Effective Date: 20.04.2026
If you reside in the United States of America, this Privacy Notice does not apply to you. It applies only to European Union residents. Please consult the Privacy Notice applicable to U.S. residents.
This Privacy Notice explains how Genomate Health, Inc. (“Genomate,” “we,” “us”) collects, uses, and shares personal data in connection with the Second Opinion Service (the “Service”) when accessed by individuals located in the European Union, European Economic Area, or the United Kingdom (“EU”).
This Notice applies when you submit an order request, upload records, make payment, and participate in the review and related communications.
This Notice does not apply to general browsing of our website or to marketing-related interactions, which are covered by our separate Website Privacy Policy.
Summary
We encourage you to read this entire Privacy Notice to understand how your information is handled in connection with the Service. If you are short on time, the key points are summarized below.
If you have questions about this Privacy Notice, how your information is used, or how to exercise your rights, you may contact us at any time at privacy@genomate.health
Genomate Health, Inc., 1 Broadway, Cambridge, MA, USA
EU establishment (for EU inquiries): Genomate Health Hungary Kft., Retek utca 34, 1024 Budapest, Hungary
Contact: privacy@genomate.health
If you have questions about this Notice or want to exercise your rights, contact us at privacy@genomate.health
The Service consists of an independent, educational review of medical information provided by a licensed oncologist (the “Independent Oncologist”). Based on the information submitted, the Independent Oncologist provides an informational second opinion intended to support understanding of a medical condition.
For the purposes of the GDPR, Genomate Health, Inc. acts as the data controller for the personal data described in this Privacy Notice, except where otherwise stated.
The Service is educational and informational in nature only. It does not constitute the provision of medical care within the European Union and does not create a doctor-patient relationship under EU healthcare laws.
The Independent Oncologist exercises independent professional judgment and is solely responsible for the content of the opinion provided.
Genomate does not practice medicine and does not provide medical advice. Genomate provides the technical and administrative infrastructure that enables the Service, including secure data collection, coordination of the review process, communication handling, and delivery of the final report.
For purposes of the General Data Protection Regulation (GDPR):
Personal data is shared between Genomate and the Independent Oncologist only to the extent necessary to provide the Service.
Genomate and the Independent Oncologist are not joint controllers, as they determine their respective purposes and means of processing independently.
The Service:
The Service is available to individuals located in the European Union, European Economic Area, and the United Kingdom.
There are no location-based licensing requirements within the EU for accessing the Service, as it is not provided as regulated medical care. However, you are responsible for ensuring that your use of the Service complies with any applicable local laws or requirements.
Genomate relies on the information provided by users regarding their eligibility to use the Service. If it is determined that the Service is being used in a manner inconsistent with these terms, access to the Service may be limited or discontinued.
To protect personal data and ensure that the Service is used appropriately, we may take reasonable steps to verify identity, eligibility, and authorization in connection with the Service.
These steps are designed to ensure that:
These steps may include, as appropriate:
We process only the information that is necessary and proportionate for these purposes, in accordance with applicable data protection laws.
If we are unable to reasonably verify identity, eligibility, or authorization, or if required confirmations or documentation are missing, insufficient, or inconsistent, the Service may be paused, limited, or cancelled, and access to Service outputs may be restricted, in accordance with applicable law and our Terms and Conditions.
You are not legally required to provide your personal data to us. However, if you do not provide the information necessary for eligibility assessment, review, payment, or communication, we may not be able to provide the Service.
Depending on how you use the Service, we may collect:
We may collect:
We may receive limited data from:
Where the Service intake form uses essential cookies or similar technical tools for security, session management, or fraud prevention, those technologies are governed by our Website Privacy Policy and, where applicable, our Cookie Policy.
We process personal data in connection with the Service only to the extent necessary to provide and operate the Service and to comply with applicable legal and regulatory obligations. We do not process personal data for purposes incompatible with those described in this Privacy Notice.
More specifically, we use personal data for the following purposes:
We process personal data to receive and review your request, organize and transmit the information you submit, coordinate scheduling and session logistics, and deliver the educational second opinion and related communications.
