Privacy Policy

Privacy
Policy

Privacy Policy Hudson River Biotechnology B.V. Last updated: 21 August 2026 1. Introduction This Privacy Policy explains how Hudson River Biotechnology B.V. (“Hudson River Biotechnology”, “HRB”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit hudsonriver.bio (the “Website”) or otherwise interact with us. It also sets out your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, “UAVG”). This policy is an information notice provided under Articles 13 and 14 GDPR. It is not a contract, and visiting the Website does not by itself constitute consent to any processing. Where we rely on your consent — for marketing emails, and for analytics and advertising cookies — we ask for it separately and specifically, and you can withdraw it at any time. 2. Who we are (Data Controller) For the purposes of the GDPR, the data controller is: Hudson River Biotechnology B.V. Nieuwe Kanaal 7V, 6709 PA Wageningen, The Netherlands Chamber of Commerce (KvK) number: 63335611 For any privacy question or to exercise your rights, contact us at media@hudsonriver.bio. We have not appointed a Data Protection Officer, as one is not required for processing of this kind. Privacy questions are handled by the contact above. 3. Definitions Personal data – any information relating to an identified or identifiable person (including a named individual at a company). Processing – any operation performed on personal data (collecting, storing, using, sharing, deleting, etc.). Data subject – the person the personal data relates to; in this policy, “you”. Controller – the party that decides why and how personal data is processed. Joint controllers – two or more controllers that together decide why and how personal data is processed (see section 9). Processor – a third party that processes personal data on our behalf and on our instructions only. Usage data – data collected automatically through your use of the Website (e.g. IP address, pages visited, duration of a visit). Cookies and similar technologies – small files, tags and pixels placed on or read from your device that store or collect information about your visit. 4. The personal data we collect 4.1 Data you provide to us Email and other direct enquiries: your name, email address and anything else you choose to include in your message. Where the Website offers a contact form, the fields marked on that form. Newsletter sign-up. The only information we need is your email address — without it we cannot send you the newsletter. You may also choose to tell us your name, company, job title and industry. These fields are optional, you can subscribe without them, and we use them only to make the content we send you more relevant to your work. On any form we use, required fields are marked as such. Everything else is optional: you can leave it blank and still use the form. The only consequence of leaving an optional field empty is that we may not be able to tailor what we send you. 4.2 Data collected automatically When you use the Website we collect usage data: IP address, browser type and version, device information, the pages you visit, the referring page, and the date, time and duration of your visit. Some of this is collected through server logs, which are necessary to run and secure the Website. The rest is collected through cookies and similar technologies, and only where you have consented — see section 8. We do not intend to collect special categories of personal data (Article 9 GDPR) through the Website, and we ask that you do not include such data in messages to us. Hudson River Biotechnology's science concerns plant genetics; we do not process human genetic data through the Website. 5. How we use your data, and our legal basis We only use your personal data where the GDPR gives us a lawful basis to do so. The table below maps each purpose to the data used and the legal basis relied on. Purpose Data used Legal basis (Art. 6 GDPR) Responding to and managing enquiries you send us Contact details, message content Legitimate interests — dealing with people who contact us (Art. 6(1)(f)); or steps prior to a contract at your request (Art. 6(1)(b)) Sending our newsletter and marketing communications Email address (required); name, company, job title, industry (optional) Consent (Art. 6(1)(a)) — given via a separate, unticked opt-in box and confirmed by email. Withdrawable at any time. Operating and securing the Website IP address, server logs, essential cookies Legitimate interests — a secure, functional site (Art. 6(1)(f)) Measuring and analysing how the Website is used Usage data via analytics cookies Consent (Art. 6(1)(a)) + Art. 11.7a Telecommunicatiewet / Art. 5(3) ePrivacy Directive Advertising: measuring our campaigns, and showing you our ads on other platforms (retargeting) Usage data and identifiers via marketing cookies and tags Consent (Art. 6(1)(a)) + Art. 11.7a Telecommunicatiewet. See section 9 on who is responsible for what. Complying with our legal obligations As required by law Legal obligation (Art. 6(1)(c)) Establishing or defending legal claims; business transfers As relevant Legitimate interests (Art. 6(1)(f)) 6. Our legitimate interests Where we rely on legitimate interests, those interests are: responding to and managing enquiries; keeping the Website secure and available; managing our business and business relationships; and establishing or defending legal claims. We weigh these interests against your rights and only rely on this basis where your interests do not override them. You can object at any time (see section 13). We do not rely on legitimate interests for analytics or advertising — those depend on your consent. 