Privacy Policy

This privacy policy is for this website www.nonacus.com and served by Nonacus Ltd and governs the privacy of its users who choose to use it

Nonacus website Privacy Notice: effective as of 15/03/2023

 

Who we are

“Data controllers” are the people or organisations that determine the purposes for which, and the manner in which, any Personal Data is processed, and make independent decisions in relation to the Personal Data and/or who/which otherwise control that Personal Data.

For the purposes of the UK and EU GDPR (the ‘’GDPR’’), Nonacus is the data controller with regard to the Personal Data described in this Privacy Policy.  Nonacus’ mission is to offer high quality, non-invasive, genetic testing with the end-user at the forefront.

Nonacus has outsourced the function of the Data Protection Officer to XpertDPO Ltd.

Our Data Protection Officer can be contacted as follows:
Telephone: 353 1 678 8997
Email: dpo@nonacus.com
Post: 20 Harcourt St, Saint Kevin's, Dublin, D02 H364, Ireland

 

Purpose and Scope of this Policy

The purpose of this Privacy Policy is to provide you, as our data subject, with a statement regarding the Data Protection and Privacy practices and obligations of Nonacus and an explanation of your rights as a data subject.

This Data Protection and Privacy Policy and Notice applies to our business practices, and our website, which is accessible from https://nonacus.com/our-team/.

As the Organisation is established in the United Kingdom, this document is written in the vein of UK and EU Data Protection Law, and Nonacus falls under the jurisdiction of the Information Commissioner’s Office UK. This Privacy Policy sets out what Personal Data we collect and process about you in connection with the services and functions of the Organisation. We are not responsible for the content or the privacy notices for any websites to which we may provide external links.
Relevant Laws that apply to us:
• General Data Protection Regulation (EU Regulation 679/2016)
• Regulations flowing from Data Protection Act 2018
• Privacy & Electronic Communications Regulation (PECR) 2003

 

Why and how do we ensure compliance?

Data protection and privacy laws provide rights to individuals with regard to the use of their Personal Data by organisations, including our organisation. UK and EU laws on data protection govern all activities we engage in with regard to our collection, storage, handling, disclosure and other uses of Personal Data.

We must comply with data protection and privacy laws because the law requires us to, but we also would like you to have confidence in dealing with us, and compliance with data protection law helps us to maintain a positive reputation in relation to how we handle Personal Data.

We are required to demonstrate accountability for our data protection obligations. This means that we must be able to show how we comply with the applicable data protection and privacy laws, and that we have in fact complied with the laws.

We do this, among other ways, by our written policies and procedures, by building data protection and privacy compliance into our systems and business rules, by internally monitoring our data protection and privacy compliance and keeping it under review, and by acting if our representatives, including employees or contractors, fail to follow the rules.

 

Who must comply?

All our representatives, which include employees and contractors, are required to comply with our Data Protection Policies and Procedures which inform this Privacy Policy when they process Personal Data on our behalf.

What are the data protection principles and rules?
We aim to comply with the following principles found in Data Protection Law:
• Lawfulness, fairness and transparency – Personal data must be processed lawfully, fairly and in a transparent manner.
• Purpose Limitation – Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
• Data minimisation – Personal Data must be adequate, relevant and limited to what is necessary in relation to purposes for which they are processed.
• Accuracy – Personal data must be accurate and, where necessary, kept up to date. Inaccurate Personal Data should be corrected or deleted.
• Retention – Personal data should be kept in an identifiable format for no longer than is necessary.
• Integrity and confidentiality – Personal data should be kept secure.
• Accountability – Under the GDPR, we must not only comply with the above six general principles, but we must be able to demonstrate that we comply by documenting and keeping records of all decisions.

 

What is personal data?

Personal data is any data that identifies you, or could be used to identify you, which is submitted and/or collected by Nonacus. It does not include anonymised data where your identity has been removed. Any personal data that you share with us is treated with the highest standards of security and confidentiality, strictly in accordance with the Data Protection Act 2018 and the UK and EU General Data Protection Regulation (GDPR).

 

What personal data do we process?