We process personal data to verify the identity of the patient and any authorized support persons, manage access to submitted materials and results, and document consents, acknowledgments, and applicable authorizations.
We process limited personal and transactional data to confirm payments, issue refunds where applicable, handle disputes, and prevent fraudulent or unauthorized transactions.
We process personal data to protect the confidentiality, integrity, and availability of the Service, including monitoring for security incidents, maintaining audit logs, and ensuring system reliability and continuity.
We process personal data to respond to inquiries, provide service-related communications, and support users before, during, and after the review.
We process personal data as necessary to comply with applicable laws and regulations, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims.
We do not use personal data for marketing, profiling, or automated decision-making, and we do not use health data for research or model training purposes.
We process personal data in connection with the Service only where a valid legal basis applies under the General Data Protection Regulation (GDPR), and only for the purposes described in this Privacy Notice.
The applicable legal basis depends on the nature of the data and the purpose of processing. Where health data is involved, we apply additional safeguards and rely on a specific condition under Article 9 GDPR, as described below.
Where the GDPR applies, Genomate relies on one or more of the following legal bases under Article 6 GDPR for the processing of personal data:
We process health data on the basis of your explicit consent (Article 9(2)(a) GDPR).
By submitting your information and confirming the relevant consent statements within the Service, you explicitly consent to the processing of your health data for the purpose of receiving the educational review and related services.
You may withdraw your consent at any time by contacting us at privacy@genomate.health. Withdrawal of consent does not affect processing carried out prior to withdrawal, but may prevent us from continuing to provide the Service.
Health data is processed solely for purposes directly related to the provision and operation of the Service and is not used for marketing, profiling, research, or model training purposes.
Genomate does not make automated medical decisions about patients. Any medical opinions provided as part of the Service are prepared and issued by a licensed Independent Oncologist exercising independent professional judgment.
Purpose of processing
Categories of data involved
Article 6 GDPR legal basis
Article 9 GDPR condition (if health data is involved)
We share personal data collected in connection with the Service only where necessary for the operation of the Service, the fulfillment of your request, or to comply with applicable legal and regulatory obligations. We do not sell personal data and we do not share personal data for cross-context behavioral advertising.
Where applicable, personal data may be disclosed to the following categories of recipients:
a) Independent Oncologists and their support staff. We share relevant personal data, including health data, with the Independent Oncologist involved in your case in order to perform the independent review and prepare the educational opinion.
Where necessary, the Independent Oncologist may involve members of their clinical or administrative support staff, who are subject to professional confidentiality obligations.
The Independent Oncologist processes personal data independently for the purpose of providing the review.
b) Service providers and processors
We may share personal data with third-party service providers that perform services on our behalf and under our instructions, including providers that support:
These service providers act as data processors and are contractually required to process personal data only for specified purposes and to implement appropriate technical and organizational measures to protect the data in accordance with GDPR.
c) Legal, regulatory, and compliance disclosures
We may disclose personal data where required to do so by law or where we reasonably believe such disclosure is necessary to:
d) Business transfers
In the event of a merger, acquisition, restructuring, bankruptcy, or sale of all or part of our assets, personal data may be transferred to a successor entity or acquirer as part of the transaction, subject to applicable data protection and confidentiality obligations.
e) With your instructions or consent
In limited circumstances, we may share personal data with third parties at your direction or with your explicit consent, for example where you authorize sharing of the educational opinion or related information with a designated support person or another professional.
Use of video conferencing and electronic communications
The Service may involve the use of third-party video conferencing platforms, email, and other electronic communication tools to support reviews and service-related communications. While we select service providers that implement reasonable administrative, technical, and organizational safeguards, no electronic communication method or third-party network can be guaranteed to be completely secure or risk-free.
By participating in the Service, you acknowledge and accept the inherent risks associated with electronic communications and remote reviews, including the possibility of unauthorized access despite reasonable safeguards.
