Effective Date: January 1, 2020
These "Privacy Highlights" provide an overview of some core components of our data handling practices.
Please be sure to review the Full Privacy Statement.
Information We Collect
We generally collect the following information:
- Information you share with us.We collect and process your information when you place an order, create an account, register your EDISON BIO membership, complete research surveys, post on our Forums or use other messaging features, and contact Client Care. This information can generally be categorized as Registration Information, Self-Reported Information, and/or User Content as defined in our full Privacy Statement.
- Health Information from our testing services. With your consent, we extract your DNA from your saliva sample and analyze it to produce your Genetic Information (the As, Ts, Cs, and Gs at particular locations in your genome), and other health related information including but not limited to blood, stool, urine, saliva, medical images and other bio samples in order to provide you with EDISON BIO reports.
- We may collect Health Information from you when you register your Account, during each EDISON BIO Service, when you choose to share your Health Information with us through your EDISON BIO profile, and when you authorize us to compile your medical records created by healthcare professionals you consulted prior to joining EDISON BIO.
- We may collect information about your healthcare professionals or other designated individuals from you when you sign up for our Services and when you choose to grant a healthcare professional or other individual permission to view your EDISON BIO profile as a Registered Non-Member.
- We may collect your payment information, as well as any needed contact information and a delivery address of any recipient when and if we provide your Health Information and any cryostored specimens at your request.
- We retain information on your behalf, such as the Personal Data and Health Information that you store using your Account.
- When your Health Information is uploaded through our Services, the information will be stored in our servers (or those of our service providers and affiliates) and shared only with individuals to whom you grant access.
- Third Party Collected Information. We may collect information about Registered Members from the third party labs and other providers that analyze your anonymized biological specimens that we gather as part of the Service.
- We may collect information gathered by third party providers we work with in order to provide the Service to Registered Members, like imaging centers.We may collect information about Registered Members from previous healthcare professionals through a third party medical records aggregation service with your consent. Individuals to whom you grant access to your Health Information through the EDISON BIO platform as Registered Members who may upload, annotate or provide supplemental information. We may collect information about Unregistered Non-Members, Registered Non-Members, and Registered Members from our partners and third parties, such as advertising networks, for to refine our Site and Services and for advertising purposes.
How We Use Information
We generally process Personal Information for the following reasons:
- To provide our Services. We process Personal Information in order to provide our Service, which includes processing payments, shipping tests to clients, creating client accounts and authenticating logins, analyzing bio samples and DNA, getting help with tests and results from third parties, tech support and delivering results and powering tools. To make telephone or video calls to you, from time to time, as a part of secondary fraud protection or to solicit your feedback
- To analyze and improve our Services. We constantly work to improve, invent and provide new reports, tools, algorithms, and Services. For example, we are constantly working to improve our ability to assign specific learnings to your DNA segments and maximize the granularity of our results. We may also need to fix bugs or issues, analyze the use of our website to improve the client experience or assess our marketing campaigns.
- For EDISON BIO Research, with your consent. If you choose to consent to participate in EDISON BIO Research, EDISON BIO researchers can include your de-identified Genetic Information and Self-Reported Information in a large pool of client data for analyses aimed at making scientific discoveries.
- Advertising Partners. We may share Anonymous Data with our advertising partners to deliver advertisements that are relevant to you, such as those displayed on third party websites, as informed by other advertisements that previously clicked or pages viewed.
Control: Your Choices
You have the ability to make decisions about how your data is shared and used. You choose:
- To store or discard your saliva sample after it has been analyzed.
- Which health report(s)you view and/or opt-in to view.
- When and with whom you share your information, including friends, family members, health care professionals, or others outside our Services, including through third party services that accept EDISON BIO data and social networks.
- To give or decline consent for EDISON BIO Research. By agreeing to the Research Consent Document, Individual Data Sharing Consent Document, or participating in a EDISON BIO Research Community you can consent to the use of your de-identified data for scientific research purposes.
- To delete your EDISON BIO account and data, at any time.
Access To Your Information
Your Personal Information may be shared in the following ways:
- With our service providers, as necessary for them to provide their services to us.
- With qualified research collaborators, only if you provide your explicit consent.
EDISON BIO will not sell, lease, or rent your individual-level information to a third party for research purposes without your explicit consent.
- We will not share your data with anypublic databases.
- We will notprovide any person’s data (genetic or non-genetic) to aninsurance companyoremployer.
- We will not provide information tolaw enforcement or regulatory authorities unless required by law to comply with a valid court order, subpoena, or search warrant for genetic or Personal Information.
How We Secure Information
EDISON BIO implements measures and systems to ensure confidentiality, integrity, and availability of EDISON BIO data. Our team regularly reviews and improves our security practices to help ensure the integrity of our systems and your information. These practices include, but are not limited to, the following areas:
- Security review and audit.Our information security management system, which protects EDISON BIO information assets supporting our Services uses the latest in security protection technologies.
- Encryption.EDISON BIO uses industry-standard security measures to encrypt Sensitive Information both when it is stored and when it is being transmitted.
- Limited access to essential personnel.We limit access of information to authorized personnel, based on job function and role. EDISON BIO access controls include multi-factor authentication and a strict least-privileged authorization policy.
Risks and Considerations
There may be some consequences of using our Services that you haven't considered.
- You may discover things about yourself and/or your family members that may be upsetting or cause anxiety and that you may not have the ability to control or change.
- In the event of a data breach it is possible that your data could be associated with your identity, which could be used against your interests.
