Privacy Policy

SFA Therapeutics, Inc.

Effective date: 25/04/2022, Last updated: 25/04/2022

1. Introduction

SFA Therapeutics, Inc. ("SFA Therapeutics," "Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you may provide through our website located at https://sfatherapeutics.com (the "Site"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have regarding your information.

SFA Therapeutics is a clinical-stage biopharmaceutical company. The information on our Site is intended for informational purposes only and is directed primarily at investors, healthcare professionals, and the general public. We do not collect protected health information ("PHI") through the Site.

Please read this Privacy Policy carefully. By accessing or using the Site, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Site.

2. Information We Collect

2.1 Information You Provide Voluntarily

We collect personal information only when you voluntarily provide it to us. This is currently limited to:

  • Investor and Business Inquiries. If you contact us via email at our investor relations address (e.g., info@sfatherapeutics.com), we will receive your email address, your name (if provided), and any other information you include in your correspondence.

We do not operate any registration forms, user accounts, or online data submission portals on the Site that collect personal information.

2.2 Information Collected Automatically

When you visit the Site, certain information may be collected automatically by our servers and any third-party service providers, including:

  • Log Data. Your Internet Protocol ("IP") address, browser type and version, operating system, referring URL, pages visited on the Site, date and time of your visit, and time spent on each page.
  • Device Information. Information about the device you use to access the Site, including device type, screen resolution, and unique device identifiers.
  • Cookies and Similar Technologies. We may use cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.

As of the effective date of this Privacy Policy, we do not use third-party analytics platforms (such as Google Analytics) on the Site. Should this change, we will update this Privacy Policy and our Cookie Policy accordingly.

2.3 Information We Do Not Collect

We do not collect any of the following through the Site:

  • Protected health information (PHI) or medical records
  • Health conditions, diagnoses, or treatment information
  • Social Security numbers or government-issued identification numbers
  • Financial account or payment information
  • Information from minors (see Section 10 below)

3. How We Use Your Information

We use the limited personal information we collect for the following purposes:

  • Responding to Inquiries. To respond to investor relations inquiries, business partnership requests, and other correspondence you send to us.
  • Site Operations. To operate, maintain, and improve the functionality and performance of the Site.
  • Security. To detect, prevent, and address technical issues, security threats, and fraudulent or illegal activity.
  • Legal Compliance. To comply with applicable laws, regulations, legal processes, or governmental requests.

We do not use your personal information for automated decision-making or profiling.

4. Legal Bases for Processing (EEA, UK, and Swiss Visitors)

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, we process your personal data only when we have a valid legal basis to do so under the General Data Protection Regulation ("GDPR") or the UK GDPR, as applicable. Our legal bases include:

  • Legitimate Interests. We process log data and device information based on our legitimate interest in operating and securing the Site, provided such interests are not overridden by your data protection rights.
  • Consent. Where required by law (e.g., for non-essential cookies), we will obtain your prior consent before processing your personal data.
  • Legal Obligation. We may process personal data to comply with applicable legal obligations.
  • Performance of a Contract. If you engage in a contractual relationship with us, we may process personal data as necessary to perform our obligations under that contract.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

We may share your information in the following limited circumstances:

  • Service Providers. We may share personal information with third-party vendors who perform services on our behalf, such as website hosting, IT support, and email delivery. These providers are contractually obligated to use your information only as necessary to perform services for us and to maintain appropriate confidentiality and security measures.
  • Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of SFA Therapeutics, our users, or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via a prominent notice on the Site of any change in ownership or use of your personal information.
  • With Your Consent. We may share your information for other purposes with your express consent.

6. International Data Transfers

SFA Therapeutics is based in the United States. If you are visiting the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses ("SCCs") approved by the European Commission or the UK Information Commissioner's Office ("ICO"), as applicable.
  • Any other legally recognized transfer mechanism under applicable data protection laws.

