At My-dna.health, your privacy is a top priority. My-dna.health
is committed to being a good steward of your Personal Information, handling it
in a responsible manner, and securing it with administrative, technical, and
physical safeguards.
We also believe in being honest, direct and
transparent when it comes to your data. My-dna.health follows three guiding
principles when it comes to your privacy:
- Transparency. We work hard to be transparent about what Personal Information we collect and process.
- Simplicity. We try to use easy-to-understand language to describe our privacy practices to help you make informed choices.
- Control. We give you control over the Personal Information you provide to us - how it is used and retained.
Other Important Things for You to Understand When You
Use Our Services
You can manage and delete your data as described in
this Privacy Policy.
You may discover unexpected facts about yourself or
your family when using our services. Once discoveries are made, we can’t undo
them.
When you make new discoveries with us, you should feel
confident and informed about how we use your Personal Information. Our full
Privacy Policy is below and we encourage you to read it.
We will not use your sensitive information without
your consent unless: (i) the information has been anonymized or aggregated so
that you cannot reasonably be identified as an individual; or (ii) a legal
obligation requires us to use it in some way e.g. a court order requires us to
disclose the information.
All information in this GDPR document is applicable
for My-dna.health and our exclusive DNA partner based in Slovenia.
SUMMARY REGARDING PRIVACY POLICY AND PERSONAL
INFORMATION
- By agreeing to our Privacy Policy and General Terms & Conditions, you consent to the storing and processing of your personal information, including sensitive information, in the Slovenia and countries outside of the country you live in. We use a range of measures to safeguard information, but these countries may have laws that are different from those of your country of residence. You also consent to your personal information, including sensitive information, being transferred in the event of a business transition such as a merger, acquisition by another company, or other transaction or proceeding. In such a case, your information would be used as set out in any pre-existing Privacy Policy.
- We will not sell, lease, or rent your individual-level information (i.e., information about a single individual's genotypes, diseases or other traits/characteristics) to any third-party or to a third-party for research purposes without your explicit consent.
- We may share anonymized and aggregate information with third-parties; anonymized and aggregate information is any information that has been stripped of your name and contact information and aggregated with information of others or anonymized so that you cannot reasonably be identified as an individual.
- We will use your genetic information and/or self-reported information and share it with third-parties for scientific research purposes only if you sign the appropriate Consent Document. Note that we will disclose your individual-level information only if we obtain additional explicit consent from you.
Effective Date: May 23, 2018
1. Key Definitions
Aggregate Information: information that has been combined with that of other users and
analyzed or evaluated as a whole, such that no specific individual may be
reasonably identified.
Anonymized Information: information that has been stripped of your Registration Information
(e.g., your name and contact information) and other identifying data such that
you cannot reasonably be identified as an individual.
Individual-level Information: information about a single individual's
genotypes, diseases or other traits/characteristics, but which is not
necessarily tied to Registration Information.
Personal Information: information that can be used to identify you, either alone or in
combination with other information. My-dna.health collects and stores the
following types of Personal Information:
- Registration Information: information you provide about yourself when registering for and/or purchasing our Services (e.g. name, email, address, user ID and password, and payment information).
- Genetic Information: information regarding your genotype (e.g. the As, Ts, Cs, and Gs at particular locations in your genome), generated through processing of your saliva by My-dna.health or by its contractors, successors, or assignees; or otherwise processed by and/or contributed to My-dna.health.
- Sensitive Information: information about your health, Genetic Information, and certain Self-Reported Information such as racial and ethnic origin.
- Web Behavior Information: information on how you use the My-dna.health website (e.g. browser type, domains, page views) collected through log files, cookies, and web beacon technology which is described with more detail in Cookie Policy.
Service or Services: My-dna.health’s products, software, services, and website (including but
not limited to text, graphics, images, and other material and information) as
accessed from time to time by the user, regardless if the use is in connection
with an account or not.
2. Introduction
At My-dna.health, we enable journeys of
self-discovery. As a result, we collect, process and store your Personal
Information as you use our websites, mobile applications, and services
(collectively the “Services”). Personal Information is information that can
identify you, such as your name, email or street address, or it may be
information that could reasonably be linked back to you, including your Genetic
Information. This Privacy Policy describes our practices for collecting,
storing and processing your Personal Information and the controls we provide
you to manage it within our Services. In addition, we have a Cookie Policy that
describes our use of browser cookies and similar tracking technologies.
3. Account Creation and Your Engagement with My-dna.health
Services
The Personal Information required to create a basic My-dna.health
account is only your email address and a password. Access to Genetic
Information to help you understand yourself better requires additional personal
information and, for the DNA test, the test code (when you activate your DNA
test kit) and a saliva sample from which we can extract Genetic Information.
