Effective Date: August 9, 2021
Evvy takes privacy very seriously. We are committed to protecting the privacy and security of “Personal Information” which could be used to identify our customers, either alone or in combination with other information. By accessing or using the Service (as defined above), customers allow us to collect, store, and use their Personal Information that enables us to provide more accurate and personalized recommendations. Evvy recognizes and understands the importance of privacy and respects our customers’ desire to store and access Personal Information in a private and secure manner.
1. What Information We Collect
When you subscribe to or use our Services, Evvy collects and uses several types of information as identified below. These include information you provide directly to us, your clinical and test data, information our customers provide in response to our questionnaires, self-reported information, data we retain in order to improve our data analytics methods and artificial intelligence engine and our Service, data we retain for provisioning our Service and securing payments for same, information we collected through tracking technology, web analytics, and other types of information we receive about you from third party sources.
If or when Evvy collects “Personal Information," it is protected by this Policy as described herein. “Personal Information” may include factual data, recorded data, or data derived from other information about you that amounts to any factual or subjective information whether recorded or not about an identifiable individual.
“Personally Identifiable Information” or “PII” is information about an individual when used alone or with other relevant data that can identify an individual (e.g., first and last name, birthdate, home address, social security number, bank account number, credit card number, passport number, Health insurance ID number, etc.).
“Personal Data” is any information relating to a natural person, when that person can be identified, directly or indirectly, in particular by reference to an identification number (e.g. social security number or credit card number) or one or more factors specific to their physical, physiological, mental, economic, cultural or social identity (e.g. last name and first name, date of birth, biometrics data, fingerprints, or DNA).
“Sensitive Information” or “Sensitive Data” is a category of Personal Information or Personal Data of an individual relating to confidential medical facts, records, racial or ethnic origins, political or religious beliefs, or sexuality.
“Self-Reported Information” is all information you provide us about yourself, including input and answers to surveys, forms, questionnaires, email, features on our website and software applications, while participating in Research Studies and Research Participations (as described in our Terms of Service), engaging with our customer service (“Customer Service”) or while using the Service (e.g., information about your personal traits (e.g., eye color, height), ethnicity, disease conditions (e.g. Type 2 Diabetes), physical health-related information (e.g., pulse rate, cholesterol levels, visual acuity, medicine you currently take, habits such as smoking), diet related information (e.g., vegetarian, vegan, allergies, etc.), mental health related information (e.g. emotional conditions such as fear or anxiety), and family history (e.g., information similar to the foregoing about your family members).
“Registration Information” is collected when you subscribe to or register for our Service. This information includes, but is not limited to Personal Information such as your name, date of birth, password, payment information (such as credit card information of which, Evvy stores only the last 4 digits and the expiration date), billing and shipping addresses, and contact information such as email address and telephone number that you provided to create your Evvy account (“Evvy Account” or “Account”) used for the Service. Evvy uses Registration Information to authenticate your access to Evvy Account and website for purposes that include but not limited to the following: use the Service, enable you to purchase or access add-ons and new features related to the Service, deliver personalized reports, send Research Studies Consent Forms and questionnaires, marketing and communications, and certain other purposes.
“Biological Samples” are the self-collected samples that you collect using Sample collection kits (“Kits”) and used for microbiome testing and analysis performed by Evvy.
“Sample Data” is molecular data created from the Samples you provide to Evvy for testing and analysis. Sample Data analysis includes, but is not limited to, microbiome analysis.
“User Content” is information that you create or content that you post or upload on our website, social media, or public forums that relate to us, such as blogs, data, text, software, documents, audio, photographs, graphics, video, messages, discussions, emails, or other materials that you create or provide to us through public or private transmissions.
“Test Data” is information we extract from Sample Data for use in our testing services that produce data and test results that help us provide you with accurate and personalized recommendations.
“De-identified Information” or “De-identified Data” as used here is Samples and other forms of data after removing personal identifiers from them immediately upon receipt, and assigning a unique code for each Sample or data, and performing all downstream testing, research, and data analyses relevant to Samples or data only using that unique code. De-identification is a well-established privacy practice followed in our industry whereby information likely to be identified with you will be scrubbed from the Sample Data, Test Data, internal records, or other forms of data before using the data for provisioning the Service. De-identification prevents Evvy from storing your personally identifying information together with your Samples, Test Data or other data in any database or records or release them externally in any way (even accidentally). Your Samples and Test Data are used with your Personal Information only to the extent necessary and for the purpose of delivering the Service to you and communicating directly with you when necessary.
