Privacy Notice

Nonacus website Privacy Notice: Effective as of 28 May 2025

Our use of your Personal Data

This privacy notice explains how Advanced Genomics Limited and other businesses in its group of companies (such as its subsidiaries and affiliates) use your Personal Data. It also tells you about how the law protects you and your rights. We value your privacy and confidentiality and we are committed to treating your Personal Data with care, integrity and transparency.

In this notice “Personal Data” means information relating to an identified or identifiable living person (called a ‘data subject’) and which can be used to identify that person. This provides for a wide range of information as further described in section 4 below.

It includes, for example, details you give us about yourself when you apply for or one or more of our products and services, together with your marketing options and other correspondence or contact you have with us. However, it does not include anonymised data where the identity of the living person has been removed.

Who this privacy notice applies to

This privacy notice applies to you if you become a customer of one of the companies in the Advanced Genomics Limited group or if you have provided your Personal Data to a business within the Group (for example if you have enquired about a product or service, applied for a job, signed up to a newsletter or made a complaint to us).

The Advanced Genomic Limited group of companies offers a range of different products and services and the way in which your Personal Data is used may vary depending on which one(s) you have or the reason for your contact with us. As a result, some sections of this notice may not always apply to you.

This privacy notice applies to both our personal and business customer relationships. If you are a business customer, the following definitions apply:

  • You/your means General Staff and Key Staff of the business.
  • General Staff means individuals (other than Key Staff) who have provided us with their Personal Data in connection with products and services provided to the business by us.
  • Key Staff means individuals who have some degree of control over the actions of the business including sole traders, partners, directors, company secretaries, member or beneficial owners or trustees.
  • The business means the business you are associated with and which is our customer, whether it is a company, limited liability partnership, partnership, sole trader, charity, trust or other entity.

Who we are

Usually when we mention "we", "us" or "our" in this privacy notice, we are referring to Nonacus Limited, a company incorporated in England with the registration number 9590278, whose registered office is at Unit 5, quinton business park, 11 Ridgeway, Quinton, Birmingham, B32 1AF.

However, if we are supplying clinical or research services to you, or if you are visiting our websites to collect information about them, when we mention "we", "us" or "our" we are referring to Informed Genomics Ltd, trading as Nonacus Clinical Services, a company incorporated in England with the registration number 13082290, whose registered office is at Unit 5, quinton business park, 11 Ridgeway, Quinton, Birmingham, B32 1AF.

When you take out a product or service with us we'll let you know which company you have a relationship with and so who is responsible for processing and safeguarding your Personal Data.

Nonacus Limited and Nonacus Clinical Services are subsidiaries of Advanced Genomics Limited. There may be other companies within Advanced Genomics Limited group from time to time. You can find out more about our group companies and what we do at About Us.

We place quality at the heart of everything we do. The patient is our priority, and we strive to provide the right testing that has meaningful impact on an individual’s healthcare experience and outcomes. We are focused on providing innovative testing solutions that can empower patients to make informed healthcare choices.

Where we process Personal Data under a contract for the provision of services to a business it is most likely that we will be processing the Personal Data of your Key Staff and General Staff (“Customer Personal Data”) as an independent Controller and the Personal Data of your patients (“Customer Patient Data”) as a Processor on behalf of you (the Controller).

If you are an individual who has come to us directly on your own behalf, we will be processing your Personal Data as an independent Controller.

Regardless of our status as Controller or Processor, we take our obligations under applicable Data Protection Laws and Local Privacy Laws (both as defined below in the Glossary) very seriously.

This document has been written in order to comply with EU and UK GDPR. On the basis that we are established in the United Kingdom, we fall under the jurisdiction of the Information Commissioner’s Office in the UK. The registration number of Nonacus Limited is ZB528691 and the registration number of Informed Genomics Limited (which trades as Nonacus Clinical Services) is ZB528277.

We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about it, including any requests to exercise your legal rights (see section 10), please contact the DPO, using the details set out below.

