Smarter oncology second opinion — AI-powered, expert-reviewed, using your existing NGS report.
Read More
Company
Our TechnologyOur StoryOur TeamCareersOncompass MedicineResourcesContact Us
Solutions
For OncologistsFor Patients
Services
Second Opinion Service
Get a Second Opinion
Terms of Use | Cookie Policy | Privacy Policy | HIPAA Notice
Genomate Logo
Company
Our TechnologyOur StoryOur TeamCareersOncompass Medicine
Solutions
For OncologistsFor PatientsFor Partners
Resources
All ResourcesNewsMedia CoveragePublicationsEnhancing NGS
Contact
Get a Second Opinion
Close Cookie Popup
We use cookies
We use cookies to enhance your browsing experience, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Learn more in our Cookie Policy.
Accept All Cookies
Reject All
Preferences
Close Cookie Preference Manager
Cookie settings
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts. More info
Strictly Necessary (Always Active)
Cookies required to enable basic website functionality.
Accept All Cookies
Save preferences
Made by Flinch 77
Oops! Something went wrong while submitting the form.
Cookies Preferences

Privacy Notice - Informational Second Opinion Service (EU Residents)

‍

Effective Date: 20.04.2026

‍

‍

‍

If you reside in the United States of America, this Privacy Notice does not apply to you. It applies only to European Union residents. Please consult the Privacy Notice applicable to U.S. residents.

‍

This Privacy Notice explains how Genomate Health, Inc. (“Genomate,” “we,” “us”) collects, uses, and shares personal data in connection with the Second Opinion Service (the “Service”) when accessed by individuals located in the European Union, European Economic Area, or the United Kingdom (“EU”).

‍

This Notice applies when you submit an order request, upload records, make payment, and participate in the review and related communications.

‍

This Notice does not apply to general browsing of our website or to marketing-related interactions, which are covered by our separate Website Privacy Policy.

‍

Summary

We encourage you to read this entire Privacy Notice to understand how your information is handled in connection with the Service. If you are short on time, the key points are summarized below.

  • We process your personal data only to provide, support, and operate the Service you request.
  • The Service is educational and informational in nature only and does not constitute the provision of medical care within the European Union.
  • We process health-related data only with your explicit consent, in accordance with Article 9(2)(a) GDPR.
  • We collect only the personal data that is strictly necessary to deliver the Service, including coordinating the review, enabling the Independent Oncologist to provide an independent opinion, verifying authorizations, processing payment, and ensuring security and compliance.
  • Your data may be shared with the Independent Oncologist involved in your case and with carefully selected service providers who support the operation of the Service and are contractually required to protect your data.
  • Your personal data may be transferred to and processed in the United States, subject to appropriate safeguards in accordance with GDPR.
  • You have rights under the GDPR, including the right to access, correct, delete, and restrict the processing of your personal data, and the right to withdraw your consent at any time.

‍

If you have questions about this Privacy Notice, how your information is used, or how to exercise your rights, you may contact us at any time at privacy@genomate.health

‍

‍

‍

1. Who we are and how to contact us

‍

Genomate Health, Inc., 1 Broadway, Cambridge, MA, USA

EU establishment (for EU inquiries): Genomate Health Hungary Kft., Retek utca 34, 1024 Budapest, Hungary

Contact: privacy@genomate.health

‍

If you have questions about this Notice or want to exercise your rights, contact us at privacy@genomate.health

‍

‍

‍

2. Role clarification - Genomate and the Independent Oncologist

‍

The Service consists of an independent, educational review of medical information provided by a licensed oncologist (the “Independent Oncologist”). Based on the information submitted, the Independent Oncologist provides an informational second opinion intended to support understanding of a medical condition.

‍

For the purposes of the GDPR, Genomate Health, Inc. acts as the data controller for the personal data described in this Privacy Notice, except where otherwise stated.

‍

The Service is educational and informational in nature only. It does not constitute the provision of medical care within the European Union and does not create a doctor-patient relationship under EU healthcare laws.

‍

The Independent Oncologist exercises independent professional judgment and is solely responsible for the content of the opinion provided.

‍

Genomate does not practice medicine and does not provide medical advice. Genomate provides the technical and administrative infrastructure that enables the Service, including secure data collection, coordination of the review process, communication handling, and delivery of the final report.

‍

‍

Data protection roles

‍

For purposes of the General Data Protection Regulation (GDPR):

  • Genomate acts as a data controller for the collection and processing of personal data in connection with the operation and administration of the Service, including intake, coordination, communication, payment processing, security, and support functions.
  • The Independent Oncologist acts as an independent data controller with respect to the personal data received to perform the independent review and prepare the opinion.