“Aggregate Information” or “Aggregate Data” means high-level information or data collected from a group of individual Samples or other data combined with similar data of the others and compiled into data collections or summaries such that when evaluated as a whole, that no specific individual may be reasonably identified. Aggregate Data is often used for data analysis and sometimes for Research.
“Individual-level Data” means information or data about a single individual's Sample or other types of data provided by the individuals themselves or collected from other sources.
“Web Information” is information on how you use Evvy website (e.g. browser type, domains, page views, etc.) or other online media owned by Evvy, and are collected through log files, cookies, and web beacon technologies.
Evvy and its third-party service providers from whom it receives your information may use “cookies” and similar tracking technologies (such as web beacons, tags, scripts and device identifiers used for automatic collection of information), for a variety of purposes. Cookies are small data files that are stored on a user’s hard drive at the request of a website to enable the website to recognize and retain certain user information such as customer preferences and history.
Cookies help us recognize when and how you use our Services, customize and improve your experience, provide security, analyze our interactions with our Services and its features, gather demographic information about our user base, make special offers of our Service, monitor the success of marketing programs; and for targeted advertising on our website and on other websites on the Internet.
When Evvy receives reports from third parties on how certain functionalities of our website works, usage and statistical information such as the user’s browser type, operating system, device ID (only for IOS users), these third parties may collect personal information from you in connection with the services they provide and may place cookies, web beacons or other devices on your device to collect non-personal information which may be used, among other things, to deliver advertising targeted to your interests and to better understand the usage of the Service and the other services tracked by these third parties. Evvy is not responsible for, and does not control, any actions or policies of any third-party service providers.
The information reports we receive from third party service providers can be de-identified, individual-level, or at aggregate-level, and we may also use these reports to improve our data analytics methods. If we combine cookies with, or link them to, any of the Personal Information, Evvy will treat this information as Personal Information.
If you wish to block, erase, or be warned of cookies, please refer to your browser instructions or help screen to learn about these functions. However, if you reject cookies or your browser or device settings does not accept cookies, you may not be able to use certain parts of our website or sign in to your Evvy Account and may not be able to access certain Service features.
3. Google Analytics
Like many websites, we use Google Analytics for web behavior monitoring, a service that provides information about how many users visit our website and online resources, when they visit, and how they navigate our website. We also may use other Google Analytics tools, such as Demographics and Interest Reporting, which enable us to learn more about the characteristics and interests of the users who visit our website, and Remarketing with Google Analytics, which enables us to provide relevant advertising on different websites and online services.
4. User Content
Some features of our Service may include functionality enabling you to post user content, whether publicly posted or privately transmitted, such as profiles, posts, emails, feedback, experiences, suggestions, notes, messages, photos, and videos (“User Content”) that may be made available to Evvy and other users of the Service.
You should be aware that any User Content you provide or post in public media may be read, collected, and used by others who access them, and we have no control over these media. Please exercise caution before and when you choose to share personal information on our blogs, forums or in any other public media.
5. Other Types of Information
From time to time, we may collect other types of information automatically about your use of our Service through the use of log files. Such information may include your device’s Internet Protocol (IP) address, operating system, browser type, location, and your device ID. Evvy uses this information for purposes such as analyzing trends, administering the Service, improving customer service, diagnosing problems with our servers, monitoring the security of our systems, tracking user movement, and gathering broad demographic information for aggregate use.
6. Information on our Services
To use certain Services of Evvy, you may be required to first purchase, receive from a third party (e.g., as a gift), or from us directly or through an authorized channel partner, a Kit, and then create an online Account, register your Kit, and return your Sample directly to our laboratory for testing within the timeframe specified in our Sample return policy.
Our laboratory will use your Samples for testing, analysis and generation of Sample Data that will be used to generate Test Data. Test Data is used with Self-Reported Data in conjunction with our data analysis methods to provide personalized recommendations.
