PHITECH G&M PRIVACY POLICY
Last Updated: May 21, 2026
This Privacy Policy (“Privacy Policy”) describes how PHITECH INC (“PHITECH”, “Company”, “we”, “our”, or “us”) collects, uses, stores, processes, discloses, and protects information in connection with the PHITECH Genomics & More (G&M) platform, including associated software, analytical tools, artificial intelligence functionalities, databases, reports, APIs, websites, applications, and related services (collectively, the “Platform” or “Services”). Privacy Policy applies solely to services offered and operated by PHITECH INC from the United States and hosted on U.S.-based cloud infrastructure, including Amazon Web Services (AWS), unless expressly stated otherwise in a separate written agreement. For the avoidance of doubt, this Privacy Policy does not govern services offered by other PHITECH group entities or services localized for jurisdictions outside the United States, which may be subject to separate privacy notices, data processing terms, or local-law disclosures.
This Privacy Policy applies to information processed through:
-
user accounts;
-
Platform usage;
-
websites and web portals;
-
communications with PHITECH;
-
support interactions;
-
evaluations and trial programs;
-
and other interactions relating to the Services.
This Privacy Policy applies to:
-
individual users;
-
researchers;
-
clinicians;
-
laboratory personnel;
-
Customer representatives;
-
website visitors;
-
and other individuals interacting with the Platform or Services.
This Privacy Policy does not replace:
-
separate commercial agreements;
-
data processing agreements;
-
business associate agreements;
-
institutional agreements;
-
or other agreements entered into between PHITECH and Customers.
Where Phitech Inc. processes information on behalf of a Customer, any use, disclosure, retention, access, transmission, or hosting of PHI shall be governed exclusively by a fully executed Business Associate Agreement (“BAA”) between Phitech Inc. and the applicable Customer, and Phitech Inc. shall have no obligation to process PHI absent such executed BAA.
By accessing or using the Platform or Services, you acknowledge that your information may be processed as described in this Privacy Policy.
1. WHO WE ARE
This Privacy Policy is provided by PHITECH INC.
PHITECH provides the G&M platform, a cloud-based multi-omics analysis and decision support platform designed for research, laboratory, clinical decision support, and related analytical workflows.
Depending on the context of Platform usage, PHITECH may process information:
-
directly on its own behalf;
-
on behalf of Customers, institutions, laboratories, hospitals, universities, or other organizations;
-
or in connection with evaluations, pilot programs, demonstrations, research collaborations, or trial access programs.
In certain situations, PHITECH may act as:
-
a service provider;
-
data processor;
-
business associate;
-
or similar service role under applicable privacy, healthcare, or data protection laws and contractual arrangements.
Customers or organizations using the Platform may separately determine:
-
what information is uploaded to the Platform;
-
who is authorized to access the Platform;
-
how information is used within their organization;
-
and what retention, compliance, or regulatory obligations apply to their use of the Services.
Additional contractual terms, data processing agreements, business associate agreements, institutional policies, or regulatory requirements may apply depending on the nature of the Services and the relationship between PHITECH and the applicable Customer.
2. INFORMATION WE COLLECT
PHITECH may collect, receive, generate, process, or otherwise handle information in connection with the Platform and Services, including information provided directly by users, Customers, organizations, integrated systems, and automated Platform processes.
The categories of information we may collect include:
Account and Registration Information
Including:
-
name;
-
email address;
-
organization or institution name;
-
account credentials;
-
user role information;
-
contact information;
-
and account-related preferences or settings.
User and Customer Communications
Including:
-
communications with PHITECH;
-
support requests;
-
onboarding information;
-
feedback;
-
meeting or demo information;
-
survey responses;
-
and other communications relating to the Services.
Multi-Omics, Biological, and Analytical Data
Including:
-
multi-omics data;
-
sequencing data;
-
genomic, transcriptomic, proteomic, epigenomic, metabolomic, or related biological data;
-
phenotype information;
-
laboratory information;
-
analytical inputs;
-
uploaded files;
-
metadata;
-
annotations;
-
reports;
-
and other scientific or research-related information submitted to or processed through the Platform.
Usage and Activity Information
Including:
-
login activity;
-
account access records;
-
audit logs;
-
workflow execution records;
-
analyses initiated;
-
Platform interactions;
-
feature usage;
-
API activity;
-
resource consumption;
-
system events;
-
and operational activity logs.