Full Privacy Statement
Effective Date: January 1, 2020
This Privacy Statement applies to all websites owned and operated by EDISON BIO, Inc ("EDISON BIO"), including www.EDISONBIO.com, and any other websites, pages, features, or content we own or operate, and to your use of the EDISON BIO app and any related Services. Our Privacy Statement is designed to help you better understand how we collect, use, store, process, and transfer your information when using our Services.
Please carefully review this Privacy Statement and our Terms of Service. Unless otherwise defined in this Privacy Statement, terms used in this Privacy Statement have the same meanings as terms defined in our Terms of Service. By using our Services, you acknowledge all of the policies and procedures described in the foregoing documents. If you do not agree with or you are not comfortable with any aspect of this Privacy Statement or our Terms of Service, you should immediately discontinue use of our Services.
- Information you provide directly to us
- Information related to our genetic testing services
- Information collected through tracking technology
- Other types of information
- To provide you with Services and analyze and improve our Services
- To process, analyze and deliver your genetic testing results
- To allow you to share your Personal Information with others
- To allow you to share your Personal Information for research purposes
- To recruit you for external research
- To provide client support
- To conduct surveys or polls, and obtain testimonials
- To provide you with marketing communications
- General Service Providers
- "Targeted advertising" service providers
- Aggregate Information
- Information we share with commonly owned entities
- As required by law
- Business Transactions
- Access to your account
- Marketing communications
- Sharing outside of the EDISON BIO Services
- Account Deletion
- Privacy Shield
- Our relationship with you
- Legal bases for processing Personal Information from the EU
- Direct Marketing
- Privacy Rights
- California Residents
- Nevada Residents
- Do-Not-Track Statement
- Changes to this Privacy Statement
- Contact information
1. Key Definitions
- Aggregate Information: information that has been combined with that of other users and analyzed or evaluated as a whole, such that no specific individual may be reasonably identified.
- De-identified Information: information that has been stripped of your Registration Information (e.g., your name and contact information) and other identifying data such that you cannot reasonably be identified as an individual, also known as pseudonymized information.
- Individual-level Information: information about a single individual's genotypes, diseases or other traits/characteristics, but which is not necessarily tied to Registration Information.
- Personal Information: information that can be used to identify you, either alone or in combination with other information. EDISON BIO collects and stores the following types of Personal Information:
- Registration Information: information you provide about yourself when registering for and/or purchasing our Services (e.g. name, email, address, user ID and password, and payment information).
- Genetic Information: information regarding your genotypes (i.e. the As, Ts, Cs, and Gs at particular locations in your genome), generated through processing of your saliva, bio samples or images by EDISON BIO or by its contractors, successors, or assignees; or otherwise processed by and/or contributed to EDISON BIO.
- Self-Reported Information: information you provide directly to us, either through the Services or through a third party, including your disease conditions, other health-related information, personal traits, ethnicity, family history, and other information that you enter into surveys, forms, or features while signed in to your EDISON BIO account.
- Sensitive Information: information about your health, Genetic Information, and certain Self-Reported Information such as racial and ethnic origin, sexual orientation, and political affiliation.
- User Content: information, data, text, software, music, audio, photographs, graphics, video, messages, or other materials - other than Genetic Information and Self-Reported Information-generated by users of EDISON BIO Services and transmitted, whether publicly or privately, to or through EDISON BIO.
- Inferences and Derived Data: information, data, assumptions, or conclusions that are derived directly or indirectly from another source of Personal Information. For example, we may use statistical techniques to infer additional genetic information based on genetic or health related information generated directly through the processing of your samples.
- Web-Behavior Information: information on how you use our Services collected through log files, cookies, web beacons, and similar technologies, (e.g., device information (device identifiers), IP address, browser type, domains, page views).
2. Information we collect
- Registration Information. When you purchase our Services or create a EDISON BIO account, we collect Personal Information, which may include your name, date of birth, billing and shipping address, payment information (e.g., credit card) and contact information (e.g. email, phone number and license number).
- Self-Reported Information. You have the option to provide us with additional information about yourself through surveys, forms, features and applications. For example, you may provide us with information about your personal traits (e.g., eye color, height), ethnicity, disease conditions (e.g., Type 2 Diabetes), other health-related information (e.g., pulse rate, cholesterol levels, visual acuity, blood tests, diagnostic images), and family history information (e.g., information similar to the foregoing about your family members). Before you disclose information about a family member, you should make sure you have permission from the family member to do so.
- User Content. Some of our Services allow you to create and post or upload content, such as data, text, software, music, audio, photographs, graphics, video, messages, or other materials that you create or provide to us through either a public or private transmission ("User Content"). For example, User Content includes any discussions, posts, or messages you send on our Forums.
- Social media features and widgets. Our Services include Social Media Features, such as the Facebook "Like" or "Share" button and widgets ("Features"). These Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. They may also allow third party social media services to provide us information about you, including your name, email address, and other contact information. The information we receive is dependent upon your privacy settings with the third party social media service. Features are either hosted by a third party or hosted directly on our site. Your interactions with these Features are governed by the privacy statements of the third party companies providing them. You should always review and, if necessary, adjust your privacy settings on third party websites and services before linking or connecting them to our website or Service.
- Third party services (e.g., social media). If you use a third party site, such as Facebook or Twitter, in connection with our Services to communicate with another person (e.g., to make or post referrals or to request that we communicate with another person), then in addition to that person's name and contact information, we may also collect other information (e.g., your profile picture, network, gender, username, user ID, age range, language, country, friends lists or followers) depending on your privacy settings on the third party site. We do not control the third party site's information practices, so please review the third party’s privacy statement and your settings on the third party’s site carefully.