‍

Personal data is shared between Genomate and the Independent Oncologist only to the extent necessary to provide the Service.

‍

Genomate and the Independent Oncologist are not joint controllers, as they determine their respective purposes and means of processing independently.

‍

‍

Nature of the service

‍

The Service:

  • is based exclusively on the information you provide;
  • is intended for informational and educational purposes;
  • is not a diagnosis or treatment recommendation under EU law; and
  • should not replace consultation with a qualified healthcare provider in your jurisdiction.

‍

‍

Service availability

‍

The Service is available to individuals located in the European Union, European Economic Area, and the United Kingdom.

‍

There are no location-based licensing requirements within the EU for accessing the Service, as it is not provided as regulated medical care. However, you are responsible for ensuring that your use of the Service complies with any applicable local laws or requirements.

‍

Genomate relies on the information provided by users regarding their eligibility to use the Service. If it is determined that the Service is being used in a manner inconsistent with these terms, access to the Service may be limited or discontinued.

‍

‍

Identity, eligibility, and authorization verification

‍

To protect personal data and ensure that the Service is used appropriately, we may take reasonable steps to verify identity, eligibility, and authorization in connection with the Service.

‍

These steps are designed to ensure that:

  • personal data is accessed only by authorized individuals;
  • the Service is used by eligible users; and
  • the information provided is sufficient to enable the educational review.

‍

These steps may include, as appropriate:

  • verifying contact details such as email address and phone number;
  • confirming basic identifying information (such as name and date of birth) for record matching and access control;
  • confirming the country of residence or location within the European Union, European Economic Area, or the United Kingdom;
  • assessing eligibility criteria relevant to the Service, such as the type of condition, availability of sufficient medical information, or other operational requirements; and
  • where the Service is requested or accessed by someone other than the patient, verifying the individual’s relationship to the patient and any claimed authority (such as parental responsibility or legal authorization), or obtaining the patient’s authorization.

‍

We process only the information that is necessary and proportionate for these purposes, in accordance with applicable data protection laws.

‍

If we are unable to reasonably verify identity, eligibility, or authorization, or if required confirmations or documentation are missing, insufficient, or inconsistent, the Service may be paused, limited, or cancelled, and access to Service outputs may be restricted, in accordance with applicable law and our Terms and Conditions.

‍

‍

‍

3. What personal data we collect

‍

You are not legally required to provide your personal data to us. However, if you do not provide the information necessary for eligibility assessment, review, payment, or communication, we may not be able to provide the Service.

‍

‍

3.1 Data you provide

‍

Depending on how you use the Service, we may collect:

  • Identity and contact details: name, email, phone number, address, country, postal code, date of birth (if required for matching), and basic identity verification information.
  • Patient details (if you are not the patient): patient name and contact details, relationship to the patient, and whether you are a legal representative.
  • Medical information you submit: symptoms, diagnosis, treatment history, pathology reports, imaging reports, lab results, molecular/genetic test results, physician notes, and other medical records you upload or describe during the review.
  • Service logistics: scheduling preferences, communications with our team, and review participation details.
  • Consents and signatures: the consent checkboxes you complete and your electronic signature, including timestamp and related audit metadata.
  • Payment information: transaction status and payment metadata. (Payment card details are generally collected directly by the payment processor, not stored by Genomate.)

‍

‍

3.2 Data we collect automatically

‍

We may collect:

  • Device and usage data: IP address, approximate location derived from IP, browser type, device identifiers, and log data related to access and security (for example, authentication events, audit logs, and error logs).

‍

‍

3.3 Data from third parties

‍

We may receive limited data from:

  • Payment processors (confirmation of payment, refunds, chargebacks)
  • Service providers supporting scheduling, communications, and secure delivery
  • The Independent Oncologist or their practice where needed to deliver the Service

‍

Where the Service intake form uses essential cookies or similar technical tools for security, session management, or fraud prevention, those technologies are governed by our Website Privacy Policy and, where applicable, our Cookie Policy.

‍

‍

‍

4. Purpose of data processing

‍

We process personal data in connection with the Service only to the extent necessary to provide and operate the Service and to comply with applicable legal and regulatory obligations. We do not process personal data for purposes incompatible with those described in this Privacy Notice.

‍

More specifically, we use personal data for the following purposes:

‍

‍

To provide the Service

‍

We process personal data to receive and review your request, organize and transmit the information you submit, coordinate scheduling and session logistics, and deliver the educational second opinion and related communications.

‍

‍

To verify identity and manage authorizations

‍

We process personal data to verify the identity of the patient and any authorized support persons, manage access to submitted materials and results, and document consents, acknowledgments, and applicable authorizations.