Device, Technical, and Network Information
Including:
-
IP address;
-
browser type;
-
operating system;
-
device identifiers;
-
session information;
-
language settings;
-
access timestamps;
-
and technical information relating to access and use of the Platform.
Website and Cookie-Related Information
Including:
-
website usage data;
-
cookie identifiers;
-
analytics information;
-
session tracking information;
-
referral sources;
-
and interactions with PHITECH websites or web portals.
Information from Third Parties
PHITECH may receive information from:
-
Customers;
-
institutions;
-
laboratories;
-
integrated systems;
-
service providers;
-
infrastructure providers;
-
analytics providers;
-
or other third parties in connection with operation of the Platform and Services.
The categories and scope of information collected may vary depending on:
-
the type of Services used;
-
Customer configurations;
-
account type;
-
applicable integrations;
-
and the nature of Platform usage.
3. SENSITIVE, HEALTH, AND MULTI-OMICS DATA
The Platform may process sensitive information, including health-related, scientific, biological, and multi-omics data, depending on how the Services are used by users and Customers.
Such information may include:
-
multi-omics data;
-
sequencing data;
-
genomic, transcriptomic, proteomic, epigenomic, metabolomic, or related biological data;
-
phenotype information;
-
laboratory information;
-
clinical or research-related information;
-
and other sensitive scientific or health-related information uploaded to or processed through the Platform.
PHITECH processes such information solely:
-
to provide and operate the Services;
-
to perform analyses and workflow execution;
-
to generate Platform Outputs;
-
to maintain Platform security and operational integrity;
-
to provide support and service-related activities;
-
and as otherwise described in this Privacy Policy or applicable agreements.
Users and Customers are solely responsible for:
-
ensuring they have appropriate rights, permissions, consents, authorizations, and legal bases to upload and process such information through the Platform; provided that no PHI may be uploaded unless and until a valid BAA is in effect and the upload is expressly authorized by the applicable Customer;
-
complying with applicable healthcare, privacy, ethical, and regulatory obligations;
-
and determining whether use of the Platform is appropriate for their intended purposes and regulatory environment.
Where PHITECH processes protected health information (“PHI”) or other regulated health-related information on behalf of Customers, such processing may additionally be governed by:
-
business associate agreements;
-
data processing agreements;
-
institutional agreements;
-
or other contractual or regulatory requirements.
PHITECH does not intentionally use uploaded sensitive biological or health-related information for advertising purposes or sell identifiable sensitive information to third parties.
Where permitted by applicable law and applicable agreements, PHITECH may irrevocably generate, use, reproduce, disclose, commercialize, and otherwise exploit anonymized, de-identified, aggregated, statistical, and derived information, provided such information does not identify a natural person, for purposes including service improvement, model training and refinement, algorithm development, quality assurance, analytics, benchmarking, security, regulatory support, and operational optimization
4. HOW WE COLLECT INFORMATION
PHITECH may collect information through a variety of sources and methods in connection with operation of the Platform and Services.
Information Provided Directly by Users or Customers
We may collect information that users, Customers, institutions, laboratories, hospitals, universities, or other organizations provide directly to PHITECH, including through:
-
account registration;
-
Platform usage;
-
data uploads;
-
workflow submissions;
-
communications;
-
support requests;
-
onboarding activities;
-
evaluations or trial programs;
-
meetings or demonstrations;
-
and other interactions relating to the Services.
Information Collected Through Platform Usage
We may automatically collect information relating to use of the Platform and Services, including:
-
login activity;
-
access records;
-
audit logs;
-
workflow execution;
-
analysis activity;
-
API usage;
-
feature interactions;
-
resource consumption;
-
device and browser information;
-
and operational or technical usage data.
Information Collected Through Cookies and Similar Technologies
PHITECH and its service providers may use:
-
cookies;
-
session technologies;
-
analytics technologies;
-
log files;
-
pixels;
-
and similar technologies
to collect information relating to website usage, Platform interactions, security, authentication, analytics, and operational functionality.
Additional information regarding cookies and similar technologies may be provided through separate cookie notices or settings interfaces where applicable.
Information Received from Customers and Third Parties
PHITECH may receive information from:
-
Customers;
-
institutions;
-
laboratories;
-
integrated systems;
-
infrastructure providers;
-
analytics providers;
-
authentication providers;
-
service providers;
-
and other third parties
in connection with operation and support of the Services.
