privacy policy

This Privacy Policy of Pheramor, Inc. (“Pheramor”) applies to all websites and mobile applications owned and operated by Pheramor, and describes the information we collect, how that information may be used, with whom it may be shared, and your choices about such uses and disclosures. We encourage you to read this Privacy Policy carefully prior to using our Platform or Services or transacting business with us. By using our Platform or Services, you are accepting the practices described in this Privacy Policy.

Definitions

Aggregate Information: information that has been combined with that of other users and analyzed or evaluated as a whole, such that no specific individual may be reasonably identified.

Anonymized Information: information that has been stripped of your Registration Information and other identifying data such that you cannot reasonably be identified as an individual.

Individual-level Information: information about a single individual’s DNA and/or social media and demographic data, but which is not necessarily tied to Registration Information.

Personal Information: information that can be used to identify you, either alone or in combination with other information. Pheramor collects and stores the following types of Personal Information: birthdate, data, analysis, reports and findings from your Genetic Information, and other demographical information provided by you on the Platform

Registration Information: information you provide about yourself when registering for and/or purchasing our Services (e.g. name, email, address, user ID and password, and payment information).

Genetic Information: information regarding your DNA, generated through processing of your saliva and/or cheek cells by Pheramor or by its contractors, successors, and assignees or otherwise processed by and/or contributed to Pheramor, including such information uploaded from other sources (including but not limited to 23andMe.com) and any resultant data, analysis, reports, and findings.

Platform: Pheramor’s websites and mobile applications including the internet-based platform developed and maintained by Pheramor for the purpose of onboarding and connecting users based on certain traits contained in their DNA and their social media and demographic data.

Sensitive Information: Genetic Information and certain Personal Information that you optionally provide that may reveal your ethnic origin, nationality, religion and/or sexual orientation.

Service or Services: Pheramor’s products (including the Platform), software, services (including collection, analysis and resultant data from user DNA, and social media and demographic data), and website (including but not limited to text, graphics, images, and other material and information) as accessed from time to time by the user, regardless if the use is in connection with an account or not.

User Content: all information, data, text, software, music, audio, photographs, graphics, video, messages, or other materials, (excluding Genetic Information but including certain analysis or “matching” data illustrating the comparative compatibility between users), generated by users of the Services and transmitted, whether publicly or privately, to or through the Platform.

Web Behavior Information: information on how you use the Platform (e.g. browser type, domains, page views) collected through log files, cookies, and web beacon and mobile technology.

Principles

We collect and handle information (i) to provide, analyze and improve our Services and our Platform, (ii) in the event that we partner with one or more bone marrow registries (“Registries”) and the user consents, to provide additional potential matches for recipients in need of bone marrow transplants, increasing the pool of potential donors and the odds that more lives will be saved by bone marrow transplant, among other potential missions (iii) as we reasonably believe is permitted by laws and regulations, including for marketing and advertising purposes, (iv) to protect the security and safety of our company, employees, customers, as we reasonably believe is permitted by laws and regulations, (v) to comply with laws and regulations we are subject to, and (vi) on an anonymized, aggregated basis, for any other purpose.

We understand and respect the sensitive nature of the information you may provide to us. We will not sell, lease, or rent your Individual-Level Information to any third-party without your explicit consent. Please see below to learn more about our sharing and consent practices.

We are committed to providing a secure and safe environment for our Services.

By providing information to us, you consent to the collection, use and disclosure of that information in accordance with this Privacy Policy.

What information we collect

Information you provide directly to us.

Registration Information; Personal Information; Genetic Information; Web Behavior Information. When you register an account with us, purchase our Services, access our Platform or otherwise provide us with information, we collect personal information, such as your name, date of birth, billing and shipping address, payment information (e.g., credit card) and contact information such as your email and phone number and license number.  We collect data from your social media accounts, including but not limited to Facebook, Twitter, and Instagram, including but not limited to likes, dislikes, groups joined, check-ins, and hashtags. We collect and store any personal information you enter on our Platform or provide to us in some other manner. We collect your DNA (directly or via import from other services) and perform analysis and generate reports with that data in furtherance of the Services and for reporting to the Registries (unless you did not consent to such reporting).  We also request information about your interests and activities, your gender and age, and other demographic information such as your hometown or your username.

User Content. Our Platform allows you to create and post or upload User Content, such as data, text, software, music, audio, photographs, graphics, video, messages, or other materials that you create or provide to us through either a public or private transmission.

