Privacy Policy
GenAIz (“GenAIz”, “we”, “us”, or “our”) is committed to protecting the privacy, confidentiality, and security of personal and sensitive data processed through our websites, applications, products and services. This Privacy Policy describes how we collect, use, disclose, process, and protect personal information in connection with our platforms, products, and services.
GenAIz may provide additional or supplemental privacy policies to individuals for specific products or services that we offer at the time we collect personal information. These supplemental privacy policies will govern how we may process the information in the context of the specific product or service.
This Privacy Policy applies globally, including users located in Canada, the United States, the European Economic Area (EEA), the United Kingdom, and other jurisdictions.
Role
Depending on context:
– GenAIz acts as a data processor/service provider when processing data on behalf of life sciences and others clients.
– GenAIz acts as a data controller for personal information collected directly from website visitors, users, and business contacts.
Personal Information We Collect
Where we collect data directly from you, a person who interacts with us, you have various rights regarding the way we use your data. These rights vary depending on where you are located. For example, you may be able to request us to correct, amend, or delete your data if you are based in a state such as California that has enacted privacy laws.
| Data Collected | Example data |
| Identity data | First name, last name, username, unique device identifier, National Provider Identifier (driving license, passport etc) |
| Contact data | Email address, organization name, organization address, telephone number |
| Customer data | Deployments are configured to send Customer Data to GenAIz for processing using the Services, for an artificial intelligence algorithm to detect suspected conditions. Customers or individuals granted access to a Deployment by a Customer (“Authorized Users”) routinely submit Customer Data to GenAIz when using the Services. Customer Data includes “Protected Health Information” as defined in the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Protected Health Information is governed by the HIPAA Business Associate Agreement between the Customer and GenAIz and not by this Privacy Policy. |
| Deployment and account information | To create or update an Authorized User account, you or your customer (e.g., your employer) supply GenAIz with an email address, phone number, password, role or title, and other similar account details. In addition, Customers provide GenAIz (or its payment processors) with billing details such as banking information and a billing address. |
| Profile data | We record your preferences and profile on our systems to enhance your experience. |
| Services metadata | When an Authorized User interacts with the Services, metadata is generated that provides additional context about the way Authorized Users work. For example, GenAIz records and logs when an Authorized User accesses the Services or uses certain functionality. We may use and share Services metadata data to improve our services, develop new products and services, and conduct research. |
| Log data | As with most technology services delivered over the Internet, our servers automatically collect information when you access or use our Services and record it in log files. This log data may include the Internet Protocol (IP) address, the address of the web page visited before using the Services, browser type and settings, the date and time the Services were used, information about configuration and plugins, language preference data. |
| Device information | GenAIz collects information about devices accessing the Services, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and crash data. Whether we collect some or all of this Other Information often depends on the type of device used and its settings. |
| Location information | We may receive information from you, your customer and other third parties that helps us approximate your location. We may, for example, use a business address submitted by your employer, or an IP address received from your browser or device to determine approximate location. GenAIz may also collect location information from devices in accordance with the consent process provided by your device. |
| Usage data | When you use the Services, we monitor and record your interactions. This recorded information, referred to as Usage Data, will be de-identified of any Protected Health Information (PHI) in accordance with HIPAA standards before being used for the purposes described below. Usage Data will not contain PHI, but it may contain personally identifiable information (PII) of Authorized Users, such as National Provider Identifiers (NPIs), related to their professional activities. Examples of Usage Data include the studies or alerts accessed, clicked, viewed, or shared by an Authorized User, average response times to alerts, and other Authorized User activity within the Services. We may use your interactions and messaging data, once de-identified of PHI, to generate Usage Data, including building a profile about you and your professional use of the Services, and about healthcare topics, themes, and trends. We use this Usage Data to improve our services, develop new products and services, conduct research, and provide this data to your Customer to help understand how the Services are used. We may also share and sell this Usage Data to interested third parties to help them improve their science or medical programs. If you are a resident of California or any other state with a privacy law that mandates a right to opt-out of the sale of personal information, you have the right to opt-out of the sale of your personal information by sending a request to privacy@genaiz.com. |
| Third party services | GenAIz may make third party services available to Customer through its Services. Customer can choose to permit or restrict such Third Party Services for their Deployment. Typically, Third Party Services are software that integrate with our Services, and Customer can permit its Authorized Users to enable and disable these integrations for their Deployment. Once enabled, the provider of a Third-Party Service may share certain information with GenAIz. For example, if a cloud storage application is enabled to permit files to be imported to a Deployment, we may receive username and email address of Authorized Users, along with additional information that the application has elected to make available to GenAIz to facilitate the integration. Authorized Users should check the privacy settings and notices in these Third-Party Services to understand what data may be disclosed to GenAIz. When a Third-Party Service is enabled, GenAIz is authorized to connect and access Other Information made available to GenAIz in accordance with our agreement with the Third-Party Provider. We do not, however, receive or store passwords for any of these Third-Party Services when connecting them to the Services. |
| Social media platforms | We may maintain pages for our Company on social media platforms, such as LinkedIn, Facebook, Twitter, Google, YouTube, Instagram, and other third-party platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use and processing of your personal information. You or the platforms may provide us with information through the platform, and we will treat such information in accordance with this Privacy Policy. |
| Aggregated data | This includes statistical information that is not particular to you or any other person but rather represents information such as the total use of the Services by Customer, the number of interactions with Customer and other aggregated data. You should be aware that Aggregated Data is not considered Personal Data under Canadian and US state laws, as it does not directly or even indirectly reveal your identity. However, if we combine or connect Aggregated Data with your Personal Data so that it can then directly or indirectly identify you, we treat the combined data as Personal Data and only use it in accordance with this Privacy Policy and relevant provincial or federal laws. |
How We Use Personal Information
We use your personal information for the following purposes and as otherwise described in this Privacy Policy or at the time of collection:
To operate the Service. We use your personal information to:
- provide, operate and improve the Service
- provide information about our products and services
- communicate with you about the Service, including by sending you announcements, updates, security alerts, and support and administrative messages
- provide support and maintenance for the Service
- respond to your requests, questions and feedback
For research and development. We analyze use of the Service to analyze and improve the Service.