Automatically Generated Information
Certain information may be generated automatically through operation of the Platform, including:
-
audit logs;
-
operational metrics;
-
system activity records;
-
workflow histories;
-
security events;
-
analytical metadata;
-
and derived operational information associated with Platform usage.
The methods and scope of information collection may vary depending on:
-
the Services used;
-
Customer configurations;
-
account type;
-
integrations;
-
technical settings;
-
and applicable legal or regulatory requirements.
5. HOW WE USE INFORMATION
PHITECH may use information collected or processed through the Platform and Services for purposes including:
Providing and Operating the Services
Including:
-
creating and managing accounts;
-
authenticating users;
-
operating the Platform;
-
executing analyses and workflows;
-
generating Platform Outputs;
-
providing storage and computational resources;
-
and delivering requested functionalities and Services.
Supporting Research, Analytical, and Clinical Decision Support Workflows
Including:
-
processing uploaded data;
-
enabling analytical workflows;
-
supporting laboratory and research activities;
-
facilitating interpretation and visualization functionalities;
-
and supporting clinical decision support activities performed by users and Customers.
Security, Compliance, and Operational Integrity
Including:
-
monitoring Platform security;
-
detecting unauthorized access or misuse;
-
maintaining audit logs and activity records;
-
preventing fraud or harmful activity;
-
investigating incidents;
-
enforcing policies and agreements;
-
and complying with legal, regulatory, contractual, or security obligations.
Customer Support and Communications
Including:
-
responding to support requests;
-
providing onboarding assistance;
-
communicating regarding accounts, workflows, analyses, or Platform usage;
-
notifying users regarding updates, security matters, or operational issues;
-
and managing relationships with users and Customers.
Platform Improvement and Development
Including:
-
improving Platform functionality and usability;
-
optimizing workflows and system performance;
-
developing new features and functionalities;
-
improving analytical capabilities and artificial intelligence functionalities;
-
conducting internal analytics and quality assurance activities;
-
and maintaining operational effectiveness.
Research, Analytics, and De-Identified Data Uses
Where permitted by applicable law and applicable agreements, PHITECH may use anonymized, aggregated, statistical, de-identified, or derived information for purposes including:
-
analytics;
-
benchmarking;
-
research;
-
service improvement;
-
algorithm development;
-
quality assurance;
-
security;
-
and operational optimization.
Legal and Regulatory Compliance
Including:
-
complying with applicable laws, regulations, court orders, governmental requests, and legal processes;
-
protecting rights, safety, and security;
-
maintaining records;
-
and fulfilling contractual or regulatory obligations.
Evaluations, Demonstrations, and Trial Programs
Including:
-
providing trial access;
-
managing evaluations and pilot programs;
-
allocating promotional or evaluation credits;
-
and supporting onboarding or demonstration activities.
PHITECH may combine information collected through different sources and methods for purposes consistent with this Privacy Policy and applicable law.
6. HOW WE SHARE INFORMATION
PHITECH does not disclose identifiable User Data to third parties except:
-
as necessary to provide, operate, secure, support, and improve the Services;
-
as authorized or instructed by the applicable user or Customer;
-
as required by applicable law, regulation, legal process, or governmental request;
-
or as otherwise described in this Privacy Policy or applicable agreements.
Sharing with Customers and Organizations
Where users access the Platform on behalf of a Customer, institution, laboratory, hospital, university, company, or other organization, PHITECH may make information available to the applicable organization in accordance with applicable agreements, organizational permissions, and applicable laws.
Such information may include:
-
account information;
-
audit logs;
-
activity records;
-
workflow information;
-
analyses and Platform Outputs;
-
usage information;
-
and operational or administrative records
associated with organizational use of the Platform.
Sharing with Service Providers and Infrastructure Providers
PHITECH may use third-party service providers, subprocessors, cloud infrastructure providers, analytics providers, authentication providers, support providers, and other vendors that assist PHITECH in operating, securing, maintaining, supporting, and improving the Platform and Services. Such providers may include AWS, authentication providers, security vendors, analytics providers, support vendors, and other infrastructure or operational subprocessors engaged to host, secure, maintain, and support the Services. PHITECH requires such providers to process information under written contractual obligations appropriate to their role, including confidentiality, security, and data protection obligations.
Such providers may process information solely on behalf of PHITECH and subject to applicable contractual, confidentiality, security, and operational obligations.
