Privacy and Security

This Privacy Policy, effective as of February 1, 2022, is intended to make clear what sorts of data we (Seven Bridges Genomics Inc.) collect from you, what we do with it, and how our users (“you”) can control what happens to it.

 

I. WHAT DATA WE COLLECT

In the course of your use of our Services, we may collect the following types of information:

Payment Information: In order to pay for Services, you may be required to submit payment information, such as a credit card number and billing address.

Account Information: In the course of registering an account or subsequently, we may ask you to provide information such as your name, employer, email address or phone number.

User Activity Information: We may keep logs of your activity as you use our Services, for example which pages you visit, when you start a task, or what calls are made to our API. We may also track user activity on our site using third-party services such as Google Analytics, which you can learn more about at http://www.google.com/analytics/, Fullstory, which you can learn more about at https://www.fullstory.com, and Appcues, which you can learn more about at https://www.appcues.com/.

Other User­ Provided Personal Information: You may provide information to us via other communications with our team, for instance emails exchanged with our support team or suggestions submitted via a feedback form.

Submitted Data: You may provide us sequencing data derived from a human or other organism, for instance by uploading a BAM file or FASTQ file.

Submitted Metadata: When you provide us Submitted Data, that Submitted Data will usually be accompanied by associated metadata describing the Submitted Data, which may include information about the subject(s) of the sequencing data, for instance phenotype or population statistics.

 

II. WHAT WE DO WITH IT

We use your Payment Information in order to bill you for the Services. We do this on the basis of your consent and our legitimate interest in getting paid for Services. Your Payment Information, and some elements of your Account Information are stored and processed on our behalf for this purpose by a third­-party service provider, Stripe Inc. - check out their privacy policy at https://stripe.com/us/privacy and their security protections at https://stripe.com/help/security. We do not store any credit card information ourselves.

On the basis of your consent, we may use your Account Information to contact you about your use of our Services, for instance to let you know a task has completed, or to otherwise inform you about our Services, for instance by letting you know about changes or improvements to our offerings. In addition, if your email address is associated with a Gravatar, we may pull that Gravatar for display on our platform. You can learn more about Gravatar at https://en.gravatar.com/. Your Account Information may be stored on our behalf on third­-party infrastructure provider Amazon Web Services Inc. (AWS).

We may use User Activity Information, Account Information and Other User­ Provided Personal Information to maintain, improve and better understand usage of our Service, on the basis of our legitimate interest in ensuring your data, our other clients’ data, and our systems are secure, in developing our Service to better serve you and other clients, and in managing and developing our business. In some cases, we may also be required to retain this information in order to meet our legal obligations.

We store and process Submitted Data and Submitted Metadata on your behalf, for instance when you run a pipeline on your data. If you consent, we may also access and process your Submitted Data and Submitted Metadata in order to provide support to you, for instance by running a few tests on your data for debugging purposes if your task fails. Your data is processed on servers provided by AWS  and stored on their servers in encrypted form. You can find more information about AWS’ security practices at http://aws.amazon.com/security/.

If you explicitly so choose (see "Controlling Your Data" below), we may share your Submitted Data and some elements of your Account Information with other users to whom you have granted permission to participate in your project. Your name and institutional affiliation may also be shared automatically with users who have granted you project permissions.

Seven Bridges may disclose your data if disclosure of your data to third parties is necessary to respond to a lawful request by public authorities, including to meet national security or law enforcement requirements, or if, at our sole discretion, we believe this is necessary in order to meet any legal requirement or enforceable governmental request or to identify, contact, or bring legal action against someone who may (either intentionally or unintentionally) be causing injury to or interference with our rights or property, users of our Service, or anyone else who could be harmed by such activities.

We will not use your data in ways that go beyond those laid out in this Privacy Policy without your consent.

 

III. COOKIES

Seven Bridges uses cookies for two primary purposes: to ensure platform security and to collect User Activity Information that will allows us to improve the user’s experiences with our platform or website. More specifically, we use cookies to authenticate users of the platform, monitor incidents of Cross-Site Request Forgery (CSRF), enable Google Analytics, enable FullStory and enable Appcues. We will obtain users’ consent for any cookies related to Google Analytics, FullStory or Appcues.

