Dietary Molecular Diagnostics SL
Tax ID No.:
Parc Científic i Tecnològic Agrolimentari, núm 23 A, 25003 Lleida (Spain)
Registered in the Companies Registry of Lleida, volume 1,366, sheet 105, sheet number L-27.410, 1st inscription.
This Privacy Statement applies to all websites owned and operated by Dietary Molecular Diagnostics SL (hereinafter “Biomeb”), including biomeb.com and any other websites, pages, features, or content we own or operate and/or when you use any related services.
In compliance with applicable data protection legislation, we inform you hereby of the following:
1. Data manager and data protection officer
Biomeb is the Data Manager of your personal data. If you have questions about this Privacy Statement, or wish to submit a complaint, you may contact our Data Protection Officer at email@example.com, or send a letter to:
Data Protection Officer
Dietary Molecular Diagnostics SL
Parc Científic i Tecnològic Agrolimentari, núm 23 A
25003 Lleida (Spain)
2. Key definitions
- Aggregate Data: data that has been combined with that of other users and analysed or evaluated as a whole, such that no specific individual may be reasonably identified.
- Anonymized Data: data that has been stripped of your Registration Data (e.g., your name and contact data) and other identifying data such that you cannot reasonably be identified as an individual.
- Individual-level Data: data about individual’s metabolomics, diseases or other traits/characteristics, but which is not necessarily tied to Registration Data.
- Personal Data: data that can be used to identify you, either alone or in combination with other data. Biomeb collects and stores the following types of Personal Data:
- Registration Data: data you provide about yourself when registering for and/or purchasing our Services (e.g. name, email, address, user ID and password, and payment data).
- Metabolomics Data: data regarding your metabolism, generated through processing of your blood sample by Biomeb.
- Self-Reported Data: all data about yourself, including your disease conditions, other health-related data, personal traits, ethnicity, family history, dietary habits, and other data that you enter into forms or web applications while signed in to your Biomeb account.
- Sensitive Data: data about your health and certain Self-Reported Data such as your ethnic origin.
- User Content: all information, graphics, text, images and other data – other than Metabolomics Data and Self-Reported Data-generated by users of Biomeb Services and transmitted, whether publicly or privately, to or through Biomeb.
- Web Behaviour Data: data on how you use the Biomeb website (e.g. browser type, domains, page views) collected through log files, cookies, and web beacon technology.
- Biomeb Service or Services: Biomeb’s products, software, web applications, and website (including but not limited to text, graphics, pages, content, images, features and other material and data) as accessed from time to time by the user, regardless if the use is in connection with an account or not.
- Intellectual and industrial property: including but not limited to trademarks, logos, texts, metabolomic reports, etc., as well as graphic design, source code and other software elements contained in our websites.
3. Personal Information we collect
- Data you provide directly to us
- Registration Data. When you purchase our Services or create a Biomeb account and register your kit, we collect Personal Data, such as your name, date of birth, billing and shipping address, payment information (e.g., credit card) and contact information (e.g. email and phone number).
- Self-Reported Data. Additionally to the registration data, we collect data about yourself through web applications. For example, you may provide us with data about your individual physical variations (e.g., weight, height), ethnicity, gender, disease conditions (e.g. metabolic diseases, hypertension), other health-related (e.g. triglycerides levels, physical activity), and de-identified family history information (e.g. familial hypercholesterolemia).
- User Content. Some of our Services allow you to create and post or upload content, such as data, text, software, audio, photographs, graphics, video, messages, or other materials that you create or provide to us through either a public or private transmission (“User Content“).
- Customer service. When you contact us about our Service, we collect data to: track and respond to your inquiry; investigate any breach of our Terms of Service, Privacy Statement or applicable laws or regulations, and analyse and improve our Services.
- Data related to our metabolomic testing services
- Blood sample storage. To use our metabolomics testing services, you must purchase, or receive as a gift, a Biomeb Metabolomics testing kit, create an online account and register your kit, and ship your blood sample to our laboratory. During kit registration you are asked to review our Consent Document. Unless you consent to sample storage and/or to Biomeb Research, your metabolomics sample is destroyed after the laboratory completes its work, pursuant to the laboratory’s legal and regulatory requirements. You can update your sample storage preference within your Account Settings once your sample has completed processing.