‍

‍

To process payments and prevent fraud

‍

We process limited personal and transactional data to confirm payments, issue refunds where applicable, handle disputes, and prevent fraudulent or unauthorized transactions.

‍

‍

To ensure security and operational reliability

‍

We process personal data to protect the confidentiality, integrity, and availability of the Service, including monitoring for security incidents, maintaining audit logs, and ensuring system reliability and continuity.

‍

‍

To provide customer support and operational communications

‍

We process personal data to respond to inquiries, provide service-related communications, and support users before, during, and after the review.

‍

‍

To comply with legal and regulatory obligations

‍

We process personal data as necessary to comply with applicable laws and regulations, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims.

‍

We do not use personal data for marketing, profiling, or automated decision-making, and we do not use health data for research or model training purposes.

‍

‍

‍

5. Legal bases for processing

‍

‍

5.1 General approach

‍

We process personal data in connection with the Service only where a valid legal basis applies under the General Data Protection Regulation (GDPR), and only for the purposes described in this Privacy Notice.

‍

The applicable legal basis depends on the nature of the data and the purpose of processing. Where health data is involved, we apply additional safeguards and rely on a specific condition under Article 9 GDPR, as described below.

‍

‍

5.2 Legal bases under the GDPR (where applicable)

‍

Where the GDPR applies, Genomate relies on one or more of the following legal bases under Article 6 GDPR for the processing of personal data:

  • Performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR). Processing is necessary to take steps at your request prior to entering into a service relationship and to perform the Service once requested. This includes intake of information, coordination of the review, delivery of the second opinion report, and related communications.
  • Legitimate interests (Article 6(1)(f) GDPR). Processing is necessary for Genomate’s legitimate interests in operating, securing, and improving the Service, including fraud prevention, system security, customer support, quality assurance, and the establishment, exercise, or defense of legal claims. These interests are balanced against your fundamental rights and freedoms, and we apply appropriate safeguards to protect your data.
  • Consent (Article 6(1)(a) GDPR). Where required by law or where no other legal basis is appropriate, we rely on your consent. This may include consent to specific disclosures, optional communications, or participation by authorized support persons. You may withdraw your consent at any time, subject to legal or contractual limitations.
  • Compliance with legal obligations (Article 6(1)(c) GDPR). Processing is necessary to comply with legal obligations to which Genomate is subject, including obligations relating to accounting, taxation, fraud prevention, data protection compliance, and lawful requests from public authorities.

‍

‍

5.3 Processing of special category data (health data) under the GDPR. The Service involves the processing of health data, which constitutes special category personal data under Article 9 GDPR.

‍

We process health data on the basis of your explicit consent (Article 9(2)(a) GDPR).

‍

By submitting your information and confirming the relevant consent statements within the Service, you explicitly consent to the processing of your health data for the purpose of receiving the educational review and related services.

‍

You may withdraw your consent at any time by contacting us at privacy@genomate.health. Withdrawal of consent does not affect processing carried out prior to withdrawal, but may prevent us from continuing to provide the Service.

‍

Health data is processed solely for purposes directly related to the provision and operation of the Service and is not used for marketing, profiling, research, or model training purposes.

‍

‍

5.4 No automated medical decision-making

‍

Genomate does not make automated medical decisions about patients. Any medical opinions provided as part of the Service are prepared and issued by a licensed Independent Oncologist exercising independent professional judgment.

‍

‍

5.4 Summary of legal bases by purpose

‍

Purpose of processing

  • Receiving and reviewing your request, opening and administering your case, and organizing the Service
  • Enabling the Independent Oncologist to review the submitted information and prepare the educational opinion
  • Managing scheduling, session logistics, and service-related communications
  • Verifying identity, eligibility, and authorization, including support person or representative access
  • Processing payments, refunds, chargebacks, and payment-related administration
  • Fraud prevention, abuse prevention, and protection of the Service
  • Security monitoring, audit logging, troubleshooting, and maintaining service reliability
  • Providing customer support and responding to inquiries
  • Complying with legal, regulatory, tax, accounting, and data protection obligations
  • Establishing, exercising, or defending legal claims

‍

Categories of data involved

  • Identity and contact details, patient details, submitted records, communications, service logistics
  • Medical information, patient details, supporting documents, communications relevant to the review
  • Identity and contact details, scheduling data, communications, service logistics
  • Identity and contact details, date of birth, country/location, authorization records, representative details, limited supporting documentation
  • Billing data, transaction metadata, payment status, limited contact details
  • Transaction metadata, device and usage data, logs, contact details, limited case-related metadata
  • Device and usage data, audit logs, access logs, error logs, limited account and communications data
  • Identity and contact details, communications, service history, submitted information relevant to the request
  • Identity data, transaction data, communications, logs, records required by law
  • Any categories of data strictly necessary for the claim or dispute