Blogs. To the extent that our Platform or other related website offers publicly accessible blogs or community forums, you should be aware that any information you provide in these areas may be read, collected, and used by others who access them. Please note that whenever you post something publicly, it may sometimes be impossible to remove the information, for example, if someone has taken a screenshot of your posting. Please exercise caution before choosing to share personal information publicly on our blogs, community forums or in any other posting. Note also that you may be required to register with a third-party application to post a comment. To learn how the third-party application uses your information, please review their privacy statement.

Social Media Features and Widgets. To the extent that our Platform includes Social Media Features, such as the Facebook Like or Share button and Widgets, and the LinkedIn Open ID application (“Features“), such Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. They may also allow third-party social media services to provide us information about you, including but not limited to your name, email address, and other contact information. The data we receive is dependent upon your privacy settings with the social network. Features are either hosted by a third-party or hosted directly on our site. Your interactions with these Features are governed by the privacy statement of the company providing it. You should always review, and if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to our Platform or Service.

Third-party services (e.g., social media). If you use a third-party site, including but not limited to Facebook, Instagram, or Twitter, in connection with our Services to communicate with another person (e.g., to make or post referrals or to request that we communicate with another person), then in addition to that person’s name and contact information, we may also collect other information (e.g., your profile picture, network, gender, username, user ID, age range, language, country, friends lists or followers) depending on your privacy settings on the third-party site. We do not control third-party site’s information practices, so please review their privacy policies and your settings on those sites carefully.

Customer service. When you contact our customer service center or correspond with us about our Service, we collect information to: track and respond to your inquiry; investigate any breach of our Terms of Use, Privacy Statement or applicable laws or regulations; and analyze and improve our Services.

Information related to our genetic testing services. To use our Services, you must register an online account, and ship your saliva and/or cheek cell sample to us, which will be tested by a third-party laboratory. Once received, your sample will be identified by its unique barcode. The barcode label identifies you to us but not to our third-party laboratory. Your sample and DNA may be stored for further sequencing such as, but not limited to, human-leukocyte antigen sequencing and personality sequencing and/or genotyping.  Your sample may be destroyed at any time after the laboratory completes its work.

Genetic Information. Genetic Information refers to features of your DNA that distinguish you from other people and is generated when we analyze and process your saliva and/or cheek cell sample, or when you otherwise contribute or access your Genetic Information through our Services. Genetic Information includes the data, analysis, and reports generated therefrom, and may be used for other purposes, as outlined in below.

Web Behavior Information. We and our third-party partners use cookies and similar technologies (such as web beacons, tags, scripts and device identifiers) to help us recognize you, customize and improve your experience, provide security, analyze usage of our Services and the Platform (such as to analyze your interactions with the results, reports, and other features of the Service), gather demographic information about our user base, to offer our products and services to you, to monitor the success of marketing programs, and to serve targeted advertising on our site and on other sites around the Internet. We may receive reports based on the use of these technologies by these companies on an individual as well as aggregated basis. Users can control the use of cookies at the individual browser level. All data that is shared is de-identified from the user.

As is true of most websites, we gather certain information automatically and store it in log files. This information may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and/or clickstream data. We may combine this automatically collected log information with other information we collect about you, such as your user profile ID or order number. We do this to improve services we offer you, and to improve marketing, analytics, and site functionality.

When you access our Service by or through a mobile device, we may receive or collect and store a unique identification numbers associated with your device or our mobile application (including, for example, a UDID, Unique ID for Advertisers (“IDFA”), Google Ad ID, or Windows Advertising ID), mobile carrier, device type, model and manufacturer, mobile device operating system brand and model, phone number, and, depending on your mobile device settings, your geographical location data, including GPS coordinates (e.g. latitude and/or longitude) or similar information regarding the location of your mobile device.

Google Analytics. Google Analytics is used to perform many of the tasks listed above. We may use any or all of the following Google Analytics Advertising features: Remarketing, Google Display Network Impression Reporting, Google Analytics Demographics and Interest Reporting, and DoubleClick Campaign Manager integration. We do not merge information collected through any Google advertising product with individual-level information collected elsewhere by our service.

Other Types of Information.  We are always working to enhance our Services with new products, applications and features that may result in the collection of new and different types of information. We will update our privacy statement, as needed.

How we use and share information

Pheramor will use and share your personal information with third-parties only in the ways that are described in this privacy statement.

