Last Updated: September 12, 2024
This Privacy Notice describes how Myriad Genetics, Inc., and certain of its subsidiaries collect, use, and disclose your personal information when you visit our Myriad.com and GeneSight.com websites, or any other of our websites, applications, products, services, social media accounts, and interactive features (which are collectively referred to here as “Services”) that link to this Privacy Notice. This Privacy Notice applies to our Services in the United States. Information about our privacy practices in the European Union and European Economic Area can be found here.
This Privacy Notice does not apply to any Services that link to a different privacy notice, such as SneakPeekTest.com, which are maintained by our subsidiary Gateway Genomics, LLC. This Privacy Notice also does not apply to your Protected Health Information (“PHI”) that is governed by HIPAA, regardless of where it is collected. For information about how we use and disclose your PHI, our legal duties with respect to your PHI and your rights with respect to your PHI and how to exercise them, please refer to our HIPAA Notice of Privacy Practices. In connection with HIPAA covered services, in the event of a conflict between this Notice and our HIPAA Notice of Privacy Practices, our HIPAA Notice of Privacy Practices will prevail.
Navigate to sections within this Privacy Notice using the below links:
The personal information we collect depends on how you interact with us, the Services you use, the choices you make, and the methods we use for information collection, which include collecting information directly from you, collecting information automatically, and collecting information from third parties.
Information we collect directly from you. We collect personal information when you provide it to us directly, which can include:
Information we collect automatically. When you use our Services, we may collect some information automatically, which can include:
Information we obtain from third-party sources. We also obtain the types of information described above from third parties. These third-party sources can include:
Sensitive Personal Information. Some of the personal information we collect directly from you, automatically, and from third-party sources is considered “sensitive.” Examples of Sensitive Personal Information we collect, depending on applicable law, can include:
Inferences. We may also generate new personal information or make inferences from personal information, including Sensitive Personal Information, that we collect from you directly, automatically, and from the third-party sources identified above. For example, we infer your general geographic location such as city, state, and country based on your IP address.
When you are asked to provide personal information, you may decline. And you may use web browser or operating system controls to prevent certain types of automatic data collection. But if you choose not to provide or allow information that is necessary for certain Services or features, those Services may not work as intended. Please see our Cookie Notice for more information on what Cookies and Similar Technologies we may use and why in connection with the Services.
We use the following categories of personal information we collect for the purposes described below:
Personal Information: Name and Contact Information, Demographic Data, Provider Information, Employment-related Information, User Generated Content and Files, Content of Communications, Financial Information, Identifiers and Device Information, Geolocation Data, Internet and Network Activity, Usage Data, Inferences
Sensitive Personal Information: Sensitive Demographic Data, Precise Geolocation Data, Health Data, Inferences
Personal Information: Name and Contact Information, Demographic Data, Provider Information, User Generated Content and Files, Content of Communications, Identifiers and Device Information, Geolocation Data, Internet and Network Activity, Usage Data, Inferences
Product improvement, development, and research. To develop new services or features and conduct research (which may include recording and analyzing your interaction with certain pages of our website to help us improve your user experience).
Personalization. To understand you and your preferences to enhance your experience and enjoyment using our Services.
Customer support. To provide customer support and respond to your questions (which may include our recording and storing telephone, video, email, or online chat communications).
Communications. To send you information, including confirmations, invoices, technical notices, updates, security alerts, and support and administrative messages.
Personal Information: Name and Contact Information, Demographic Data, Provider Information, User Generated Content and Files, Content of Communications, Financial Information, Identifiers and Device Information, Geolocation Data, Internet and Network Activity, Usage Data, Inferences
Marketing. To communicate with you about new services, offers, promotions, rewards, contests, upcoming events, and other information about our services and those of our selected partners (see the Choice and Control of Personal Information section of this Privacy Notice for information about how to change your preferences for promotional communications).
Personal Information: Name and Contact Information, Demographic Data, Provider Information, Employment-related Information, User Generated Content and Files, Content of Communications, Identifiers and Device Information, Geolocation Data, Internet and Network Activity, Usage Data, Inferences
Advertising. To display advertising to you (see our Cookie Notice for more information on what Cookies and Similar Technologies are used to deliver advertising to you and Your Privacy Choices).
We combine data we collect from different sources for these purposes and to give you a more seamless, consistent, and personalized experience.
We disclose personal information with your consent or as we determine necessary to complete your transactions or provide the Services you have requested or authorized. In addition, we disclose each of the categories of personal information described above, to these types of third parties, for the following business purposes:
Please note that some of our Services also include integrations, references, or links to services provided by third parties whose privacy practices differ from ours. If you provide personal information to any of those third parties, or allow us to share personal information with them, that data is governed by their privacy notices.