The Service may allow the participation of a support person (such as a family member or trusted contact) in the review process and/or the receipt of service-related communications and results, subject to the conditions described below.
a) Patient control and authorization
Where the patient is the individual requesting the Service, the patient may choose to designate a support person to:
Such designation is subject to the completion of the applicable consent and authorization steps within the Service workflow. The patient may modify or revoke this authorization at any time prior to delivery of the report, subject to operational limitations.
b) Requests submitted by someone other than the patient
In some cases, the Service may be requested by an individual other than the patient, such as a family member or caregiver.
In these cases:
c) Identity verification and access controls
To protect patient privacy, we implement reasonable measures to verify identity and manage access to Service information, including:
We may decline or limit shared access where authorization is unclear, incomplete, or inconsistent with applicable law.
d) Scope and limitations of shared access
Shared access is limited to the purposes authorized by the patient or permitted by law. Support persons and representatives are not granted independent rights to control or reuse the patient’s information beyond participation in the Service as authorized.
We are not responsible for how a support person or representative handles information once it has been lawfully shared at the patient’s request or direction.
e) Legal and regulatory considerations
Nothing in this section limits the rights of patients under applicable privacy laws or the obligations of Independent Oncologists to maintain medical confidentiality and professional standards.
The Service is operated through technical and organizational infrastructure that may involve the processing of personal data in different jurisdictions, depending on your location and the nature of the Service.
a) Primary processing locations
Personal data relating to individuals located in the European Union, European Economic Area, or the United Kingdom is primarily stored and processed within the European Union, using secure cloud infrastructure operated by our service providers.
However, in order to provide the Service, personal data - including health data - will be transferred to and accessed in the United States, including by the Independent Oncologist and certain service providers involved in the operation of the Service.
Where feasible and appropriate, we configure our systems and service providers to limit unnecessary cross-border transfers and to process data in region-specific environments.
b) Transfers from the EU/EEA/UK
Where personal data is transferred from the EU/EEA/UK to the United States, we ensure that such transfers are subject to appropriate safeguards in accordance with Chapter V of the GDPR.
These safeguards include:
c) Safeguards for sensitive data
Given the sensitivity of health data processed in connection with the Service, we apply additional safeguards to international transfers, including:
Transfers are limited to what is necessary to provide and support the Service.
d) Transparency and inquiries
You have the right to obtain information about the safeguards applied to international transfers of your personal data.
If you would like more information about how your data is transferred or to obtain a copy of the relevant safeguards, you may contact us at privacy@genomate.health.
If you are located in the European Union, European Economic Area, or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR), subject to applicable conditions and limitations:
Right of access
You may request confirmation as to whether we process your personal data and, if so, request access to that data and related information.
Right to rectification
You may request that inaccurate or incomplete personal data be corrected.
Right to erasure
You may request deletion of your personal data where, for example, the data is no longer necessary for the purposes for which it was collected, or where processing is based on consent and you withdraw that consent. This right is subject to legal and regulatory retention obligations, including health-related recordkeeping requirements.
Right to restriction of processing
You may request restriction of processing in certain circumstances, such as where the accuracy of the data is contested or where the data is needed for the establishment, exercise, or defense of legal claims.
Right to data portability
Where applicable, you may request that personal data you have provided be made available in a structured, commonly used, and machine-readable format, or transmitted to another controller, where technically feasible.
Right to object
You may object to processing based on legitimate interests, subject to our ability to demonstrate compelling legitimate grounds for the processing.
Right not to be subject to automated decision-making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The Service does not involve automated medical decision-making.
Right to lodge a complaint
You have the right to lodge a complaint with a competent supervisory authority in your country of residence, place of work, or place of the alleged infringement.
We encourage you to contact us first so that we can address your concerns directly and promptly.
Where your request relates specifically to personal data processed by the Independent Oncologist in their role as an independent data controller (for example, content of the educational opinion), we may direct you to the relevant professional to ensure your request is handled appropriately.