We use the information described above to operate, provide, analyze and improve our Services and our Platform. These activities may include, among other things, using your information in a manner consistent with other commitments in this privacy statement, to:

open your account, enable purchases and process payments, communicate with you, and implement your requests;

host our Platform via our website, run our mobile application(s), authenticate your visits, provide custom, personalized content and information, and track your usage of our Services;

deliver our products and services, and manage our business;

conduct analytics to improve and enhance our Services;

offer new products or services to you, including through emails, promotions or contests;

implement online marketing campaigns and targeted advertising, including by utilizing third-party ads (subject to your cookie settings and preferences), and to measure the effectiveness of our marketing and targeted advertising;

conduct surveys or polls, and obtain testimonials;

process and deliver your genetic testing results;

enforce or exercise any rights in our terms and conditions; and

perform research & development activities, which may include, for example, conducting data analysis and research in order to develop new or improve existing products and services, and performing quality control activities.

You may be able to opt-in, opt-out or otherwise adjust your preferences of having your information used for certain of these activities.

We use mobile analytics software to allow us to better understand the functionality of our mobile software on your phone. This software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from. We do not link the information we store within the analytics software to any personally identifiable information you submit within the mobile application.

In the event that we partner with one or more Registries, you have the choice to allow us to provide certain Genetic Information and Personal Information to such Registries to provide additional potential matches for recipients in need of bone marrow transplants, increasing the pool of potential donors and the odds that more lives will be saved by bone marrow transplant.

Information we share with third-parties

General service providers. We share the information described above with our service providers, as necessary to provide their services to us. Service providers are third-parties (other companies or individuals) that help us to provide, analyze and improve our Services. For example, we work with third-party laboratories and contractors to process and analyze your saliva and/or cheek cell sample for purposes of generating your Genetic Information. While we implement procedures and contractual terms to protect the confidentiality and security of your information, we cannot guarantee the confidentiality and security of your information due to the inherent risks associated with storing and transmitting data electronically.

Laboratory service providers. When you send in your saliva and/or cheek cell sample, it will go to our third-party laboratory with a unique barcode label. The unique barcode identifies you to us but not to the laboratory. We are also required to provide certain information to the laboratory including your sex and date of birth or age pursuant to clinical laboratory requirements. No other Registration Information (such as your name, address, email, phone number or other contact information) is required or provided to the laboratory. The receiving personnel at the laboratory will remove and discard your “sender information” from the packaging (e.g., name, address) before testing personnel receive the samples for processing. Receiving personnel do not perform testing, and testing personnel handle samples that are labeled only with the unique barcode. DNA and samples are destroyed after the laboratory completes its work, provided that laboratory legal and regulatory requirements no longer require the actual samples to be maintained. A de-identified copy of genotyping data will be kept in accordance with CLIA. The laboratory securely sends the resulting Genetic Information to us along with your unique barcode. Genetic Information is stored securely on our servers; the laboratory also stores your Genetic Information, but again, labeled only with the barcode.

“Targeted advertising” service providers. In the event that we partner with any third-party advertising networks and providers, they may collect Web Behavior Information on our Service to help us to deliver targeted online advertisements (“ads”) to you. They use cookies and similar technologies (such as JavaScript, beacons, device identifiers, location data, and clear gifs) to compile information about your browser’s or device’s visits and usage patterns on our Services and on other websites over time, which helps to better personalize ads to match your interests, and to measure the effectiveness of ad campaigns.

Aggregate Information. We may share Aggregate Information with third-parties, which is any information that has been stripped of your Registration and aggregated with information of others so that you cannot reasonably be identified as an individual. This Aggregate Information is different from Individual-level Information. We may provide such Aggregate Information in commercial arrangements with our business partners.

Disclosures required by law. Under certain circumstances your information may be subject to disclosure pursuant to judicial or other government subpoenas, warrants, or orders, or in coordination with regulatory authorities, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Pheramor will preserve and disclose any and all information to law enforcement agencies or others if required to do so by law or in the good faith belief that such preservation or disclosure is reasonably necessary to: (a) comply with legal or regulatory process (such as a judicial proceeding, court order, or government inquiry) or obligations that Pheramor may owe pursuant to ethical and other professional rules, laws, and regulations; (b) enforce the Pheramor Terms of Use and other policies; (c) respond to claims that any content violates the rights of third-parties; or (d) protect the rights, property, or personal safety of Pheramor, its employees, its users, its clients, and the public.