Account creation also requires you to agree to the
General Terms & Conditions and this Privacy Policy by clicking “Continue”,
“Register” or “Accept” on the account creation and claim kit page
By clicking “Continue”, “Register” or “Accept” you are
telling us that you consent to My-dna.health collecting, processing, and
sharing your Personal Information (including your Genetic Information) as
described in this Privacy Policy and in any other documents referenced in this
Privacy Policy.
At any time, you can request My-dna.health to delete
information you have provided or your Genetic Information. Please see below
sections for specific details about deleting your data.
If you no longer wish to have My-dna.health account,
please contact us and we will help you close your account.
4. What Information Does My-dna.health Collect
From You?
The table below describes the information we collect
from you to provide the Services. In this Privacy Policy, we refer to this as
your “Personal Information.”
| Information category | Use Description |
| Account Information | - Your name
- Email address
- A password that you provide us when you create a My-dna.health account
|
| Credit Card/Payment Information | - Payment information, such as your credit card number, and your billing and shipping address(es), when you purchase something from My-dna.health
|
| DNA Kit Activation Information | When you activate a DNA test kit, we collect: - DNA test kit code
- Name, Surname
- Address
- Email
- Phone number
- Gender
- Year of birth
- Height
- Weight
|
| Genetic Information | - We extract DNA from your saliva when you send it back to us in the tube provided with your DNA test kit.
- We convert your DNA into machine-readable code (“DNA Data”), which is used to provide your Genetic Information.
- A note about your DNA and Saliva: Once our laboratory partner has produced your DNA Data, the DNA and saliva (also referred to as “biological samples”), stored in their facilities are destroyed after 90 days.
|
| Additional User Information | Information that you provide to us when you answer email surveys or online questionnaires offered through the Services. |
| Your Communications | Information you provide in communications with My-dna.health Services. |
| Contests and Promotions | Personal Information when you voluntarily participate in contests and special promotions we run through our Services. |
5. What Information Does My-dna.health Collect Through
Your Use of the Services?
| Information category | Use Description |
| Computer and Mobile Device Information | Information about how you access our Services as defined in Cookie Policy. |
| Information from Cookies and similar technologies | Cookies and similar technologies as described in our Cookie Policy. Please refer to our cookie policy to learn about our practices and the controls we provide you. |
| Information shared through social media features | If you interact with social media through the Services, for example “Like,” “Tweet,” “Pin,” or “Follow Us” links to sites such as Facebook, Twitter, Pinterest, Instagram, and YouTube, My-dna.health will collect these interactions and whatever account information these services make available to us. Your interactions with these features are governed by the privacy policy of the applicable third party company. |
| Information from your use of the Services | Information about your use of the Services, such as when you access your profile and related activities. |
6. How does My-dna.health use your Personal
Information?
| Information category | Use Description |
| Personal Information (generally) | We use your Personal Information to provide, personalize, improve, update and expand our Services. This includes: - Authenticating your access to the Services and improving My-dna.health information security;
- Processing your payments for My-dna.health services and test kits, and other products and features;
- Building new and improving existing products and Services;
- Issuing surveys and questionnaires to collect Additional User Information for use in the Services, as well as facilitating product development and research initiatives;
- Conducting statistical research;
- Detecting and protecting against error, fraud, or other criminal or malicious activity and enforcing our General Terms & Conditions.
|
| Communications | We use your Personal Information to communicate with you about the Services, such as when we: - Respond to your inquiries to Services;
- Inform you about activities related to your Genetic analysis process;
- Inform you of product changes or new products and services;
- Ask you to participate in My-dna.health media productions or testimonials;
- Provide you with information or request action in response to technical, security, and other operational issues.
|
| Market new products and offers from us or our business partners. | We use your Personal Information to market new products and offers from us or our business partners. Note: You can control how we market to you by using the unsubscribe link in any email you receive, by changing your account preferences, or by following the instructions in any other marketing communications you receive. |
| Genetic Information | My-dna.health uses your Genetic Information for the following primary purposes: - Delivering Genetic analysis results;
- We may also invite you to participate in surveys and questionnaires (entirely optional) based on your DNA data.
- Studying aggregated Genetic Information to better understand population and ethnicity-related health, wellness, aging, or physical conditions;
- Conducting scientific, statistical, and historical research; and,
- Improving features and functionality in our existing DNA-related products, enhancing the customer experience across My-dna.health products, improving the quality of our laboratory processes and technology, and building new products and services, including services related to personal health and wellness.