Sharing Through Integrations and Authorized Workflows
Information may be shared with integrated systems, APIs, laboratories, institutional systems, collaborators, or other authorized third parties where:
-
enabled by Platform functionality;
-
requested or configured by users or Customers;
-
required for workflow execution;
-
or otherwise authorized within the scope of Platform usage.
Sharing for Legal, Security, and Compliance Purposes
PHITECH may disclose information where reasonably necessary to:
-
comply with applicable laws, regulations, court orders, legal processes, or governmental requests;
-
protect the rights, safety, security, operations, or integrity of PHITECH, users, Customers, or third parties;
-
investigate fraud, misuse, security incidents, or violations of agreements;
-
or enforce legal rights, agreements, or policies.
Business Transactions
Information may be disclosed or transferred in connection with:
-
mergers;
-
acquisitions;
-
financing transactions;
-
reorganizations;
-
asset sales;
-
or other corporate transactions
involving PHITECH, subject to applicable confidentiality and legal obligations.
De-Identified and Aggregated Information
Where permitted by applicable law and applicable agreements, PHITECH may use and share anonymized, aggregated, statistical, de-identified, or derived information that does not identify individual users or data subjects for purposes including:
-
analytics;
-
benchmarking;
-
scientific and operational research;
-
service improvement;
-
quality assurance;
-
security;
-
operational optimization;
-
and internal business operations.
PHITECH does not sell identifiable personal information or identifiable sensitive biological, health-related, or multi-omics data to third parties for advertising purposes.
7. HIPAA, BUSINESS ASSOCIATE, AND CUSTOMER-RELATED DATA
Depending on the nature of the Services and the relationship between PHITECH and the applicable Customer, PHITECH may process PHI or other regulated health-related information on behalf of healthcare providers, laboratories, institutions, or other regulated entities.
Where applicable, PHITECH may act as:
-
a business associate;
-
service provider;
-
data processor;
-
or similar service role under applicable healthcare, privacy, or data protection laws and contractual arrangements.
Processing of PHI or other regulated information may additionally be governed by:
-
business associate agreements;
-
data processing agreements (“DPAs”);
-
institutional agreements;
-
Customer contracts;
-
or other applicable legal or regulatory arrangements.
Customers and users remain solely responsible for:
-
determining whether uploaded information is subject to HIPAA or other healthcare or privacy regulations;
-
obtaining required authorizations, consents, approvals, and legal bases for processing;
-
configuring and using the Platform in accordance with applicable regulatory obligations;
-
and ensuring appropriate clinical, institutional, and compliance oversight.
PHITECH processes Customer-related data and regulated information solely:
-
to provide and operate the Services;
-
to execute analyses and workflows;
-
to maintain security and operational integrity;
-
to provide support and service-related activities;
-
and as otherwise permitted under applicable agreements and laws.
Nothing in this Privacy Policy is intended to modify, replace, or supersede:
-
applicable BAAs;
-
DPAs;
-
Customer agreements;
-
or other contractual obligations governing regulated information.
8. DE-IDENTIFIED, AGGREGATED, AND DERIVED DATA
Where permitted by applicable law and applicable agreements, PHITECH may generate, use, analyze, and retain anonymized, aggregated, statistical, de-identified, or derived information generated from:
-
Platform usage;
-
workflow activity;
-
operational metrics;
-
analytical processes;
-
User Data;
-
and other information processed through the Services.
Such information may be used for purposes including:
-
service improvement;
-
workflow optimization;
-
algorithm development;
-
artificial intelligence model improvement;
-
benchmarking;
-
analytics;
-
quality assurance;
-
operational optimization;
-
security;
-
scientific and operational research;
-
and internal business operations.
PHITECH implements reasonable measures designed to ensure that such information does not identify individual users or data subjects before it is used or disclosed in de-identified or aggregated form.
De-identified, aggregated, statistical, or derived information:
-
is not considered identifiable User Data;
-
may be retained independently of User Data;
-
and may continue to be used after deletion of identifiable information, subject to applicable law and contractual obligations.
PHITECH does not attempt to re-identify de-identified information except where:
-
required for security, legal, compliance, or operational purposes;
-
permitted by applicable law;
-
or necessary to validate de-identification processes or maintain Platform integrity.
Where PHI is involved and a BAA applies, any de-identification shall be performed in accordance with applicable law, including HIPAA requirements where relevant, and the applicable contractual restrictions.