By using the Site, you acknowledge that your personal data may be transferred internationally as described in this section.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Correspondence. Emails and investor inquiries are retained for as long as necessary to respond to and manage the inquiry, and thereafter as required for our legitimate business and legal purposes.
  • Log Data. Automatically collected server log data is retained for a reasonable period for security and operational purposes and is then deleted or anonymized.

When personal information is no longer needed, we will securely delete or anonymize it.

8. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information.

8.1 Rights of EEA, UK, and Swiss Residents

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") of your personal data in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Data Portability — to receive your personal data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw Consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a Complaint with your local data protection supervisory authority.

8.2 Rights of California Residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell or share.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt Out of the sale or sharing of personal information. Note: SFA Therapeutics does not sell or share personal information as defined under the CCPA/CPRA.
  • Non-Discrimination for exercising your CCPA/CPRA rights.

8.3 Rights of Residents of Other U.S. States

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights, including the right to access, delete, correct, and opt out of certain processing activities. We will honor such requests in accordance with applicable law.

8.4 Exercising Your Rights

To exercise any of the above rights, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

We will respond to verified requests within the time frames required by applicable law (generally 30 days under GDPR/UK GDPR, and 45 days under CCPA/CPRA). We may need to verify your identity before processing your request.

9. Data Security

We implement reasonable administrative, technical, and organizational measures designed to protect the personal information we collect against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Site is not directed at individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18 (or under 16 in the EEA/UK), we will take steps to delete such information promptly. If you believe that we may have collected information from a child, please contact us at jameskirwin@sfatherapeutics.com.

11. Third-Party Links

The Site may contain links to third-party websites, services, or resources that are not owned or controlled by SFA Therapeutics (for example, ClinicalTrials.gov). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party websites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify you by posting a prominent notice on the Site or through other appropriate channels.

We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

For EEA and UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 SFA Therapeutics, Inc. All rights reserved.

Resetting the immune system © 2026 SFA Therapeutics, Inc.

SFA-002 and all SFA Therapeutics pipeline candidates are investigational therapies and have not been approved by the U.S. Food and Drug Administration (FDA) or any other regulatory authority. The safety and efficacy of these therapies have not been established. The information on this website is intended for informational purposes only and should not be construed as medical advice or an offer to participate in a clinical trial. ClinicalTrials.gov Identifier: [pending registration].

Privacy Policy

SFA Therapeutics, Inc.

Effective date: 25/04/2022, Last updated: 25/04/2022

1. Introduction

SFA Therapeutics, Inc. ("SFA Therapeutics," "Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you may provide through our website located at https://sfatherapeutics.com (the "Site"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have regarding your information.

SFA Therapeutics is a clinical-stage biopharmaceutical company. The information on our Site is intended for informational purposes only and is directed primarily at investors, healthcare professionals, and the general public. We do not collect protected health information ("PHI") through the Site.

Please read this Privacy Policy carefully. By accessing or using the Site, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Site.

2. Information We Collect

2.1 Information You Provide Voluntarily

We collect personal information only when you voluntarily provide it to us. This is currently limited to:

  • Investor and Business Inquiries. If you contact us via email at our investor relations address (e.g., info@sfatherapeutics.com), we will receive your email address, your name (if provided), and any other information you include in your correspondence.

We do not operate any registration forms, user accounts, or online data submission portals on the Site that collect personal information.

2.2 Information Collected Automatically

When you visit the Site, certain information may be collected automatically by our servers and any third-party service providers, including:

  • Log Data. Your Internet Protocol ("IP") address, browser type and version, operating system, referring URL, pages visited on the Site, date and time of your visit, and time spent on each page.
  • Device Information. Information about the device you use to access the Site, including device type, screen resolution, and unique device identifiers.
  • Cookies and Similar Technologies. We may use cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.

As of the effective date of this Privacy Policy, we do not use third-party analytics platforms (such as Google Analytics) on the Site. Should this change, we will update this Privacy Policy and our Cookie Policy accordingly.