7. How We Use your Information
a) Provide you with the Services
We may also use your information to fix bugs or issues, analyze use of our website, to improve or optimize the customer experience and Customer Service, or assess the efficacy of our marketing campaigns.
b) For Research and Research Studies
In the event we require use of individual-level Personally Identifiable Information in Research or for other purposes, we will reach out to you for obtaining specific consents applicable to such other use. When you use our Services, Evvy may use your Personal Information, and other data at individual-level or otherwise (in de-identified, pseudonymized, or aggregate forms) for ongoing research conducted by Evvy that help us better understand the connections among microbiome and your health and wellness at individual as well as at population scale (“Research”). The information we use in Research is often summarized, aggregated, or combined across a group of subjects to minimize the chance of identification.
The Research activities may include but not limited to conducting data analysis to develop new or improve existing Services, perform quality control, and identifying potential areas or targets for specific recommendations. Research Studies may encompass population-scale studies, development of a specific diagnosis or treatment, predict certain health conditions, or develop scientific knowhow, discoveries, and intellectual property assets to improve healthcare for the population as a whole. They may also include publishing study results in peer reviewed scientific journals publications and commercialization activities.
c) Improve Our Service, Analysis Methods, and Artificial Intelligence Engine
We are constantly working on improving our Service and enhancing the capacity and accuracy of our data analysis methods and artificial intelligence engine we use for the purpose of delivering more accurate and personalized recommendations to you.
We may use your Sample Data and Self-Reported Information in de-identified, pseudonymized, anonymized, or aggregate forms (after carefully removing the identifiers that easily identify who you are), together with similar data of others, for the purpose of improving Evvy’s data analysis methods.
We may use Web Information to improve our website and online presence, and to facilitate accessibility for you and our other users. We may also use other data we collect for our internal business purposes to improve our Service and operations.
d) Provide Customer Service and Support
When you contact Evvy customer service (“Customer Service”), we may use or request additional Personal Information, as necessary to verify your identity, answer your questions, resolve disputes, and/or investigate and troubleshoot problems or complaints. In certain instances, we may require using one customer’s Personal Information to resolve another customer’s request. For example, if a customer reports behavior of another customer that violates our Terms of Service, we will separately process both customers’ Personal Information and respond separately to each customer as appropriate. We will not share your Personal Information with another customer or any third party without your specific consent.
e) Surveys and Testimonials
We value our customers’ feedback and may send you surveys, polls, or requests for testimonials to improve and optimize our Services. We may use your Personal Information to send you surveys, questionnaires, and requests for testimonials that we use to optimize our Service and perform quality control activities. You are in control of the information you would like to share with us.
f) Marketing and communications
By creating an Evvy Account and using our Service, you agree to receiving Service-related email with information such as new features, add-ons, promotions, contests and other notifications about our Services. You can unsubscribe from receiving these marketing communications at any time. To unsubscribe, click the email footer “unsubscribe” link or send a request to our Customer Service (email@example.com) using the details provided above. You may not opt-out of receiving non-promotional messages regarding your Account, such as technical notices, purchase confirmations, important Evvy policies and deadlines applicable to use of Kits and Sample returns or Service-related emails.
We may also use the Personal Information you submit to us to personalize your user experience and to allow us to recommend or deliver the type of content, new features, or Service offering in which you are most interested. We may also use your Personal Information to compile usage statistics and other data regarding use of our Services and for other types of marketing and communication purposes, without asking for and receiving your explicit consent (e.g., targeted advertising that uses third party advertising networks and providers who help us deliver targeted online advertisements or measure the effectiveness of ad campaigns). We and our third-party service providers will not use your Sensitive Information for marketing and communication purposes.
8. Withdrawing Consent
You may withdraw your consent for Research Studies, as expressed by acceptance of a Consent Form, at any time by sending a request to our Studies Team to change your Consent Form status as stated below:
Send in a request on “Consent Withdrawal” using firstname.lastname@example.org.
Allora Health Inc.
245 8th Ave
New York, NY 10011
Pursuant to your request, we will not include your Individual-level Personal Information in Research Studies that start more than forty-five (45) days after the date of receipt of your consent withdrawal. Any Research Studies that used your Individual-level Personally Identifiable data that have already been performed or published prior to your withdrawal for which you have given consent to cannot and will not be reversed, undone, or withdrawn.
