Data Privacy Policy
Effective Date: April 15, 2026
Disclaimer Regarding Changes to This Policy: We may update this Data Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page. We encourage you to review this Data Privacy Policy periodically. Your continued use of the Website following the posting of changes constitutes your acceptance of such changes.
1. General
1.1. Biofrontera Inc., 660 Main Street, First Floor, Woburn, MA 01801 ("Biofrontera," "we," "us," or "our") is committed to protecting the privacy of individuals who visit our website at biofrontera-us.com and any related subdomains or successor URLs (collectively, the “Website”). This Data Privacy Policy describes how we collect, use, store, and disclose personal information in connection with your use of the Website, and the choices available to you regarding our use of your personal information.
1.2. As a user of our website please note that you may be forwarded by links to other internet sites operated by third parties. Such links are either clearly marked or can be identified by a change to the address bar of your browser. We are not responsible for those internet sites and the fact whether they comply with the applicable legal provisions or not and whether their carriers handle your personal data carefully or not.
2. Personal Information
As used in this Data Privacy Policy, "personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identifiable individual, including but not limited to name, postal address, email address, telephone number, and IP address.
3. Third-Party Service Providers
We may engage third-party service providers to host, maintain, or support the operation of this website. These service providers may have access to personal data collected through this website solely for the purpose of performing services on our behalf and are contractually obligated to maintain the confidentiality and security of such data.
4. Data Storage and Location
4.1. Personal data collected through this website is stored on servers located in the United States. If you are accessing this website from outside the United States, please be aware that your personal data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using this website, you consent to the transfer of your personal data to the United States.
4.2. In certain circumstances, your personal data may also be shared with our affiliated entities located in the European Union for legitimate business purposes, including corporate administration and reporting. Such transfers are made in accordance with applicable data protection laws.
5. Processing of Personal Data by Biofrontera
The use of our website is possible without the disclosure of your identity to Biofrontera neither partially nor completely. You need to disclose your identity if you want to contact us. In this case we will process your personal data only for the purpose of processing your petition. Your personal data is not forwarded or in any other way transferred to third parties unless it is necessary for the processing of your petition or in case it is explicitly allowed by law.
6. Data Retention; Cookies; Third Party Analytics
6.1. Our website is provided by a specialized computer (“Server”) which collects and stores information in a server log (“Log Files”) every time the website is requested. Those pieces of information are (a) browser type and version, (b) the operating system used, (c) the previous website visited, (d) the IP address of the computer through which the website is accessed, and (e) the request’s time stamp. This information is transmitted by your browser unless you disabled the transfer of this information, in case by using a browser add-on. When you access our website, the data stored in the log files cannot be used by us to be attributed to a specific user. This data is not used by Biofrontera in conjunction with any other data from any other sources. Server Log Files are deleted automatically after ninety (90) days, at most. Personal data submitted through contact forms or other direct communications is retained only as long as necessary to fulfill the purpose for which it was provided, unless a longer retention period is required or permitted by law.
6.2. This website uses cookies to facilitate site functionality and to analyze website traffic. Cookies are small text files stored on your device by your browser.
6.3. We use Google Analytics to analyze website traffic. Google Analytics uses cookies to collect information about your use of this website. You may opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on.
7. Data Security
We use commercially reasonable technical and organizational measures, including encryption of data in transit via TLS/SSL, to protect personal data collected through this website against unauthorized access, loss, destruction, or alteration. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. This website does not currently respond to 'Do Not Track' browser signals. For more information about Do Not Track, visit https://allaboutdnt.com.
8. State-Specific Privacy Rights
8.1. California Residents. If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with certain rights regarding your personal information. These include the right to know what personal information we collect, use, and disclose; the right to request deletion of your personal information; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of your personal information. Biofrontera does not sell or share personal information as those terms are defined under the CCPA. To exercise your rights, contact us by using the contact information in Section 11 of this Data Privacy Policy. We will respond to verifiable consumer requests within forty-five (45) days.
8.2. Other State Privacy Laws. Residents of Virginia, Colorado, Connecticut, Texas, Oregon, and other states with comprehensive privacy legislation may have similar rights under applicable state law, including rights of access, correction, deletion, and opt-out. To exercise any rights available to you under your state's privacy law, please contact us by using the contact information in Section 11 of this Data Privacy Policy.
9. Children's Privacy
This website is not directed to children under the age of thirteen (13), and Biofrontera does not knowingly collect personal information from children under thirteen. If we become aware that we have inadvertently collected personal information from a child under thirteen, we will take reasonable steps to delete such information promptly. If you believe that a child under thirteen has provided personal information to us through this website, please contact us by using the contact information in Section 11 of this Data Privacy Policy.
10. Right to Information
10.1. If you have any further questions concerning data protection not answered by this data privacy policy please feel free to contact us! In accordance with the relevant legal provisions, we make information available to you at all times, free of charge and without delay, on personal data processed by us.
10.2. In case of questions concerning our use of your personal data or about how we process personal data and in case of petitions for deletion or correction of personal data processed by us by using the contact information in Section 11 of this Data Privacy Policy.
11. Contact Us.
If you have questions or concerns about this Data Privacy Policy or our data practices, please contact us at:
Biofrontera Inc.
660 Main Street, First Floor
Woburn, MA 01801
compliance@bfinc.com