To send you marketing and promotional communications. We may send you GenAIz marketing communications as permitted by law. You will have the ability to opt-out of our marketing and promotional communications as described in the Opt out of marketing section below.
To comply with law. We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
For compliance, fraud prevention, and safety. We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Service; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
With your consent. In some cases, we may specifically ask for your consent to collect, use or share your personal information, such as when required by law.
To create anonymous, aggregated or de-identified data. We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect. We make personal information into anonymous, aggregated or de-identified data by removing information that makes the data personally identifiable to you. We may use this anonymous, aggregated or de-identified data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business.
How We Share Personal Information
We may disclose your Personal Data within GenAIz, affiliated companies and with third parties for the purposes set out in this Privacy Policy.
We may share your data where we seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your Personal Data in the same way as set out in this Policy and for the same purposes.
We may also be required to disclose Personal Data to comply with our legal obligations. This can include situations where we must respond to government requests, investigate fraud, and respond to public and government authorities for national security and / or law enforcement purposes.
We may disclose your Personal Data with a third party if there is a valid commercial reason to do so, including for purposes related to providing services, developing new products and services, and research. Where we disclose your Personal Data and it is not integral to the provision of services, you may have the right to opt out of such disclosures under applicable state laws (e.g., by exercising your “Do Not Sell” rights).
We require all third parties to respect the security of your Personal Data and to treat it in accordance with applicable privacy and security law. Where we use third parties to provide services to GenAIz that are part of the Service, we do not allow such third parties to use your Personal Data for their own purposes and will only permit them to process your Personal Data for agreed and specified purposes and in accordance with our written instructions such as those given in a contract. We collect data from both direct and indirect sources. When we collect data from third parties who provide applications or services to support our delivery of the Services, these third parties have different privacy policies to GenAIz and we recommend that you visit them to understand how they treat your data and to exercise your rights with them.
Security practices
The security of your personal information is important to us. We employ a number of organizational, technical and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.
If we identify any potential risks that we believe you should be aware of, we will inform you and assist you in taking steps to enhance your protection.
We strive diligently to safeguard you and GenAIz from unauthorized access, modification, disclosure, or destruction of the information we possess, which includes:
- Utilization of encryption to ensure your data remains private during transmission.
- Assessment of our data gathering, storage, and processing methods, along with physical security procedures where applicable, to avert unauthorized access to our systems.
International data transfers
We are headquartered in Canada and have service providers in other countries, and your personal information may be transferred to the Canada or other locations outside of your state, province, or country where privacy laws may not be as protective as those in your state, province, or country.
European users should read the important information provided below about transfer of personal information outside of the European Economic Area
Children
As a general rule, children are not allowed to use the Service, and we do not collect personal information from them. We define “children” as follows:
Residents outside of Europe: anyone under 13 years old; and
Residents of Europe: anyone under 16 years old, or age needed to consent to the processing of personal information in your country of residence.
If we learn that we have collected personal information about a child without the consent of the child’s parent or guardian, we will delete it. We encourage parents with concerns to contact us.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service. We may, and if required by law will, also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if we have your contact information) or another manner through the Service.
Any modifications to this Privacy Policy will be effective upon our posting the new terms and/or upon implementation of the new changes on the Service (or as otherwise indicated at the time of posting). In all cases, your continued use of the Service after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.
How to Contact Us
Please direct any questions or comments about this Policy or privacy practices to privacy@genaiz.com. You may also write to us via postal mail at:
GenAIz.
303-80 rue Prince, Montréal (Québec) H3C2M8 Canada.
Your privacy rights
Your location will determine your privacy rights, and these vary from province to province.
California Privacy Rights
The CCPA provides California residents with specific rights regarding their Personal Data.