- Third party sign in. You may create a EDISON BIO account and/or sign in to our Services using an account you created with a third party service, such as Google. If you provide authorization to EDISON BIO, we will collect and use the information you share with us via that third party service (such as your email address, name, and date of birth as specified in your third party service account) in accordance with this Privacy Statement. You are responsible for managing your credentials for your third party service account, and for maintaining the security of your third party service account. EDISON BIO does not have access to the credentials for your third party service account. If you choose to use third party sign in and you lose access to your credentials for your third party service account, you may not be able to access your EDISON BIO account. You may manage authorization for third party sign in through your EDISON BIO Account Settings or through your third party service account.
- Referral information and sharing. When you refer a person to EDISON BIO or choose to share your EDISON BIO results with another person, we will ask for that person's email address. We will use their email address solely, as applicable, to make the referral or to communicate your sharing request to them, and we will let your contact know that you requested the communication. By participating in a referral program or by choosing to share information with another person, you confirm that the person has given you consent for EDISON BIO to communicate (e.g., via email) with him or her. The person you referred may contact us at support@EDISON BIO.com to request that we remove this information from our database.
- Gifts & Corporate Benifits. If you provide us with Personal Information about others, if others give us your information, or if you authorize another individual to share or send your Personal Information to our third party service provider(s) for the purpose of ordering the Service or other personalized gift(s), we will only use that information for the purpose for which it was provided to us. These purposes may include, for example, where you provide us with a friend or employees shipping address when placing an order or where you authorize a family member to order personalized products or services based on your report results. Once a recipient registers for our Services and agrees to our Privacy Statement, our Terms of Service, and if applicable, certain Consent Documents, his or her Personal Information will be used in manners consistent with this Privacy Statement, and will not be shared with the purchaser, unless they independently choose to share their own Personal Information through the Services with the purchaser. Information shared directly with our third party service provider(s) for personalized gifts are subject to such third party’s terms of service and privacy policies.
- client service. When you contact Client Care or correspond with us about our Service, we collect information to: track and respond to your inquiry; investigate any breach of our Terms of Service, Privacy Statement or applicable laws or regulations; and analyze and improve our Services.
- Saliva and bio samples and storage. To use our genetic and other testing services, you must purchase, or receive as a gift or benefit, a EDISON BIO Personal testing kit, create an account and register your kit, and ship or consent to your saliva or other bio samples to us or our third party laboratorys. Your DNA and other results will be extracted from your saliva and bio sample for analysis. During registration you are asked to review our Consent Document for Sample Storage and Additional Genetic & Bio Analyses. Unless you consent to sample storage and additional analyses, your saliva sample and DNA are destroyed after the laboratory completes its work, subject to laboratory legal and regulatory requirements. You can update your preference to discard a stored sample once your sample has completed processing.
- Genetic Information. Information regarding your genotype (e.g. the As, Ts, Cs, and Gs at particular locations in your genome), your Genetic Information, is generated when we analyze and process your saliva sample, or when you otherwise contribute or access your Genetic Information through our Services. Genetic Information includes the EDISON BIO results reported to you as part of our Services, and may be used for other purposes, as outlined in Section 3 below.
- Web-Behavior Information collected through tracking technology (e.g. from cookies and similar technologies)
- help us recognize you when you use our Services;
- customize and improve your experience;
- provide security;
- analyze usage of our Services (such as to analyze your interactions with the results, reports, and other features of the Service);
- gather demographic information about our user base;
- offer our Services to you;
- monitor the success of marketing programs; and
- serve targeted advertising on our site and on other sites around the Internet.
Google Analytics. Google Analytics is used to perform many of the tasks listed above. We use the User-ID feature of Google Analytics to combine behavioral information across devices and sessions (including authenticated and unauthenticated sessions). We have enabled the following Google Analytics Advertising features: Remarketing, Google Display Network Impression Reporting, Google Analytics Demographics and Interest Reporting, and DoubleClick Campaign Manager integration. We do not merge information collected through any Google advertising product with individual-level information collected elsewhere by our Service. Learn more about how Google collects and uses data here. To opt out of Google Analytics Advertising Features please use Google Ad Settings. To opt out of Google Analytics entirely please use this link.
- Other Types of Information
We continuously work to enhance our Services with new products, applications and features that may result in the collection of new and different types of information. We will update our Privacy Statement and/or obtain your prior consent to new processing, as needed.
3. How we use your information
EDISON BIO will use and share your Personal Information with third parties only in the ways that are described in this Privacy Statement.
- To provide you with Services and to analyze and improve our Services
We use the information described above in Section 2 to operate, provide, analyze and improve our Services. These activities may include, among other things, using your information in a manner consistent with this Privacy Statement to:
- open your account, enable purchases and process payments, communicate with you, and implement your requests (e.g., referrals);
- enable and enhance your use of our website and mobile application(s), including authenticating your visits, providing personalized content and information, and tracking your usage of our Services;
- contact you about your account, and any relevant information about our Services (e.g. policy changes, security updates or issues, etc.);
- enforce our Terms of Service and other agreements;
- monitor, detect, investigate and prevent prohibited or illegal behaviors on our Services, to combat spam and other security risks; and
- perform research & development activities, which may include, for example, conducting data analysis in order to develop new or improve existing products and services, and performing quality control activities.
- For individuals located in the European Economic Area (“EEA”), United Kingdom, or Switzerland (collectively the “Designated Countries”): We process your Personal Information in this way to provide our Services to you in accordance with our Terms of Service.
- To process, analyze and deliver your genetic testing results
As described above, to receive results, you must create a EDISON BIO account, register, and submit your bio samples to be genotyped and analysed by us or our contracted laboratory. Once analysed and genotyped, we further analyze your Information to provide you with information depending on the Service purchased. EDISON BIO continuously works to improve our Services based on our research and product development, and associations identified in scientific literature. If you are eligible to receive additional reports or updates in the future, you may be notified of or may directly access these updates.
