data practices, please contact us at legaldept@larimartx.com.