‍

Article 6 GDPR legal basis

  • Article 6(1)(b) - processing necessary for the performance of a contract or to take steps at your request before entering into a contract
  • Article 6(1)(b) - processing necessary for the performance of a contract
  • Article 6(1)(b) - processing necessary for the performance of a contract
  • Article 6(1)(b) - where necessary to provide the Service; and/or Article 6(1)(f) - legitimate interests in preventing misuse, protecting personal data, and ensuring secure access
  • Article 6(1)(b) - processing necessary for the performance of a contract; and Article 6(1)(c) - compliance with legal obligations, where applicable
  • Article 6(1)(f) - legitimate interests in fraud prevention, service protection, and security
  • Article 6(1)(f) - legitimate interests in ensuring the security, confidentiality, integrity, and availability of the Service
  • Article 6(1)(b) - where support is necessary to provide the Service; and/or Article 6(1)(f) - legitimate interests in customer support and service administration
  • Article 6(1)(c) - compliance with legal obligations
  • Article 6(1)(f) - legitimate interests in defending legal rights; and/or Article 6(1)(c) - compliance with legal obligations where applicable

‍

Article 9 GDPR condition (if health data is involved)

  • Article 9(2)(a) - your explicit consent
  • Article 9(2)(a) - your explicit consent
  • Article 9(2)(a) - your explicit consent, where health data is included in those communications
  • Article 9(2)(a) - your explicit consent, where health data is involved
  • Not normally applicable
  • Article 9(2)(a) - your explicit consent, but only if health data is exceptionally involved
  • Not normally applicable
  • Article 9(2)(a) - your explicit consent, where health data is included in support communications
  • Article 9(2)(a) - your explicit consent, where health data must be retained or disclosed in connection with the Service and applicable law permits or requires such processing
  • Article 9(2)(a) - your explicit consent, where health data is involved

‍

‍

‍

6. Sharing your personal data

‍

We share personal data collected in connection with the Service only where necessary for the operation of the Service, the fulfillment of your request, or to comply with applicable legal and regulatory obligations. We do not sell personal data and we do not share personal data for cross-context behavioral advertising.

‍

Where applicable, personal data may be disclosed to the following categories of recipients:

‍

a) Independent Oncologists and their support staff. We share relevant personal data, including health data, with the Independent Oncologist involved in your case in order to perform the independent review and prepare the educational opinion.

‍

Where necessary, the Independent Oncologist may involve members of their clinical or administrative support staff, who are subject to professional confidentiality obligations.

‍

The Independent Oncologist processes personal data independently for the purpose of providing the review.

‍

b) Service providers and processors

‍

We may share personal data with third-party service providers that perform services on our behalf and under our instructions, including providers that support:

  • secure intake forms and electronic signatures;
  • payment processing and billing support;
  • secure storage and hosting of information;
  • scheduling, communications, and review delivery (including video conferencing where used);
  • IT operations, security monitoring, and audit logging; and
  • customer support tools.

‍

These service providers act as data processors and are contractually required to process personal data only for specified purposes and to implement appropriate technical and organizational measures to protect the data in accordance with GDPR.

‍

c) Legal, regulatory, and compliance disclosures

‍

We may disclose personal data where required to do so by law or where we reasonably believe such disclosure is necessary to:

  • comply with applicable laws, regulations, court orders, subpoenas, or lawful requests from public authorities;
  • cooperate with regulatory or professional oversight bodies;
  • protect and defend the rights, property, or safety of Genomate, Independent Oncologists, users, or others;
  • investigate, prevent, or take action regarding suspected fraud, security incidents, or unlawful activity; or
  • establish, exercise, or defend legal claims.

‍

d) Business transfers

‍

In the event of a merger, acquisition, restructuring, bankruptcy, or sale of all or part of our assets, personal data may be transferred to a successor entity or acquirer as part of the transaction, subject to applicable data protection and confidentiality obligations.

‍

e) With your instructions or consent

‍

In limited circumstances, we may share personal data with third parties at your direction or with your explicit consent, for example where you authorize sharing of the educational opinion or related information with a designated support person or another professional.

‍

Use of video conferencing and electronic communications
The Service may involve the use of third-party video conferencing platforms, email, and other electronic communication tools to support reviews and service-related communications. While we select service providers that implement reasonable administrative, technical, and organizational safeguards, no electronic communication method or third-party network can be guaranteed to be completely secure or risk-free.

‍

By participating in the Service, you acknowledge and accept the inherent risks associated with electronic communications and remote reviews, including the possibility of unauthorized access despite reasonable safeguards.