2.3 Information We Do Not Collect

We do not collect any of the following through the Site:

  • Protected health information (PHI) or medical records
  • Health conditions, diagnoses, or treatment information
  • Social Security numbers or government-issued identification numbers
  • Financial account or payment information
  • Information from minors (see Section 10 below)

3. How We Use Your Information

We use the limited personal information we collect for the following purposes:

  • Responding to Inquiries. To respond to investor relations inquiries, business partnership requests, and other correspondence you send to us.
  • Site Operations. To operate, maintain, and improve the functionality and performance of the Site.
  • Security. To detect, prevent, and address technical issues, security threats, and fraudulent or illegal activity.
  • Legal Compliance. To comply with applicable laws, regulations, legal processes, or governmental requests.

We do not use your personal information for automated decision-making or profiling.

4. Legal Bases for Processing (EEA, UK, and Swiss Visitors)

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, we process your personal data only when we have a valid legal basis to do so under the General Data Protection Regulation ("GDPR") or the UK GDPR, as applicable. Our legal bases include:

  • Legitimate Interests. We process log data and device information based on our legitimate interest in operating and securing the Site, provided such interests are not overridden by your data protection rights.
  • Consent. Where required by law (e.g., for non-essential cookies), we will obtain your prior consent before processing your personal data.
  • Legal Obligation. We may process personal data to comply with applicable legal obligations.
  • Performance of a Contract. If you engage in a contractual relationship with us, we may process personal data as necessary to perform our obligations under that contract.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

We may share your information in the following limited circumstances:

  • Service Providers. We may share personal information with third-party vendors who perform services on our behalf, such as website hosting, IT support, and email delivery. These providers are contractually obligated to use your information only as necessary to perform services for us and to maintain appropriate confidentiality and security measures.
  • Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of SFA Therapeutics, our users, or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via a prominent notice on the Site of any change in ownership or use of your personal information.
  • With Your Consent. We may share your information for other purposes with your express consent.

6. International Data Transfers

SFA Therapeutics is based in the United States. If you are visiting the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses ("SCCs") approved by the European Commission or the UK Information Commissioner's Office ("ICO"), as applicable.
  • Any other legally recognized transfer mechanism under applicable data protection laws.

By using the Site, you acknowledge that your personal data may be transferred internationally as described in this section.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Correspondence. Emails and investor inquiries are retained for as long as necessary to respond to and manage the inquiry, and thereafter as required for our legitimate business and legal purposes.
  • Log Data. Automatically collected server log data is retained for a reasonable period for security and operational purposes and is then deleted or anonymized.

When personal information is no longer needed, we will securely delete or anonymize it.

8. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information.

8.1 Rights of EEA, UK, and Swiss Residents

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") of your personal data in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Data Portability — to receive your personal data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw Consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a Complaint with your local data protection supervisory authority.

8.2 Rights of California Residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell or share.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt Out of the sale or sharing of personal information. Note: SFA Therapeutics does not sell or share personal information as defined under the CCPA/CPRA.
  • Non-Discrimination for exercising your CCPA/CPRA rights.

8.3 Rights of Residents of Other U.S. States

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights, including the right to access, delete, correct, and opt out of certain processing activities. We will honor such requests in accordance with applicable law.

8.4 Exercising Your Rights

To exercise any of the above rights, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

We will respond to verified requests within the time frames required by applicable law (generally 30 days under GDPR/UK GDPR, and 45 days under CCPA/CPRA). We may need to verify your identity before processing your request.

9. Data Security

We implement reasonable administrative, technical, and organizational measures designed to protect the personal information we collect against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Site is not directed at individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18 (or under 16 in the EEA/UK), we will take steps to delete such information promptly. If you believe that we may have collected information from a child, please contact us at jameskirwin@sfatherapeutics.com.

