Effective date: June 29, 2020

Concert Genetics, Inc. (“Concert,” “our,” or “we”) operates the website and online platform that links to this Privacy Policy and other services that link to this Privacy Policy (collectively, the “Services”). Concert values and respects the privacy of its customers and visitors. The purpose of this Privacy Policy is to provide you with information about Concert’s practices regarding the collection, processing, use, storage, and disclosure of information when you use our Services. This Privacy Policy also describes the choices you can make about our use of your information.

We may update or modify this Privacy Policy at any time, by posting the amended version including the effective date of the updated version. We will announce any material changes to this Privacy Policy through an alert on our website and/or via email. By using the Services and accepting these terms, you agree to the terms of this Privacy Policy and the collection and use of information in accordance with this Policy. If you do not agree to be bound by this Privacy Policy, you should not access or use our Services or disclose any personal information through our Services.

HOW TO CONTACT US

You can update your preferences and information by updating your account information through our Services or contacting us at the e-mail address or phone number below. Additionally, if you have any questions or concerns about our use of your Personal Information (defined below), please do not hesitate to contact us through any of the methods below.

Phone: (615) 861-2634

Email: legal@concertgenetics.com

You can write to us at:
Attn: Legal Department
Concert Genetics, Inc.
3011 Armory Drive, Suite 290
Nashville, Tennessee 37204

PERSONAL INFORMATION

While using our Services, we may ask you to provide us with certain personally identifiable information (“Personal Information”). Personal Information is information that identifies, relates to, describes, can reasonably be associated with, or can reasonably be linked to a particular individual or household.

We collect information from you both when you provide it voluntarily and also automatically when you use our Services.  We may also collect Personal Information from other sources, as described below.

We collect Personal Information from you and any devices (including mobile devices) you use when you: use our Services, register for an account with us, provide us information on a web form, or over the telephone or online chat, update or add information to your account, when you otherwise correspond with us, engage or connect with us through one of our social media pages, or chat with a customer support specialist.

In addition, we also collect Personal Information about you from third parties in connection with our Services, including from the following sources:

  • Service providers (including hosting providers)
  • Data analytics service providers
  • Email, chat and other communications service providers
  • Customer service providers
  • Social media platforms

INFORMATION WE COLLECT

We may collect the following categories of Personal Information from you, depending on your interactions with our Services and the choices you make, as further described in the chart below:

Information collected through use of our Services
Categories of Information Description of category How We Use Information
Account Registration Information

To use certain portions of our Services, you may be required to establish and register your account. This is the Personal Information that is provided by you or collected by us to enable you to login and/or access your account and our platform services. This includes your name, phone number, state, zip code, email address, employer, and occupation.

Some of the Personal Information we will ask you to provide is required in order to create your account.

  • To provide, maintain, personalize, and improve our Services.
  • To respond to your questions and requests.
  • To create, maintain, and personalize your account with us.
  • To provide customer support.
  • To notify you about changes to our Services.
  • To allow you to participate in interactive features of our Services.
  • To contact you with newsletters, marketing or promotional materials and other information that may be of interest to you.
Health Information

In order to provide our Services to you, including without limitation to respond to and process your lab test order, the Services may access and process protected health information, as defined under the Health Insurance Portability and Accountability Act (“PHI”). If you are a healthcare provider, our use of PHI is governed by separate terms and conditions between Concert and its healthcare provider customers. PHI should only be submitted through the Services as permitted or required for use of the Services.

  • To provide our Services.
Newsletter Registration Information

You may provide your email address in order to receive our newsletter via email.

  • To contact you with newsletters, marketing or promotional materials and other information that may be of interest to you.
Request Information

This is the Personal Information provided by you to enable you to request information on your own behalf or on behalf of your employer concerning certain services provided by Concert. This includes your name, email address, company name, and job title.

  • To respond to your questions and requests.
  • To provide customer support.
  • To provide our Services.
  • To contact you with promotional information that may be of interest to you.
Resources

You may provide certain Personal Information in order to receive certain reports and research summaries from Concert. This includes your name, company name, job title, email address, and phone number.

  • To provide our Services.
  • To contact you with promotional information that may be of interest to you.
Customer Support Information

This includes any information that you choose to provide, whether by phone, email, or web form, to our sales representatives or customer service representatives. Our customer support web form requires your name, email address, and any information you provide in the message box. Our general contact web form requires your name, company name, job title, email address, and any information you provide in the message box.

  • To provide, maintain, personalize, and improve our Services.
  • To respond to your questions and requests.
  • To provide customer support.
  • To allow you to participate in interactive features of our Services when you choose to do so.
Third Party Data

This includes both Personal Information and non-personally identifiable data from our affiliates, customers, partners or vendors, data brokers, or public sources.

