DATA PRIVACY NOTICE
Last Updated: 08.14.2024
Baylor Genetics is a leading pioneer in genetic testing and is leading the way in precision medicine. Baylor Genetics is committed to protecting the privacy of individuals with whom it interacts and respects their right to determine the best way to manage and protect their information.
This Data Privacy Notice (Privacy Notice) applies to baylorgenetics.com and Baylor Genetics (e.g., “BG,” “we,” “our,” or “us”). It explains what information we collect from you when you use our website, online portal, and applications (“BG Website”), how we use the information collected and your rights regarding information provided to us. By using the BG Website, you consent to the data practices described in this statement. The collection, use, and disclosure of Protected Health Information (PHI) through the BG Website, or that is accessed via the BG Website, that is subject to provisions of the Health Insurance Portability and Accountability Act (HIPAA) and subsequent amendments are subject to our Notice of Privacy Practices which can be found here and is not governed by this Privacy Notice.
Baylor Genetics may revise this Privacy Notice from time to time. If we decide to change our Privacy Notice, we will post the revised policy here. If changes are significant and material, we will notify you by sending a notice to the primary email address specified in your account, by placing a prominent notice on the BG Website, and/or by updating any privacy information. Your continued use of the Website and/or services available after such changes will constitute your: (1) acknowledgment of the modified Privacy Policy; and (2) agreement to abide and be bound by our Privacy Policy.
- Personal Information We Collect
Information You Voluntarily Provide
To better provide you with products and services we offer, Baylor Genetics may collect personally identifiable information (Personal Information) you voluntarily provide to us, such as your:
- First and Last Name
- Mailing Address (street number and name, city, state, province, zip/postal code)
- E-mail Address
- Phone and/or Fax Number
Account and Interaction Data
We may collect additional Personal Information that you voluntarily submit to us through the BG Website and/or BG Platforms for other purposes, including information needed to register for an account if you choose to do so. This Personal Information, which may include sensitive information, includes information such as: (1) username and password; (2) name, email address, phone number, home address, employer’ name, business address, occupation, job title, professional specialty, National Provider Identifier (NPI). We will use your Personal Information for, but not limited to, communicating with you in relation to services and/or products you have requested from us.
Website Visitor or User Data
We may use third-party web analytics services on the BG Website to track the websites and pages you visit within the BG Website to determine what services are the most popular. This data is used to deliver customized content and advertising within Baylor Genetics to customers whose behavior indicates that they are interested in a particular subject area.
The information obtained for this purpose may be disclosed to or collected directly by these service providers to help us analyze how visitors use the BG Website. These third-party service provider(s) may collect certain information about you from your computer, including through the use of cookies. This may include information regarding your visit (e.g., pages visited and length of your visit), information about your device (IP address), how you got to the BG Website and other information about you.
Use of Cookies
The BG Website uses “cookies” to help personalize your online experience. A cookie is a text file that is placed on your hard disk by a web page server. Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you and can only be read by a web server in the domain that issued the cookie to you.
One of the primary purposes of cookies is to provide a convenience feature to save you time. The purpose of a cookie is to tell the web server that you have returned to a specific page. For example, if you personalize Baylor Genetics pages, or register with BG Platforms, a cookie helps Baylor Genetics to recall your specific information on subsequent visits.
This simplifies the process of recording your Personal Information, such as billing address, shipping address, and so on. When you return to the same website, the information you previously provided can be retrieved, so you can easily use the Baylor Genetics features you customized.
You can accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser setting to decline cookies if you prefer. If you choose to decline cookies, you may not be able to fully experience the interactive features of the BG Website and/or BG Platforms you visit.
Links
The BG Website contains links to third-party sites, including social media sites (e.g., Facebook, X (formerly Twitter), YouTube, LinkedIn, etc.). Any information you share on those third-party sites will be covered by the third-party site and not this Privacy Notice. Individuals seeking employment at Baylor Genetics or submitting payment to Baylor Genetics for services provided will be directed to third-party sites and no longer be on the BG Website. We encourage our users to be aware when they leave the BG Website and to read the privacy statements of any other site that collects personally identifiable information.
