Privacy Policy (UK/EU GDPR)

This website is operated by PeerQuity Limited whose registered address is 128 City Road, London, EC1V 2NX, United Kingdom. (“We”) are committed to protecting and preserving the privacy of our visitors when visiting our site or communicating electronically with us. This policy sets out how we process any personal data we collect from you or that you provide to us through our website. We confirm that we will keep your information secure and that we will comply fully with all applicable UK Data Protection legislation and regulations. Please read the following carefully to understand what happens to personal data that you choose to provide to us, or that we collect from you when you visit this site. By visiting www.biomesight.com, www.biomesight.co.uk or www.biomesight.co.za (our website) you are accepting and consenting to the practices described in this policy.

Types of information we may collect from you

We may collect, store and use the following kinds of personal information about individuals who visit and use our website:

Information you supply to us

You may supply us with information about you by filling in forms on our website. This includes information you provide when you submit a:

  • Contact/enquiry form
  • Sample Submission Form
  • Symptoms/Health Questionnaire

The information you give us may include your name, address, e-mail address and phone number, microbiome data and symptom and health information.

Information our website automatically collects about you

With regard to each of your visits to our website we may automatically collect information including the following:

  • Technical information, including a truncated and anonymised version of your IP address, browser type and version, operating system and platform.
  • Information about your visit, including what pages you visit, how long you are on the site, how you got to the site (including date and time); page response times, length of visit, what you click on, documents downloaded and download errors.

Emails from us

System/Status Emails. These relate to usage of this site and its services (e.g., sample received, results ready). We send these as necessary to perform the service (legal basis: contract/legitimate interests). You cannot unsubscribe from essential service messages.

Newsletter & Marketing Emails. We only send these if you opt in (legal basis: consent). You can withdraw consent at any time via the unsubscribe link in each email or in your account settings.

Cookies

Our website uses cookies to distinguish you from other users and improve your experience. We use necessary cookies to run the site and may use analytics cookies with your consent, collected via our cookie banner. See our Cookie Policy for cookie types, providers, and retention.

How we may use the information we collect

Information you supply to us

  • to provide you with information and/or services that you request from us;
  • to conduct analysis, correlating health/disease states to microbiome make-up; as a result your data may, where deemed appropriate, be viewed by staff or third parties contracted by PeerQuity Ltd when performing their day-to-day duties.

Information we automatically collect about you

  • to administer our site including troubleshooting and statistical purposes;
  • to improve our site to ensure that content is presented in the most effective manner for you and for your computer;
  • security and debugging as part of our efforts to keep our site safe and secure.

This information is collected anonymously and is not linked to information that identifies you as an individual. We use Google Analytics to track this information.

Data usage: purposes and legal bases

  • Provide services (orders, kit linkage, results, support): Contract
  • Service communications & account security (login, MFA, fraud prevention, troubleshooting): Legitimate interests / Contract
  • Marketing newsletters and product updates: Consent
  • Research/metrics using de-identified or aggregated data: Legitimate interests
  • Legal, tax and compliance record-keeping: Legal obligation

How long we keep your data

We keep data only as long as needed: account/profile data while your account is active; order and billing records for 6 years; support tickets for 2 years; audit logs/backups per rotating schedules. When no longer needed, we delete or anonymise data.

Disclosure of your information

Any information you provide to us will either be emailed directly to us or may be stored on a secure server located near London within the United Kingdom. We use a trusted third-party cloud service (AWS) to host the infrastructure underlying this website. We do not rent, sell or share personal information about you with other people or non-affiliated companies.

We will use all reasonable efforts to ensure that your personal data is not disclosed to regional/national institutions and authorities, unless required by law or other regulations.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

We use vetted processors to help deliver our services (e.g., hosting, email, e-commerce). We have appropriate data processing agreements in place.

International data transfers

We primarily host in the UK/EU. Where data is transferred outside the UK/EU (e.g., to service providers), we use approved safeguards such as the UK IDTA and/or EU Standard Contractual Clauses (SCCs), and where applicable adequacy decisions.

Third party links

Our site may, from time to time, contain links to and from third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

Your rights under UK/EU GDPR

  • Access your data
  • Rectify inaccurate data
  • Erase data (“right to be forgotten”)
  • Restrict processing
  • Data portability
  • Object to processing (including to direct marketing)
  • Withdraw consent at any time (where processing is based on consent)

To exercise your rights, contact support@biomesight.com. UK residents may complain to the ICO. EU residents may complain to their local Data Protection Authority.

Changes to our privacy policy

Any changes we may make to our privacy policy in the future will be posted on this page. Please check back frequently to see any updates or changes to our privacy policy.

Contact

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to support@biomesight.com.

For information on how we align with U.S. HIPAA safeguards when handling health information, see our HIPAA Compliance page.

DISCLAIMER This service has not been evaluated by the Food and Drug Administration or other healthcare authorities. Our platform and related products and services are not intended to diagnose, treat, cure or prevent any disease. Ranges apply to over 18s only.