  • To provide, maintain, personalize, and improve our Services.
  • To monitor the usage of our Services.
  • To gather analysis and assess trends and interests.
  • To provide you with advertising content in which we think you will be interested. As part of this customization, we may observe your behaviors on the Services or on other websites.
Social Media Platforms

If you choose to access, visit, and/or use any of our pages on social media platforms such as Twitter or LinkedIn (“Social Media Platforms”), we may receive aggregate information and analysis about visitors’ usage of our pages on such Social Media Platforms. You may choose to provide Personal Information through Social Media Platforms, including without limitation your name, phone number, or address when you communicate with us on the Social Media Platforms, post suggestions or comments for us, or through other such interactions on the Social Media Platforms.

  • To respond to your questions and requests.
  • To  provide customer support.
  • To gather analysis and assess trends and interests.
Usage Information

This can be Personal Information and non-Personal Information that is collected about you when you are using our Services, and this may include:

  • Information about your interactions with our Services, which includes the date and time of any information you enter into our Services and your interactions with other users of our Services and what content or features you interacted with.
  • User content you post to our Services including messages you send through our web forms and your interactions with our customer service team and other users.
  • Technical data which may include URL information, cookie data, web beacons, pixels, and other tracking technology information, your IP address, the types of devices you are using to access or connect to our Services, unique device IDs, device attributes, network connection type (e.g., WiFi, 3G, LTE, Bluetooth) and provider, network and device performance, browser type, language, and operating system. Further details about the technical data that is processed by us can be found below.

Our Services uses cookies, unique identifiers and similar technologies to collect information over time and across different websites when you use or visit our Services. We or our third-party partners use common tracking tools to collect information about the pages you view, our Services functions that you access, the buttons and icons you click, and to remember your login information and Services settings to make it easier and more efficient for you to use our Services, and to provide advertising content that we think may be of interest to you.

Cookies. Cookies are small data files that are downloaded onto your computer or mobile device when you use our Services, which are unique to your device or account.  Cookies make it easier for you to use our Services by saving your preferences so that we can use these to improve your next and subsequent visits to our Services. Cookies help us learn which areas of our Services are useful and which areas need improvement.

Cookies may be either persistent or temporary (or session) cookies. A persistent cookie retains user preferences for a particular website, app or service, allowing those preferences to be used in future use sessions and remains valid until its set expiry date (unless deleted by the user before the expiry date). A temporary cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.

You can choose whether to accept cookies by changing the settings on your browser or device.  For more information regarding your choices with respect to cookies and other tracking technologies, please see “Your Rights and Choices Regarding Your Information” below.  However, if you choose to disable this function, your experience with our Services may be impaired and some features may not work as they were intended. When we use cookies or other similar technologies, we may set the cookies ourselves or ask third parties to do so to help us.

Pixels, Web Beacons. We or third party partners may use invisible pixels or beacons on our Services to count how many users access or use certain pages, features or content. This information is collected and reported in the aggregate. We may use this information to improve our current Services offerings, develop new products or services, and target information to you that may be helpful and useful to you based upon your use of our Services.

  • To administer our Services and system.
  • To create, maintain, and personalize your account with us.
  • To provide, maintain, personalize, and improve our Services.
  • To provide customer support.
  • To monitor the usage of our Services.
  • To gather analysis and assess trends and interests.
  • To detect, prevent, and address technical issues and provide customer support.
  • To provide you with advertising content in which we think you will be interested. As part of this customization, we may observe your behaviors on the Services or on other websites.
  • To help monitor the security of our Services.
Anonymized Information

We use anonymized and aggregated information that may be created or derived from your Personal Information or usage of our Services for purposes that include data analysis, improving our Services, advertising, and developing new features and functionality within our Services.

  • To provide, maintain, personalize, and improve our Services.
  • To monitor the usage of our Services.
  • To gather analysis and assess trends and interests.
  • To detect, prevent, and address technical issues.
  • To help maintain the safety, security, and integrity of our Services and technology assets.

SHARING YOUR INFORMATION

We share non-Personal Information with third parties at our discretion. We do not sell Personal Information. In connection with our Services, we may share your Personal Information with certain third parties who we engage to help us run our business and perform the services, including under the following circumstances:

  • Software and service providers we use to manage and process your information.
  • Affiliates, subsidiaries, and customers.
  • Web analytics providers who monitor and analyze the use of our Services (including Google Analytics). For more information about Google Analytics, please visit www.google.com/policies/privacy/partners.
  • Marketing service providers we use to communicate with you.
  • Business partners, including payors, your healthcare provider, and labs.
  • Advertising service providers we use to assist us in providing personalized advertising.
  • Other third parties that you expressly request us to share your Personal Information with.

Additionally, we will share your Personal Information with third parties where required by law, where it is necessary in connection with our Services or products, or where we have another legitimate interest in doing so.