7. Direct marketing We send marketing emails only to people who have opted in, and we confirm each sign-up by email before adding you to our list. Every marketing email contains an unsubscribe link, and withdrawing your consent is as easy as giving it. You can also object or unsubscribe by contacting us. If you unsubscribe, we may still contact you for non-marketing reasons — for example, to answer a question you have sent us. 8. Cookies and similar technologies We place strictly necessary cookies — those needed to run and secure the Website, and to remember your consent choice — without consent, as permitted by Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet). All other cookies and similar technologies — analytics and advertising — are placed only after you have given your prior consent through our cookie banner. Nothing non-essential is set before you choose. Refusing is as easy as accepting, and you can change or withdraw your choices at any time via the “Cookie settings” link in the footer of the Website. Withdrawing consent does not affect anything done beforehand. Tool Provider & role Purpose Category Cookiebot Usercentrics A/S — processor (EU) Shows the cookie banner and records your consent choices. Necessary Google Tag Manager Google Ireland Limited — processor Manages and loads the tags below. Tags fire only in line with your consent choices. Necessary (container only) Google Analytics 4 Google Ireland Limited — processor Measures how visitors find and use the Website so we can improve it. Analytics — consent Google Ads (conversion tracking) Google Ireland Limited — independent controller Measures the performance of our ad campaigns. Marketing — consent LinkedIn Insight Tag LinkedIn Ireland Unlimited Company — joint controller Measures our ad campaigns and lets us show ads to Website visitors on LinkedIn. Marketing — consent A full list of the individual cookies set on the Website, with their provider, purpose and lifespan, is available at any time via the “Details” view of our cookie banner. 9. Our advertising tools: who is responsible for what Advertising tools are not all alike, and the law treats them differently depending on who decides what happens to the data. We think it is worth being precise about this. LinkedIn Insight Tag — joint controllers For the LinkedIn Insight Tag, we and LinkedIn Ireland Unlimited Company act as joint controllers under Article 26 GDPR for the collection of your data on the Website and its transmission to LinkedIn. This reflects the Court of Justice of the European Union's ruling in Fashion ID (C-40/17). In practice: we decide to place the tag and define the audiences we want to reach; LinkedIn decides how the tag operates and what it does with the data afterwards. Once LinkedIn receives the data it also uses it for its own purposes as an independent controller, which we neither control nor have access to. Because we are joint controllers, you can exercise your GDPR rights against either of us, regardless of how we have divided responsibilities between ourselves. The essence of our arrangement with LinkedIn is set out in the LinkedIn Ads Agreement and its data protection terms: linkedin.com/legal/sas-terms Google Ads — independent controllers For Google Ads conversion tracking, Google Ireland Limited acts as an independent controller under the Google Ads Controller-Controller Data Protection Terms, rather than on our instructions. This means each of us is separately responsible for our own processing. To exercise your rights against Google, see the Google Privacy Policy: policies.google.com/privacy. Google Analytics and Google Tag Manager — processors For website analytics and tag management, Google Ireland Limited acts as our processor under the Google Ads Data Processing Terms, handling data only on our instructions. If you would rather none of the advertising tools ran, refuse marketing cookies in our banner. They will not load. 10. Who we share your data with Beyond the parties named in section 9, we share personal data with: Recipient What they do for us Location Transfer safeguard Vercel Inc. Hosts and delivers the Website United States EU–US Data Privacy Framework + Standard Contractual Clauses Amazon Web Services, Inc. Underlying cloud infrastructure used by Vercel (sub-processor) United States / EU regions EU–US Data Privacy Framework + Standard Contractual Clauses Usercentrics A/S (Cookiebot) Runs the cookie banner and stores consent records European Union None needed — data stays in the EU Google Ireland