11. Third-Party Links

The Site may contain links to third-party websites, services, or resources that are not owned or controlled by SFA Therapeutics (for example, ClinicalTrials.gov). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party websites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify you by posting a prominent notice on the Site or through other appropriate channels.

We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

For EEA and UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 SFA Therapeutics, Inc. All rights reserved.

Resetting the immune system © 2026 SFA Therapeutics, Inc.

SFA-002 and all SFA Therapeutics pipeline candidates are investigational therapies and have not been approved by the U.S. Food and Drug Administration (FDA) or any other regulatory authority. The safety and efficacy of these therapies have not been established. The information on this website is intended for informational purposes only and should not be construed as medical advice or an offer to participate in a clinical trial. ClinicalTrials.gov Identifier: [pending registration].

For investors

Privacy Policy

SFA Therapeutics, Inc.

Effective date: 25/04/2022, Last updated: 25/04/2022

1. Introduction

SFA Therapeutics, Inc. ("SFA Therapeutics," "Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you may provide through our website located at https://sfatherapeutics.com (the "Site"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have regarding your information.

SFA Therapeutics is a clinical-stage biopharmaceutical company. The information on our Site is intended for informational purposes only and is directed primarily at investors, healthcare professionals, and the general public. We do not collect protected health information ("PHI") through the Site.

Please read this Privacy Policy carefully. By accessing or using the Site, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Site.

2. Information We Collect

2.1 Information You Provide Voluntarily

We collect personal information only when you voluntarily provide it to us. This is currently limited to:

  • Investor and Business Inquiries. If you contact us via email at our investor relations address (e.g., info@sfatherapeutics.com), we will receive your email address, your name (if provided), and any other information you include in your correspondence.

We do not operate any registration forms, user accounts, or online data submission portals on the Site that collect personal information.

2.2 Information Collected Automatically

When you visit the Site, certain information may be collected automatically by our servers and any third-party service providers, including:

  • Log Data. Your Internet Protocol ("IP") address, browser type and version, operating system, referring URL, pages visited on the Site, date and time of your visit, and time spent on each page.
  • Device Information. Information about the device you use to access the Site, including device type, screen resolution, and unique device identifiers.
  • Cookies and Similar Technologies. We may use cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.

As of the effective date of this Privacy Policy, we do not use third-party analytics platforms (such as Google Analytics) on the Site. Should this change, we will update this Privacy Policy and our Cookie Policy accordingly.

2.3 Information We Do Not Collect

We do not collect any of the following through the Site:

  • Protected health information (PHI) or medical records
  • Health conditions, diagnoses, or treatment information
  • Social Security numbers or government-issued identification numbers
  • Financial account or payment information
  • Information from minors (see Section 10 below)

3. How We Use Your Information

We use the limited personal information we collect for the following purposes:

  • Responding to Inquiries. To respond to investor relations inquiries, business partnership requests, and other correspondence you send to us.
  • Site Operations. To operate, maintain, and improve the functionality and performance of the Site.
  • Security. To detect, prevent, and address technical issues, security threats, and fraudulent or illegal activity.
  • Legal Compliance. To comply with applicable laws, regulations, legal processes, or governmental requests.

We do not use your personal information for automated decision-making or profiling.

4. Legal Bases for Processing (EEA, UK, and Swiss Visitors)

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, we process your personal data only when we have a valid legal basis to do so under the General Data Protection Regulation ("GDPR") or the UK GDPR, as applicable. Our legal bases include:

  • Legitimate Interests. We process log data and device information based on our legitimate interest in operating and securing the Site, provided such interests are not overridden by your data protection rights.
  • Consent. Where required by law (e.g., for non-essential cookies), we will obtain your prior consent before processing your personal data.
  • Legal Obligation. We may process personal data to comply with applicable legal obligations.
  • Performance of a Contract. If you engage in a contractual relationship with us, we may process personal data as necessary to perform our obligations under that contract.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

We may share your information in the following limited circumstances:

  • Service Providers. We may share personal information with third-party vendors who perform services on our behalf, such as website hosting, IT support, and email delivery. These providers are contractually obligated to use your information only as necessary to perform services for us and to maintain appropriate confidentiality and security measures.
  • Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of SFA Therapeutics, our users, or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via a prominent notice on the Site of any change in ownership or use of your personal information.
  • With Your Consent. We may share your information for other purposes with your express consent.