We will seek additional consent from you before we collect and process additional sensitive Personal Information (for example, health history) as part of your interaction with the Services. |
7. When Do We Share Your Information and Who are
the Recipients?
My-dna.health does not share your individual Personal
Information (including your Genetic Information) with third-parties without
your additional consent other than as described in this Privacy Policy. In
particular, we will not share your Genetic Information with insurance
companies, employers, or third-party marketers without your express consent. The circumstances
described below explain when sharing might occur:
| People with whom your Information may be shared / Circumstances in which sharing might occur | Description |
| Other you may choose to share with | If you share details of your Genetic Information outside the Services, you do so at your own risk. |
| Service Providers | We use other companies to help us provide the Services to you. As a result, these partner companies will have some of your information in their systems. Our partners are subject to contractual obligations governing data security and confidentiality consistent with this Privacy Policy and applicable laws. These processing partners include our: - Laboratory partners;
- Shipping providers;
- Payment processors;
- Cloud services infrastructure providers;
- Biological sample storage facilities;
- Vendors that assist us in marketing; analytics, and fraud prevention; and,
- Services functions / functionality providers.
|
| Legal or Regulatory Process | We may share your Personal Information if we believe it is reasonably necessary to: - Comply with valid legal process (e.g., subpoenas, warrants);
- Enforce or apply the My-dna.health General Terms & Conditions;
- Protect the security or integrity of the Services; or
- Protect the rights, property, or safety, of My-dna.health, our employees or users.
If we are compelled to disclose your Personal Information to law enforcement, we will do our best to provide you with advance notice, unless we are prohibited under the law from doing so. |
| If My-dna.health is Acquired | If My-dna.health or its businesses are acquired or transferred (including in connection with bankruptcy or similar proceedings), we will share your Personal Information with the acquiring or receiving entity. The promises in this Privacy Policy will continue to apply to your Personal Information that is transferred to the new entity. |
8. Your Choices and Access to Your Personal
Information
Subject to certain exceptions, you have a right to
request access to your Personal Information and to be provided with a copy of
certain information you provided in a portable form, as well as to seek to
update, delete or correct this information by using the tools described below
or by contacting My-dna.health. Details and options for accessing this
information are listed below.
| Type | Choices |
| My-dna.health | You can access and update your account email and password information at any time in the My account settings. You can request My-dna.health to provide you with Personal Information collected and processed with regards to you. |
| Genetic Information | Your Genetic Information belongs to you and you can access it through your online profile in case your results were in electronic format. If your results were in printed format and we have already delivered them to you, it is possible to request another copy. Additional fee may be applied in this case. Genetic Information raw data are considered My-dna.health’s Intelectual property and cannot be shared with you. |
9. What are My-dna.health retention practices?
My-dna.health services are fundamentally premised on
the notion that the personal voyage of self-discovery is not a one-time event
and continues over lengthy periods of time—possibly lifetimes. Additionally,
the ongoing enhancement of My-dna.health features provide benefits and insights
to our users over time. As a result, My-dna.health’s retention practices
reflect this ongoing value by retaining user accounts and Personal Information
on our system until our users inform us of their desire to delete their data or
close their accounts.
| Category of Information | Retention Period |
| Account | My-dna.health will retain the Personal Information you provide while creating your account until such time as you ask us to close it. |
| DNA | My-dna.health retains your DNA data as needed to provide you with the features and functionality you purchased (or were gifted), including update / upgrade features. Saved / stored by My-dna.health are: - Saliva sample
- DNA sample
- Genetic Information
|
| Usage Information | In some cases we choose to retain usage information (e.g., visits to sites) in a depersonalized or aggregated form. Once aggregated, this information ceases to be personal and will not be subject to My-dna.health user deletion requests. |
10. How can I delete my Personal Information?
You can delete your Personal Information from My-dna.health
in following ways.
| Information Category | How to delete |
| Personal Information | You can delete your Personal Information from My-dna.health by contacting us. My-dna.health may hold records containing your Personal Information that we are obligated to maintain as archives and to meet legal or regulatory obligations. We keep Registration Information as it is related to your order history for accounting purposes. |
| Genetic | If you request that My-dna.health delete your DNA data, we will delete all Genetic Information from our systems within 60 days. To request the destruction of your biological samples, you must send request by email or post. When sending email, you must request confirmation of delivery to be sure email was not lost or delivered to spam. |
| General | Please note that there may be some latency in deleting your Personal Information from our backup systems after it has been deleted from our systems. Also, our partners may retain certain information they receive from us in order to comply with laws or regulations that may require them to do so. My-dna.health may also retain certain information as reasonably necessary to comply with our legal obligations (including law enforcement requests), resolve disputes, maintain security, prevent fraud and abuse, as well as to comply with tax, payment industry, securities, and clinical regulatory compliance requirements. |
11. Security
My-dna.health maintains a comprehensive information
security program designed to protect our customers’ Personal Information using
administrative, physical, and technical safeguards.