Limited (and Google LLC) Tag management and website analytics Ireland; United States EU–US Data Privacy Framework + Standard Contractual Clauses The Rocket Science Group LLC d/b/a Mailchimp (an Intuit company) Sends our newsletter and stores subscriber records United States EU–US Data Privacy Framework + Standard Contractual Clauses HubSpot, Inc. Manages our contacts and enquiries (CRM) United States EU–US Data Privacy Framework + Standard Contractual Clauses Each processor acts only on our instructions and under an Article 28 data processing agreement. We may also share data with professional advisers where necessary, with public authorities where we are required to by law, and with a buyer or successor entity in the event of a merger, acquisition or reorganisation. We do not sell your personal data. 11. International transfers As the table in section 10 shows, some of our providers process personal data outside the European Economic Area (EEA), primarily in the United States. Where that happens, we rely on an appropriate transfer mechanism under Chapter V GDPR: the European Commission's EU–US Data Privacy Framework adequacy decision of 10 July 2023, where the recipient is certified under it; and/or the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with any supplementary measures identified by a transfer impact assessment. Our cookie banner provider, Cookiebot (Usercentrics A/S), processes consent records within the EU, so no transfer safeguard is needed for that data. You can request a copy of the relevant safeguards using the contact details in section 18. 12. How long we keep your data We keep personal data only for as long as necessary for the purposes set out above: Enquiry and contact data: up to 24 months after our last contact with you. Newsletter data: until you unsubscribe, then deleted within 30 days (we keep a minimal suppression record so we do not email you again). Consent records: kept for as long as we rely on the consent, and for a reasonable period afterwards so we can demonstrate it was given. Cookie and analytics data: for the lifespan of the relevant cookie, as set out in the “Details” view of our cookie banner. Records we must keep by law (e.g. financial and tax records): 7 years, under Dutch tax law. Where no fixed period applies, we determine retention based on the nature and sensitivity of the data, the purpose, and any legal or contractual requirement. 13. Your rights Under the GDPR you have the right to: access your personal data and receive a copy; have inaccurate or incomplete data corrected (rectification); have your data erased (the “right to be forgotten”) where there is no lawful reason for us to keep it; restrict our processing in certain circumstances; data portability – receive certain data in a structured, commonly used, machine-readable format; object to processing based on our legitimate interests, and to object to direct marketing at any time; withdraw consent at any time, where processing is based on consent, without affecting processing carried out beforehand. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such automated decision-making. To exercise any of these rights, contact us at media@hudsonriver.bio. We may need to verify your identity. We will respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you if we do. Exercising your rights is free of charge. Right to complain: you can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority in your EU country of residence. 14. Children The Website is not directed at children. We do not knowingly collect personal data from children under 16 — the age of digital consent in the Netherlands under the UAVG. If you believe a child has provided us with personal data, please contact us and we will delete it. 15. Security We implement appropriate technical and organisational measures to protect personal data, as required by Article 32 GDPR. These include encryption of data in transit (HTTPS/TLS), hosting with providers that maintain recognised security certifications (our host, Vercel, holds ISO 27001 and SOC 2 Type 2 attestations), access controls limiting who at HRB can see personal data, and confidentiality obligations on our staff. No method of transmission or storage is completely secure, but we take reasonable steps to keep your data safe. 16. Links to other websites The Website may link to sites we do not operate, including our LinkedIn page. If you follow such a link, we are not responsible for the content or privacy practices of that site, and we encourage you to read its privacy policy. 17. Changes to this policy We may update this policy from time to time — for example, when we add or remove a tool. We will post the updated version here with a new “last updated” date. For material changes we will display a notice on the Website and, where appropriate, notify newsletter subscribers by email. 18. Contact If you have any questions about this Privacy Policy or how we handle your data, contact us at media@hudsonriver.bio, or by post at Hudson River Biotechnology B.V., Nieuwe Kanaal 7V, 6709 PA Wageningen, The Netherlands.