Children Under Sixteen
Baylor Genetics does not knowingly collect Personal Information from children under the age of 16. If you are under the age of 16, you must ask your parents or guardian for permission to use the BG Website. If you learn that a child under 16 has provided us with Personal Information without consent, please contact us. If we become aware that a child under 16 has provided us with their Personal Information, without consent, we will promptly delete such data.
- How We Use Your Personal Information
Baylor Genetics collects and uses your Personal Information to operate and deliver the services you have requested and as outlined in this Privacy Notice. Unless you inform us in writing otherwise, we retain your Personal Information for as long as necessary to meet our business purpose or as required by law.
We may also use your Personal Information to inform you of other products or services available from Baylor Genetics. If you do not want us to contact you, you may opt out of future communications, which is described in more detail in Section 4 below.
BG Website
We use Personal Information or non-personally identifiable information collected via the BG Website:
- To Administer our BG Website, our events, and for internal operations, including troubleshooting, data analysis, testing, statistical and survey purposes.
- For marketing, advertising, analytics or performance management purposes.
- To sign you up for our newsletters or other communications or subscribe or unsubscribe you to our mailing list upon your request.
- To improve our services to ensure that content is presented in the most effective manner for you and for your computer.
- For purposes made clear to you at the time you submit your information. For example, to provide services you have requested from us or to pay for services provided by us.
- To provide you with support and respond to your inquiries and complaints, including to investigate and address your concerns and monitor and improve our responses.
- To investigate and respond to suspected illegal activities or fraud.
- To comply with applicable federal, state, and other laws and regulations and respond to law enforcement requests or other valid legal requests and as required by applicable law, court order or governmental regulations.
- As described to you when collecting your Personal Information.
- As part of our efforts to keep the BG Website secure, including detection and removal of spammers, non-compliant images, links, etc.
DO-NOT-TRACK
You may have implemented a “do-not-track” signal through your browser. As there currently is no fixed standard for do-not-track signals, we currently do not respond to do-not-track signals from your web browser.
Sharing Information with Third Parties
Limitations on sharing Personal Information
We will not sell, rent, or otherwise disclose any of your Personal Information to any third party without your consent, except as disclosed in this Privacy Notice, as required by law, and when we believe it is necessary to prevent or take action regarding illegal activities, suspected fraud, or to protect the safety of any person.
Vendors, Consultants, and Other Service Providers
Baylor Genetics may share Personal Information with trusted partners, vendors, consultants, auditors, and other third-party service providers who need access to your Personal Information to perform their work on our behalf. These companies may include our website analytics companies, CRM service providers, email service providers, credit card servicer, survey vendors and others. All such third parties are prohibited from using your Personal Information except to provide these services to Baylor Genetics, and they are required to maintain the confidentiality of your Personal Information.
Baylor Genetics may sell Personal Information (limited to name; institution, email, address, phone number, fax number) of healthcare providers to pharmaceutical and/or research institutions as it relates to clinical trials. We do not share or sell sensitive Personal Information. You may opt-out of the sharing or sale of this limited Personal Information through our on-line Opt-Out form described below.
We may share non-personal, anonymous, summary, or aggregate user data with third parties.
Deidentified Health Information
Baylor Genetics may collaborate with other scientists, researchers and drug developers to advance knowledge of genetic diseases, to develop new treatments, and provide greater access to genetic testing opportunities for patients. Any research that results in medical advances, including new products, tests or discoveries, may have potential commercial value and may be developed and owned by Baylor Genetics or the collaborating researchers.
We may create deidentified health information regarding genetic variants that may be collated with other deidentified health data and transmitted to a third party for commercial purposes. The deidentified information does not include any personally identifying information but may include information about the ordering provider who has consented to the sharing of their information with third parties. In these cases, Baylor Genetics will share deidentified test results data to third parties for research or commercial purposes and Baylor Genetics may be compensated for the provision of testing services and for data sharing with third parties that is compliant with applicable law.
We do not collect, use or share biometric data for the purposes of identifying an individual.