6. International Data Transfers

SFA Therapeutics is based in the United States. If you are visiting the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses ("SCCs") approved by the European Commission or the UK Information Commissioner's Office ("ICO"), as applicable.
  • Any other legally recognized transfer mechanism under applicable data protection laws.

By using the Site, you acknowledge that your personal data may be transferred internationally as described in this section.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Correspondence. Emails and investor inquiries are retained for as long as necessary to respond to and manage the inquiry, and thereafter as required for our legitimate business and legal purposes.
  • Log Data. Automatically collected server log data is retained for a reasonable period for security and operational purposes and is then deleted or anonymized.

When personal information is no longer needed, we will securely delete or anonymize it.

8. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information.

8.1 Rights of EEA, UK, and Swiss Residents

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") of your personal data in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Data Portability — to receive your personal data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw Consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a Complaint with your local data protection supervisory authority.

8.2 Rights of California Residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell or share.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt Out of the sale or sharing of personal information. Note: SFA Therapeutics does not sell or share personal information as defined under the CCPA/CPRA.
  • Non-Discrimination for exercising your CCPA/CPRA rights.

8.3 Rights of Residents of Other U.S. States

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights, including the right to access, delete, correct, and opt out of certain processing activities. We will honor such requests in accordance with applicable law.

8.4 Exercising Your Rights

To exercise any of the above rights, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

We will respond to verified requests within the time frames required by applicable law (generally 30 days under GDPR/UK GDPR, and 45 days under CCPA/CPRA). We may need to verify your identity before processing your request.

9. Data Security

We implement reasonable administrative, technical, and organizational measures designed to protect the personal information we collect against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Site is not directed at individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18 (or under 16 in the EEA/UK), we will take steps to delete such information promptly. If you believe that we may have collected information from a child, please contact us at jameskirwin@sfatherapeutics.com.

11. Third-Party Links

The Site may contain links to third-party websites, services, or resources that are not owned or controlled by SFA Therapeutics (for example, ClinicalTrials.gov). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party websites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify you by posting a prominent notice on the Site or through other appropriate channels.

We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

For EEA and UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 SFA Therapeutics, Inc. All rights reserved.

Resetting the immune system © 2026 SFA Therapeutics, Inc.

SFA-002 and all SFA Therapeutics pipeline candidates are investigational therapies and have not been approved by the U.S. Food and Drug Administration (FDA) or any other regulatory authority. The safety and efficacy of these therapies have not been established. The information on this website is intended for informational purposes only and should not be construed as medical advice or an offer to participate in a clinical trial. ClinicalTrials.gov Identifier: [pending registration].

For investors

Privacy Policy

SFA Therapeutics, Inc.

Effective date: 25/04/2022, Last updated: 25/04/2022

1. Introduction

SFA Therapeutics, Inc. ("SFA Therapeutics," "Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you may provide through our website located at https://sfatherapeutics.com (the "Site"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have regarding your information.

SFA Therapeutics is a clinical-stage biopharmaceutical company. The information on our Site is intended for informational purposes only and is directed primarily at investors, healthcare professionals, and the general public. We do not collect protected health information ("PHI") through the Site.

Please read this Privacy Policy carefully. By accessing or using the Site, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Site.

2. Information We Collect

2.1 Information You Provide Voluntarily

We collect personal information only when you voluntarily provide it to us. This is currently limited to:

  • Investor and Business Inquiries. If you contact us via email at our investor relations address (e.g., info@sfatherapeutics.com), we will receive your email address, your name (if provided), and any other information you include in your correspondence.

