Statement of Additional Information for California Residents
This Statement of Additional Information for California residents (the “Policy”) is for California residents only and describes the type of information that GoToKnow™ (“GoToKnow™,” “we” or “us”) gathers from users of its genetic test and diagnostic test websites and mobile applications who are residents of California, as well as certain additional privacy rights of California residents.
This Statement is a part of GoToKnow™’s Terms of Service, which controls in the event of any conflicts.
Collection, Use, and Sharing of Personal Information
“Personal Information” means information that can be associated with a particular user. The chart below details the Personal Information that we collect, how and why we collect such Personal Information, and how – if at all – such Personal Information is shared.
|What Personal Information We Collect||How We Collect the Personal Information||Why We Collect the Personal Information|
|Identifying information.||We request certain identifying information as part of verifying the identity of a user.||We use this information to ensure that only authorized users are able to access test results through the websites and/or applications offered by GoToKnow™.|
|Payment information.||We request certain information related to method of payment when a user purchases a test through the Platform.||We require this information in order to process orders and deliver tests when they are ordered.|
|Data collected by cookies and Google Analytics.||Cookies to which a user may agree as part of using the site automatically collect certain analytics data.||We use this information in order to improve the Site and the Platform.|
Users’ Rights Regarding Personal Information
Users of the Platform have the right to request information about our collection, use, and disclosure of their information (a “Request to Know”), including:
- the categories and specific pieces of Personal Information we have collected about the user;
- the categories of sources from which we have collected the user’s Personal Information;
- the business or commercial purpose for collecting or selling the user’s Personal Information;
- the categories of Personal Information we have sold about the user; and
- the categories of Third Parties with whom we have shared, disclosed for a business purpose, or sold the user’s Personal Information, and which categories of Personal Information we have sold to which categories of Third Part
Users of the Platform also have the right to request that we delete their Personal Information (a “Request to Delete”).
Requests to Know
Users may submit a Request to Know by completing the form provided here or by emailing us at firstname.lastname@example.org.
Users may submit two types of Requests to Know: (1) A request for the specific pieces of Personal Information that we have collected about you in the past twelve months; or (2) A request for the categories of Personal Information that we have collected about you in the past twelve months, and how we have used and disclosed that Personal Information.
When you submit a Request to Know, we may ask you to provide certain pieces of information in order to verify your identity, such as your name, email address, and phone number. If you submit a Request to Know for the specific pieces of information that we have collected about you, we may also require you to submit a signed declaration under the penalty of perjury stating that you are the consumer whose Personal Information is the subject of the Request to Know.
If we are able to verify your identity, we will respond to your Request to Know by: (a) providing the requested information; or (b) explaining why we are not required to provide the requested information. If we are unable to verify your identity, we will respond by explaining why we cannot verify your identity. We will confirm receipt of your Request to Know within 10 days and will respond to your Request to Know within 45 days. If a response requires additional time, we will notify you of the basis for the delay and may extend our response period up to an additional 45 days.
If we provide the information requested, we will provide the information free of charge and in a readily useable portable format. We have no obligation to provide Personal Information to you more than twice in a 12-month period. If a Request to Know or series of Requests to Know are manifestly unfounded or excessive, we may charge a reasonable fee for processing the Request(s) to Know, or may refuse to process the Request(s) to Know.
Requests to Delete
Users may submit a Request to Delete by completing the form provided here or by emailing us at email@example.com. When you submit a Request to Delete, we may ask you to provide certain pieces of information in order to verify your identity, such as your name, email address, and phone number. If we are able to verify your identity, we will respond to your Request to Delete by (a) deleting your Personal Information and, if applicable, directing any of our Service Providers to delete your Personal Information; or (b) explaining why we are not required to delete your Personal Information. We may choose to delete Personal Information by de-identifying, aggregating, or completely erasing the Personal Information. We will specify the manner in which we delete your Personal Information.
If a Request to Delete or series of Requests to Delete are manifestly unfounded or excessive, we may charge a reasonable fee for processing the Request(s) to Delete, or may refuse to process the Request(s) to Delete.
Protection and Retention of Personal Information
We follow generally accepted industry standards, including the use of appropriate administrative, physical and technical safeguards, to protect Personal Information. The appropriate administrative, physical, and technical safeguards employed by us may vary depending on the nature of Personal Information collected, with more stringent measures applied to information of a sensitive nature.
However, no method of transmission over the Internet, or method of electronic storage, is entirely secure. Therefore, while we strive to use commercially reasonable means to protect Personal Information, we cannot guarantee its absolute security or confidentiality. Please be aware that certain Personal Information and other information provided by you in connection with your use of the Site may be stored on your device (even if that information is not collected by us). You are solely responsible for maintaining the security of your device from unauthorized access.
Personal Information will be retained for as long as is reasonably necessary to achieve the purposes set forth in this Policy, and to comply with all applicable laws.
If you have questions about this Policy, please contact firstname.lastname@example.org.
Last Updated: March 29, 2022