Business Transfers
We may choose to buy or sell assets and may share and/or transfer Personal Information in connection with the evaluation of and entry into such transactions. Also, if we (or our assets) are acquired, go out of business, enter bankruptcy, or go through some other change in control, your Personal Information could be one of the assets transferred to or acquired by a third party.
Baylor Genetics Affiliates
We may also share your Personal Information with our business partners, H.U. Group Holdings, Inc., or Baylor College of Medicine for purposes consistent with this Privacy Notice.
National Security or Law Enforcement
We may be required to disclose your Personal Information in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
Other Purposes
We may use your Personal Information for any other purpose disclosed by us when you provide the information, or with your consent. We may disclose aggregated information about our users and information that does not identify an individual, without restriction.
- Security of Your Personal Information
Baylor Genetics secures your personal information from unauthorized access, use, or disclosure. Baylor Genetics uses the following methods for this purpose:
- Secure Sockets Layer (SSL) Protocol
When Personal Information (such as a credit card number) is transmitted to other websites, it is protected using encryption, such as the SSL Protocol.
We use technical, organizational, and administrative security measures to protect Personal Information we hold from loss, misuse, unauthorized access, disclosure, alteration, and destruction. We evaluate these safeguards on an ongoing basis to help minimize risks from new security threats as they become known. Please understand that no data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, you acknowledge that: (a) there are security and privacy limitations inherent to the Internet which are beyond our control; and (b) security, integrity, and privacy of all information and data exchanged between you and us through the BG Website cannot be guaranteed.
We restrict access to Personal Information to personnel and third parties that require access for legitimate, relevant business purposes. All Baylor Genetics staff, contractors, and third parties that have access to Personal Information are bound to confidentiality and we use controls to limit access to individuals that is necessary to perform their assigned responsibilities and tasks on behalf of Baylor Genetics.
- Your Privacy Rights
You can choose what Personal Information you disclose to us but understand that some Personal Information may be required for you to register for or use our services.
Communications Opt-in/Opt-out
By using the BG Website, you expressly allow us to contact you and use your Personal Information as set for in this Privacy Notice. You can opt-out of receiving promotional or marketing communications emails from us at any time by using the instructions for unsubscribing contained in email communications we send. You may also opt-out through our on-line opt-out form described below.
Surveys
To provide better service for our patients and customers, BG may conduct surveys. BG may use a third-party vendor (processor), such as Survey Monkey, to conduct surveys. You may access Survey Monkey’s privacy notice at https://www.surveymonkey.com/mp/legal/privacy/
State Data Privacy Protections
Some states have enacted data privacy laws which provide certain rights and protections to residents of those states. Baylor Genetics has adopted the most stringent state data privacy protection standards which are outlined below.
- Know what Personal Information is Collected and Shared. You have the right to request us to identify the types of Personal Information we have collected and used about you over the 12-month period prior to the date of your request. You may make this request only twice within a 12-month period. Generally, Baylor Genetics has collected, used and shared the categories of Personal Information described in this Privacy Notice.
- Deletion of Personal Information. You have the right to request that your Personal Information maintained by Baylor Genetics be deleted, with some exceptions as outlined under state law. If no exception applies, we will delete, aggregate, or anonymize your Personal Information from our records in accordance with applicable state law.
- Correction of Personal Information. You have the right to request correction of your Personal Information that is inaccurate.
- Limit Use or Disclosure Sensitive Information. You have the right to request that we limit the use or disclosure of your sensitive information to what is necessary to provide the services requested or to perform our business functions.
- Right to Opt-Out of Selling or Sharing. In the last 12 months, we have sold (within the meaning of California Consumer Privacy Act, as amended and other state laws) or disclosed deidentified protected health information that was deidentified using the methodology described at 45 CFR 164.514(b). At any time, you have the right to opt-out of the sale or sharing of your Personal Information. You may exercise this right by clicking here. If you opt-out, we will not sell or share your Personal Information unless you later provide consent to sell or share your Personal Information.