‍

‍

‍

7. Support persons, representatives, and shared access

‍

The Service may allow the participation of a support person (such as a family member or trusted contact) in the review process and/or the receipt of service-related communications and results, subject to the conditions described below.

‍

a) Patient control and authorization

‍

Where the patient is the individual requesting the Service, the patient may choose to designate a support person to:

  • participate in the review; and/or
  • receive copies of the educational opinion and related communications.

‍

Such designation is subject to the completion of the applicable consent and authorization steps within the Service workflow. The patient may modify or revoke this authorization at any time prior to delivery of the report, subject to operational limitations.

‍

b) Requests submitted by someone other than the patient

‍

In some cases, the Service may be requested by an individual other than the patient, such as a family member or caregiver.

‍

In these cases:

  • If the requester is the patient’s legal representative (for example, a parent of a minor or a person holding a valid power of attorney), the Service may proceed upon verification of such authority, and the representative may submit information and receive results on the patient’s behalf.
  • If the requester is not a legal representative, the Service may proceed only where the patient has provided valid authorization permitting the requester to submit information and/or receive results. We may require the patient to complete additional consent or authorization steps directly.

‍

c) Identity verification and access controls

‍

To protect patient privacy, we implement reasonable measures to verify identity and manage access to Service information, including:

  • verification of contact details;
  • confirmation of consent and authorization records;
  • access controls limiting who may view or receive review materials and results.

‍

We may decline or limit shared access where authorization is unclear, incomplete, or inconsistent with applicable law.

‍

d) Scope and limitations of shared access

‍

Shared access is limited to the purposes authorized by the patient or permitted by law. Support persons and representatives are not granted independent rights to control or reuse the patient’s information beyond participation in the Service as authorized.

‍

We are not responsible for how a support person or representative handles information once it has been lawfully shared at the patient’s request or direction.

‍

e) Legal and regulatory considerations

‍

Nothing in this section limits the rights of patients under applicable privacy laws or the obligations of Independent Oncologists to maintain medical confidentiality and professional standards.

‍

‍

‍

8. International transfer of personal data

‍

The Service is operated through technical and organizational infrastructure that may involve the processing of personal data in different jurisdictions, depending on your location and the nature of the Service.

‍

a) Primary processing locations

‍

Personal data relating to individuals located in the European Union, European Economic Area, or the United Kingdom is primarily stored and processed within the European Union, using secure cloud infrastructure operated by our service providers.

‍

However, in order to provide the Service, personal data - including health data - will be transferred to and accessed in the United States, including by the Independent Oncologist and certain service providers involved in the operation of the Service.

‍

Where feasible and appropriate, we configure our systems and service providers to limit unnecessary cross-border transfers and to process data in region-specific environments.

‍

b) Transfers from the EU/EEA/UK

‍

Where personal data is transferred from the EU/EEA/UK to the United States, we ensure that such transfers are subject to appropriate safeguards in accordance with Chapter V of the GDPR.

‍

These safeguards include:

  • Participation in the EU-U.S. Data Privacy Framework (DPF)
    Genomate Health, Inc. complies with the EU-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce and relies on this framework for the lawful transfer of personal data from the EU/EEA/UK to the United States.
  • Standard Contractual Clauses (SCCs)
    Where required, we also rely on the European Commission’s Standard Contractual Clauses, together with supplementary technical and organizational measures designed to ensure an adequate level of protection.

‍

c) Safeguards for sensitive data

‍

Given the sensitivity of health data processed in connection with the Service, we apply additional safeguards to international transfers, including:

  • strict access controls;
  • encryption of data in transit and at rest, where appropriate;
  • audit logging and monitoring of access; and
  • contractual confidentiality and data protection obligations imposed on recipients.

‍

Transfers are limited to what is necessary to provide and support the Service.

‍

d) Transparency and inquiries

‍

You have the right to obtain information about the safeguards applied to international transfers of your personal data.

‍

If you would like more information about how your data is transferred or to obtain a copy of the relevant safeguards, you may contact us at privacy@genomate.health.

‍

‍

‍

9. Your rights

‍

If you are located in the European Union, European Economic Area, or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR), subject to applicable conditions and limitations:

‍

Right of access

‍You may request confirmation as to whether we process your personal data and, if so, request access to that data and related information.

‍

Right to rectification

‍You may request that inaccurate or incomplete personal data be corrected.

‍

Right to erasure

‍You may request deletion of your personal data where, for example, the data is no longer necessary for the purposes for which it was collected, or where processing is based on consent and you withdraw that consent. This right is subject to legal and regulatory retention obligations, including health-related recordkeeping requirements.