We do not operate any registration forms, user accounts, or online data submission portals on the Site that collect personal information.

2.2 Information Collected Automatically

When you visit the Site, certain information may be collected automatically by our servers and any third-party service providers, including:

  • Log Data. Your Internet Protocol ("IP") address, browser type and version, operating system, referring URL, pages visited on the Site, date and time of your visit, and time spent on each page.
  • Device Information. Information about the device you use to access the Site, including device type, screen resolution, and unique device identifiers.
  • Cookies and Similar Technologies. We may use cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.

As of the effective date of this Privacy Policy, we do not use third-party analytics platforms (such as Google Analytics) on the Site. Should this change, we will update this Privacy Policy and our Cookie Policy accordingly.

2.3 Information We Do Not Collect

We do not collect any of the following through the Site:

  • Protected health information (PHI) or medical records
  • Health conditions, diagnoses, or treatment information
  • Social Security numbers or government-issued identification numbers
  • Financial account or payment information
  • Information from minors (see Section 10 below)

3. How We Use Your Information

We use the limited personal information we collect for the following purposes:

  • Responding to Inquiries. To respond to investor relations inquiries, business partnership requests, and other correspondence you send to us.
  • Site Operations. To operate, maintain, and improve the functionality and performance of the Site.
  • Security. To detect, prevent, and address technical issues, security threats, and fraudulent or illegal activity.
  • Legal Compliance. To comply with applicable laws, regulations, legal processes, or governmental requests.

We do not use your personal information for automated decision-making or profiling.

4. Legal Bases for Processing (EEA, UK, and Swiss Visitors)

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, we process your personal data only when we have a valid legal basis to do so under the General Data Protection Regulation ("GDPR") or the UK GDPR, as applicable. Our legal bases include:

  • Legitimate Interests. We process log data and device information based on our legitimate interest in operating and securing the Site, provided such interests are not overridden by your data protection rights.
  • Consent. Where required by law (e.g., for non-essential cookies), we will obtain your prior consent before processing your personal data.
  • Legal Obligation. We may process personal data to comply with applicable legal obligations.
  • Performance of a Contract. If you engage in a contractual relationship with us, we may process personal data as necessary to perform our obligations under that contract.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

We may share your information in the following limited circumstances:

  • Service Providers. We may share personal information with third-party vendors who perform services on our behalf, such as website hosting, IT support, and email delivery. These providers are contractually obligated to use your information only as necessary to perform services for us and to maintain appropriate confidentiality and security measures.
  • Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of SFA Therapeutics, our users, or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via a prominent notice on the Site of any change in ownership or use of your personal information.
  • With Your Consent. We may share your information for other purposes with your express consent.

6. International Data Transfers

SFA Therapeutics is based in the United States. If you are visiting the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses ("SCCs") approved by the European Commission or the UK Information Commissioner's Office ("ICO"), as applicable.
  • Any other legally recognized transfer mechanism under applicable data protection laws.

By using the Site, you acknowledge that your personal data may be transferred internationally as described in this section.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Correspondence. Emails and investor inquiries are retained for as long as necessary to respond to and manage the inquiry, and thereafter as required for our legitimate business and legal purposes.
  • Log Data. Automatically collected server log data is retained for a reasonable period for security and operational purposes and is then deleted or anonymized.

When personal information is no longer needed, we will securely delete or anonymize it.

8. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information.

8.1 Rights of EEA, UK, and Swiss Residents

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") of your personal data in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Data Portability — to receive your personal data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw Consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a Complaint with your local data protection supervisory authority.

8.2 Rights of California Residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell or share.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt Out of the sale or sharing of personal information. Note: SFA Therapeutics does not sell or share personal information as defined under the CCPA/CPRA.
  • Non-Discrimination for exercising your CCPA/CPRA rights.

8.3 Rights of Residents of Other U.S. States

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights, including the right to access, delete, correct, and opt out of certain processing activities. We will honor such requests in accordance with applicable law.