For individuals located in the Designated Countries: Our legal basis for processing your Sensitive Information for the purposes described above is based on your consent. You may withdraw your consent at any time by deleting your Account via your EDISON BIO Account Settings, however, the withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
- To allow you to share your Personal Information with others
EDISON BIO gives you the ability to share information, including Personal Information, through the Services. You have the option to share directly with individuals with EDISON BIO accounts through (i) our Forums, (ii) other sharing features and tools. You may also have the ability to share information directly with individuals who have not participated in our Service via a unique, shareable URL or through a social media platform (such information is "User Content"). Some sharing features, including receiving sharing invitations, may require that you opt-out, however you will always be required to take a positive action, such as opting in, to share Sensitive Information.
You should be thoughtful about your sharing choices. Once you have chosen to share any Personal Information, the individuals with whom you share this information, may also use or share your Personal Information, including any Sensitive Information you choose to share.
For individuals located in the Designated Countries: Our legal basis for processing your Personal Information for the purpose described above is based on your consent. You may withdraw your consent at any time, however, the withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
- To allow you to share your Personal Information for EDISON BIO Research purposes
You have the choice to participate in EDISON BIO Research by providing your consent. "EDISON BIO Research" refers to research aimed at publication in peer-reviewed journals and other research funded by government (such as the National Institutes of Health (“NIH”)) conducted by EDISON BIO.
EDISON BIO Research may be sponsored by, conducted on behalf of, or in collaboration with third parties, such as non-profit foundations, academic institutions or pharmaceutical companies. EDISON BIO Research may study a specific group or population, identify potential areas or targets for therapeutics development, conduct or support the development of drugs, diagnostics or devices to diagnose, predict or treat medical or other health conditions, work with public, private and/or non-profit entities on medical or genetic research initiatives, or otherwise create, commercialize, and apply this new knowledge to improve health care. EDISON BIO Research uses Aggregate and/or Individual-level Genetic, Bio and Imagery Information and Self-Reported Information as specified in the appropriate Consent Document(s), as explained in greater detail below.
Your De-identified Genetic, Medical and Self-Reported Information may be used for EDISON BIO Research only if you have consented to this use by completing a Consent Document. If you have completed the main Research Consent Document:
- Your Genetic Information and/or Self-Reported Information will be used for research purposes, but it will be de-identified and will not be linked to your Registration Information.
- EDISON BIO may use individual-level Information and Self-Reported Information internally at EDISON BIO for research purposes.
- EDISON BIO may share summary statistics, which do not identify any particular individual or contain individual-level information, with our qualified research collaborators.
- If you have completed the Individual Level Data Sharing Consent, or additional consent agreement, in addition to the uses above under the main Research Consent Document, EDISON BIO may share De-identified Individual-level Genetic Information and Self-Reported Information with select third party research collaborators for EDISON BIO Research purposes.
Withdrawing your Consent. You may withdraw your consent to participate in EDISON BIO Research at any time by changing your consent status within your EDISON BIO Account Settings. If you experience difficulties changing your consent status, contact the Human Protections Administrator at support@EDISONBIO.com. EDISON BIO will not include your Genetic Information or Self-Reported Information in studies that start more than 30 days after you withdraw (it may take up to 30 days to withdraw your information after you withdraw your consent). Any research involving your data that has already been performed or published prior to your withdrawal from EDISON BIO Research will not be reversed, undone, or withdrawn. You may also discontinue your participation in EDISON BIO Research by deleting your EDISON BIO account.
For individuals located in the Designated Countries: Our legal basis for processing your Sensitive Information for the purpose described above is based on your consent. You may withdraw your consent at any time, however, the withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
- To recruit you for external research
Research is an important aspect of our Services and we want to ensure interested participants are aware of additional opportunities to contribute to interesting, novel scientific research conducted by academic institutions, healthcare organizations, pharmaceutical companies, and other groups. If you have chosen to participate in EDISON BIO Research, from time to time we may inform you of third party research opportunities for which you may be eligible. For example, if a university tells us about a new cancer research project, we may send an email to EDISON BIO research participants who potentially fit the relevant eligibility criteria to make them aware of the research project and provide a link to participate with the research organization conducting the study. We will not share Individual-level Genetic Information or Self-Reported Information with any third party without your explicit consent. If you do not wish to receive these notifications, you can manage them by contacting us anytime. For individuals located in the Designated Countries: Our legal basis for processing your Sensitive Information for the purpose described above is based on your consent. You may withdraw your consent at any time, however, the withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
- To provide Client support
When you contact Client Care, we may use or request Personal Information, including Sensitive Information, as necessary to answer your questions, resolve disputes, and/or investigate and troubleshoot problems or complaints. In some instances, we may be required to process one client’s Personal Information to resolve another client’s dispute or request. For example, if a client reports behavior that violates our Terms of Service, we will separately process both clients’ Personal Information and respond separately to each individual as appropriate. We will not share your Personal Information with another client without your consent.
For individuals located in the Designated Countries: Our legal basis for processing your Personal Information for the purpose described above depends on the nature of the client support request. Our legal basis can be to satisfy our contractual or legal obligations and/or our legitimate interest to improve our Services.
- To conduct surveys or polls, and obtain testimonials
We value your feedback and may send you surveys, polls, or requests for testimonials to improve and optimize our Services. You are in control of the information you would like to share with us. If you do not wish to receive these requests please contact our team.