‍

Right to restriction of processing

‍You may request restriction of processing in certain circumstances, such as where the accuracy of the data is contested or where the data is needed for the establishment, exercise, or defense of legal claims.

‍

Right to data portability

‍Where applicable, you may request that personal data you have provided be made available in a structured, commonly used, and machine-readable format, or transmitted to another controller, where technically feasible.

‍

Right to object
You may object to processing based on legitimate interests, subject to our ability to demonstrate compelling legitimate grounds for the processing.

‍

Right not to be subject to automated decision-making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The Service does not involve automated medical decision-making.

‍

Right to lodge a complaint

‍You have the right to lodge a complaint with a competent supervisory authority in your country of residence, place of work, or place of the alleged infringement.

‍

We encourage you to contact us first so that we can address your concerns directly and promptly.

‍

Where your request relates specifically to personal data processed by the Independent Oncologist in their role as an independent data controller (for example, content of the educational opinion), we may direct you to the relevant professional to ensure your request is handled appropriately.

‍

You may contact us by email at privacy@genomate.health. We promise to respond to any valid requests within a maximum of 30 days, unless this is particularly complicated or if you have made multiple requests, in which case we will respond within a maximum of 60 days, prior to which you will be contacted about the delay.

‍

Alternatively, you can also submit your request to exercise your rights by post, at the following address:

‍

Genomate Health, Inc.

1 Broadway, Cambridge, MA

United States of America

‍

Given the global reach of our Website, we strongly recommend that you contact us by email at the address provided above. We cannot guarantee the arrival on time by post. If you, however, choose to submit a request through the mail, we recommend that you mail your request with confirmation of receipt. 

‍

If you are located in the European Union, you have the right under Article 77 of the General Data Protection Regulation (GDPR) to lodge a complaint with a Data Protection Authority (DPA) if you believe that our processing of your personal data infringes applicable data protection law.

For EU data subjects, Genomate Health Hungary Kft. serves as our representative entity in the European Union. 

‍

Genomate Health Hungary Kft.

Retek utca, 34

Budapest, 1054

Hungary

‍

The competent supervisory authority in Hungary is:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Szilágyi Erzsébet fasor 22/C,
1125 Budapest, Hungary
Website: https://www.naih.hu
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu

‍

You may also find a full list of EU data protection authorities and their contact details at the official EDPB website: https://edpb.europa.eu/about-edpb/about-edpb/members_en

‍

We encourage you to contact us first with any questions, concerns, or complaints regarding the processing of your personal data. You can reach our Data Protection Officer at: privacy@genomate.health

‍

How to submit a rights request

‍

Email privacy@genomate.health with your request and the country you reside in. We may ask for limited additional information to verify your identity. We respond within 30 days (or 60 days if permitted and necessary due to complexity, in which case we will notify you). If we cannot fully comply, we will explain why and the options available to you.

‍

We are committed to addressing your privacy concerns and will make every effort to resolve any issue promptly and transparently.

‍

‍

9.3 Exercising your rights

‍

To exercise your rights under the GDPR, or to obtain further information, you may contact us at privacy@genomate.health. We may request additional information to verify your identity and determine the applicable legal framework.

‍

We will respond to valid requests within the timeframes required by applicable law.

‍

‍

‍

10. Duration of retention of personal data

‍

We retain personal data collected in connection with the Service only for as long as necessary to fulfill the purposes for which it was collected, including the provision of the Service, compliance with legal and regulatory obligations, and the establishment, exercise, or defense of legal claims.

‍

Retention periods vary depending on the type of data, the role under which it is processed, and applicable legal requirements.

‍

a) Clinical records and review materials

‍

Genomate may retain limited copies of clinical information as necessary to operate and support the Service (for example, for secure delivery, quality assurance, or dispute resolution), subject to contractual obligations and retention controls. Where such copies are retained, access is restricted and the data is deleted or de-identified when no longer required for these purposes, unless continued retention is required or permitted by law.

‍

b) Administrative and operational data

‍

Personal data related to service administration, including intake records, consent and authorization logs, identity verification data, customer support communications, billing metadata, audit logs, and security records, is retained for as long as necessary to:

  • operate and support the Service;
  • comply with legal, tax, accounting, and regulatory obligations;
  • maintain security and prevent fraud; and
  • manage disputes or enforce agreements.

‍

In the absence of specific legal retention requirements, such data is retained for a limited period consistent with our internal retention policies and then securely deleted or anonymized.

‍

c) Data subject requests and complaints

‍

Records relating to privacy requests, complaints, or inquiries are retained for as long as necessary to document compliance with applicable law and to respond to or resolve the request or complaint.