8.4 Exercising Your Rights

To exercise any of the above rights, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

We will respond to verified requests within the time frames required by applicable law (generally 30 days under GDPR/UK GDPR, and 45 days under CCPA/CPRA). We may need to verify your identity before processing your request.

9. Data Security

We implement reasonable administrative, technical, and organizational measures designed to protect the personal information we collect against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Site is not directed at individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18 (or under 16 in the EEA/UK), we will take steps to delete such information promptly. If you believe that we may have collected information from a child, please contact us at jameskirwin@sfatherapeutics.com.

11. Third-Party Links

The Site may contain links to third-party websites, services, or resources that are not owned or controlled by SFA Therapeutics (for example, ClinicalTrials.gov). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party websites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify you by posting a prominent notice on the Site or through other appropriate channels.

We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

For EEA and UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 SFA Therapeutics, Inc. All rights reserved.

Resetting the immune system © 2026 SFA Therapeutics, Inc.

SFA-002 and all SFA Therapeutics pipeline candidates are investigational therapies and have not been approved by the U.S. Food and Drug Administration (FDA) or any other regulatory authority. The safety and efficacy of these therapies have not been established. The information on this website is intended for informational purposes only and should not be construed as medical advice or an offer to participate in a clinical trial. ClinicalTrials.gov Identifier: [pending registration].

For investors

Privacy Policy

SFA Therapeutics, Inc.

Effective date: 25/04/2022, Last updated: 25/04/2022

1. Introduction

SFA Therapeutics, Inc. ("SFA Therapeutics," "Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you may provide through our website located at https://sfatherapeutics.com (the "Site"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have regarding your information.

SFA Therapeutics is a clinical-stage biopharmaceutical company. The information on our Site is intended for informational purposes only and is directed primarily at investors, healthcare professionals, and the general public. We do not collect protected health information ("PHI") through the Site.

Please read this Privacy Policy carefully. By accessing or using the Site, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Site.

2. Information We Collect

2.1 Information You Provide Voluntarily

We collect personal information only when you voluntarily provide it to us. This is currently limited to:

  • Investor and Business Inquiries. If you contact us via email at our investor relations address (e.g., info@sfatherapeutics.com), we will receive your email address, your name (if provided), and any other information you include in your correspondence.

We do not operate any registration forms, user accounts, or online data submission portals on the Site that collect personal information.

2.2 Information Collected Automatically

When you visit the Site, certain information may be collected automatically by our servers and any third-party service providers, including:

  • Log Data. Your Internet Protocol ("IP") address, browser type and version, operating system, referring URL, pages visited on the Site, date and time of your visit, and time spent on each page.
  • Device Information. Information about the device you use to access the Site, including device type, screen resolution, and unique device identifiers.
  • Cookies and Similar Technologies. We may use cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.

As of the effective date of this Privacy Policy, we do not use third-party analytics platforms (such as Google Analytics) on the Site. Should this change, we will update this Privacy Policy and our Cookie Policy accordingly.

2.3 Information We Do Not Collect

We do not collect any of the following through the Site:

  • Protected health information (PHI) or medical records
  • Health conditions, diagnoses, or treatment information
  • Social Security numbers or government-issued identification numbers
  • Financial account or payment information
  • Information from minors (see Section 10 below)

3. How We Use Your Information

We use the limited personal information we collect for the following purposes:

  • Responding to Inquiries. To respond to investor relations inquiries, business partnership requests, and other correspondence you send to us.
  • Site Operations. To operate, maintain, and improve the functionality and performance of the Site.
  • Security. To detect, prevent, and address technical issues, security threats, and fraudulent or illegal activity.
  • Legal Compliance. To comply with applicable laws, regulations, legal processes, or governmental requests.

We do not use your personal information for automated decision-making or profiling.