For individuals located in the Designated Countries: Our legal basis for processing your Personal Information for the purpose described above is based on our legitimate interest. We think it is important to continue improving our Services to ensure your continued enjoyment.
- To provide you with marketing communications
By creating a EDISON BIO account, you are agreeing that we may send you product and promotional emails or notifications about our Services, and offers on new products, services, promotions or contests. You may also opt-in to receiving similar notifications on the website, application or mobile application(s). You can unsubscribe from receiving these marketing communications at any time. To unsubscribe, click the email footer “unsubscribe” link or go to the “Preferences” section of your EDISON BIO Account Settings to edit your email notification preferences. To opt-out of receiving website and mobile notifications, you may do so within your browser or device settings. Please note, the opt-out process differs between web browsers and mobile devices. You may not opt-out of receiving non-promotional messages regarding your account, such as technical notices, purchase confirmations, or Service-related emails.
Individuals located in Designated Countries should review Section 9.d. to understand our marketing practices in relation to the Designated Countries.
4. Information we share with third parties
- General service providers.
We share the information described above in Section 2 with our third party service providers, as necessary for them to provide their services to us and help us perform our contract with you. Service providers are third parties (other companies or individuals) that help us to provide, analyze and improve our Services. While EDISON BIO directly conducts the majority of data processing activities required to provide our Services to you, we engage some third party service providers to assist in supporting our Services, including in the following areas:
- Order fulfillment and shipping. Our payment processor processes certain Registration Information, such as your billing address and credit card information, as necessary to enable you to purchase a EDISON BIO membership from the EDISON BIO.com online store. Our distribution centers or partners ship your kit(s) to you, and in some cases help return your kit safely to us or to our third party laboratory so your sample can be processed.
- Our diagnosti labs. To use our services, you must purchase, or receive as a gift or benift, a EDISON BIO testing kit(s), and ship your sample to us or our third party laboratory. Once delivered, receiving personnel at the laboratory remove and discard kit packaging, which in some cases may contain "sender information" (e.g., name, address), before testing personnel receive the samples for processing. Receiving personnel do not perform testing, and testing personnel handle samples that are only identified by a unique barcode. For samples processed by our third party laboratorys, when the laboratory has completed their analysis, they securely send the resulting Information to us identified by your unique barcode.
During membership registration, you are asked to review our Consent Document for Sample Storage and Additional Health related Analyses. Unless you consent to data storage and additional analyses, your samples and data are destroyed after the laboratory completes its work, subject to the legal and regulatory requirements. Should you wish to update your sample storage preference to discard a stored sample, you can do so by contacting our client care team once your sample has completed processing. Our laboratory or contracted genotyping laboratory will retain certain information as necessary to comply with applicable regulatory and legal obligations.
- Client Care support. Our client Care team uses a number of tools to help organize and manage the requests we receive. These tools help to ensure we provide timely, high quality support.
- Cloud storage, IT, and Security. Our cloud storage providers provide secure storage for information in EDISON BIO databases, ensure that our infrastructure can support continued use of our Services by EDISON BIO clients, and protect data in the event of a natural disaster or other disruption to our Service. Our IT and security service providers assist with intrusion detection and prevention measures to stop any potential attacks against our networks. We have these third party experts perform regular penetration tests and periodically audit EDISON BIO’s security controls.
- Marketing and analytics. When you use our Services, including our website or mobile app(s), our third party service providers may collect Web-Behavior Information about your visit, such as the links you clicked on, the duration of your visit, and the URLs you visited. This information can help us improve site navigability and assess our Marketing campaigns. Per applicable data protection regulations, our EU, UK, and International websites present visitors with a cookie opt in to allow the processing described above via Functionality and Advertising Cookies.
NOTE: Our service providers act on EDISON BIO's behalf. We implement procedures and maintain contractual terms with each service provider to protect the confidentiality and security of your information. However, we cannot guarantee the confidentiality and security of your information due to the inherent risks associated with storing and transmitting data electronically.
- For individuals located in the European Economic Area (“EEA”), United Kingdom, or Switzerland (collectively the “Designated Countries”): Where personal data are transferred to a third country or to an international organisation, EDISON BIO implements appropriate safeguards, such as contractual obligations, relating to the transfer.
- "Targeted advertising" service providers
- Aggregate information
We may share Aggregate Information, which is information that has been stripped of your name and contact information and combined with information of others so that you cannot reasonably be identified as an individual, with third parties. This Information is different from "Individual-level" information and is not Personal Information because it does not identify any particular individual or disclose any particular individual’s data. For example, Aggregate Information may include a statement that "30% of our female users share a particular trait," without providing any data or testing results specific to any individual user. In contrast, Individual-level Genetic Information or Self-Reported Information consists of data about a single individual's genotypes, diseases or other traits/characteristics information and could reveal whether a specific user has a particular genetic trait, or consist of all of the Information about that user. EDISON BIO will ask for your consent to share Individual-level Genetic Information or Self-Reported Information with any third party, other than our service providers as necessary for us to provide the Services to you.
- Information we share with commonly owned entities
We may share some or all of your Personal Information with other companies under common ownership or control of EDISON BIO, which may include our subsidiaries, our corporate parent, or any other subsidiaries owned by our corporate parent in order to provide you better service and improve user experience. Generally, sharing such information is necessary for us to perform on our contract with you. We may provide additional notice and ask for your prior consent if we wish to share your Personal Information with our commonly owned entities in a materially different way than discussed in this Privacy Statement.