Do not sell
We can sell your data if there is a valid commercial reason to sell your Personal Data collected during the use of the services.
Your rights under the CCPA
If you are a resident of California, You have the following rights:
- The right to notice.
You have the right to be notified which categories of Personal Data are being collected and the purposes for which the Personal Data is being used.
- The right to request.
Under the CCPA, you have the right to request that we disclose information to you about our collection, use, sale, disclosure for business purposes and about how we share your Personal Data. If we receive a request, we will seek to identify you and if your identity is confirmed, we will disclose:
- The categories of Personal Data that we collected about you.
- The categories of sources for the Personal Data we collected about you.
- Our business or commercial purpose for collecting or selling your Personal Data.
- The categories of third parties with whom we shared that Personal Data.
- The specific pieces of Personal Data we collected about you.
- If we sold your Personal Data or disclosed your Personal Data for a business purpose, we will disclose:
- The categories of Personal Data categories sold if we sold your data.
- The categories of Personal Data categories disclosed.
- If we sold your Personal Data or disclosed your Personal Data for a business purpose, we will disclose:
- You have the right to say no to the sale of Personal Data (opt-out).
You have the right to request us to not sell your Personal Data. To submit an opt-out request please contact us at privacy@genaiz.com
- The right to delete Personal Data.
You have the right to request the deletion of your Personal Data, subject to certain exceptions. To submit a request to delete your Personal Data, please send a written request to privacy@genaiz.com.
If we receive a request and if your identity is confirmed, we will delete and request our service providers to delete your Personal Data from our records unless an exception applies. We may deny your deletion request if the retention of your Personal Data is necessary for us or our service providers to:
- Complete the transaction for which we collected the Personal Data, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
- The right not to be discriminated against.
You have the right not to be discriminated against for exercising any of your rights, including by:
- Denying goods or services to you
- Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties
- Providing a different level or quality of goods or services to You
Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
Notice to European Users
The information provided in this “Notice to European Users” section applies only to individuals in Europe.
Personal information. References to “personal information” in this Privacy Policy are equivalent to “personal data” defined in European data protection legislation.
Controller. GenAIz, is the controller of your personal information covered by this Privacy Policy for purposes of European data protection legislation.
We value your privacy and your rights as a data subject and have therefore we have appointed a Data Protection Officer, whose contact information is: privacy@genaiz.com
Legal bases for processing. We use your personal information only as permitted by law. Our legal bases for processing the personal information described in this Privacy Policy are described in the table below.
| Processing purpose | Legal basis |
| To operate the Service | Processing is necessary to perform the contract governing our provision of the Service or to take steps that you request prior to signing up for the Service. If we have not entered into a contract with you, we process your personal information based on our legitimate interest in providing the Service you access and request. |
| To send you marketing communications To manage our recruiting and process employment applications For compliance, fraud prevention and safety To create anonymous data | These activities constitute our legitimate interests. We do not use your personal information for these activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). |
| To comply with law | Processing is necessary to comply with our legal obligations. |
| With your consent | Processing is based on your consent. Where we rely on your consent you have the right to withdraw it any time in the manner indicated when you consent or in the Service. |
Use for new purposes. We may use your personal information for reasons not described in this Privacy Policy where permitted by law and the reason is compatible with the purpose for which we collected it. If we need to use your personal information for an unrelated purpose, we will notify you and explain the applicable legal basis.
Sensitive personal information. We ask that you not provide us with any sensitive personal information (e.g., information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Service, or otherwise to us.
If you provide us with any sensitive personal information to us when you use the Service, you must consent to our processing and use of such sensitive personal information in accordance with this Privacy Policy. If you do not consent to our processing and use of such sensitive personal information, you must not submit such sensitive personal information through our Service.
Automated Decision-Making and Profiling. We do not use automated decision-making and/or profiling in regard to your personal information.
Retention
We retain personal information for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal information we have collected about you, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. If we anonymize your personal information (so that it can no longer be associated with you), we may use this information indefinitely without further notice to you.
Your rights
European data protection laws give you certain rights regarding your personal information. If you are located within Europe, you may ask us to take the following actions in relation to your personal information that we hold:
- Access. Provide you with information about our processing of your personal information and give you access to your personal information.
- Correct. Update or correct inaccuracies in your personal information.
- Delete. Delete your personal information.
- Transfer. Transfer a machine-readable copy of your personal information to you or a third party of your choice.
- Restrict. Restrict the processing of your personal information.
- Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.
You may submit these requests by email to privacy@genaiz.com or our postal address provided above. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal information or our response to your requests regarding your personal information, you may contact us or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.
Cross-Border Data Transfer
If we transfer your personal information out of European Economic Area to a country not deemed by the European Commission to provide an adequate level of personal information protection, the transfer will be performed:
Pursuant to the recipient’s compliance with standard contractual clauses or Binding Corporate Rules Pursuant to the consent of the individual to whom the personal information pertains As otherwise permitted by applicable European requirements.
You may contact us if you want further information on the specific mechanism used by us when transferring your personal information out of Europe.