Privacy Policy

Privacy Policy

This page outlines the principles and practices GenXys follows in protecting users’ information. Please read this Privacy Policy carefully before using our Services.

At GenXys Health Care Systems Inc., we are committed to providing exceptional service. Our services involve the collection and use of personal information and protecting users’ personal information is one of our highest priorities.

We will inform our users of why and how we collect, use and disclose their personal information, obtain their consent where required, and only handle their personal information in a manner that a reasonable person would consider appropriate in the circumstances.

This Privacy Policy, in compliance with the Personal information Protection Act (PIPA), outlines the principles and practices GenXys Health Care Systems Inc. will follow in protecting users’ information. Our privacy commitment includes ensuring the accuracy, confidentiality, and security of our users’ information and allowing our users to request access to, and correction of, their information.

1. Definitions

  • “Aggregated Pharmacogenetic Information and Bio-Physical Information” means Pharmacogenetic Information and Bio-Physical Information that has been stripped of individual name and contact information and aggregated with information from other users sufficient to minimize the possibility of exposing individual-level information while still providing evidence for scientific research.
  • “Consent Form” means the document by which GenXys obtains consent from individuals to participate in GenXys Research. The Consent Form describes how GenXys will use and protect individual’s data, the benefits and risks of participation in GenXys Research and how to withdraw from participation in GenXys Research.
  • “GenXys Research” means scientific research conducted by GenXys with the intent to publish peer-reviewed scientific papers. GenXys Research only uses Pharmacogenetic Information and Bio-Physical Information from users who have given consent by way of a Consent Form. GenXys Research activities do not include internal GenXys R&D.
  • “Personal Information” means information that is about an individual. GenXys collects and stores the following types of Personal Information:
    • “Bio-physical Information” – information about an individual, including, age, sex at birth, weight, disease conditions, medications, other health-related information, ethnicity and other information.
    • “Ordering Information” means the information an individual supplies to GenXys when purchasing Services (e.g., name, email, and address).
    • “Pharmacogenetic Information” means means genetic information that affects a person’s response to drugs.
  • “R&D” means research and development activities performed by GenXys on user samples and data. These activities may include but are not limited to performing quality control activities, improving the Services and/or offering new products or services and conducting data analysis that may lead to and/or include commercialization with a third party.
  • “Services” means GenXys’ products, software, services, social networking sites, and website, regardless if the use is in connection with an account or not, and “Service” means any one of the foregoing described in this paragraph.
  • “TreatGx” means GenXys’ proprietary medication decision support system that uses Bio-physical Information and/or Pharmacogenetic Information to generate Treatment Options.
  • “Treatment Options” means the medication options generated by TreatGx based on an individual’s Bio-physical Information and Pharmacogenetic Information.
  • “User” means users of the Services.
  • “User Content” means all information, data, text, software, audio, photographs, graphics, video, messages or other materials, other than Pharmacogenetic Information and Bio-Physical Information, generated by users of the Services and transmitted, whether publicly or privately, to or through GenXys.
  • “Business Contact Information” – means information that would enable an individual to be contacted at a place of business and includes name, position name or title, business telephone number, business address, business email or business fax number. Business Contact Information is not covered by this policy.
  • “Privacy Officer” – means the individual designated for ensuring that GenXys Health Care Systems Inc. complies with this policy.

2. Policy 1 – Collecting Personal Information

1.1 We collect information (i) provided to us directly, (ii) entered into TreatGx, (iii) collected from our pharmacogenetic testing services, and (iv) collected through tracking technology (e.g. from cookies and similar technologies).

1.2 Unless the purposes for collecting personal information are obvious and the user voluntarily provides his or her personal information for those purposes, we will communicate the purposes for which personal information is being collected, either orally or in writing, before or at the time of collection.

1.3 We will only collect user information that is necessary to fulfill the purposes stated in Policy 3 – Using and Disclosing personal information.

1.4 We are always working to enhance our Services with new products, applications and features that may result in the collection of new and different types of information. We will update our privacy statement, as needed.

3. Policy 2 – Consent

2.1 We will obtain user consent to collect, use or disclose personal information (except where, as noted below, we are authorized to do so without consent). If you are using the Services on behalf of someone else, you take full responsibility to ensure that the information is lawfully collected with the informed consent of your dependent.

2.2 Consent can be provided orally, in writing, electronically, through an authorized representative or it can be implied where the purpose for collecting using or disclosing the personal information would be considered obvious and the user voluntarily provides personal information for that purpose.

2.3 Consent may also be implied where a user is given notice and a reasonable opportunity to opt-out of his or her personal information being used for mail-outs, updates or the marketing of new services or products and the user does not opt-out.