You may contact us by email at privacy@genomate.health. We promise to respond to any valid requests within a maximum of 30 days, unless this is particularly complicated or if you have made multiple requests, in which case we will respond within a maximum of 60 days, prior to which you will be contacted about the delay.
Alternatively, you can also submit your request to exercise your rights by post, at the following address:
Genomate Health, Inc.
1 Broadway, Cambridge, MA
United States of America
Given the global reach of our Website, we strongly recommend that you contact us by email at the address provided above. We cannot guarantee the arrival on time by post. If you, however, choose to submit a request through the mail, we recommend that you mail your request with confirmation of receipt.
If you are located in the European Union, you have the right under Article 77 of the General Data Protection Regulation (GDPR) to lodge a complaint with a Data Protection Authority (DPA) if you believe that our processing of your personal data infringes applicable data protection law.
For EU data subjects, Genomate Health Hungary Kft. serves as our representative entity in the European Union.
Genomate Health Hungary Kft.
Retek utca, 34
Budapest, 1054
Hungary
The competent supervisory authority in Hungary is:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Szilágyi Erzsébet fasor 22/C,
1125 Budapest, Hungary
Website: https://www.naih.hu
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu
You may also find a full list of EU data protection authorities and their contact details at the official EDPB website: https://edpb.europa.eu/about-edpb/about-edpb/members_en
We encourage you to contact us first with any questions, concerns, or complaints regarding the processing of your personal data. You can reach our Data Protection Officer at: privacy@genomate.health
Email privacy@genomate.health with your request and the country you reside in. We may ask for limited additional information to verify your identity. We respond within 30 days (or 60 days if permitted and necessary due to complexity, in which case we will notify you). If we cannot fully comply, we will explain why and the options available to you.
We are committed to addressing your privacy concerns and will make every effort to resolve any issue promptly and transparently.
To exercise your rights under the GDPR, or to obtain further information, you may contact us at privacy@genomate.health. We may request additional information to verify your identity and determine the applicable legal framework.
We will respond to valid requests within the timeframes required by applicable law.
We retain personal data collected in connection with the Service only for as long as necessary to fulfill the purposes for which it was collected, including the provision of the Service, compliance with legal and regulatory obligations, and the establishment, exercise, or defense of legal claims.
Retention periods vary depending on the type of data, the role under which it is processed, and applicable legal requirements.
a) Clinical records and review materials
Genomate may retain limited copies of clinical information as necessary to operate and support the Service (for example, for secure delivery, quality assurance, or dispute resolution), subject to contractual obligations and retention controls. Where such copies are retained, access is restricted and the data is deleted or de-identified when no longer required for these purposes, unless continued retention is required or permitted by law.
b) Administrative and operational data
Personal data related to service administration, including intake records, consent and authorization logs, identity verification data, customer support communications, billing metadata, audit logs, and security records, is retained for as long as necessary to:
In the absence of specific legal retention requirements, such data is retained for a limited period consistent with our internal retention policies and then securely deleted or anonymized.
c) Data subject requests and complaints
Records relating to privacy requests, complaints, or inquiries are retained for as long as necessary to document compliance with applicable law and to respond to or resolve the request or complaint.
d) Deletion and legal limitations
Where you request deletion of personal data, we will assess the request in light of applicable legal and regulatory obligations. Certain data may not be deleted immediately or at all where retention is required or permitted by law, including health recordkeeping requirements, audit obligations, or the need to establish, exercise, or defend legal claims. Where deletion is not possible, we will restrict processing and limit access to the data as required by applicable law.
Genomate implements appropriate technical and organizational measures designed to protect personal data processed in connection with the Service against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
These measures are proportionate to the nature of the data processed, including health information, and are designed to support confidentiality, integrity, and availability in line with applicable data protection and privacy laws.
a) Administrative safeguards
We maintain internal policies and procedures governing data protection, access control, incident response, and employee confidentiality. Access to personal data is limited to authorized personnel and service providers who require such access to perform their duties in connection with the Service.