Most of the third parties with whom we share your Personal Information are located and store your information in the United States, although some may be located or store your information outside of the United States. These third parties are only permitted to use your Personal Information to the extent necessary to enable them to provide their services to us.

If we are subject to a merger or acquisition with/by another company, we may share information with the other company in connection with the transaction, and your Personal Information may be transferred to such company upon completion of the transaction.

HOW WE SAFEGUARD YOUR INFORMATION

The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security. Any transmission of Personal Information is at your own risk.

HOW LONG WE STORE YOUR INFORMATION

We will retain your Personal Information only for as long as is necessary for the legitimate business purposes set out in this Privacy Policy. We will retain and use your Personal Information to the extent necessary to comply with our legal, accounting, or reporting obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies. Additionally, we may continue to store your Personal Information contained in our standard back-ups.

We also will retain Usage Information for internal analysis purposes. Usage Information is generally retained for a shorter period of time, except when Usage Information is used to strengthen the security or to improve the functionality of our Services or products, or we are legally obligated to retain Usage Information for longer periods.

YOUR RIGHTS AND CHOICES REGARDING YOUR INFORMATION

Marketing Preferences. You can opt out from receiving future marketing communications from us at any time by using the unsubscribe function in the email you receive from us, or contacting us as set forth under “How to contact us” above. Please allow sufficient time for your preferences to be processed. Even if you opt out of receiving marketing messages, we may still contact you for transactional purposes like confirming or following up on an order or service request, asking you to review a product or service you have ordered, or notifying you of product recalls. If you later opt back into getting marketing communications from us, we will remove your information from our opt-out databases.

As noted above in “The Information We Collect About You,” you can choose whether to accept cookies by changing the settings on your browser or device. However, if you choose to disable cookies, your experience with our Services may be impaired and some features may not work as they were intended.

Additionally, Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the preferences or settings page of your web browser. However, these features are not yet uniform, so we do not currently respond to such features or signals. Therefore, if you select or turn on a “do not track” feature in your web browser, we and our third-party providers may continue collecting information about your online activities as described in this Privacy Policy.

You can choose to limit the data that third party services (e.g., Social Media Platforms) share with us using the options provided to you by the applicable third party service (for example, the options provided by a Social Media Platforms when you connect your social media account with our Services).  You can also disconnect your use of our Services from the third-party service at any time using the options provided to you by the applicable third-party service.  Please note, however, that if you disconnect from the third-party service, that will not delete the data we may have previously collected while you were connected.

TRANSFER OF DATA; SPECIAL NOTICE TO NON-U.S. USERS

Your information, including Personal Information, may be transferred to – and maintained on – computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside of the United States and choose to provide information to us, please note that we transfer the data, including Personal Information, to the United States and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

SENSITIVE PERSONAL INFORMATION

Subject to the following paragraph, we ask that you not send us, and you not disclose, any sensitive personal information as this term is defined under applicable data protection and privacy laws (for example, social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Services or otherwise to us.

If you send or disclose any sensitive personal information to us, you consent to our processing and use of such sensitive personal data in accordance with this Privacy Policy. If you do not consent to our processing and use of such sensitive personal information, you must not submit such content to our Services.

POLICY ON CHILDREN’S INFORMATION

Our Services are not created for anyone under the age of 13 (“Children” or “Child”). By using the Services, you represent that you are at least 13 years old.  If you do not meet this age requirement, then you must not access or use our Services. We do not knowingly collect personally identifiable information from Children, and we do not target the Services to Children. If you are a parent or guardian and you are aware that your Child has provided us with Personal Information, please contact us though one of the methods listed under “How to Contact Us”, above. If we become aware that we have collected Personal Information from Children without verification of parental consent, we take reasonable steps to remove that information from our servers.

For more information about the Children’s Online Privacy Protection Act (“COPPA”), which applies to websites that direct their services to Children, please visit the Federal Trade Commission’s website https://www.ftc.gov/tips-advice/business-center/guidance/complying-coppa-frequently-asked-questions.

LINKS TO OTHER SITES

Our Services contain links to third-party websites. If you click on one of those links, you will be taken to websites we do not control. This Privacy Policy does not apply to the information practices of those third-party websites. You should read the privacy policies of third-party websites carefully. We are not responsible for the content, privacy policies, actions or security of third-party websites.

GOVERNING LAW AND JURISDICTION

This Privacy Policy shall be construed and governed under the laws of the United States and State of Tennessee (without regard to rules governing conflicts of laws provisions). You agree that venue for all actions, arising out of or relating in any way to your use of our Services, shall be in federal or state court of competent jurisdiction located in Davidson County, Tennessee, within one (1) year after the claim arises. Each party waives any objections based on forum non conveniens and waives any objection to venue of any action instituted hereunder to the extent that an action is brought in the courts identified above. Each party consents to personal jurisdiction in the courts identified above.