The specific security measures used are based on the
sensitivity of the Personal Information collected. We have measures in place to
protect against inappropriate access, loss, misuse, or alteration of Personal Information
(including Genetic Information) under our control.
My-dna.health Security Team regularly reviews our
security and privacy practices and enhances them as necessary to help ensure
the integrity of our systems and your Personal Information.
We use latest standard security mechanisms while
processing and storing Personal Information (including Genetic Information),
and we only partner with security companies that meet and commit to our
security standards. While we cannot guarantee that loss, misuse or alteration
of data will not occur, we use reasonable efforts to prevent this.
It is also important for you to guard against
unauthorized access to your Personal Information by maintaining strong
passwords and protecting against the unauthorized use of your own computer or
device.
Your password for your account will be used only for
online login. We will not ask for your password under any other circumstances.
Inform My-dna.health immediately of any unauthorized use of your account.
Should you wish to reset or change your password, you can do so by clicking on
the relevant links on My-dna.health web page.
Sharing self-reported information through surveys, or
other website features, is voluntary and your liability. My-dna.health cannot
take responsibility for information that you release or that you request us to
release publicly.
12. Data transfer
Your information, including Personal Data, may be
transferred to — and maintained on — computers located outside of your state,
province, country, or other governmental jurisdiction where the data protection
laws may differ than those from your jurisdiction.
If you are located outside EU and choose to provide
information to us, please note that we process the data, including Personal
Information, in the EU.
Your consent to this Privacy Policy followed by your
submission of such information represents your agreement to that processing.
My-dna.health will take all steps reasonably necessary
to ensure that your data is treated securely and in accordance with this
Privacy Policy and no transfer of your Personal Information will take place to
an organization or a country unless there are adequate controls in place
including the security of your data and other personal information.
13. Changes to this Privacy Policy
We may modify this Privacy Policy at any time, but we
will provide prominent advance notice of any material changes, such as posting
a notice through the Services, on our websites, or sending you an email, to
provide you the opportunity to review the changes and choose whether to
continue using the Services.
We will also notify you of non-material changes to
this Privacy Policy as of their effective date by posting a notice through the
Services, on our websites, or sending you an email. Your continued use of our
Services after notice of non-material changes means that you consent to the
updated Privacy Policy.
If you object to any changes, you may delete your
account by contacting us.
14. Information about children
My-dna.health is committed to protecting the privacy
of children as well as adults. Neither My-dna.health nor any of its Services
are designed for, intended to attract, or directed toward children under the
age of 18. A parent or guardian, however, may collect a saliva sample from,
create an account for, and provide information related to, his or her child.
The parent or guardian assumes full responsibility for ensuring that the
information that he/she provides to My-dna.health about his or her child is
kept secure and that the information submitted is accurate. If you are under
18, we ask that you do not use our Service or give us your personal information
without your parent or guardian consent.
15. Legal basis under EU General Data Protection
Regulation for processing personal information of EU residents.
Where you have consented to data processing, your
consent provides the legal basis to process your Personal Information. We rely
on your explicit consent to process your Genetic Information. You have the
right to withdraw consent at any time. Please note that your withdrawal of
consent to collect and process your Personal Information will not affect the
lawfulness of processing your Personal Information based on your consent before
you withdrew your consent.
We may also process your Personal Information on the
basis of contractual necessity to perform a contract we have with you. For
example, we process your credit card details when you provide them in order to
use our Services or purchase update / upgrade features such as our DNA testing
services.
We may also process your Personal Information on the
basis of our legitimate interests, including in providing and improving the
Services. For example, My-dna.health has a legitimate interest in understanding
your login history so we can assess your interaction with our Services. We also
have a legitimate interest in providing and developing interesting features to
provide to our users. We use your Personal Information to keep our Services
safe and secure and we do so as it necessary to pursue your and our legitimate
interests in ensuring that our Services are secure, and to protect against
fraud, spam and abuse.
Where we rely on legitimate interests to process your
Personal Information, you have the right to object to such processing (meaning
that you can ask us to stop). You can use your Privacy Settings to control
certain ways in which we process your data. You can also contact us, using the
details below, to object to other forms of processing.
16. Identity and Contact Details of the Data
Controller
Contact Details of the Data Protection Officer
- Email: legal@My-dna.health.com
My-dna.health customers can reach us using phone
number, or you may submit questions using email. Contact details can be found on
web page https://my-dna.health