9. COOKIES AND SIMILAR TECHNOLOGIES
PHITECH and its service providers may use cookies and similar technologies in connection with operation of the Platform, websites, applications, and related Services.
Such technologies may include:
-
cookies;
-
session identifiers;
-
local storage technologies;
-
analytics technologies;
-
log files;
-
and similar tracking or operational technologies.
These technologies may be used for purposes including:
-
authentication and account management;
-
maintaining user sessions;
-
Platform functionality;
-
security and fraud prevention;
-
operational monitoring;
-
analytics and performance measurement;
-
remembering preferences and settings;
-
troubleshooting and debugging;
-
and improving the Platform and Services.
The types of information collected through these technologies may include:
-
IP address;
-
browser type;
-
device information;
-
operating system;
-
session activity;
-
usage interactions;
-
access timestamps;
-
referral information;
-
and other technical or usage-related information.
Certain cookies or technologies may be necessary for operation and security of the Platform and may not be disabled without affecting functionality.
Depending on applicable law and your location, PHITECH may provide:
-
cookie notices;
-
consent mechanisms;
-
browser preference tools;
-
or cookie management settings through the Platform or associated websites.
You may also manage certain cookie settings through your browser or device settings. However, disabling certain technologies may affect Platform functionality, authentication, security, or user experience.
Additional information regarding cookies and similar technologies may be provided through separate cookie notices or settings interfaces where applicable.
10. DATA RETENTION
Phitech Inc. may retain information for as long as reasonably necessary to provide and operate the Services, maintain Platform functionality and security, comply with legal, regulatory, tax, audit, and operational obligations, resolve disputes, enforce agreements, and support legitimate business purposes; provided that, with respect to PHI or other regulated health information processed under a BAA, retention, return, destruction, access, and deletion shall be governed first by the applicable BAA and any applicable Customer agreement, and, to the extent inconsistent, the BAA shall control. Retention periods may vary depending on:
-
the type of information;
-
Customer agreements;
-
applicable laws or regulations;
-
account type;
-
workflow configurations;
-
support or operational requirements;
-
and the nature of Platform usage.
PHITECH may retain:
-
account information;
-
audit logs;
-
workflow records;
-
support communications;
-
operational records;
-
security records;
-
and related metadata for compliance, operational integrity, security, legal, research, or business continuity purposes.
Uploaded data, analyses, and Platform Outputs may be retained:
-
according to Customer configurations;
-
applicable agreements;
-
retention settings;
-
operational policies;
-
or regulatory obligations.
Unless otherwise required by applicable agreements or law:
-
PHITECH is not obligated to retain User Data indefinitely;
-
users and Customers remain responsible for exporting and retaining copies of information they wish to preserve;
-
and PHITECH may delete or anonymize information following expiration of applicable retention periods.
Where permitted by applicable law and applicable agreements, PHITECH may retain anonymized, aggregated, statistical, de-identified, or derived information independently of identifiable User Data.
PHITECH may also retain information where reasonably necessary to:
-
investigate security incidents;
-
prevent fraud or misuse;
-
comply with legal obligations;
-
protect the rights, safety, and security of PHITECH, users, Customers, or third parties;
-
or maintain Platform integrity and operational continuity.
The retention practices described in this Section apply solely to the U.S.-based Services governed by this Privacy Policy and do not supersede any separate retention or destruction policy applicable to other jurisdictions or affiliates.
11. DATA SECURITY
PHITECH implements commercially reasonable administrative, technical, organizational, and physical safeguards designed to protect information processed through the Platform against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Such safeguards may include:
-
access controls;
-
authentication mechanisms;
-
encryption technologies;
-
audit logging;
-
infrastructure monitoring;
-
backup and recovery processes;
-
network and system security measures;
-
role-based access controls;
-
and security review and operational procedures.
PHITECH may use:
-
cloud infrastructure providers;
-
subprocessors;
-
security service providers;
-
and other third-party technologies in connection with operation and security of the Platform and Services.
Despite reasonable safeguards, no:
-
internet-based service;
-
cloud environment;
-
software platform;
-
transmission method;
-
or electronic storage system can be guaranteed completely secure.
Accordingly, PHITECH does not guarantee absolute security of information processed through the Platform.
Users and Customers are also responsible for maintaining appropriate security practices, including:
-
protecting account credentials;
-
managing authorized access;
-
using secure devices and networks;
-
and complying with applicable security, institutional, and regulatory requirements.
