image

Privacy Policy

Last Updated: Nov 1, 2020

COVIDx, including its affiliates and subsidiaries (collectively referred to as “COVIDx,” “we” or “us”) is committed to protecting your privacy. This Privacy Policy (this “Policy”) describes how collect, use, store, secure, and disclose your personal information when you access or use our websites, including without limitation www.covidxtesting.com, (the “Website”), and when you transmit information to us electronically or in hard copy in relation to our testing services (our “Services”).

This Privacy Policy is in addition to and does not replace our Notice of Privacy Practices, which explains how we handle personally-identifiable health information under U.S. law.

We may revise this Policy from time to time. All updates will be posted on this web page. If we make any material changes in the way your personal information is handled, we will notify you by email (sent to the email address specified in your account) or by means of a notice on our Websites prior to the change becoming effective.

ACCEPTANCE OF THIS PRIVACY POLICY

Before you use our Services (whether you are a provider or a patient), please read the COVIDx Terms of Service. By accepting the applicable Terms of Use, you agree with our privacy practices as described in this Policy. If you do not agree with the terms of this Policy, please do not access the Websites or use our Services.

TYPES OF PERSONAL INFORMATION WE COLLECT AND HOW WE USE IT

Depending on which of our Services are being used, or which individual (provider or patient) is involved, COVIDx processes and stores different combinations of personal information as set forth in this Policy.

PERSONAL INFORMATION COLLECTED FROM PATIENTS

Through our forms and based on and by virtue of the respective consent provided by the patient, we may collect and process personal information of a patient, including the following categories:

  • Personal details (including first and middle name, last name, birth date and/or age)
  • Family relationships (if applicable)
  • Address
  • Gender
  • Ethnicity
  • Nationality
  • Disease
  • Payment information for services (where provided)
  • Test results and findings

Such collected personal information is used to provide the Services and test results to the patient and to perform the billing. All the collected personal information of a patient will be stored for as long as stated in the applicable patient informed consent form. The personal information will be processed by COVIDx for the performance of the specific tests requested by the patient on the applicable form, and for informing the patient of the results of such analysis, all on the basis of the consent provided by the patient. COVIDx will de-identify (pseudonymize) the personal information to the extent possible.

PERSONAL INFORMATION COLLECTED FROM VISITORS TO COVIDx WEBSITE

Generally, individuals are able to visit www.covidxtesting.com (“Website”) without disclosing personal information, except as may be necessary to provide a service at his or her request. Data are collected from the Website only to the extent technically necessary. For example, in some cases we may recognize personal data like the IP address as well as non-personal data like the name of the visitor’s Internet service provider, the website from which the visitor came to our Website, the pages that the visitor views on the Website, and what the visitor clicks on any given page. This data could possibly identify an individual, but COVIDx does not use it to do so.

Cookies: We use cookies and similar tracking technologies to personalize your experience on our Websites. Please see our Cookie Policy for more information. Without processing your personal information for such purposes, you may not be able to access part or all of our Services. Our servers automatically record information created by your use of our Website and we use visitor logs to compile anonymous statistics. The aggregate information is collected sitewide and contains anonymous website statistics and is not considered personal information.

“Do Not Track”: Some browsers incorporate a "Do Not Track" (DNT) or similar feature that signals to digital services that a visitor doesn’t want to have their online activity tracked. Because there is not yet an accepted standard for how to respond to DNT signals, we and our service providers (like many digital service operators) do not respond to DNT signals.

PERSONAL INFORMATION PROVIDED VOLUNTARILY

We collect any personal information that you voluntarily provide to use, such as inquiries through our Website, information you provide about your business, etc., and is used only for the purpose of addressing the request received. In cases where social media services may be used, we do not have any influence on the storage and processing of providing personal information via the respective social media service. You are encouraged to review those privacy policies before sending COVIDx personal information via a social media service.

INFORMATION WE SHARE

COVIDx may disclose your personal information as follows:

  • Our service providers, vendors, and other processors. We may share your personal information with our service providers, business partners, or other vendors that help us provide our Services to you. Such entities will be given access as is reasonably necessary to provide our Services, and only under contractual obligations that are at least as restrictive as this Policy and in compliance with applicable privacy laws. Agents, vendors, and service providers who may have access to protected health information and other special categories of personal data are contractually obligated to protect the privacy and security of such information. We share your payment information with our third party payment processor. We do not store any credit card information on COVIDx servers.
  • Affiliated businesses. We may share your personal information with group companies and affiliates. Affiliated businesses may use your information to help provide, understand, and improve our Services and the affiliates’ own services.
  • Change of control. We may share your personal information as part of a purchase, transfer, or sale of the Services or the company (for example, a corporate restructuring, merger or consolidation with, or sale of substantially all of our assets to a third party).
  • Safety and legal compliance. We may share your personal information if we believe that such disclosure is necessary to comply with any applicable laws, regulations, legal processes, or requests by public authorities (e.g., law enforcement, tax authorities, etc.); protect you, us, or other users’ rights or property, or to protect our Services, comply with or enforce our terms, agreements or policies. Such disclosure may be to parties outside your country of residence.
  • Your consent or express actions. We will share personal information when we have your consent to do so. Also, any information or content that you voluntarily disclose for posting in public areas of our Website, such as blog comments or social media posts on our social media profiles, become available to the public.
  • Anonymous or aggregate data. We may share anonymized or aggregated information with any third parties. Such information no longer reasonably identifies you and is not considered personal information.