9. What happens if you do NOT sign a Consent Form?
If you choose not to accept the Consent Form or grant a study specific Consent to us, your Individual-level Personal Information will not be used for Research Studies. However, you may still have an opportunity to participate, if we identify you as a potential candidate for and extend you an invitation to participate in a Research Study. You may or may not accept the invitation and study specific Consent Form or you may decide not to respond.
10. How We Disclose Your Information
In general, Evvy will not disclose individual-level Personal Information (including Self-Reported Information) to third parties, except under the following circumstances:
a) With Express Written Permission
Evvy may disclose your Personal Information to third parties in accordance with our Terms of Service or where you have otherwise provided express written consent for sharing (e.g. by way of accepting a Consent Form).
b) Facilitate Business Operations
c) As Required by Law
Under certain circumstances, Personal Information may be subject to disclosures pursuant to judicial or other government subpoenas, warrants, or orders, or in coordination with regulatory authorities. You acknowledge and agree that Evvy is free to preserve and disclose any and all Personal Information to law enforcement agencies or others regulatory agencies that oversee manufacturing and logistics service, if required to do so by law or in the good faith belief that such preservation or disclosure is reasonably necessary to: (i) comply with legal or regulatory process (such as a judicial proceeding, court order, or government inquiry); (ii) obligations that Evvy may owe pursuant to ethical, regulatory (such as Food and Drug Administration), and other professional rules, laws, and regulations; (iii) enforce Terms of Service; (iv) respond to claims that any content violates the rights of third parties; or (v) protect the rights, property, or personal safety of Evvy, its employees, its customers (including you), and the public. In the event Evvy is required by law to disclose Personal Information, Evvy will notify you through the contact information provided to Evvy in advance, unless doing so would violate the law or a court order.
d) Sharing with Third Parties
We may share your individual-level Personal Information, without explicit consent, to the extent necessary, with third parties: i) in order to perform business operations that help deliver the Services to you (e.g., Sample collection services, laboratory service, inventory controllers that ship Kits, supplements and probiotics + prebiotics manufacturers, logistics operators, IT service providers, customer service optimizers, etc.); ii) for marketing and communication purposes and iii) if the third party is a clinical partner that referred you to us, we may share Personal
Information and your results with that partner.
We may also share Personal Information in de-identified, pseudonymized, or aggregate forms (without your personal details or aggregated with the information of others so that you cannot reasonably be identified as an individual) for: i) Research and Research Studies; ii) strategic initiatives with Research partners; and iii) for other purposes, to the extent necessary, and as permitted by law.
e) Lost Capacity
When a customer has lost capacity or passed away, we will only give their Account information to individuals who are legally authorized to make decisions on their behalf, such as an executor, a personal representative, or a beneficiary of a deceased's estate. The person requesting the information must complete an authorization form and provide evidence and legal documentation indicating they are allowed to act on behalf of the individual before we will provide any information.
f) Business Transitions
11. Information Security Measures
Evvy uses a number of physical, technical, and administrative measures to keep your Personal Information safe and secure. By employing these safeguards, we aim to prevent unauthorized access, minimize accidental disclosure, maintain data accuracy and integrity, and ensure appropriate use of the information in accordance with current technological and industry standards.
Protecting Personal Information is a responsibility shared between you and Evvy. In this regard, we ask all users of our Service to be responsible for keeping their login IDs, passwords, and other authentication information used to access the Service in a secure manner and maintain strict confidentiality. You should not share Account and authentication information with any third parties and should inform Evvy immediately of any prohibited use of your Account or authentication information. Evvy cannot secure and assumes no liability for Personal Information that is released by our customers to third parties, such as physicians, insurance companies, or healthcare service providers.
Evvy implements several physical and technical security measures to ensure confidentiality, integrity, security, and availability of Evvy and customer data by employing industry standard safeguards such as de-identification, pseudonymization, encryption, and data segmentation. Your Sample Data and other Personal Information you provided to us are stored after labeling them with an assigned code without your name or other Personal Information that can easily identify your Sample with you.