PHITECH may:
-
monitor Platform activity;
-
investigate suspected security incidents;
-
implement additional security measures;
-
restrict access;
-
or suspend functionalities where reasonably necessary to maintain security, operational integrity, compliance, or protection of the Platform and associated information.
Where required by applicable law or applicable agreements, PHITECH may provide notifications relating to qualifying security incidents within commercially reasonable timeframes.
12. DATA HOSTING AND DATA LOCATION
For accounts and Services covered by this Privacy Policy, PHITECH processes and hosts information in the United States using U.S.-based cloud infrastructure, including AWS and related U.S.-based service providers. This Privacy Policy applies solely to such U.S.-hosted Services provided by PHITECH. For the avoidance of doubt, this Privacy Policy does not apply to services offered, localized, or hosted outside the United States by any other Phitech group entity, which may be governed by separate contracts, privacy notices, or local-law disclosures.
PHITECH does not intentionally transfer identifiable User Data outside the United States except:
-
as authorized or instructed by the applicable user or Customer;
-
as required by applicable law, legal process, or governmental request;
-
or as otherwise expressly agreed with the applicable Customer.
PHITECH may use U.S.-based cloud infrastructure providers, subprocessors, security providers, analytics providers, and operational service providers in connection with operation, maintenance, security, and support of the Platform and Services.
Customers and users remain responsible for:
-
determining whether additional regulatory, institutional, or contractual requirements apply to their use of the Platform;
-
and ensuring that their use of the Services complies with applicable laws, organizational policies, and regulatory obligations.
Additional requirements relating to regulated information, data hosting, or compliance obligations may be addressed through:
-
Customer agreements;
-
business associate agreements;
-
data processing agreements;
-
or other applicable contractual arrangements.
13. YOUR PRIVACY RIGHTS
Depending on your location, applicable laws, relationship with PHITECH, and the nature of the Services used, you may have certain rights relating to information processed through the Platform.
Subject to applicable law, regulatory obligations, contractual restrictions, institutional requirements, and verification procedures, such rights may include the right to:
-
request access to certain information relating to you;
-
request correction of inaccurate information;
-
request deletion of certain information;
-
request restriction or limitation of certain processing activities;
-
object to certain processing activities where applicable;
-
request information regarding categories of collected or disclosed information;
-
or request copies of certain information where legally required.
Certain rights may be limited where:
-
PHITECH processes information on behalf of a Customer or institution;
-
retention is required for legal, regulatory, security, scientific, operational, or compliance purposes;
-
information relates to other individuals;
-
or applicable laws or contractual obligations restrict modification or deletion.
Where PHITECH processes information on behalf of a Customer, institution, laboratory, hospital, university, or other organization, requests relating to such information may need to be directed to the applicable organization.
PHITECH may take reasonable steps to:
-
verify identity;
-
confirm authorization;
-
and validate requests before responding to privacy-related requests.
PHITECH will not discriminate against individuals for exercising applicable privacy rights where prohibited by law. Privacy-related requests or questions may be submitted using the contact information provided in this Privacy Policy.
The rights described in this Section are intended to reflect applicable U.S. privacy law and the U.S.-based Services covered by this Privacy Policy. Individuals interacting with non-U.S. services may be subject to separate local-law notices and rights processes.
14. CALIFORNIA AND OTHER U.S. STATE PRIVACY RIGHTS
Depending on your U.S. state of residence and applicable law, you may have additional privacy rights relating to personal information processed by PHITECH.
Such rights may include, where applicable:
-
the right to know or access categories of personal information collected, used, disclosed, or processed;
-
the right to request deletion of certain personal information;
-
the right to request correction of inaccurate personal information;
-
the right to obtain information regarding categories of third parties with whom information is disclosed;
-
the right to limit certain uses of sensitive personal information where required by law;
-
or the right to appeal certain privacy request decisions where applicable.
PHITECH does not:
-
sell identifiable personal information;
-
sell identifiable sensitive biological, health-related, or multi-omics data;
-
or share identifiable personal information with third parties for cross-context behavioral advertising purposes.
PHITECH may collect, use, disclose, and process categories of information described in this Privacy Policy for purposes including:
-
providing and operating the Services;
-
security and operational integrity;
-
analytics and service improvement;
-
customer support;
-
compliance and legal obligations;
-
and other purposes described in this Privacy Policy.