HOW WE USE AND DISCLOSE DE-IDENTIFIED, ANONYMIZED OR PSEUDONYMIZED INFORMATION

“De-identified” or “pseudonymized” information is data we have stripped of your personally identifiable information, such as your name, address, or birthdate. We retain the ability to re-identify such information. “Anonymized” information is when personal information is stripped of all identifiers and cannot reasonably be linked back to you.

We may use “de-identified” or “pseudonymized” information for various purposes, including:

  • For quality control and validation:
    • In accordance with regulatory requirements, we may de-identify, store and use patients’ samples and information for internal quality control, validation, research and development. This is an important use for COVIDx to maintain our high quality Services and to develop new Services.

To the extent we have relied on your consent to process such de-identified personal information in relation to the above, you may withdraw your consent to participate at any time by contacting us at info@covidxtesting.com.

CHILDREN’S INFORMATION

Our Website is directed towards adults and is not designed for, intended to attract, or directed towards children under the age of 16. If you are under the age of 16, you must obtain the authorization of a responsible adult (parent or legal guardian) before accessing or using our Website. If we become aware that we have collected any personal information from children under 16 without appropriate authorization, we will promptly remove such information from our databases.

THIRD-PARTY INFORMATION

You agree that you have provided notice to, and obtained consent from, any third party individuals whose personal information you supply to us, including with regard to (a) the purposes for which such third party’s personal information has been collected; (b) the intended recipients or categories of recipients of the third party’s personal information; (c) which of the third party’s information is obligatory and which information, if any, is voluntary; and (d) how the third party can access and, if necessary, rectify the information held about them.

LINKED WEBSITES

Our Website may contain links to external websites. COVIDx does not maintain these sites and is not responsible for the privacy practices of sites that it does not operate. Please refer to the specific privacy policies posted on these sites.

INFORMATION ACCESS, UPDATES, AND CHOICE

You can update, amend or delete your account information and preferences at any time or by contacting us at info@covidxtesting.com

All COVIDx email correspondence will include instructions on how to update certain personal information and how to unsubscribe from our emails and postal mail correspondence. Please follow the instructions in the emails to notify COVIDx of changes to your name, email address, and preference information.

COVIDx will take reasonable steps, such as confirmation emails, to verify your identity before granting access to your personal information.

RETENTION

We store your personal information for as long as we need it to provide you our Services, to serve the purpose(s) for which your personal information was processed, or as necessary to comply with our legal obligations, resolve disputes, or enforce our agreements to the extent permitted by law. While retention requirements can vary by country, we generally apply the retention periods noted below.

We store information used for marketing purposes indefinitely until you unsubscribe. Once you unsubscribe from marketing communications, we add your contact information to our suppression list to ensure we respect your unsubscribe request. Also, we retain any information collected via cookies, clear gifs, flash cookies, webpage counters and other technical or analytics tools up to one year from expiry of the cookie or the date of collection. If you have any questions about our retention periods, please feel free to contact us at info@covidxtesting.com.

SECURITY MEASURES

We use reasonable technical, administrative and physical measures to protect information contained in our system against misuse, loss or alteration. Information that you provide through our Website is encrypted using industry-standard Secure Sockets Layer (SSL) technology, with the exception of information you send via email. Your information is processed and stored on controlled servers with restricted access, and in compliance with the Security Rule of the Health Insurance Portability and Accountability Act of 1966 (HIPAA). Unfortunately, no method of electronic transmission is 100% secure, so we cannot ensure or warrant the security of any information you transmit to our Website, and you do so at your own risk. Please do not submit any personal health information or credit card information via email.

Please recognize that protecting your personal information is also your responsibility. You should keep your username, password, ID numbers, or other access credentials secure as COVIDx cannot secure personal information that you release on your own or that you request us to release. If we receive instructions using your log-in information we will consider that you have authorized the instructions.

CONTACT US

If you have any questions regarding this Policy or our privacy practices, you may contact us at info@covidxtesting.com