Your Options

Access to your account. If your Registration Information changes, you may access, correct or update most of it from your Account Settings page. You may also modify and delete certain of your information, or update your consent status and biobanking options. Please note that you may not be able to delete User Content that has been shared with others through the Service and that you may not be able to delete information that has been shared with third-parties, though we can work with you to prohibit your data from being shared with third-parties in the future. We will respond to your request to access within 30 days.

You can choose not to provide us with certain information, but that may result in you being unable to use certain features of our site because such information may be required in order for you to register as a member; purchase products or services; participate in a contest, promotion, survey, or sweepstakes; ask a question; or initiate other transactions.

Marketing communications. By registering for an account, you are agreeing that we may send you promotional emails about our Services. You may be able to opt-out of receiving certain messages or notifications from us by changing your settings on your Account page. You can also click the “unsubscribe” button at the bottom of promotional email communications. Please note that you may not opt-out of receiving non-promotional messages regarding your account, such as technical notices, purchase confirmations, or Service-related emails.

Information you choose to share with others. We provide areas on our site where you can post information about yourself and others and communicate with others or upload content such as photographs, all of which is considered User Content. Such postings are governed by our Terms of Use. Also, whenever you voluntarily disclose personal information on publicly-viewable web pages, that information will be publicly available and can be collected and used by others. For example, if you post your email address, you may receive unsolicited messages. We cannot control who reads your posting or what other users may do with the information you voluntarily post, so we encourage you to exercise discretion and caution with respect to your personal information

Account closure. If you no longer wish to participate in our Services or no longer wish to have your personal information be used, you may close your account by changing your settings on your Account page or sending a request to our customer service center. Pheramor may maintain your genetic information, social media and demographic data indefinitely, but reserves its right to remove all information from closed accounts from its system. If you reenroll into Pheramor’s service, you may be required to have your DNA analyzed again. If you do not want Pheramor to continue to store your genetic information and social media and demographic data then you must email Pheramor at info@pheramor.com to request removal of all such information. If your genetic information is removed then you will be responsible for paying the sequencing fee if you subsequently re-enroll in Pheramor’s service.  As stated in any applicable Consent Document, however, Genetic Information that has been previously provided to any Registry may not be able to be deleted or removed. We may also retain backup copies for a limited period of time pursuant to our data protection policies. In addition, we retain limited Registration Information related to your order history (e.g., name, contact, and transaction data) as long as your account is active or as needed to provide you services, as well as for accounting, audit and compliance purposes.

Important Information

Security measures. Pheramor takes seriously the trust you place in us. To prevent unauthorized access or disclosure, to maintain data accuracy, and to ensure the appropriate use of information, Pheramor uses a range of physical, technical, and administrative measures to safeguard your Personal Information. In particular, all connections to and from our website and mobile application are encrypted using Secure Socket Layer (SSL) technology.

Please recognize that protecting your Personal Information is also your responsibility. We ask you to be responsible for safeguarding your password, secret questions and answers, and other authentication information you use to access our Services. You should not disclose your authentication information to any third-party and should immediately notify Pheramor of any unauthorized use of your password. Pheramor cannot secure Personal Information that you release on your own or that you request us to release.

Business transactions. In the event that Pheramor goes through a business transition such as a merger, acquisition by another company, or sale of all or a portion of its assets, your information will likely be among the assets transferred. In such a case, your information would remain subject to the promises made in any pre-existing Privacy Policy.

Linked websites. Pheramor provides links to third-party websites operated by organizations not affiliated with Pheramor. Pheramor does not disclose your information to organizations operating such linked third-party websites. Pheramor does not review or endorse, and is not responsible for, the privacy practices of these organizations. We encourage you to read the privacy statements of each and every website that you visit. This Privacy Policy applies solely to information collected by Pheramor.

Children’s privacy. Pheramor is committed to protecting the privacy of children as well as adults. Neither Pheramor nor any of its Services are designed for, intended to attract, or directed toward children under the age of 18. Persons must be at least 18 years of age to use the Services and the Platform, and by so engaging, you represent that you are at least 18.

Changes to this Privacy Statement. Whenever this Privacy Policy is changed in a material way, a notice will be posted as part of this Privacy Policy and on our customers’ account login pages for 30 days. After 30 days the changes will become effective. In addition, all customers will receive an email with notification of the changes prior to the change becoming effective.

Contact Information

If you have questions about this Privacy Policy, please email Pheramor’s Privacy Administrator at info@pheramor.com, or send a letter to: Pheramor, Inc., Attn. Privacy Administrator, 720 Rusk Street Houston, TX 77002.

*This Privacy Statement was last updated on August 12th, 2017.