GX SCIENCES PRIVACY POLICY (updated 9/1/2022)

GX Sciences, a Fagron company, is a United States based biotechnology company and laboratory specializing in the development and servicing of medical genetic testing. Our company is committed to provide the highest-quality clinical genetic interpretation and deliver accurate, clinically actionable results to help health professionals make better and more informed decisions. We are also committed to protecting your information, handling it responsibly and securing it with administrative, technical, and physical measures and safeguards. All personal information, including genetic test results, are maintained under a strict policy of confidentiality.

1. GENERAL STATEMENT

The purpose of this privacy statement is to provide transparency about GX Sciences’ point of view regarding the privacy and processing of personal data. Our goal is to demonstrate that our company handles personal data with care and in accordance with the applicable laws, guidelines, and lab certifications, included but not limited to: the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and Clinical Laboratory Improvement Amendments (CLIA). This privacy policy applies to GX Sciences which operates the gxsciences.com website and its subdomains, mylabtest123.com, and gxresults.com.

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Sites and Services and the choices you have associated with that data. We will not use or share your information with anyone except as described in this Privacy Policy. This Privacy Policy does not apply to information we collect by other means (including offline) or from other sources. The use of information collected through our Sites shall be limited to the purposes under this Privacy Policy and our Terms of Use to customers.

2. CHILDREN’S INFORMATION

Our websites are directed towards adult healthcare professionals, and are not designed for, intended to attract, or directed towards children under the age of 18. If you are under the age of 18, you must obtain the authorization of a responsible adult (parent or legal guardian) before accessing or using our websites. If we become aware that we have collected any personal information from children under 18 without appropriate authorization, we will promptly remove such information from our databases.

3. ACCEPTANCE OF THIS PRIVACY POLICY

Before you use our Services (whether you are a provider or a patient), please read our Terms of Service, and the patient’s informed consent, if applicable. By accepting the applicable Terms of Use, you agree with our privacy practices as described in this Policy. If you do not agree with the terms of this Policy, please do not access the website or use our Services.

4. USE OF PERSONAL DATA

GX Sciences’ activities as a company are primarily business-to-business. We serve different customer groups within the healthcare and wellness industry, including prescribers, hospitals and clinics. The following activities are a core part of our activities:

  • Performing internal research and product development activities.
  • Documenting our medical devices to comply with applicable laws
  • Providing nutrigenetic and pharmacogenetic testing and related services, including preparation and delivery of test reports to licensed & certified healthcare providers.
  • Performing operational activities in support of providing and obtaining payment for genetic testing services, such as billing for services our company provides and complying with laboratory regulations.
  • Conducting quality improvement activities that support medical device development and genetic testing services.

The processing of personal data is therefore only to support our business processes and is not at the core of our activities.

4.1 TYPES OF PERSONAL INFORMATION WE COLLECT AND HOW WE USE IT

Our company processes personal data of the following categories of persons, or data subjects:

  • Customers.
  • Suppliers.
  • Patients.
  • Website visitors.
  • Visitors.
  • Employees & applicants, which are out of scope in this Privacy statement.
4.2 Information collected from customers

GX Sciences serves different customer groups within the healthcare industry, including individual prescribers, hospitals, and clinics. In order to provide the Services requested (including billing, etc.), we will mainly collect and process the following personal information:

  • Personal details (including name, address)
  • Contact details (Phone, fax, and email address)
  • Business address and department
  • Payment information (where provided)
  • Healthcare professional medical license information (where provided)

Such personal information will be processed to inform the customer of the patient’s test results, any other requests from the customer, and for invoicing. All of such processing is for the purpose of performing a contract as between Fagron Genomics and the customer to provide the Services.
We may also use the personal information to share marketing information about our Services, and to do so, we may process your contact information or information about your interaction with our Services to send you marketing communications, provide you with information about events, webinars, or other materials, deliver targeted marketing to you, and keep you updated about our Services. You can opt-out of our marketing activities at any time by using the “unsubscribe” link in any email communications or by contacting info@fagrongenomics.com.
We will never share your contact details with any third parties

4.3 Information collected from suppliers

Fagron Genomics collects and processes the following personal information of suppliers to guarantee a correct handling of the ordering process and fulfil its contractual obligations the suppliers:
• Name of supplier representative
• Contact details (Phone, fax, and email address)
• Job title
• Business address and department
• Payment information (where provided)

4.4 Information collected from patients

Patients are a special category of data subjects for Fagron Genomics because of the high sensitivity of health information. Through our medical questionnaire filled by the healthcare provider and the informed consent provided by the patient, we collect and process the following personal information of the patient:
• Personal details (name, family name(s), age)
• Gender
• Ethnicity (if applicable)
• Relevant medical information (intolerance, allergy, medication, biomarker profile, lifestyle, etc)
• Biological sample
• Genetic test results and findings
We collect and process this information of individual patients with the only purposes of:
1) complying with the Catalan decree 76/1995 that defines the minimal content of a patient report (name, family name, age, prescriber).
2) including relevant medical information in our medical algorithms to generate safe and accurate recommendations.
After complying with the minimum retention period, the patient could solicitate the elimination of its records and sample. If not, data and sample may be used in an anonymized manner for research or set up purposes. Fagron Genomics will never share patient’s personal information, genetic data or results with any third parties.