Type of Data (what information is it) Purpose (why we're doing it) Legal Basis (why we can do it)
Identity Data: Name, Title, Email Address, Phone Number To contact and communicate with you, to provide information around our services Contract
Commercial/business and/or professional data (e.g., company/university name, address, and email address) To contact and communicate with you, to provide information around our services Contract
Employment Data, including Clinician / General Practitioner details (e.g., organisation name, job title, and contact details) To contact and communicate with you, to provide information around our services Contract
Education Data (e.g., educational institution) To contact and communicate with you, to provide information around our services Contract
Account Login Details (e.g., email address and password) To allow individuals to log on to the Nonacus Portal for results and other communications Contract
Mixed Social Media data (e.g., Facebook name, profile ID, Instagram handle, comments made on posts, messages sent via social media, activity on our pages via insight tools) To communicate with customers and individuals on social media, to provide help and assistance, record details and respond to customers and followers, and for general social media communications Legitimate interests
Social Media Plug-Ins, Sharing Links, and Analytics (Pixel ID, Meta Cookies, Button Click Data To analyse website visitor activity from social platforms Legitimate interests
Name, Phone Number, Email Address To receive feedback and/or complaints Legitimate interests
Payment Information (e.g., Name, credit card details) To receive and process payments Contract
Technical data such as operating system (OS), internet protocol (IP) address, browser type/version, time zone and location, browser plug-in types and versions. Usage data (e.g., how you use our website via Cookies, Log Files and other similar technologies) To analyse how visitors are using our website and how effective it is, to show customers ads that are relevant to them, and to understand how successful our marketing and advertising is including on other third-party websites Legitimate interests
Data Protection Requests Name, Email Address, Phone, Address, Mixed Data -other data that we may hold on you To comply with data protection laws and assist individuals with requests around their rights. To respond to any GDPR Requests (e.g., Data Subject Rights Requests) Legal obligation
Cookies In order to improve customer experience and use of our website, to analyse how our website is being used and for marketing purposes Consent
Special Category Data (Sensitive Data)
Type of Data (what information is it) Purpose (why we're doing it) Legal Basis (why we can do it)
Genetic data from samples e.g., blood, plasma, saliva, FFPE curls, FF tissue, and cell-free foetal DNA samples To allow individuals to test for diseases, and to share results with labs and clinicians Consent
Reasoning for sequencing of genetic data To record the sequencing information and provide results for patients and for clinician to make informed decision, and to support further and future analysis of data types for research and for service integrity, development, and improvement Consent
Data related to any samples and sample analysis when requested To record the sequencing information and provide results for patients and for clinician to make informed decision, and to support further and future analysis of data types for research and service development and improvement Consent
Data regarding conditions, diet, health, family history including hereditary diseases, and virus detection, smoking status To assess risk of disease in samples when requested Consent
Data concerning a natural person’s sex life or sexual orientation (e.g., gender, pregnancy status) To assess risk of disease in samples when requested Consent
Personal data revealing racial or ethnic origin (e.g., your nationality) To assess risk of disease in samples when requested Consent

Criminal convictions/ Offence Data

Nonacus does not collect data around criminal convictions and offences.

 

Aggregated Data

As with most websites, we gather statistical data and other analytical information (for example, demographic information, usage data etc.) collected on an aggregated basis of all visitors to our website. This data is not considered personal data in law as it does not directly or indirectly reveal your identity. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Policy.

 

Legal Bases for using your data

We use your personal data for the purposes outlined above. In doing so we rely on a number of separate and overlapping legal bases to lawfully process your personal data. These may include:

• Where necessary to perform our contract with you
• Where you have consented to the processing
• Where necessary for statutory obligations
• Where necessary for us to comply with a legal obligation, or to establish, exercise or defend legal claims

 

Social Media Platforms

Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are subject to the terms and conditions as well as the privacy policies held with each social media platform respectively.

Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution in regard to their own privacy and personal details. This website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.

This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.

How long do we keep your data

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

We have a Retention Policy and Retention Schedule in place, and we ensure data is destroyed confidentially when it is required to do so.

In some circumstances you can ask us to delete your data: see below for further information. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

In some cases, by law, we have to keep basic information about our customers (including Contact, Identity, and Transaction Data) for six years after they cease being customers for tax purposes.

If you have any queries about our retention periods you can contact us on dpo@nonacus.com.

 

Third Parties and Disclosures of your Personal Data

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

When you consent to providing us with your personal data, we will also ask you for your consent to share your personal data with the third parties set out below.

Nonacus has contracts in place and carry out due diligence in regards to our suppliers and relevant third parties.

 

Third Parties we may disclose your data to:

Laboratories
Informed Genomics uses approved Laboratories based in the EU as well as Non-EU Countries dependent on client location.