- As required by law
Under certain circumstances your Personal Information may be subject to processing pursuant to laws, regulations, judicial or other government subpoenas, warrants, or orders. For example, we may be required to disclose Personal Information in coordination with regulatory authorities in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. EDISON BIO will preserve and disclose any and all information to law enforcement agencies or others if required to do so by law or in the good faith belief that such preservation or disclosure is reasonably necessary to: (a) comply with legal or regulatory process (such as a judicial proceeding, court order, or government inquiry) or obligations that EDISON BIO may owe pursuant to ethical and other professional rules, laws, and regulations; (b) enforce the EDISON BIO Terms of Service and other policies; (c) respond to claims that any content violates the rights of third parties; or (d) protect the rights, property, or personal safety of EDISON BIO, its employees, its users, its clients, and the public.
NOTE: If you are participating in EDISON BIO Research, EDISON BIO will withhold disclosure of your Personal Information involved in such Research in response to judicial or other government subpoenas, warrants or orders in accordance with any applicable Certificate of Confidentiality that EDISON BIO has obtained from its partners.
- Business transactions
In the event that EDISON BIO goes through a business transition such as a merger, acquisition by another company, or sale of all or a portion of its assets your Personal Information will likely be among the assets transferred. In such a case, your information would remain subject to the promises made in any pre-existing Privacy Statement.
5. Your choices
- Access to your account
We provide access to your EDISON BIO data within your EDISON BIO account. You can access and download data processed by EDISON BIO within your EDISON BIO Account Settings and within applicable Reports, Tools, and features. If you lose access to your EDISON BIO account or account email address, please contact Client Care for assistance. If you lose access to your EDISON BIO account, in certain circumstances, we may require that you submit additional information sufficient to verify your identity before providing access or otherwise releasing information to you. If you choose not to submit the required documentation, or the information provided is not sufficient for the purposes sought, EDISON BIO will not be able to sufficiently verify your identity in order to complete your request.
You may access, correct or update most of your Registration Information on your own within your EDISON BIO Account Settings. You may also review and update your consent to EDISON BIO Research and storage. You may be able to correct Self-Reported Information entered into a survey, form, or feature within your account, such as on the surveys page. Please note that you may not be able to delete User Content that has been shared with others through the Service and that you may not be able to delete information that has been shared with third parties.
Individuals located in Designated Countries should review to understand their rights to access Personal Information.
- Maketing communications
As noted in Section 3.h. you may be asked to opt-in to receive product and promotional emails or notifications when creating your EDISON BIO account or when using our Services. You may view or update your notification preferences for marketing communications by visiting your EDISON BIO Account Settings, opting out at the browser or device level, or by contacting our Privacy Administrator at support@EDISONBIO.com. You can also click the "unsubscribe" button at the bottom of promotional email communications, as applicable.
- Sharing outside of the EDISON BIO Services
You may decide to share your Personal Information with friends and/or family members, doctors or other health care professionals, and/or other individuals outside of our Services, including through third party services such as social networks and third party apps that connect to our website and mobile apps through our application programming interface ("API"). These third parties may use your Personal Information differently than we do under this Privacy Statement. Please make such choices carefully and review the privacy statements of all other third parties involved in the transaction. EDISON BIO does not endorse or sponsor any API applications, and does not affirm the accuracy or validity of any interpretations made by third party API applications.
In general, it can be difficult to contain or retrieve Personal Information once it has been shared or disclosed. EDISON BIO will have no responsibility or liability for any consequences that may result because you have released or shared Personal Information with others. Likewise, if you are reading this because you have access to the Personal Information of a EDISON BIO client through a multi-profile account, we urge you to recognize your responsibility to protect the privacy of each person within that account. Users with multi-profile accounts (i.e., where multiple family members register their kits to one account) should use caution in setting profile-level privacy settings.
- Account deletion
If you no longer wish to participate in our Services, or no longer wish to have your Personal Information be processed, you may delete your EDISON BIO account and Personal Information by contacting us anytime. Once you submit your request, we will send an email to the email address linked to your EDISON BIO account detailing our account deletion policy and requesting that you confirm your deletion request. Once you confirm your request to delete your account and data, your account will no longer be accessible while we process your request. Once you confirm your request, this process cannot be cancelled, undone, withdrawn, or reversed. When your account is deleted, all associated Personal Information is deleted and any stored samples are discarded, subject to the following limitations:
- Information previously included in EDISON BIO Research. As stated in any applicable Consent Document, Genetic Information and/or Self-Reported Information that you have previously provided and for which you have given consent to use in EDISON BIO Research cannot be removed from completed studies that use that information. Your data will not be included in studies that start more than 30 days after your account is closed (it may take up to 30 days to withdraw your information after your account is closed).
- Legal Retention Requirements. EDISON BIO and/or our contracted laboratories will retain your Genetic Information, date of birth, and sex as required for compliance with applicable legal obligations, including the federal Clinical Laboratory Improvement Amendments of 1988 (CLIA), California Business and Professions Code Section 1265 and College of American Pathologists (CAP) accreditation requirements. EDISON BIO will also retain limited information related to your account and data deletion request, including but not limited to, your email address, account deletion request identifier, communications related to inquiries or complaints and legal agreements for a limited period of time as required by law, contractual obligations, and/or as necessary for the establishment, exercise or defense of legal claims and for audit and compliance purposes.
6. Security measures
EDISON BIO takes seriously the trust you place in us. EDISON BIO implements physical, technical, and administrative measures to prevent unauthorized access to or disclosure of your information, to maintain data accuracy, to ensure the appropriate use of information, and otherwise safeguard your Personal Information. Our team regularly reviews and improves our security practices to help ensure the integrity of our systems and your information. These practices include, but are not limited to the following areas:
- Encryption. EDISON BIO uses industry standard security measures to encrypt Sensitive Information both at rest and in transit.