Finally, we may use and disclose de-identified information in accordance with applicable law. Where we do so, we will take reasonable measures to maintain and use the information in deidentified form and not reidentify the information except as permitted by applicable law.
We provide a variety of ways for you to control the personal information we hold about you, including choices about how we use that data. In some jurisdictions, these controls and choices may be enforceable as rights under applicable law.
Access, portability, correction, and deletion. If you wish to access, download, correct, or delete personal information about you that we hold, send us a request by using the contact methods described at the bottom of this Privacy Notice.
Communications preferences. You can choose whether to receive promotional communications from us by email, SMS, and telephone. If you receive promotional email or SMS messages from us and would like to stop, you can do so by following the directions in the messages you receive. These choices do not apply to certain transactional or informational communications including surveys and mandatory service communications.
Data sales or sharing. Some privacy laws define “sale” or “sharing” broadly to include some of the disclosures described in the Our Disclosure of Personal Information section above. To opt-out from such data “sales” or “sharing” please utilize the controls described in Your Privacy Choices. You can also send us a request by using the contact methods described at the bottom of this Privacy Notice, and we can walk you through the use of our Cookie Manager and Consent Tools, as described in Your Privacy Choices.
Targeted advertising. To opt-out from or otherwise control targeted advertising, you have several options. Please review our Cookie Notice or Your Privacy Choices to learn more about your targeted advertising choices.
If you send us a request to exercise your rights or these choices, to the extent permitted by applicable law, we may decline requests in certain cases. For example, we may decline requests where granting the request would be prohibited by law, could adversely affect the privacy or other rights of another person, would reveal a trade secret or other confidential information, or would interfere with a legal or business obligation that requires retention or use of the data. Further, we may decline a request where we are unable to authenticate you as the person to whom the data relates, the request is unreasonable or excessive, or where otherwise permitted by applicable law. If you receive a response from us informing you that we have declined your request, in whole or in part, you may appeal that decision by submitting your appeal to our privacy office using the contact methods described at the bottom of this Privacy Notice.
If you are a California resident and the processing of personal information about you is subject to the California Consumer Privacy Act (“CCPA”), you have certain additional rights with respect to that information.
Notice at Collection. At or before the time of collection, you have a right to receive notice of our practices, including the categories of personal information and sensitive personal information to be collected, the purposes for which such information is collected or used, whether such information is sold or shared, and how long such information is retained. You can find those details in this Privacy Notice by clicking on the above links.
Right to Know. You have a right to request that we disclose to you the personal information we have collected about you. You also have a right to request additional information about our collection, use, sharing, or sale of such personal information. Note that we have provided much of this information in this Privacy Notice. You may make such a “request to know” by sending us a request using the contact methods described at the bottom of this Privacy Notice.
Rights to Request Correction or Deletion. You also have a right to request that we correct inaccurate personal information and that we delete personal information under certain circumstances, subject to a number of exceptions. To make a request to correct or delete, send us a request by using the contact methods described at the bottom of this Privacy Notice.
Right to Opt-Out / “Do Not Sell or Share My Personal Information”. You have a right to opt-out from future “sales” or “sharing” of personal information as those terms are defined by the CCPA.
Note that the CCPA defines “sell,” “share,” and “personal information” very broadly, and some of our data sharing described in this Privacy Notice may be considered a “sale” or “sharing” under those definitions. In particular, we let advertising and analytics providers collect identifiers (IP addresses, cookie IDs, and mobile IDs), activity data (browsing, clicks, app usage), device data, and geolocation data through our Services, but do not “sell” or “share” any other types of personal information. Please see the table below for more details about disclosures of categories of personal information in the last year.
Disclosure
Categories of Personal Information
Categories of personal information about California residents “sold” or “shared” in the preceding 12 months
Categories of personal information disclosed for a business purpose in the preceding 12 months
If you do not wish for us or our partners to “sell” or “share” personal information relating to your interactions with our Services for targeted advertising purposes, you can make your request by using the controls described in Your Privacy Choices and our Cookie Notice, which describe how to use our Cookie Manger and Consent Tools. You may also email us for assistance using the contact methods described at the bottom of this Privacy Notice. If you opt-out using these choices, we will not share or make available such personal information in ways that are considered a “sale” or “sharing” under the CCPA. However, we will continue to make available to our partners (acting as our service providers) some personal information to help us perform advertising-related functions. Further, using these choices will not opt you out of the use of previously “sold” or “shared” personal information or stop all interest-based advertising.
Right to Limit Use and Disclosure of Sensitive Personal Information. You have a right to limit our use of sensitive personal information for any purposes other than to provide the Services or goods you request or as otherwise permitted by law. To do so, send us a request by using the contact methods described at the bottom of this Privacy Notice.
You may designate, in writing or through a power of attorney, an authorized agent to make requests on your behalf to exercise your rights under the CCPA. Before accepting such a request from an agent, we will require the agent to provide proof you have authorized it to act on your behalf, and we may need you to verify your identity directly with us.
