Promethease Privacy Policy (last update: Sept 18 2019)

NOTE: MyHeritage Ltd. (https://www.myheritage.com) (“MyHeritage”) has acquired Promethease. See blog post. MyHeritage has made the Promethease service free until the end of 2019.

This privacy policy governs how MyHeritage may process or use your personal data. You can contact us at privacy@myheritage.com if you have any questions or concerns regarding your privacy on Promethease. See further details about how your personal information will be treated in the scope of the acquisition by MyHeritage under “HOW WILL THE ACQUISITION OF PROMETHEASE BY MYHERITAGE AFFECT MY PERSONAL INFORMATION” below.

Promethease (the “Website”) is a literature retrieval system that creates a personal report (a “Report”) based on a raw DNA data file (“DNA Data File”) uploaded by the user, using the scientific and medical literature cited in SNPedia, our online genomic analysis wiki that is investigating human genetics (“SNPedia”). Promethease is a platform for genetic analysis, that allows its users to: (i) upload DNA Data Files generated by different DNA testing service providers; (ii) optionally store DNA Data Files; (iii) generate and re-generate Reports based on the uploaded DNA Data Files; and (iv) optionally create a private account through which they can manage the DNA Data Files and the Reports. Promethease is a service for a personal, private and informational use only and may not be used in connection with any clinical purpose and/or commercial or research endeavors. Illegal and/or unauthorized use of Promethease is prohibited.

Your privacy is important to us. We want to do it right. The system was designed to maximize your privacy.

By using Promethease and uploading a DNA Data File, you consent to the collection, use and storage by us of your DNA Data File in accordance with this Privacy Policy, until the DNA Data File is deleted by you or by us.

WHAT PERSONAL DATA WILL WE COLLECT AND PROCESS?

If you upload a DNA Data File and/or create an account, your DNA Data File and your email address will be processed by us. We will process this information for as long as needed to provide you with the service. We plan to collect the full name, country of residence and age of new users during account signup in the near future.

If you make a payment to use Promethease, we use the Stripe service for billing and therefore we do not store your credit card information or other billing information on Promethease; it is stored by Stripe and we do not have access to it.

When you generate a Report, you can enter your email address for the Report to be emailed to you. You may choose to blank your email, but it makes it much more likely that you will lose the ability to retrieve your Report.

Reports presented by Promethease are based on SNPedia. When you look at SNPedia with your web browser, the pages you’ve requested are part of the SNPedia web server logs. This makes it possible to match a set of genotypes to a given IP address. Since most users will eventually click through from their Promethease report into SNPedia, and use their web browser to look at the full details of some of their genotypes, this too may leak information about a user’s genotypes and IP address into server logs. These logs are not kept long term; typically, they are removed after one month, however this is currently not automated.

STORAGE OF PERSONAL INFORMATION

After 45 days Promethease deletes your Report.

Whenever you order a Report, you can choose whether to create a password-protected account (default) or continue without creating an account.

If you choose not to create an account, Promethease deletes your DNA Data file after 24 hours. All DNA Data Files uploaded before August 28, 2017 were deleted. If you create an account, Promethease will store your DNA Data File, until such time that you delete it from Promethease. You can log into your account at any time, and for as long as your DNA Data File is stored on Promethease, you can re-generate a Report for free, gaining the most up-to-date data from SNPedia, or delete your DNA Data File permanently.

If you upload a DNA Data File but you do not continue and generate a Report, the DNA Data File is automatically deleted after 24 hours. As soon as a Report has been generated (typically 10 minutes) the uploaded DNA Data File is deleted, unless an account was created.

Storage of DNA Data Files in detail. As scientific knowledge constantly advances and SNPedia continues to improve constantly, storage of your DNA Data File/s allows Promethease to provide you with better and more up-to-date Reports each time you generate a Report. Nonetheless, storage is optional. You may opt-out from the storage option at the time of requesting the Report, in which case we will delete your DNA Data Files/s right after the Report is generated and within 24 hours. If you create an account and store DNA Data File/s in it, then after your Report is generated, such DNA Data Files can be deleted by you by logging into your account and using the Delete action. The option to create an account and store your DNA Data Files was added on August 28 2017 so the storage option only applies to DNA Data Files uploaded on or after that date.

HOW WILL THE ACQUISITION OF PROMETHEASE BY MYHERITAGE AFFECT MY PERSONAL INFORMATION?

Note that Promethease sent all its users a notification email about the acquisition by MyHeritage before Sept 17, 2019. It will send at least one more reminder email before November 1, 2019.