- Limited access to essential personnel. We limit access to Sensitive Information to authorized personnel, based on job function and role. EDISON BIO access controls include multi-factor authentication, and strict least-privileged authorization policy.
Your Responsibility. Please recognize that protecting your Personal Information is also your responsibility. We ask you to be responsible for safeguarding your password, and other authentication information you use to access our Services. You should not disclose your authentication information to any third party and should immediately notify EDISON BIO of any unauthorized use of your password. EDISON BIO cannot secure Personal Information that you release on your own or that you request us to release.
Your information collected through the Service may be stored and processed in the United States or any other country in which EDISON BIO or its subsidiaries, affiliates or service providers maintain facilities and, therefore, your information may be subject to the laws of those other jurisdictions which may be different from the laws of your country of residence.
7. Children's privacy
EDISON BIO is committed to protecting the privacy of children as well as adults. Neither EDISON BIO nor any of its Services are designed for, intended to attract, or directed toward children under the age of 18. A parent or guardian, however, may collect a samples from, create an account for, and provide information related to, his or her child who is under the age of 18. The parent or guardian assumes full responsibility for ensuring that the information that he/she provides to EDISON BIO about his or her child is kept secure and that the information submitted is accurate.
8. Linked websites
EDISON BIO provides links to third party websites operated by organizations not affiliated with EDISON BIO. EDISON BIO does not disclose your information to organizations operating such linked third party websites. EDISON BIO does not review or endorse, and is not responsible for the privacy practices of these organizations. We encourage you to read the privacy statements of each and every website that you visit. This Privacy Statement applies solely to information collected by EDISON BIO and our service providers on our behalf.
9. Information for clients in Designated Countries
Our Site is not designed for Users Outside of the United States
Section 9 only applies to individuals located in the European Economic Area (“EEA”), United Kingdom, or Switzerland (the “Designated Countries”).
- Privacy Shield
EDISON BIO participates in and has certified its compliance with both the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Information transferred from the European Union (EU), European Economic Area (EEA), and Switzerland to the United States, respectively. EDISON BIO is committed to subjecting all Personal Information received from the EU member countries, EEA and Switzerland, in reliance on the Privacy Shield Frameworks, to the Framework's applicable Principles. If there is any conflict between the terms in this Privacy Statement and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit U.S. Department of Commerce's Privacy Shield List.
EDISON BIO is responsible for the processing of Personal Information it receives, under the Privacy Shield Frameworks, or subsequently transfers to a third party acting as an agent on its behalf. EDISON BIO complies with the Privacy Shield Principles for all onward transfers of Personal Information from the EU, EEA and Switzerland, including the onward transfer liability provisions.
With respect to Personal Information received or transferred pursuant to the Privacy Shield Frameworks, EDISON BIO is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, EDISON BIO may be required to disclose Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- Our relationship with you
We are the “controller” with respect to your Personal Information because we determine the means and purposes of processing your information when using our Services.
- Legal bases for processing Personal Information from the EU
We describe how we process your Personal Information in Sections 2 through 4 of this Privacy Statement. We may process your Personal Information if you consent to the processing, to satisfy our legal obligations, if it is necessary to carry out our obligations arising from any contracts we entered with you or to take steps at your request prior to entering into a contract with you, or for our legitimate interests to protect our property, rights or safety of EDISON BIO, our clients or others.
- Direct Marketing
We will obtain your consent where required to send you marketing communications using electronic means. You may withdraw your consent at any time within your EDISON BIO Account Settings or by emailing support@EDISONBIO.com. We will only contact you by electronic means (email, push notification, SMS, etc.) with information about our Services that are similar to those which were the subject of a previous sale or negotiation of a sale to you.
We will only share your Personal Information with third parties for marketing purposes with your explicit consent. If you do not want us to use your Personal Information in this way, please review and update your EDISON BIO Account Settings as necessary or contact us at support@EDISON BIO.com. You may raise such objection with regard to initial or further processing for purposes of direct marketing at any time and free of charge. The withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
Other marketing activities will happen based on the legitimate interests of EDISON BIO. E.g., where we tailor marketing communications or send targeted marketing messages via post, phone or social media and other third party platforms; and in providing existing clients with information (via email or other channels) about similar products and services.
- Privacy Rights
You can exercise your privacy rights by following the instructions below or contacting us at support@EDISONBIO.com. We will handle your request under applicable law. When you make a request, we may verify your identity to protect your privacy and security.
- Right to withdraw consent. To the extent EDISON BIO requests and you provide your consent to the processing of your Personal Information, you can withdraw your consent at any time. Your withdrawal will not affect the lawfulness of our processing based on consent before your withdrawal.
- Right of access to and rectification of your Personal Information. Our site allows you to access and rectify certain Registration Information within your EDISON BIO Account, and other information as required by applicable law. If you would like to access or rectify any other information, contact Client Care and we will do our best to assist you without undue delay. We may reject part or all of your request if responding to your request could adversely affect the rights and freedoms of others.
- Right to erasure (or, “Right to be Forgotten”). As explained under Section 5.d. (Account Deletion), we allow you to delete your account at any time. You can request erasure of Personal Information that: (a) is no longer necessary in relation to the purposes for which it was collected or otherwise processed; (b) was collected in relation to processing to which you previously consented, but later withdrew such consent; or (c) was collected in relation to processing activities to which you object, and there are no overriding legitimate grounds for our processing. If we have made your Personal Information public and we are required to erase such Personal Information, we will take reasonable steps, including technical measures, to inform controllers that are processing any links to or copies or replications of your Personal Information of your erasure request. Our assistance with your request for erasure is subject to limitations by relevant data protection laws, available technology and the cost of implementation.