Privacy Policy

Hudson River Biotechnology B.V.

Last updated: 21 August 2026

1. Introduction

This Privacy Policy explains how Hudson River Biotechnology B.V. (“Hudson River Biotechnology”, “HRB”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit hudsonriver.bio (the “Website”) or otherwise interact with us. It also sets out your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, “UAVG”).

This policy is an information notice provided under Articles 13 and 14 GDPR. It is not a contract, and visiting the Website does not by itself constitute consent to any processing. Where we rely on your consent — for marketing emails, and for analytics and advertising cookies — we ask for it separately and specifically, and you can withdraw it at any time.

2. Who we are (Data Controller)

For the purposes of the GDPR, the data controller is:

Hudson River Biotechnology B.V.

Nieuwe Kanaal 7V, 6709 PA Wageningen, The Netherlands

Chamber of Commerce (KvK) number: 63335611

For any privacy question or to exercise your rights, contact us at media@hudsonriver.bio.

We have not appointed a Data Protection Officer, as one is not required for processing of this kind. Privacy questions are handled by the contact above.

3. Definitions

  • Personal data – any information relating to an identified or identifiable person (including a named individual at a company).
  • Processing – any operation performed on personal data (collecting, storing, using, sharing, deleting, etc.).
  • Data subject – the person the personal data relates to; in this policy, “you”.
  • Controller – the party that decides why and how personal data is processed.
  • Joint controllers – two or more controllers that together decide why and how personal data is processed (see section 9).
  • Processor – a third party that processes personal data on our behalf and on our instructions only.
  • Usage data – data collected automatically through your use of the Website (e.g. IP address, pages visited, duration of a visit).
  • Cookies and similar technologies – small files, tags and pixels placed on or read from your device that store or collect information about your visit.

4. The personal data we collect

4.1 Data you provide to us

  • Email and other direct enquiries: your name, email address and anything else you choose to include in your message. Where the Website offers a contact form, the fields marked on that form.
  • Newsletter sign-up. The only information we need is your email address — without it we cannot send you the newsletter. You may also choose to tell us your name, company, job title and industry. These fields are optional, you can subscribe without them, and we use them only to make the content we send you more relevant to your work.

On any form we use, required fields are marked as such. Everything else is optional: you can leave it blank and still use the form. The only consequence of leaving an optional field empty is that we may not be able to tailor what we send you.

4.2 Data collected automatically

When you use the Website we collect usage data: IP address, browser type and version, device information, the pages you visit, the referring page, and the date, time and duration of your visit. Some of this is collected through server logs, which are necessary to run and secure the Website. The rest is collected through cookies and similar technologies, and only where you have consented — see section 8.

We do not intend to collect special categories of personal data (Article 9 GDPR) through the Website, and we ask that you do not include such data in messages to us. Hudson River Biotechnology's science concerns plant genetics; we do not process human genetic data through the Website.

5. How we use your data, and our legal basis

We only use your personal data where the GDPR gives us a lawful basis to do so. The table below maps each purpose to the data used and the legal basis relied on.

Purpose

Data used

Legal basis (Art. 6 GDPR)

Responding to and managing enquiries you send us

Contact details, message content

Legitimate interests — dealing with people who contact us (Art. 6(1)(f)); or steps prior to a contract at your request (Art. 6(1)(b))

Sending our newsletter and marketing communications

Email address (required); name, company, job title, industry (optional)

Consent (Art. 6(1)(a)) — given via a separate, unticked opt-in box and confirmed by email. Withdrawable at any time.

Operating and securing the Website

IP address, server logs, essential cookies

Legitimate interests — a secure, functional site (Art. 6(1)(f))

Measuring and analysing how the Website is used

Usage data via analytics cookies

Consent (Art. 6(1)(a)) + Art. 11.7a Telecommunicatiewet / Art. 5(3) ePrivacy Directive

Advertising: measuring our campaigns, and showing you our ads on other platforms (retargeting)

Usage data and identifiers via marketing cookies and tags

Consent (Art. 6(1)(a)) + Art. 11.7a Telecommunicatiewet. See section 9 on who is responsible for what.