• Service providers acting as processors based in the UK, Ireland and Europe who provide development, IT, and system administration services.
• Technical providers who are other entities that interact with us in connection with the services we provide.
• Professional advisers acting as processors, controllers or joint controllers including lawyers, bankers, auditors and insurers based in the UK and EU who provide consultancy, banking, legal, insurance and accounting services.
• Regulators and other authorities as processors, controllers or joint controllers based in the UK and EU who require reporting of processing activities in certain circumstances.

International Transfers
Nonacus’ data is hosted in the European Union and United Kingdom on secure servers. Should Informed Genomics engage a data processor or controller outside of the EU or UK (subject to adequacy findings) standard contractual clauses will be put in place, and a transfer impact assessment will be carried out.

Security features

If Nonacus have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.

Nonacus utilises encryption, access controls and other features to ensure the security of your data.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.

Nonacus limit access to your personal data to those employees, contractors and other third parties on a need-to-know basis and under contract. We will only process your personal data for the purposes for which it was collected, and third parties are only permitted to process your data on our instructions.

 

Information on Consent

By consenting where this is the appropriate and lawful basis for processing, to our processing your Personal Data in line with this Data Protection and Privacy Policy and Notice you are giving us permission to process your Personal Data specifically for the purposes identified.

You may withdraw consent at any time by providing an unambiguous indication of your wishes by which you, by a statement or by a clear affirmative action, signify withdrawal of consent to the processing of Personal Data relating to you. If you have any queries relating to withdrawing your consent, please contact our Data Protection Officer using the contact details set out below.

Withdrawal of consent shall be without effect to the lawfulness of processing based on consent before its withdrawal.

 

Email Newsletters

Nonacus send a newsletter out to our subscribers. You can opt-out of receiving our email newsletter and/ or marketing at any time through an automated system. This process is detailed at the footer of each email campaign. If an automated un-subscription system is unavailable clear instructions on how to un-subscribe will by detailed instead.

 

Your Rights
Under certain circumstances, and dependent on legal basis under which your personal data is processed, by law you have the right to:

• Request information about whether we hold Personal Data about you, and, if so, what that Personal Data is and why we are holding/using it.
• Request access to your Personal Data (commonly known as a “Data Subject access request”). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
• Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
• Request erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Data where you have exercised your right to object to processing (see below).                                                                                • Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your Personal Data for direct marketing purposes.
• Object to automated decision-making including profiling, that is not to be subject of any automated decision-making by us using your Personal Data or profiling of you.
• Request the restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of Personal Data about you, for example if you want us to establish its accuracy or the reason for processing it.
• Request transfer of your Personal Data in an electronic and structured form to you or to another party (commonly known as a right to “data portability”). This enables you to take your data from us in an electronically useable format and to be able to transfer your data to another party in an electronically useable format.

 

How do you exercise your rights?

We have appointed a Data Protection Officer to monitor compliance with our data protection obligations and with this policy and our related policies. If you have any questions about this policy or about our data protection compliance, please contact the Data Protection Officer.

If you wish to exercise your rights please contact our Data Protection Officer who will respond to the request within one calendar month.

Our Data Protection Officer can be contacted as follows:
XpertDPO
Telephone: 353 1 678 8997
Email: dpo@xpertdpo.com
Post: 20 Harcourt St, Saint Kevin's, Dublin, D02 H364, Ireland

 

Your Right to Lodge a Complaint
You as the Data Subject have the right to complain at any time to a supervisory authority in relation to any issues related to our processing of your Personal Data. We would like to hear from you first if you have a complaint about how we use your data so that we may rectify the issue.

As our organisation is located in the United Kingdom, and since we conduct our data processing here, we are regulated for data protection purposes by the Information Commissioner’s Office.

You can contact the Information Commissioner’s Office:
Website: http://www.ico.org.uk/
Phone: (+44) 0303 123 1113
Address: Head Office - Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK

 

Updates

Our practices as described in this Privacy Policy may be changed,  but any changes will be posted, and changes will only apply to activities and information on a going forward, not retroactive basis.

Your are encouraged to review this Privacy Policy periodically to make sure that you understand how any personal information you provide will be used.

We may also email you in certain circumstances to let you know if and when we update this Privacy Policy to ensure you are informed.

Any changes to this Privacy Policy will be posted on this website so you are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If at any time we decide to use Personal Data in a manner significantly different from that stated in this Privacy Policy, or otherwise disclosed to you at the time it was collected, we will notify you by email, and you will have a choice as to whether or not we use your Personal Data in the new manner.

Resources