4.5 Anonymous information collected from website visitors

When you use our website, our third-party service and analytics providers may collect Web-Behavior Information about your visit, such as the links you clicked on, the duration of your visit, and the URLs you visited. More specifically, we use cookies and other tracking technologies to personalize your experience and to help us improve site navigability and assess our Marketing campaigns. Our servers automatically record information created by your use of our website and we use visitor logs to compile anonymous statistics.
Some browsers incorporate a “Do Not Track” (DNT) or similar feature that signals to digital services that a visitor doesn’t want to have their online activity tracked. Because there is not yet an accepted standard for how to respond to DNT signals, we and our service providers (like many digital service operators) do not respond to DNT signals.

4.6 Personal information provided voluntarily

We collect any personal information that you voluntarily provide to use, such as inquiries through our Main Website for further information about our Services. This information is used only for the purpose of addressing the request received. In cases where social media services may be used, we do not have any influence on the storage and processing of providing personal information via the respective social media service. You are encouraged to review those privacy policies before sending us personal information via a social media service.

4.7 Information collected from visitors

Fagron Genomics processes the personal data of visitors to ensure security and safety within its installations and to identify individuals in case of misconduct. Delimiting physical security perimeter and controls is a requirement of the ISO/IEC 27001 standard that provides a globally recognised framework for best-practice information security management. Fagron Genomics collects and processes the following personal information of visitors:
• Personal information (name, ID card number, company if applicable)
• Contact information
• Video image

5. SECURITY PRECAUTIONS

Fagron Genomics takes appropriate technical, administrative and physical security measures to protect information contained in our system against misuse, loss or alteration. Information that you provide through our website is encrypted using industry-standard Secure Sockets Layer (SSL) technology, with the exception of information you send via email. Your information is processed and stored on controlled servers with restricted access. All personal information (genetic or otherwise) is encrypted when stored on our servers and is always transmitted over secure protocols. Despite these efforts, we cannot guarantee that our security measures will be able to completely defeat all unauthorized accesses attempts.

6. DATA PROCESSING AND TRANSFERS

Fagron Genomics uses external servers for a number of supporting activities. We only use servers that provide sufficient guarantees of appropriate technical and organizational measures for security. In case personal data is being processed on an external server, there is always a processing agreement in place.
When you use or interact with any services offered through our sites, you consent to the data processing, sharing, transferring and uses of your information as outlined in this Privacy Policy. Regardless of the country where you reside, you authorize us to transfer, process, store and use your information in countries other than your own in accordance with this Privacy Policy and to provide you with Services.
We may process information related to individuals in the EU and may transfer that information from the EU by using various compliance mechanisms, including informed consent and/or data processing agreements based on EU approved language. By using our Sites and Services, you consent to us transferring information about you as needed.
Some of these countries may not have the same legal data protection safeguards as the country where you reside.We may store, process and transmit personal information in locations around the world, including locations outside of the country or jurisdiction where you are located.

7. RETENTION TIME

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Time duration up to which personal data are kept is be decided taking into consideration requirements for analysis of data (frequency), Audit requirements, Statutory and regulatory requirements. Minimum retention periods are specified below:

Type of data Minimum retention period
Information collected from customers 5 years from the date of the last patient report
Information collected from suppliers 5 years after last supplied product or service
Information collected from patients:
Personal data of patients
Genetic data of patients 5 years from the date of the patient report
Patient reports
Sample of patients
Anonymous information from website visitors 3 to 12 months
Personal information provided voluntarily 3 years
Information collected from visitors 3 years

Due to regulatory requirement, personal genetic data shall be kept during a period of no less than five years from the date in which they were obtained. The minimum retention period of related data has been adjusted to this requirement.

8. YOUR LEGAL RIGHTS

Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:
Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request rectification of your personal data. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to processing of your personal data. You may request to restrict your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdraw consent to process your personal data. You may object to the processing of your personal data on grounds related to your particular situation. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the rights set out above, please contact our customer service at info@fagrongenomics.com.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data or to exercise any of your other rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may refuse to comply with your request if your request is clearly unfounded, repetitive or excessive.

9. CHANGES TO PRIVACY POLICY

This Privacy Policy may be revised from time to time as we add new features and services, as laws change, and as industry privacy and security best practices evolve. We display an effective date on the policy in the upper right corner of this Privacy Policy so that it will be easier for you to know when there has been a change.