4. Legal Bases for Processing (EEA, UK, and Swiss Visitors)

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, we process your personal data only when we have a valid legal basis to do so under the General Data Protection Regulation ("GDPR") or the UK GDPR, as applicable. Our legal bases include:

  • Legitimate Interests. We process log data and device information based on our legitimate interest in operating and securing the Site, provided such interests are not overridden by your data protection rights.
  • Consent. Where required by law (e.g., for non-essential cookies), we will obtain your prior consent before processing your personal data.
  • Legal Obligation. We may process personal data to comply with applicable legal obligations.
  • Performance of a Contract. If you engage in a contractual relationship with us, we may process personal data as necessary to perform our obligations under that contract.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

We may share your information in the following limited circumstances:

  • Service Providers. We may share personal information with third-party vendors who perform services on our behalf, such as website hosting, IT support, and email delivery. These providers are contractually obligated to use your information only as necessary to perform services for us and to maintain appropriate confidentiality and security measures.
  • Legal Requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of SFA Therapeutics, our users, or the public.
  • Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via a prominent notice on the Site of any change in ownership or use of your personal information.
  • With Your Consent. We may share your information for other purposes with your express consent.

6. International Data Transfers

SFA Therapeutics is based in the United States. If you are visiting the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses ("SCCs") approved by the European Commission or the UK Information Commissioner's Office ("ICO"), as applicable.
  • Any other legally recognized transfer mechanism under applicable data protection laws.

By using the Site, you acknowledge that your personal data may be transferred internationally as described in this section.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Correspondence. Emails and investor inquiries are retained for as long as necessary to respond to and manage the inquiry, and thereafter as required for our legitimate business and legal purposes.
  • Log Data. Automatically collected server log data is retained for a reasonable period for security and operational purposes and is then deleted or anonymized.

When personal information is no longer needed, we will securely delete or anonymize it.

8. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information.

8.1 Rights of EEA, UK, and Swiss Residents

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten") of your personal data in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Data Portability — to receive your personal data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw Consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
  • Lodge a Complaint with your local data protection supervisory authority.

8.2 Rights of California Residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell or share.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt Out of the sale or sharing of personal information. Note: SFA Therapeutics does not sell or share personal information as defined under the CCPA/CPRA.
  • Non-Discrimination for exercising your CCPA/CPRA rights.

8.3 Rights of Residents of Other U.S. States

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights, including the right to access, delete, correct, and opt out of certain processing activities. We will honor such requests in accordance with applicable law.

8.4 Exercising Your Rights

To exercise any of the above rights, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

We will respond to verified requests within the time frames required by applicable law (generally 30 days under GDPR/UK GDPR, and 45 days under CCPA/CPRA). We may need to verify your identity before processing your request.

9. Data Security

We implement reasonable administrative, technical, and organizational measures designed to protect the personal information we collect against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Site is not directed at individuals under the age of 18, and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18 (or under 16 in the EEA/UK), we will take steps to delete such information promptly. If you believe that we may have collected information from a child, please contact us at jameskirwin@sfatherapeutics.com.

11. Third-Party Links

The Site may contain links to third-party websites, services, or resources that are not owned or controlled by SFA Therapeutics (for example, ClinicalTrials.gov). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party websites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify you by posting a prominent notice on the Site or through other appropriate channels.

We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

James Kirwin, Data Protection Officer SFA Therapeutics, Inc. 610 Old York Road, Suite 400, Jenkintown, PA 19046 Email: jameskirwin@sfatherapeutics.com

For EEA and UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

© 2026 SFA Therapeutics, Inc. All rights reserved.

Resetting the immune system © 2026 SFA Therapeutics, Inc.

SFA-002 and all SFA Therapeutics pipeline candidates are investigational therapies and have not been approved by the U.S. Food and Drug Administration (FDA) or any other regulatory authority. The safety and efficacy of these therapies have not been established. The information on this website is intended for informational purposes only and should not be construed as medical advice or an offer to participate in a clinical trial. ClinicalTrials.gov Identifier: [pending registration].