Complying with our legal obligations

As required by law

Legal obligation (Art. 6(1)(c))

Establishing or defending legal claims; business transfers

As relevant

Legitimate interests (Art. 6(1)(f))

6. Our legitimate interests

Where we rely on legitimate interests, those interests are: responding to and managing enquiries; keeping the Website secure and available; managing our business and business relationships; and establishing or defending legal claims. We weigh these interests against your rights and only rely on this basis where your interests do not override them. You can object at any time (see section 13). We do not rely on legitimate interests for analytics or advertising — those depend on your consent.

7. Direct marketing

We send marketing emails only to people who have opted in, and we confirm each sign-up by email before adding you to our list. Every marketing email contains an unsubscribe link, and withdrawing your consent is as easy as giving it. You can also object or unsubscribe by contacting us. If you unsubscribe, we may still contact you for non-marketing reasons — for example, to answer a question you have sent us.

8. Cookies and similar technologies

We place strictly necessary cookies — those needed to run and secure the Website, and to remember your consent choice — without consent, as permitted by Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet).

All other cookies and similar technologies — analytics and advertising — are placed only after you have given your prior consent through our cookie banner. Nothing non-essential is set before you choose. Refusing is as easy as accepting, and you can change or withdraw your choices at any time via the “Cookie settings” link in the footer of the Website. Withdrawing consent does not affect anything done beforehand.

Tool

Provider & role

Purpose

Category

Cookiebot

Usercentrics A/S — processor (EU)

Shows the cookie banner and records your consent choices.

Necessary

Google Tag Manager

Google Ireland Limited — processor

Manages and loads the tags below. Tags fire only in line with your consent choices.

Necessary (container only)

Google Analytics 4

Google Ireland Limited — processor

Measures how visitors find and use the Website so we can improve it.

Analytics — consent

Google Ads (conversion tracking)

Google Ireland Limited — independent controller

Measures the performance of our ad campaigns.

Marketing — consent

LinkedIn Insight Tag

LinkedIn Ireland Unlimited Company — joint controller

Measures our ad campaigns and lets us show ads to Website visitors on LinkedIn.

Marketing — consent

A full list of the individual cookies set on the Website, with their provider, purpose and lifespan, is available at any time via the “Details” view of our cookie banner.

9. Our advertising tools: who is responsible for what

Advertising tools are not all alike, and the law treats them differently depending on who decides what happens to the data. We think it is worth being precise about this.

LinkedIn Insight Tag — joint controllers

For the LinkedIn Insight Tag, we and LinkedIn Ireland Unlimited Company act as joint controllers under Article 26 GDPR for the collection of your data on the Website and its transmission to LinkedIn. This reflects the Court of Justice of the European Union's ruling in Fashion ID (C-40/17). In practice: we decide to place the tag and define the audiences we want to reach; LinkedIn decides how the tag operates and what it does with the data afterwards. Once LinkedIn receives the data it also uses it for its own purposes as an independent controller, which we neither control nor have access to.

Because we are joint controllers, you can exercise your GDPR rights against either of us, regardless of how we have divided responsibilities between ourselves. The essence of our arrangement with LinkedIn is set out in the LinkedIn Ads Agreement and its data protection terms: linkedin.com/legal/sas-terms

Google Ads — independent controllers

For Google Ads conversion tracking, Google Ireland Limited acts as an independent controller under the Google Ads Controller-Controller Data Protection Terms, rather than on our instructions. This means each of us is separately responsible for our own processing. To exercise your rights against Google, see the Google Privacy Policy: policies.google.com/privacy.

Google Analytics and Google Tag Manager — processors

For website analytics and tag management, Google Ireland Limited acts as our processor under the Google Ads Data Processing Terms, handling data only on our instructions.

If you would rather none of the advertising tools ran, refuse marketing cookies in our banner. They will not load.

10. Who we share your data with

Beyond the parties named in section 9, we share personal data with:

Recipient

What they do for us

Location

Transfer safeguard

Vercel Inc.

Hosts and delivers the Website

United States

EU–US Data Privacy Framework + Standard Contractual Clauses

Amazon Web Services, Inc.