 

IV. TRANSFERS

In addition to the potential transfer of data to the third-party services we mention in the previous sections, we may also transfer any and all information we collect from users to a third party in the event of any corporate reorganization, merger, sale, joint venture, assignment, transfers, or other disposition of all or any portion of Seven Bridges Genomics' business, assets, or stock. All data transfers of EU and UK subjects shall be subject to a Seven Bridges’ Data Protection Addendum (DPA), as noted within our Terms of Use. If a DPA is not currently in place, please find one at Data Protection or contact dpo@sevenbridges.com prior to processing any data on our platform.

ANY transfers of European or UK citizen personal data outside of the European Union or the United Kingdom, including transfers to Seven Bridges affiliates or subsidiaries, will only be transferred if a legal basis for such transfer exists (as is required under Articles 46, 47 and 49 of the General Data Protection Regulation (EU GDPR), and the UK General Data Protection Regulation Act 2018 (UK GDPR 2018) and the Privacy and Electronic Communications Regulations 2019 (together known as the “UK GDPR”), subject to the Model Contractual Clauses of the aforementioned DPA. For example, our team members in Serbia may have access to your data to provide customer support. Such access will be governed by contractual provisions between Seven Bridges Genomics Inc. and its subsidiary in Belgrade that include the E.U. MCCs as incorporated into our DPA. Transfer of personal data of EU or UK persons to countries outside the EU or UK shall be performed only if a DPA is in place and subject to its terms.

V. CONTROLLING YOUR DATA

You can access and edit most elements of your Account Information via the "Account Settings" menu. You can see which billing groups and projects you're associated with via the "Payments" and "Projects" menus respectively.

You can control which users have access to your project, including your Submitted Data and Submitted Metadata, via the "Project Members" section of a project's "Dashboard". Permissions can be tailored to a project participant's needs, with separate permissions for writing data, copying data, executing tasks, and administering a project. (CAUTION: allowing a user to administer a project may allow them to grant themselves further permissions.) You can also access and delete your Submitted Data and Submitted Metadata from the "Files" or "Dashboard" menus of a project. It may take up to a week for all back-up copies of your Submitted Data and Submitted Metadata to be deleted.

To withdraw consent, request access, restrict processing, or lodge a complaint regarding your personal data, please contact us at dpo@sbgenomics.com. Seven Bridges resolves to respond to such requests in accordance with local privacy and data protection laws.

Seven Bridges Genomics Inc. complies with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland transferred to the United States pursuant to Privacy Shield.  Seven Bridges Genomics Inc. has certified that it adheres to the Privacy Shield Principles with respect to such data. If there is any conflict between the policies in this privacy policy and data subject rights under the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/ .

In compliance with the Privacy Shield Principles, Seven Bridges Genomics Inc. commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Privacy Shield. European Union and Swiss individuals with Privacy Shield inquiries or complaints should first contact Seven Bridges Genomics Inc. at:

dpo@sbgenomics.com

You may also contact our subsidiary Seven Bridges Genomics UK Ltd. by mail at:

Oury Clark Solicitors
10 John Street
London WC1N 2EB
United Kingdom

Or our EU Representative at:

INSTANT EU GDPR REPRESENTATIVE LTD

Office 2,

12A Lower Main Street, Lucan Co. Dublin

K78 X5P8

Ireland

Seven Bridges Genomics Inc. has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the BBB National Programs, Inc. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers  for more information and to file a complaint. This service is provided free of charge to you.

If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms.  See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction

 

VI. FURTHER INFORMATION

Links to Third Party Sites

Our Site and Services may contain links to sites and services maintained by third parties. For instance, earlier in this Privacy Policy we link to http://aws.amazon.com/security/, a site maintained by Amazon Web Services. This Privacy Policy does not apply to such third-party sites and services, and Seven Bridges Genomics is not responsible for and makes no representations about their practices. Third-­party sites and services may collect and disclose information about you in various ways, and may have different rules and policies regarding collection, use and disclosure of such information.

Questions, Comments, and Complaints

If you have any questions, comments, or complaints about this Privacy Policy or our use of your personal data, please contact us at dpo@sbgenomics.com.

 

VII. PRIVACY POLICY CHANGES

We may update or otherwise modify this Privacy Policy periodically. We shall notify you of changes to this Privacy Policy by posting it on this page, so please check back periodically. In some cases, we may also notify you via email or other mechanisms.