- Metabolomic Data: data regarding your metabolism, generated through the processing of your blood sample by Biomeb. Our laboratory processes your blood sample for the purposes of generating your Metabolomics Results reported to you as part of our Services.
- Web Behaviour Data collected through tracking technology
There are instructions available to configure how the Chrome/Chromium, Internet Explorer, Mozilla Firefox or Safari browsers work with cookies. For other programs, you can consult the help documentation specific to each browser.
If you reject cookies, you may still use our site, but your ability to use some features or areas of our site may be limited.
Google Analytics. We use Google Analytics to perform many of the tasks listed above. We have enabled the following Google Analytics Advertising features: Remarketing, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. We do not merge data collected through any Google advertising product with individual-level data collected elsewhere by our Service. To opt out of Google Analytics Advertising Features please use Google Ad Settings. To opt out of Google Analytics entirely please use this link.
4. How we use your data
Biomeb will use and share your Personal Data with third parties only in the ways that are described in this Privacy Statement.
- To provide you with Services and analyse and improve our Services
We use the data described above to operate, provide, analyse and improve our Services. These activities may include, among other things, using your data in a manner consistent with other commitments in this Privacy Statement, to:
- open your account, enable purchases and process payments, and communicate with you;
- host our website, run our website application(s), authenticate your visits, provide custom, personalized content and data, and track your usage of our Services;
- contact you about your account, and any relevant information about our Services (e.g. policy changes, security updates or issues, etc.);
- enforce our Terms of Service and other agreements;
monitor, detect, investigate and prevent prohibited or illegal behaviours on our Services, to combat spam and
- other security risks; and
- perform research & development activities, which may include, for example, conducting data analysis and research in order to develop new or improve existing products and services, and performing quality control activities.
- To process, analyse and deliver your metabolomics testing results
As described above, to receive results through the Service, you must create a Biomeb account, register your kit in our website application, and submit your blood sample to our laboratory, which processes and analyses your sample to provide you with our metabolomics health reports, dependent on the Service purchased. Biomeb continuously works to improve our Services based on our research and product development. If we are able to offer additional reports, or otherwise improve reports in the future, we will notify you of these changes.
- To allow you to share your Personal Data for Biomeb Research purposes
You have the choice to participate in Biomeb Research by providing your consent. Biomeb aims to make and support metabolomic scientific discoveries and publish those discoveries in scientific journals. We invite you to take part in our research.
Biomeb Research may be in collaboration with third parties, such as academic institutions or pharmaceutical companies.
Your Anonymized Metabolomic and Self-Reported Data may be used for Biomeb Research only if you have consented to this use by completing a Consent Document. If you have completed the Research Consent Document:
- Your Metabolomic Data and/or Self-Reported Data will be used for research purposes, but it will be anonymized and will not be linked to your Registration Data.
- Biomeb may use individual-level Metabolomic Data and Self-Reported Data internally at Biomeb for Research purposes.
Withdrawing your Consent. You may withdraw your consent to participate in Biomeb Research at any time by changing your consent status within your Account Settings. If you experience difficulties changing your consent status, contact the Data Manager at firstname.lastname@example.org. Biomeb will not include your Metabolomic Data or Self-Reported Data in new research occurring after 30 days from the receipt of your request. Any research involving your data that has already been performed or published prior to our receipt of your request will not be reversed, undone, or withdrawn.
What happens if you do NOT consent to Biomeb Research? If you choose not to complete a Consent Document or any additional agreement with Biomeb, your Personal Data will not be used for Biomeb Research. However, your Metabolomic Data and Self-Reported Data may still be used by us and shared with our third party service providers to as outlined in this Privacy Statement.
- To recruit you for external research
If you have chosen to participate in Biomeb Research, we may inform you of third party research opportunities for which you may be eligible. We will not share Individual-level Metabolomic Data or Self-Reported Data with any third party without your consent.