Underlying cloud infrastructure used by Vercel (sub-processor)

United States / EU regions

EU–US Data Privacy Framework + Standard Contractual Clauses

Usercentrics A/S (Cookiebot)

Runs the cookie banner and stores consent records

European Union

None needed — data stays in the EU

Google Ireland Limited (and Google LLC)

Tag management and website analytics

Ireland; United States

EU–US Data Privacy Framework + Standard Contractual Clauses

The Rocket Science Group LLC d/b/a Mailchimp (an Intuit company)

Sends our newsletter and stores subscriber records

United States

EU–US Data Privacy Framework + Standard Contractual Clauses

HubSpot, Inc.

Manages our contacts and enquiries (CRM)

United States

EU–US Data Privacy Framework + Standard Contractual Clauses

Each processor acts only on our instructions and under an Article 28 data processing agreement. We may also share data with professional advisers where necessary, with public authorities where we are required to by law, and with a buyer or successor entity in the event of a merger, acquisition or reorganisation.

We do not sell your personal data.

11. International transfers

As the table in section 10 shows, some of our providers process personal data outside the European Economic Area (EEA), primarily in the United States. Where that happens, we rely on an appropriate transfer mechanism under Chapter V GDPR:

  • the European Commission's EU–US Data Privacy Framework adequacy decision of 10 July 2023, where the recipient is certified under it; and/or
  • the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with any supplementary measures identified by a transfer impact assessment.

Our cookie banner provider, Cookiebot (Usercentrics A/S), processes consent records within the EU, so no transfer safeguard is needed for that data.

You can request a copy of the relevant safeguards using the contact details in section 18.

12. How long we keep your data

We keep personal data only for as long as necessary for the purposes set out above:

  • Enquiry and contact data: up to 24 months after our last contact with you.
  • Newsletter data: until you unsubscribe, then deleted within 30 days (we keep a minimal suppression record so we do not email you again).
  • Consent records: kept for as long as we rely on the consent, and for a reasonable period afterwards so we can demonstrate it was given.
  • Cookie and analytics data: for the lifespan of the relevant cookie, as set out in the “Details” view of our cookie banner.
  • Records we must keep by law (e.g. financial and tax records): 7 years, under Dutch tax law.

Where no fixed period applies, we determine retention based on the nature and sensitivity of the data, the purpose, and any legal or contractual requirement.

13. Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy;
  • have inaccurate or incomplete data corrected (rectification);
  • have your data erased (the “right to be forgotten”) where there is no lawful reason for us to keep it;
  • restrict our processing in certain circumstances;
  • data portability – receive certain data in a structured, commonly used, machine-readable format;
  • object to processing based on our legitimate interests, and to object to direct marketing at any time;
  • withdraw consent at any time, where processing is based on consent, without affecting processing carried out beforehand.

You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such automated decision-making.

To exercise any of these rights, contact us at media@hudsonriver.bio. We may need to verify your identity. We will respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you if we do. Exercising your rights is free of charge.

Right to complain: you can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority in your EU country of residence.

14. Children

The Website is not directed at children. We do not knowingly collect personal data from children under 16 — the age of digital consent in the Netherlands under the UAVG. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Security

We implement appropriate technical and organisational measures to protect personal data, as required by Article 32 GDPR. These include encryption of data in transit (HTTPS/TLS), hosting with providers that maintain recognised security certifications (our host, Vercel, holds ISO 27001 and SOC 2 Type 2 attestations), access controls limiting who at HRB can see personal data, and confidentiality obligations on our staff.

No method of transmission or storage is completely secure, but we take reasonable steps to keep your data safe.

16. Links to other websites

The Website may link to sites we do not operate, including our LinkedIn page. If you follow such a link, we are not responsible for the content or privacy practices of that site, and we encourage you to read its privacy policy.

17. Changes to this policy

We may update this policy from time to time — for example, when we add or remove a tool. We will post the updated version here with a new “last updated” date. For material changes we will display a notice on the Website and, where appropriate, notify newsletter subscribers by email.

18. Contact

If you have any questions about this Privacy Policy or how we handle your data, contact us at media@hudsonriver.bio, or by post at Hudson River Biotechnology B.V., Nieuwe Kanaal 7V, 6709 PA Wageningen, The Netherlands.


© 2026 Hudson River Biotechnology

Privacy Policy - Hudson River Biotechnology