2.4 If you invite a Healthcare Professional to see your account, you are agreeing to share the personal information within your TreatGx account with them. We will inform this Healthcare Professional that you have made this request. By choosing to share your TreatGx account, you confirm that the person has given consent for GenXys to communicate with him or her via email. The Healthcare Professional may contact us at info@GenXys.com to request that we remove their information from our database or unsubscribe at any time.

2.5 Users can withhold or withdraw their consent for GenXys Health Care Systems Inc. to use their personal information for communications about updates, surveys, promotions, products and services that may be of interest by contacting us at info@GenXys.com.

2.6 We may collect, use or disclose personal information without the user’s knowledge or consent in the following limited circumstances:

  • When the collection, use or disclosure of personal information is permitted or required by law;
  • In an emergency that threatens an individual’s life, health, or personal security;
  • When the personal information is available from a public source;
  • When we require legal advice from a lawyer;
  • For the purposes of collecting a debt;
  • To protect ourselves from fraud;
  • To investigate an anticipated breach of an agreement or a contravention of law.

A full listing of such circumstances can be found in the Personal Information Protection Act (PIPA).

4. Policy 3 – Using and Disclosing Personal Information

3.1 We will only use users personal information to fulfill the purposes identified at the time of collection or for the following purposes:

  • Verify identity;
  • Collect and process payments;
  • Open and manage an account;
  • Deliver requested products and services;
  • Provide personalized medication options;
  • Ensure a high standard of service to our users;
  • Meet regulatory requirements;
  • Conduct analytics in order to enhance the provision of our services;
  • Contact our users directly about updates, surveys, promotions, products and services that may be of interest;
  • Perform R&D activities, which may include conducting data analysis and research in order to develop new or improve existing products and services, or quality control activities.

We will only disclose to trusted third parties information that has been stripped of an individual name and contact information and aggregated with information from other users sufficient to minimize the possibility of exposing individual-level information. This information will be disclosed to conduct analytics in order to enhance the provision of our services or for R&D.

3.2 We will not use or disclose user personal information for any additional purpose unless we obtain consent to do so.

3.3 We will not sell user lists or personal information to other parties unless we have consent to do so.

5. Policy 4 – Retaining Personal Information

4.1 We will retain user personal information only as long as necessary to fulfill the identified purposes or a legal or business purpose. If you no longer wish to use our Services, you should close your GenXys account(s) by sending a request to info@genxys.com. GenXys, its contractors, successors, assignees and collaborating partners will retain your Pharmacogenetic Information, date of birth, and sex as required for compliance with applicable legal obligations, including the Clinical Laboratory Improvement Amendments (CLIA) and CAP accreditation requirements. GenXys will also retain limited information related to your account and data deletion request, including but not limited to, your email address, account deletion request identifier, and record of legal agreements for a limited period of time as required by contractual obligations, and/or as necessary for the establishment, exercise or defense of legal claims and for audit and compliance purposes.

6. Policy 5 – Ensuring Accuracy of Personal Information

5.1 Users can change and update all personal information within their account, the only data that cannot be changed is “Pharmacogenetic Information”.

5.2 If personal information is inaccurate or incomplete, a user can enter their account and correct the information.

7. Policy 6 – Securing Personal Information

6.1 We are committed to ensuring the security of user personal information in order to protect it from unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks.

6.2 The following security measures will be followed to ensure that user personal information is appropriately protected:

  • Physically securing offices where personal information is held;
  • The use of user ids, passwords, encryption, firewalls;
  • Restricting employee access to personal information as appropriate (i.e., only those that need to know will have access);
  • Contractually requiring any service providers to provide comparable security measures.

6.3 We will use appropriate security measures when destroying user’s personal information such as deleting electronically stored information.

6.4 We will continually review and update our security policies and controls as technology changes to ensure personal information security.

8. Policy 7 – Providing Users Access to Personal Information

7.1 Users have a right to access their personal information, subject to limited exceptions such as:

  • Disclosure would reveal personal information about another individual;
  • Health and safety concerns.

A full listing of the exceptions to access can be found in the Personal information Protection Act (PIPA).

7.2 Upon request, we will tell users how we use their personal information and to whom it has been disclosed if applicable.

7.3 We will make the requested information available within 30 business days, or provide written notice of an extension where additional time is required to fulfill the request.

7.6 If a request is refused in full or in part, we will notify the user in writing, providing the reasons for refusal and the resource available to the user.

9. Policy 8 – Questions and Complaints

8.1 The Privacy Officer is responsible for ensuring GenXys Health Care Systems Inc.’s compliance with this policy and the Personal information Protection Act (PIPA).

8.2 Users should direct any complaints, concerns or questions regarding GenXys Health Care Systems Inc.’s compliance by contacting us at info@GenXys.com. 

10. Contact information

info@GenXys.com