I.              Users who joined Promethease (or will join) prior to November 1, 2019:

1.    If you are a non-European (i.e. reside outside of Europe) and have DNA Data File(s) stored on Promethease, then as of November 1st, 2019, your DNA Data File(s) on Promethease will be copied to the MyHeritage website into a new MyHeritage user account that will be created for you (using the email address associated with your Promethease account). If you are not interested in having your DNA Data File(s) and account copied to MyHeritage, you can log in to Promethease and delete your DNA Data File(s) permanently before November 1st, 2019, in which case nothing will be copied to MyHeritage.

Once copied to MyHeritage, all of your data (including the copied DNA Data File(s)) will be governed by the MyHeritage Terms and Conditions and Privacy Policy, which you will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted.

2.    If you are a European (i.e. reside in Europe) and have DNA Data File(s) stored on Promethease, your DNA Data File will not be copied to MyHeritage unless you send an email to promethease-opt-in@myheritage.com from the email address associated with your Promethease account, mentioning your wish to opt in. If you do so, your data will be copied over from Promethease to MyHeritage on or after November 1, 2019 and you will be notified by an email once this process takes place.

Once an account for you is created on MyHeritage in accordance with the above, you will receive a notification email. You will then be able manage your copied DNA Data File(s) on the MyHeritage website in a secure private account (created using the email address associated with your Promethease account) accessible only to you, and receive free value-add services (free DNA Matching for relatives and free Ethnicity Estimates). You will at all times retain ownership of your DNA Data File (MyHeritage asserts no ownership rights over the DNA Data File). Your account on Promethease will remain active and you can continue to use it. You will be able to delete your DNA Data File and/or account on MyHeritage at any time (while still continuing to use Promethease if you wish). MyHeritage will de-duplicate the DNA Data File, so that DNA Data Files that have already been uploaded separately to MyHeritage by the same users will not be copied over to MyHeritage again.

3.    If you do not have any DNA data stored on Promethease, none of your data will be copied to MyHeritage on such date.

II.            Users who join Promethease on or after November 1, 2019:

If you join Promethease at any time on or after November 1, 2019, the sign-up page will allow you to opt-in to creating an account on MyHeritage and sharing the DNA Data File with MyHeritage (if European) or opt-out (if non-European). Links to the terms and privacy policy of MyHeritage will be provided during the sign-up process. If you opt in, or do not opt out, as applicable, you acknowledge that Promethease is owned by MyHeritage and any information you provide to Promethease is governed by this Privacy Policy and also by the MyHeritage Terms and Conditions and Privacy Policy (together, the “MyHeritage Terms") (in case of any contradiction between this Privacy Policy and the MyHeritage Terms, the latter shall prevail); and you hereby agree that Promethease may transfer your DNA Data File(s) to the MyHeritage platform from time to time (e.g., once a month) to use it for purposes of providing you with DNA matching and ethnicity estimates for free. .

All users, regardless of where they reside or the date on which they joined Promethease, are able to delete their DNA Data File(s) and accounts permanently from Promethease and/or MyHeritage, at any time. Please note that deleting information from one account (e.g. Promethease or MyHeritage), will not automatically delete any information from the other account. If you don’t need any of those accounts, you need to delete information from each account separately.

RIGHTS; LICENSE

We do not claim any ownership rights in your DNA Data File and genome and it belongs to you only.

By uploading your DNA Data File, you grant us a temporary, limited, revocable, royalty-free, world-wide license to process and use your DNA Data File for the purpose of providing you with the service. i.e., for generating and re-generating Reports, and if you created an account and stored your DNA Data File, also to use it with new genetic features of the service we may develop in the future, at no additional cost to you. You may delete your DNA Data File at any time.

By uploading DNA Data Files to Promethease, you acknowledge that you acquire no rights in any research or commercial products that may be developed by us (whether or not they relate to the said DNA Data Files).

WHAT ARE THE PURPOSES OF USING YOUR PERSONAL DATA?

i)               To provide you with the service.

ii)              To communicate with you. We may communicate with you for the purpose of informing you of changes or additions to the service or of any of our products and services or to seek feedback from you on the service.

iii)             For internal business purposes. To improve Promethease or to develop new products and service, we may use personal data you provided for internal data analysis.

SECURITY

When you provide us with any personal data, that personal data may be transferred to and stored by us in our secure data centers which may provide a different level of protection for personal data than in your country of residence. By providing us with personal data, you specifically consent to the transfer and processing of personal data and its storage in our data centers. By using services, you consent to have your personal data transferred to and processed in the United States and you acknowledge that your personal data may be used as described herein.

All traffic is encrypted via https and your upload is retained in a well-protected location, and we take industry standard security measures to ensure the privacy protection of the personal data provided by you. We have implemented commercially reasonable security measures in place to attempt to protect users' data under our control. However, we cannot guarantee unauthorized use. You acknowledge that you provide your personal data at your own risk.