- Right to data portability. If we process your Personal Information based on a contract with you or based on your consent, or the processing is carried out by automated means, you may request your Personal Information in a structured, commonly used and machine-readable format. You may also request the transfer of your Personal Information directly to another controller, where technically feasible, unless choosing to exercise this right adversely affects the rights and freedoms of others. A “controller” is a natural or legal person, public authority, agency or other body which alone or jointly with others, determines the purposes and means of the processing of your Personal Information.
- Right to restriction of our processing. You can restrict our processing of your Personal Information where one of the following applies: (a) you dispute the accuracy of Personal Information processed by EDISON BIO (for a period enabling us to verify its accuracy); (b) the processing is unlawful and you oppose the erasure of the Personal Information and request the restriction of its use instead; (c) EDISON BIO no longer needs the Personal Information for the purposes of the processing, but it is required by you for the establishment, exercise or defense of legal claims; and (d) you have objected to certain processing relying on legitimate interest, pending the verification whether EDISON BIO’s legitimate grounds override your rights. Restricted Personal Information shall only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest. We will notify you if the restriction is lifted.
- Notification of erasure, rectification and restriction. We will provide notice to each recipient that we disclosed your Personal Information to regarding any rectification or erasure of Personal Information or restriction of processing, unless you initiated the disclosure or providing notice proves impossible or involves disproportionate effort. Upon your request, we will share the list of recipients with you.
- Right to object to processing. Where the processing of your Personal Information is based on consent, contract, or legitimate interests described under the Legal Bases for Processing heading above, you may restrict or object, at any time, to the processing of your Personal Information as permitted by applicable law. We may continue to process your Personal Information if it is necessary for the defense of legal claims, or for any other exceptions permitted by applicable law.
- Automated individual decision-making, including profiling. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you, except as allowed under applicable data protection laws.
- Retention of your Personal Information. Unless you delete your account or delete certain Personal Information (i.e., User Content, etc.), we will store your Personal Information as long as your account is open. If you delete your account, we will take the steps described under “Your Choices – Account Deletion” and delete all your Personal Information, unless a longer retention period is required or permitted by law.
- The rights described above may be limited by local laws. Further, your right of access and deletion is not absolute and may not be available if fulfillment of such right would, among other things:
- cause interference with execution and enforcement of the law and legal private rights (such as in the case of the investigation or detection of legal claims or the right to a fair trial);
- breach or prejudice the rights of confidentiality and security of others;
- prejudice security or grievance investigations, corporate re-organizations, future and ongoing negotiations with third parties, the compliance with regulatory requirements relating to economic and financial management; or
- otherwise violate the interests of others or where the burden or cost of providing access would be disproportionate.
If you believe that we have infringed your rights, we encourage you to contact us so that we can try to address your concerns or dispute informally. Our contact information is:
EDISON BIO, LLC.
5900 Balcones Drive STE 100,
Austin, TX 78731
- Alternatively, you may contact EDISON BIO’s EU member representative,
EDISON BIO’s commitment to the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks entitle you to lodge a complaint via our Privacy Shield independent dispute resolution mechanism. To send your privacy complaints under the Privacy Shield Principles, please contact the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and/or to file a complaint.
As a last resort and under limited circumstances, EU, EEA and Swiss individuals with residual privacy complaints may invoke a binding arbitration option before the Privacy Shield Panel.
You also have a right to lodge a complaint with a competent supervisory authority situated in a Member State of your habitual residence, place of work, or place of alleged infringement. You can find the relevant supervisory authority name and contact details here: https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-are-data-protection-authorities-dpas_en.
10. California Residents
Pursuant to the California Consumer Privacy Act of 2018, California residents are afforded certain additional rights regarding our use of your personal information. To learn more about your California privacy rights, visit our Privacy Notice for California Residents.
11. Nevada Residents
Pursuant to Nevada law, you may direct a business that operates an internet website not to sell certain Personal Information a business has collected or will collect about you. EDISON BIO does not sell your Personal Information pursuant to Nevada law. For more information about how we handle and share your Personal Information or your rights under Nevada law, contact us at email@example.com
12. Do Not Track Statement
Some browsers have a ”do not track” feature that allows you to tell websites that you do not want to have your online activities tracked. At this time, due to a lack of industry standards, we do not respond to browser ”do not track” signals. To learn more about interest-based advertising or to opt-out of this type of advertising, visit the Network Advertising Initiative website and the Digital Advertising Alliance website. Options you select are browser- and device-specific.
13. Changes to this Privacy Statement
EDISON BIO modifies this Privacy Statement from time to time. We recommend revisiting this page periodically to stay aware of any changes to this Privacy Statement. If we modify this Privacy Statement, we’ll make it available through our website. Whenever material changes to this Privacy Statement are made, we will provide you with notice before the modifications are effective, such as by posting a notice on our website or sending a message to the email address associated with your account.
By continuing to access or use the Services after changes to this Privacy Statement becomes effective, you agree to be bound by the revised Privacy Statement. If any changes are unacceptable to you, you may stop using our Services and delete your account at any time.
We also may provide additional "just-in-time" disclosures or additional information about the data collection, use and sharing practices of specific Services. Such notices may supplement or clarify our privacy practices or may provide you with additional choices about how EDISON BIO processes your Personal Information.
14. Contact Information
If you have questions about this Privacy Statement, or wish to submit a complaint, request or inquiry, please email EDISON BIO's Privacy Administrator at firstname.lastname@example.org, or send a letter to:
EDISON BIO, LLC.
1321 Upland Dr.
Houston, TX 77043