‍

d) Deletion and legal limitations

‍

Where you request deletion of personal data, we will assess the request in light of applicable legal and regulatory obligations. Certain data may not be deleted immediately or at all where retention is required or permitted by law, including health recordkeeping requirements, audit obligations, or the need to establish, exercise, or defend legal claims. Where deletion is not possible, we will restrict processing and limit access to the data as required by applicable law.

‍

‍

‍

11. Security of personal data

‍

Genomate implements appropriate technical and organizational measures designed to protect personal data processed in connection with the Service against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

‍

These measures are proportionate to the nature of the data processed, including health information, and are designed to support confidentiality, integrity, and availability in line with applicable data protection and privacy laws.

‍

a) Administrative safeguards

‍

We maintain internal policies and procedures governing data protection, access control, incident response, and employee confidentiality. Access to personal data is limited to authorized personnel and service providers who require such access to perform their duties in connection with the Service.

Personnel with access to personal data are subject to confidentiality obligations and receive appropriate training on privacy, security, and data protection requirements.

‍

b) Technical safeguards

‍

We use technical measures appropriate to the sensitivity of the data, which may include:

  • access controls and authentication mechanisms;
  • encryption of data in transit and, where appropriate, at rest;
  • logging and monitoring of system access and activity;
  • secure configuration and maintenance of systems supporting the Service; and
  • regular review of system security and risk management measures.

‍

c) Organizational safeguards

‍

We engage service providers that are required by contract to implement appropriate security measures and to process personal data only in accordance with our instructions. Where health information is involved and HIPAA applies, such providers are subject to business associate or equivalent contractual obligations.

‍

We periodically assess our security practices and take reasonable steps to address identified risks, taking into account the evolving nature of security threats.

‍

d) Incident management

‍

We maintain procedures to detect, respond to, and investigate suspected security incidents involving personal data. Where required by applicable law, we will notify affected individuals and relevant authorities of a data breach within the timeframes prescribed by law.

‍

e) No absolute guarantee

‍

Despite the safeguards we implement, no method of transmission over the internet or method of electronic storage is completely secure. Accordingly, while we take reasonable and appropriate steps to protect personal data, we cannot guarantee absolute security.

If you believe that your personal data has been accessed or disclosed without authorization, please contact us promptly at privacy@genomate.health.

‍

‍

‍

12. Use by minors

‍

The Service is not intended for individuals under the age of 18.

‍

Personal data relating to a minor may be submitted only where the Service is explicitly offered for that purpose and only by a parent or legal guardian or other individual with lawful authority to act on behalf of the minor. In such cases, additional verification and consent requirements may apply.

‍

If you believe that personal data relating to a minor has been submitted to the Service without appropriate authorization, please contact us at privacy@genomate.health, and we will take appropriate steps in accordance with applicable law.

‍

‍

‍

13. Data Privacy Framework

‍

Genomate Health, Inc complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) as set forth by the U.S. Department of Commerce.  Genomate Health, Inc has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF.  If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern.  To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit Data privacy framework website.

‍

Genomate Health employees located in the United States may provide services and support to customers, partners, or users located in the European Union (EU), European Economic Area (EEA), Switzerland, and the United Kingdom. To provide such services, Genomate Health may process or access Personal Data originating from these regions.

‍

Genomate Health complies with the EU-U.S. Data Privacy Framework (DPF) Principles as issued by the U.S. Department of Commerce. These principles apply to Personal Data physically or remotely transferred from the EEA.

‍

Genomate Health adheres to the following DPF Principles for all such transfers:

  • Notice – Individuals are informed about the purposes for which their personal data is collected and used, how to contact Genomate Health, the types of third parties to which the data may be disclosed, and available choices for limiting its use or disclosure.
  • Choice – Individuals are given the opportunity to opt out of having their personal data disclosed to a third party or used for a purpose materially different from that for which it was originally collected. For personal data subject to the DPF, individuals may opt out of: (a) disclosures to third parties not acting as agents, or (b) uses for purposes materially different from those for which the data was collected. Submit opt-out requests to privacy@genomate.health. For sensitive data, we obtain opt-in consent where required by the DPF.
  • Accountability for onward transfer – Genomate Health ensures that any onward transfers of personal data to third parties are conducted in compliance with the DPF Principles, with appropriate contractual safeguards in place. When we transfer personal data to third-party agents, we remain responsible under the DPF Principles if those agents process such personal data in a manner inconsistent with the Principles, unless we prove we are not responsible for the event giving rise to the damage.
  • Security – Personal data is protected against loss, misuse, unauthorized access, disclosure, alteration, and destruction through appropriate technical and organizational measures.
  • Data integrity and purpose limitation – Personal data is limited to what is relevant for the purposes of processing and is kept accurate, complete, and up to date as required for those purposes.
  • Access – Individuals have the right to access their personal data held by Genomate Health and to correct, amend, or delete it where it is inaccurate or processed in violation of the DPF Principles.
  • Recourse, enforcement, and liability – Genomate Health maintains procedures for verifying compliance with the DPF Principles and provides independent recourse and enforcement mechanisms to resolve complaints and disputes, as detailed in this Policy.
  • Types of personal data we process: user account and professional identity data, contact details, authentication and audit logs, Service usage data, and support communications collected from professionals using the Service. Patient data may be processed on behalf of medical experts to generate reports, as described in this Privacy Policy.
  • U.S. entities or U.S. subsidiaries also adhering: Genomate Health, Inc. is the certifying U.S. entity. Genomate Health has no other U.S. subsidiaries adhering to the Principles. If this changes, we will update this notice.
  • Commitment and scope: Genomate Health commits to apply the DPF Principles to all personal data received from the EU/EEA in reliance on the EU-U.S. DPF, when such data is transferred to the United States.
  • Purposes of processing: we process personal data to provide, secure, and support the Service; manage accounts and authentication; generate and deliver Genomate reports; provide customer support; meet regulatory and security obligations; and improve service performance, as detailed in the sections above.
  • How to contact us: privacy@genomate.health. For EU inquiries, you may also contact our EU establishment: Genomate Health Hungary Kft., Retek utca 34, 1024 Budapest, Hungary.
  • Third parties: we disclose personal data to service providers and other recipients as 
  • Public authority requests: we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

‍

‍How to exercise DPF choices and rights: please contact us at privacy@genomate.health. We will respond consistent with the DPF and applicable law.

‍

Recourse, enforcement & liability

In compliance with the EU-U.S. Data Privacy Framework (DPF) Principles, Genomate Health commits to resolve complaints concerning your privacy and our collection or use of Personal Data transferred to the United States under this Policy.

‍

Individuals in the European Union with inquiries or complaints regarding our compliance with the DPF should first contact the Genomate Privacy Office at privacy@genomate.health

‍

Genomate Health has further committed to cooperate with and refer unresolved DPF-related complaints to JAMS, an independent dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://www.jamsadr.com/dpf-dispute-resolution  for more information and to file a complaint. This service is provided free of charge to you.

‍

If your DPF complaint cannot be resolved through the above channels, under certain conditions you may be entitled to invoke binding arbitration for some residual claims not otherwise resolved by other redress mechanisms. For more information, please visit the Data Privacy Framework website at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction.

‍

The U.S. Federal Trade Commission (FTC) has jurisdiction over Genomate Health’s compliance with the Data Privacy Framework.

‍

‍

‍

14. Changes to this Privacy Notice

‍

We may update this Privacy Notice from time to time to reflect changes in our practices, the operation of the Service, or applicable legal and regulatory requirements. Any updates will be posted on our website and will become effective as of the “Last updated” date shown at the top of this Privacy Notice. Where changes materially affect how personal data is processed or where required by applicable law, we will take additional steps to notify users or obtain consent, as appropriate.

‍

We encourage you to review this Privacy Notice periodically to stay informed about how your personal data is handled in connection with the Service.

‍

‍

‍

15. Contact information

‍

If you have any questions about this Privacy Notice, the processing of your personal data, or wish to exercise your rights under applicable law, you may contact us at: privacy@genomate.health

‍

Genomate Health, Inc.
1 Broadway, Cambridge, MA, United States

‍

For individuals located in the European Union, European Economic Area, or the United Kingdom, you may also contact our EU establishment:

Genomate Health Hungary Kft.Retek utca 341024 Budapest, Hungary

Award banner - genomeweb, best place to work 2025
Company
About Genomate®
Our Story
Our Team
Oncompas Medicine
Careers
Contact
Solutions
For Oncologists
For Patients
For Partners
Order a Report
Services
For Patients
Order a Second Opinion
Resources
Browse
Publications
News
Events
Opinions
Enhancing NGS
Precision Care Pledge
Connect with Us
TW
IG
FB
LI
BL
Certified ISO 13485 quality management for medical devices.
The Genomate® Report can be used and clinically interpreted only by physicians or other qualified healthcare professionals. Genomate® is a clinical decision support software and is not intended to diagnose, treat, cure, prevent, or mitigate any condition. None of the statements contained herein have been evaluated by the U.S. Food and Drug Administration. Learn more.
© 2022-2026 Genomate Health Inc
Terms of Use
Cookies Policy
Privacy Policy
HIPAA Notice
Instructions For Use
Designed by onecreative