- Do Not Track (DNT) Requests. If you reject “all cookies” then you will not be tracked but you will not be able to fully utilize the functions within our website. As noted above, we do not currently respond to do not track signals from your computer.
- Right to Non-Discrimination. You will not be discriminated against in price and/or service, for exercising any of these rights under any state privacy law.
Making a Consumer Request
To make your verifiable consumer request to exercise your rights under CCPA or other state data privacy law, please contact [email protected] or use the address below.
A verifiable consumer request must be made by you, or a person you have authorized to make the request on your behalf. A representative must be authorized by you in writing or have a valid power of attorney. You may also make a verifiable request to us on behalf of your minor child.
The request must:
- Provide sufficient information for us to reasonably verify you or your authorized agent (see below); and
- Describe your request in reasonable detail so we can correctly understand, evaluate and respond to the request. We reach out for additional information.
Verification of You or Your Authorized Agent
Please note that we will need to verify your identity and state of residency, such as matching Personal Information you give us to our records, whenever possible, or ask for a copy of your legal form of identification before processing any request. If you are acting on behalf of another individual, we will need proof that you are authorized to make a request on that individual’s behalf, such as a valid power of attorney or comparable documentation. Absent such proof, we reserve the right to refuse to comply with your request.
Responding to your Verifiable Consumer Request
We will use reasonable efforts to respond to your request within 45 days of our receipt. Additional time may be required in which case we will notify you in writing of the reason for and length of the anticipated delay (not more than 90 days).
A request from an ordering provider to opt-out of the sale of their Personal Information will be responded to within 15 business days from receipt.
Residents of the European Economic Union
Under the General Data Protection Regulation (GDPR), residents of the EU have the following rights as it pertains to the Personal Information, including your health information (Personal Data) we collect, receive and process about you.
- Right of Access. You have the right to obtain information as to whether we process your Personal Data and to receive a copy of your Personal Data retained by us as a Controller. In addition, you have the right to obtain certain information about how and why we process your Personal Data.
- Right to Correct. You have the right to request an amendment or correction of inaccurate information and to have incomplete Personal Data corrected to include complete information.
- Right to Deletion. You have the right to request we delete your Personal Data in the following situations:
- Your Personal Data is no longer necessary in relation to the purpose for which it was collected and processed;
- You withdraw your consent which was required to process your Personal Data and we have no other legal basis to process your Personal Data;
- We are legally processing your Personal Data necessary for legitimate interests pursued by us or a third party, you object to our processing and we do not have any overriding legitimate basis to continue processing;
- Your Personal Data was unlawfully processed or provided to us;
- We must comply with a legal obligation that applies to us.
- Right to Restrict Processing. You have the right to request that we restrict processing of your Personal Data in the following circumstances:
- For a period of time that allows us to verify the accuracy of your Personal Data where you have contested its accuracy;
- Your Personal Data may have been unlawfully processed and you are requesting restriction instead of deletion;
- Your Personal Data is no longer necessary for the purpose for which it was collected and processed, but it is required by you to establish, exercise or defend legal claims; or
- For a period of time to allow us to verify whether our legitimate interests override your interests you have objected to the processing of your Personal Data.
- Right to Object to Processing. You have the right to object to processing of your Personal Data in the following cases:
- Our legal basis for processing is that it is necessary for a legitimate interest pursued by us or a third party; or
- Our processing is for direct marketing purposes.
- Right to Data Portability. You can ask to receive your Personal Data provided to us and to ask that we send your Personal Data to another organization if it is technically feasible, where you consented to the processing of your Personal Data, or where processing is necessary for performance of our contract with you and is carried out by automated means.
- Right to Withdraw Consent. You can withdraw your consent at any time where Baylor Genetics relied on your consent to process your Personal Data.
If you want to exercise any of the rights listed above, you can send a request to [email protected] or our contact address below. Our team will examine your request and respond to you as quickly as possible.
How to Contact Us
Baylor Genetics welcomes your questions or comments regarding this Privacy Notice.
Baylor Genetics
Privacy Official
2450 Holcombe Blvd, Ste 2210
Houston, TX 77021
Email: [email protected]
T: 1.800.411.4363