Our Data Protection Officer can be contacted as follows:

Email: dpo@nonacus.com

Post: Quinton Business Park, unit 5, 11 Ridgeway, Quinton, Birmingham, B32 1AF, England.

If you are a customer outside the EU and UK, please have regard to references to Local Privacy Laws below.

Our commitment to you

We will not publish your Personal Data or share/distribute your Personal Data to any third parties unless we have your prior agreement, or to do so is compliant with applicable Data Protection Laws. We use technical and organisational measures which help us to safeguard your Personal Data and ensure that access to your Personal Data is limited to our officers, employees or affiliates of Advanced Genomics Limited who are directly involved in the provision of our services. Where we use other companies in the support of our services (Processors/Sub-Processors), we ensure that their officers, employees and affiliates are bound by a contractual duty of confidentiality.

We may not accept (or process) Personal Data of patients (Customer Patient Data) under the age of 18.

Interpretation

The words of which the initial letter is capitalised have meanings as defined in our Glossary (see end of this document). All definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Glossary

Controller(s) are the individuals or organisations who determine the purposes for which, and the manner in which, any Personal Data is processed.

Customer Personal Data means, for our business customers, such Personal Data which relates to our Customers’ Key Staff and General Staff, including their name, job title, telephone number and email address. In most cases, we will process Customer Personal Data as an independent Controller. If you are an individual who has come to us directly on your own behalf, Customer Personal Data means your Personal Data and we will be processing it as an independent Controller

Customer Patient Data means Special Category Data (in the form of Data Concerning Health and/or Genetic Data) which we process (a) as a Processor on behalf of our customers (Controllers) for the purposes of providing our products or services, OR (b) if you are an individual who has come to us directly on your own behalf, this means Special Category Data relating to you.

Data Concerning Health is defined in EU/UK GDPR as personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.

Data Protection Laws means the EU General Data Protection Regulation (2016/679) (“EU GDPR"), EU GDPR as transposed into English Law by virtue of section 3 of the European Union Withdrawal Act (“UK GDPR”), the Data Protection Act 2018 and the Privacy & Electronic Communications Regulation (PECR) 2003, and any applicable Local Privacy Laws, all as amended from time to time.

Direct Identifiers: is only relevant in the context of our GALEAS Software Services and means, by way of example, name, date of birth, or any other information, such that Nonacus would be able to identify the patient without recourse to other, externally available information.

GALEAS Software: means the combination of various software designed to enable the rapid Analysis and interpretation of sequencing data at scale, being composed of (downloadable) software for the uploading of Customer Patient Data, as well as Cloud hosted bioinformatic workflows for the interpretation and Analysis of Customer Patient Data.

GALEAS Software Services: means those services as fully described in our GALEAS Terms of Use, available on our website.

Genetic Data means Personal Data related relating to the inherited or acquired genetic characteristics of a natural person which can give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question. EU/UK GDPR classifies Genetic Data as Special Category Data.

Local Privacy Laws means the national or federal laws that apply to a specific geographical area which govern how personal information (including ‘Customer Personal Data’ and ‘Customer Patient Data’) is to be protected and may be shared with a service provider such as Nonacus Clinical Services.

Personal Data means information relating a natural living person (called a ‘data subject’) which can be used to identify such person. This provides for a wide range of information as set out in section 5 of this Privacy Notice. It does not include anonymised data where the identity of the living person has been removed.

Processor(s) means the individuals or organisations who process Personal Data based on the instructions of the Controller(s).

Sub-Processor(s) means a company which acts on behalf of the instructions of a Processor.

Special Category Data is a type of Personal Data which is legally deemed to be extra sensitive in nature such as information about ethnicity, race, health or genetic information. The processing of ‘Special Category’ data is only permitted where one of the conditions 9 of (EU/UK) GDPR is present.

Standard Terms of Business means our contractual terms for the provision of services as published on our website https://nonacus.com/terms-and-conditions/