You hereby acknowledge and agree that: (1) downloading your Reports will create a copy that is not protected by our security and privacy settings; (2) such download and the storage of your Reports after you have downloaded them, shall all be made at your own risk; and (3) we shall not have any control over the downloaded Reports and shall not be liable to you or to any third party in connection with any such download and/or storage.

WILL WE DISCLOSE ANY OF YOUR PERSONAL DATA TO THIRD PARTIES?

We will never sell or license your DNA information to insurance companies under any circumstances. Your personal data (including the DNA Data Files and/or the Reports) will never be sold, licensed or otherwise shared by us with any other third parties without your explicit informed consent, except in the very specific scenarios described below:

1.    To third parties providing services on our behalf, like processing payments from you by Stripe or storing data on the Amazon cloud. The use of the personal data by such third parties is limited in scope and subject to contractual protections. Such parties are prohibited from using it for any other purposes other than providing us or you with the required services. With respect to processors outside Europe, we attempt to ensure adequate safeguards for your personal data, as required by applicable law.

2.    In business transfers. In the event that MyHeritage, or substantially all of its assets or stock, are acquired, transferred, disposed of (in whole or part and including in connection with any merger, bankruptcy or similar proceedings), personal information including DNA Data Files will be one of the transferred assets. In such event, your personal information would remain subject to the promises made in the pre-existing Privacy Policy prior to the event.

EMAILS

We may send to you the following types of emails:

i)               Transactional emails. Emails that are sent following a purchase of a Report. For example, if you make a payment, you will receive an email with a confirmation that your payment was received, or the charge has failed.

ii)              Notification emails. Emails that include a link to your Report.

You cannot unsubscribe from transactional and notification emails, and by providing your email address you give your consent to receive such emails as necessary.

iii)             Announcement emails. Emails concerning the service that announce new features, promotions and offers. 

LEGAL GROUNDS FOR PROCESSING

Under EU data protection law, all processing of personal information is justified by a "condition" for processing. In the majority of cases, any processing will be justified on the basis that:

1.    As is necessary for the performance of a contract with you, in this case, your usage of our services;

2.    As is necessary for our legitimate commercial interests subject to your interests and fundamental rights (e.g. analytics which we carry out of your use of the service)

3.    The processing is necessary for us to comply with a relevant legal obligation.

In addition, the processing of "special category data" is only permitted where a relevant exemption exists. Special category data includes genetic information. The special category data is processed on the basis of your explicit consent. Where the basis of processing is your consent, you have the right to withdraw your consent, and therefore prevent that processing, at any time.

CHILDREN

If you are a child under the age of 18, please do not use our service. We will not knowingly contact or engage with children under the age of 18. If you have reason to believe that a child has provided us with their personal information, please contact us at the address given above and we will endeavor to delete that personal information from our databases.

MODIFICATIONS

Your use of Promethease constitutes your agreement to follow and be bound by this Privacy Policy. We reserve the right to update or modify this Privacy Policy at any time. For this reason, we encourage you to review this Privacy Policy whenever you use the service.

If we decide to modify our Privacy Policy, we will issue an updated version of this Privacy Policy with an updated date legend (and notify you via email or by other appropriate means if the changes are material) so that you will be aware of what information we collect, how we use it and under what circumstances we disclose it in accordance with applicable law. If you do not consent to the Privacy Policy or to any changes thereto and as a result you would like us not to use or hold your information in accordance with the revised terms, you may delete your DNA Data Files and/or delete your account.

Whenever this Privacy Policy is modified in substance, the label "updated" will be displayed prominently next to the "Privacy Policy" link in the footer of the Website pages. The "updated" label will be removed after 30 days.

Use of the Website following any changes constitutes your acceptance of the revised Privacy Policy then in effect. 

YOUR RIGHTS UNDER THE GDPR

You have the right to request access to your personal data that we process, and further have such personal data rectified or erased. 

If you feel like your data protection rights under the GDPR have been violated, you may lodge a complaint at the supervisory authority in the Member State in which you reside, or alternatively with the ICO.

CALIFORNIA PRIVACY RIGHTS

California residents are entitled to ask us for a notice describing what categories of personal customer information we share with third parties or corporate affiliates for those third parties or corporate affiliates’ direct marketing purposes. We do not share your personal information with third parties or corporate affiliates for their direct marketing purposes.

If you do not agree to this Privacy Policy, please do not use the service.



Privacy policy (updated)

Need help? Visit our Help Center to get instant answers for most frequently asked questions.

Promethease is provided for personal use only. Commercial users may request a license by contacting us.