Certain rights and obligations may vary depending on:
-
applicable state law;
-
the nature of the information;
-
the relationship between PHITECH and the applicable Customer;
-
and whether PHITECH processes information on its own behalf or on behalf of a Customer or regulated entity.
Where PHITECH processes information on behalf of a Customer, institution, laboratory, hospital, university, or other organization, privacy requests relating to such information may need to be directed to the applicable organization.
Users may submit privacy-related requests using the contact information provided in this Privacy Policy. PHITECH may take reasonable steps to verify identity and authorization before responding to requests.
15. CHILDREN’S PRIVACY
The Platform and Services are not directed to or intended for use by children under the age of 13.
PHITECH does not knowingly collect personal information directly from children under 13 through the Platform or Services except where such information is uploaded by authorized users or Customers in connection with lawful research, laboratory, healthcare, or clinical decision support activities conducted under applicable legal, regulatory, ethical, institutional, or parental authorization requirements.
Users and Customers are solely responsible for:
-
ensuring that they have appropriate authorizations, consents, permissions, and legal bases for uploading or processing information relating to minors;
-
complying with applicable healthcare, privacy, research, and regulatory obligations;
-
and determining whether use of the Platform is appropriate for their intended activities involving minors.
If PHITECH becomes aware that personal information has been collected directly from a child under 13 in violation of applicable law or this Privacy Policy, PHITECH may take reasonable steps to delete or restrict such information where appropriate and legally permitted.
Depending on applicable laws and the nature of Platform usage, additional protections or requirements may apply to information relating to minors.
16. THIRD-PARTY SERVICES AND LINKS
The Platform and Services may incorporate, integrate with, rely on, or provide access to third-party services, infrastructure, software, databases, APIs, websites, tools, libraries, authentication providers, analytics providers, cloud providers, or other third-party technologies and materials.
PHITECH may also provide links or access to third-party websites, documentation, resources, publications, or services for operational, informational, analytical, or workflow-related purposes.
Third-party services and technologies may operate under separate:
-
terms of service;
-
privacy policies;
-
licensing terms;
-
security practices;
-
or operational conditions that are not controlled by PHITECH.
PHITECH is not responsible for:
-
the content, availability, security, privacy practices, or functionality of third-party services or websites;
-
acts or omissions of third-party providers;
-
or failures, interruptions, inaccuracies, vulnerabilities, or limitations arising from third-party systems or technologies.
Users and Customers are responsible for reviewing applicable third-party terms, privacy policies, and operational practices before using third-party services or integrations in connection with the Platform.
Use of third-party services, integrations, or external links may be subject to additional legal, technical, operational, or compliance considerations depending on the applicable workflow, Customer configuration, or regulatory environment.
17. CHANGES TO THIS PRIVACY POLICY
PHITECH may modify, update, or revise this Privacy Policy from time to time.
Updated versions may be made available through:
-
the Platform;
-
PHITECH websites;
-
account notifications;
-
email communications;
-
or other reasonable methods of notice.
Unless otherwise required by applicable law, updated versions of this Privacy Policy become effective upon:
-
publication;
-
posting;
-
or other communicated effective dates specified by PHITECH.
Your continued access to or use of the Platform or Services after an updated Privacy Policy becomes effective constitutes acknowledgment of the revised Privacy Policy.
If required by applicable law, PHITECH may provide additional notice or obtain additional consent before certain changes become effective.
PHITECH may also update:
-
operational practices;
-
security measures;
-
data handling procedures;
-
Platform functionalities;
-
compliance processes;
-
or service-related workflows in connection with ongoing operational, legal, regulatory, security, or business requirements.
In the event of a conflict between this Privacy Policy and an applicable Order, BAA, or DPA relating to the U.S.-based Services, the applicable BAA or DPA shall prevail with respect to regulated data processing, and the applicable Order shall prevail with respect to service configuration or committed hosting arrangements.
18. CONTACT INFORMATION
If you have questions, requests, notices, or concerns relating to this Privacy Policy, privacy practices, or information processed through the Platform or Services, you may contact PHITECH using the contact information below:
PHITECH INC
Adress: PHITECH INC., 205 North Michigan Avenue, Suite 810, Chicago, Illinois 60611, USA
Website: https://www.phitech.bio/
Email: privacy@phitech.bio
PHITECH may update contact information from time to time through the Platform or its website.