Evvy keeps all customer Personal Data and information on secure cloud servers. Only a small group of qualified personnel within Evvy can access the information that can be used to identify you. These are personnel who need that information in order to provide, complete, testing, analysis, and reporting related to the Services. The Personal Information that matches the assigned codes will be kept in a secure, access controlled, and protected database at Evvy. Only a small group of essential personnel will have access to this secure and protected database.
We will not include any Personal Information that would make it possible to identify you in any Research, studies or publications. All Evvy employees, consultants, and others who might have access to your Personal Information must sign confidentiality and non-disclosure agreements that mandate them to keep customer Personal Information confidential. Your Personal Information may be shared with your health care service provider only with your written permission. Your Samples and their specimens and their remnants, after testing and analysis, will be stored securely with de-identified alphanumeric IDs (with no Personal Information that can identify you).
12. Children’s Privacy
Evvy is committed to protecting the privacy of children and abiding by the provisions of the Children’s Online Privacy Protection Act (“COPPA”). The Service is not directed, designed, or intended to attract children under the age of 18.
In the event Evvy is notified or becomes aware that the Service has been used by a child under the age of 18 to store information of that child without parental consent, Evvy shall be and is authorized to delete, in its entirety, with no notice to you, any of the information stored by that child or by you on that child’s behalf. Evvy also reserves the right to revoke any license to use the Service, which is being used or has been used by a child under the age of 18.
13. Retention of Personal Information
Unless you close your Account that results in deletion of your Personal Information in the Account as described in the Account Closure process as specified below, Evvy will store your Personal Information as long as your Account is open.
14. Correction of Personal Information
Your Personal Information and Registration Information, if incorrect, can be corrected, changed, or updated by sending a request to our Customer Service using the information stated below:
Send in a request on “Correcting Personal Information” using email@example.com
Submit by mail:
Evvy Customer Service (Correction of Personal Information)
245 8th Ave
New York, NY 10011
15. Account Closure
If you no longer wish to use the Service, or have your Personal Information processed by us in order to provide you the Service, you may close your Account and have your Account information deleted by sending our Customer Service a request using the information specified below.
Send in a request on “Account Closure” using firstname.lastname@example.org
Once we receive your request, we will send an email to the email address linked to your Account detailing our Account Closure Policy and requesting that you confirm your closure request. Once you confirm your request to close your Account and delete your Account information, your Account will no longer be accessible. When your request is processed, it cannot be cancelled, undone, withdrawn, or reversed. When closing an Account, Evvy removes or deletes Personal Information associated with that Account, subject to certain limitations stated below:
To the extent necessary and permitted by law, Evvy may still retain:
i) Limited Registration Information on order history (e.g., name, contact details, closure request, and transaction data) for accounting, audit, and compliance purposes;
ii) Limited Personal Information for compliance with legal retention requirements (e.g., CLIA requirements);
iii) Limited Personal Information to fulfill contractual obligations, exercise or defend legal claims;
iv) Limited Personal Information to fulfill audit and compliance processes;
v) Information already used for Research and Study Participants; and
vi) Limited information in de-identified, pseudonymized, or aggregate forms used in Research, data analysis and artificial intelligence.
16. Retention of Personal Information
Unless you close your Account and delete your Personal Information in the Account as described under Account Closure as specified above, Evvy will store your Personal Information as long as your Account is open.
17. Nevada Residents:
Pursuant to Nevada Privacy Law (“NPL”), Nevada residents may direct a business that operates an internet website not to sell certain Personal Information about you.
Evvy does not sell your Personal Information to third parties. If you are a Nevada resident, for more information about your rights under NPL or how we handle and share your Personal Information, contact our Customer Service by sending a request using the information specified below:
Send in a request on “Nevada Information Disclosures” using email@example.com
18. California Do-Not-Track Disclosures
Evvy does not track its customers over time and across third party websites to provide targeted advertising and therefore does not respond to Do Not Track ("DNT") signals. Third parties that have content embedded on Evvy’s websites or mobile applications (e.g. social features) may set cookies on a user’s browser and obtain information about the web browser visiting a specific Evvy website from a certain IP address. Third parties cannot collect any other Personal Information from Evvy’s websites, software, or mobile applications unless you provide it to them directly.