Further, to provide, correct, or delete specific pieces of personal information we will need to verify your identity to the degree of certainty required by law. We will verify your request by asking you to send it from the email address associated with your account or requiring you to provide information necessary to verify your identity.
Finally, you have a right to not be discriminated against for exercising these rights set out in the CCPA.
Additionally, under California Civil Code Section 1798.83, also known as the “Shine the Light” law, California residents with whom we have an established business relationship are entitled to request and receive, free of charge, once per calendar year, information about the Personal Information we shared, if any, with other businesses for their own direct marketing uses during the prior year. California residents may request further information about our compliance with this law by using the contact methods at the bottom of this Privacy Notice.
If the processing of personal information about you is considered consumer health information subject to the Washington My Health My Data Act (“MHMDA”), you have certain additional rights with respect to that information. MHMDA protects consumer health data that is not protected under HIPAA. This section of the Privacy Notice applies to personal information defined as “consumer health data” subject to MHMDA.
Consumer Health Data We Collect (categories). As described in the Personal Information We Collect section of this Privacy Notice, the data we collect depends on how you interact with us, the Services you use, and the choices you make. Because consumer health data is defined very broadly, many of the categories of data we collect are or could be considered consumer health data.
Consumer health data can include:
Sources of Consumer Health Data
As described further in the Personal Information We Collect section of this Privacy Notice, we collect Personal Information (which may include consumer health data) directly from you, from your interactions with our Services, from third parties, and from publicly available sources.
Why We Collect and Use Consumer Health Data
We collect and use consumer health data for the purposes described in the How We Use Personal Information section of the Privacy Notice. Primarily, we collect and use consumer health data as reasonably necessary to provide you with the products you have requested or authorized. This may include delivering and operating the Services and their features, personalization of certain product features, ensuring the secure and reliable operation of the Services and the systems that support them, troubleshooting and improving the Services, and other essential business operations that support the provision of the products such as analyzing our performance, meeting our legal obligations, developing our workforce, and conducting research and development.
We may use consumer health data for other purposes for which we give you choices and/or obtain your consent as required by law – for example, for advertising or marketing purposes. See the Choice and Control of Personal Information section of this Privacy Notice and the Cookie Notice for more details on the controls and choices you may have.
Our Sharing of Consumer Health Data
We may share each of the categories of consumer health data described above for the purposes described in the Our Disclosure of Personal Information section of this Privacy Notice. In particular, we may share Personal Information, including consumer health data, with your consent or as reasonably necessary to complete any transaction or provide any Services you have requested or authorized, as described in the previous section above.
Third Parties With Which We Share Consumer Health Data
As necessary for the purposes described above, we share consumer health data with the following categories of third parties:
How to Exercise Your Rights
MHMDA, if applicable, provides certain rights with respect to consumer health data, including rights to access, delete, or withdraw consent relating to such data, subject to certain exceptions. You can request to exercise such rights using the various tools and mechanisms described in the Choice and Control of Personal Information section of this Privacy Notice or the contact methods at the bottom of this Privacy Notice.
If your request to exercise a right under the MHMDA is denied, you may appeal that decision by contacting our Privacy Office using the contact methods at the bottom of this Privacy Notice. You can raise a concern or lodge a complaint with the Washington Attorney General at https://www.atg.wa.gov/file-complaint
We retain personal information for as long as necessary to provide the services and fulfill the transactions you have requested, comply with our legal obligations, resolve disputes, enforce our agreements, and other legitimate and lawful business purposes. Because these needs can vary for different data types in the context of different Services, actual retention periods can vary significantly based on criteria such as user expectations or consent, the sensitivity of the data, the availability of automated controls that enable users to delete data, and our legal or contractual obligations.
Our Services are not directed at or intended for use by minors.
We take reasonable and appropriate steps to help protect personal information collected in connection with our Services from unauthorized access, use, disclosure, alteration, and destruction. Please be aware that despite our efforts, no security system is foolproof; we cannot guarantee the security of information.
To help us protect personal information, we request that you use a strong password and never share your password with anyone or use the same password with other sites or accounts.
We will update this Privacy Notice on an ongoing basis for a variety of purposes, including when necessary to reflect changes in our Services, how we use personal information, or the applicable law. When we post changes to the Privacy Notice, we will revise the “Last Updated” date at the top of the Notice. If we make material changes to the notice, we will provide notice (either through the Services or by email) or obtain consent regarding such changes as may be required by law.
If you have a privacy concern, complaint, or a question for the Myriad Privacy Office, please contact us at [email protected] or (866) 485-1599. You may also write to us at:
Attn: Privacy Office Myriad Genetics, Inc. 322 North 2200 West Salt Lake City, UT 84116
Download
Spanish version