Personnel with access to personal data are subject to confidentiality obligations and receive appropriate training on privacy, security, and data protection requirements.
b) Technical safeguards
We use technical measures appropriate to the sensitivity of the data, which may include:
c) Organizational safeguards
We engage service providers that are required by contract to implement appropriate security measures and to process personal data only in accordance with our instructions. Where health information is involved and HIPAA applies, such providers are subject to business associate or equivalent contractual obligations.
We periodically assess our security practices and take reasonable steps to address identified risks, taking into account the evolving nature of security threats.
d) Incident management
We maintain procedures to detect, respond to, and investigate suspected security incidents involving personal data. Where required by applicable law, we will notify affected individuals and relevant authorities of a data breach within the timeframes prescribed by law.
e) No absolute guarantee
Despite the safeguards we implement, no method of transmission over the internet or method of electronic storage is completely secure. Accordingly, while we take reasonable and appropriate steps to protect personal data, we cannot guarantee absolute security.
If you believe that your personal data has been accessed or disclosed without authorization, please contact us promptly at privacy@genomate.health.
The Service is not intended for individuals under the age of 18.
Personal data relating to a minor may be submitted only where the Service is explicitly offered for that purpose and only by a parent or legal guardian or other individual with lawful authority to act on behalf of the minor. In such cases, additional verification and consent requirements may apply.
If you believe that personal data relating to a minor has been submitted to the Service without appropriate authorization, please contact us at privacy@genomate.health, and we will take appropriate steps in accordance with applicable law.
Genomate Health, Inc complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) as set forth by the U.S. Department of Commerce. Genomate Health, Inc has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit Data privacy framework website.
Genomate Health employees located in the United States may provide services and support to customers, partners, or users located in the European Union (EU), European Economic Area (EEA), Switzerland, and the United Kingdom. To provide such services, Genomate Health may process or access Personal Data originating from these regions.
Genomate Health complies with the EU-U.S. Data Privacy Framework (DPF) Principles as issued by the U.S. Department of Commerce. These principles apply to Personal Data physically or remotely transferred from the EEA.
Genomate Health adheres to the following DPF Principles for all such transfers:
How to exercise DPF choices and rights: please contact us at privacy@genomate.health. We will respond consistent with the DPF and applicable law.
Recourse, enforcement & liability
In compliance with the EU-U.S. Data Privacy Framework (DPF) Principles, Genomate Health commits to resolve complaints concerning your privacy and our collection or use of Personal Data transferred to the United States under this Policy.
Individuals in the European Union with inquiries or complaints regarding our compliance with the DPF should first contact the Genomate Privacy Office at privacy@genomate.health
Genomate Health has further committed to cooperate with and refer unresolved DPF-related complaints to JAMS, an independent dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://www.jamsadr.com/dpf-dispute-resolution for more information and to file a complaint. This service is provided free of charge to you.
If your DPF complaint cannot be resolved through the above channels, under certain conditions you may be entitled to invoke binding arbitration for some residual claims not otherwise resolved by other redress mechanisms. For more information, please visit the Data Privacy Framework website at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction.
The U.S. Federal Trade Commission (FTC) has jurisdiction over Genomate Health’s compliance with the Data Privacy Framework.
We may update this Privacy Notice from time to time to reflect changes in our practices, the operation of the Service, or applicable legal and regulatory requirements. Any updates will be posted on our website and will become effective as of the “Last updated” date shown at the top of this Privacy Notice. Where changes materially affect how personal data is processed or where required by applicable law, we will take additional steps to notify users or obtain consent, as appropriate.
We encourage you to review this Privacy Notice periodically to stay informed about how your personal data is handled in connection with the Service.
If you have any questions about this Privacy Notice, the processing of your personal data, or wish to exercise your rights under applicable law, you may contact us at: privacy@genomate.health
Genomate Health, Inc.
1 Broadway, Cambridge, MA, United States
For individuals located in the European Union, European Economic Area, or the United Kingdom, you may also contact our EU establishment:
Genomate Health Hungary Kft.Retek utca 341024 Budapest, Hungary