- To provide customer support
When you contact us, we may use or request Personal Data and/or Sensitive Data as necessary to answer your questions, resolve disputes, or troubleshoot problems. In some instances, we may be required to process one customer’s Personal Data to resolve another customer’s dispute or request. For example, if a customer reports behaviour that violates our Terms of Service, we will separately process both customers’ Personal Data and respond separately to each individual as appropriate. We will not share your Personal Data with another customer without your consent.
- To provide you with marketing communications
By creating a Biomeb account, you are agreeing that we may send you product and promotional emails or notifications about our Services, and offers on new products, services, promotions or contests. You can unsubscribe from receiving these marketing communications at any time.
5. Data we share with third parties
- General Service Providers. We share the data described above with our third party service providers, as necessary to provide their services to us and help us perform our contract with you. Service providers are third parties (other companies or individuals) that help us to provide, analyse and improve our Services. We engage some third party service providers to assist in supporting our Services, including in the following areas:
- Order fulfilment and shipping. Our payment processor processes certain Registration Data, such as your billing address and credit card information, as necessary to enable you to purchase a Biomeb Metabolomics testing kit from our online stores. Our courier services ship your kit to you, and help return your kit safely to our third laboratory so your sample can be processed.
- Our lab. Once delivered, receiving personnel at the laboratory remove and discard kit packaging, which in some cases may contain “sender information” (e.g., name, address, email), before testing personnel receive the samples for processing. When we complete the analysis, we process your Metabolomic Data identified by your unique barcode.
During kit registration, you are asked to review our Consent Document for Sample Storage and Additional Metabolomic Analyses. Unless you acknowledge your consent, your blood sample is destroyed after the laboratory completes its work, pursuant to the laboratory’s legal and regulatory requirements. Should you wish to update your sample storage preference to discard a stored sample, you can do so within your Account Settings once your sample has completed processing, according to applicable regulatory and legal obligations.
- Customer Service. Our Customer Support team uses tools to help organize and manage the requests we get to ensure they receive timely and helpful information and quality support, including email and phone support.
- Cloud storage, IT, and Security. Our cloud storage providers provide secure storage for data in Biomeb databases, ensure that our infrastructure can support continued use of our Services by Biomeb customers, and protect data in the event of a natural disaster or other disruption to the Service.
- Marketing and analytics. When you visit our website you will be presented with a cookie opt in. If you choose to consent to allow Functionality and Advertising Cookies our third party service providers may collect data about your visit, the links you clicked on, and the URLs you visited. This data can help us improve site navigability and assess our Marketing campaigns.
NOTE: Our service providers act on Biomeb’s behalf. While we implement procedures and maintain contractual terms with each service provider to protect the confidentiality and security of your data, we cannot guarantee the confidentiality and security of your data due to the inherent risks associated with storing and transmitting data electronically.
- As required by law
Under certain circumstances, your Personal Data may be subject to processing pursuant to laws, regulations, judicial or other government requirements (warrants, orders, etc). Biomeb will preserve and disclose any and all information to law enforcement agencies or others if required to do so by law or in the good faith belief that such preservation or disclosure is reasonably necessary to: (a) comply with legal or regulatory process (such as a judicial proceeding, court order, or government inquiry) or obligations that Biomeb may owe pursuant to ethical and other professional rules, laws, and regulations; (b) enforce the Biomeb Terms of Service and other policies; (c) respond to claims that any content violates the rights of third parties; or (d) protect the rights, property, or personal safety of Biomeb, its employees, its users, its clients, and the public.
6. Your choices
- Access to your account
We provide access to your data within your Biomeb account. If you lose access to your Biomeb account, please contact us for assistance. If you lose access to your Biomeb account, in certain circumstances, we may require that you submit additional information sufficient to verify your identity before providing access or otherwise releasing information to you. If you choose not to submit the required documentation, or the information provided is not sufficient for the purposes sought, Biomeb will not be able to sufficiently verify your identity in order to complete your request.
You may access, correct or update most of your Registration Data on your own within your Account Settings. You may also review and update your consent to Biomeb Research and sample storage choices.
- Marketing communications
You may be asked to opt-in to receive product and promotional emails or notifications when creating your Biomeb account depending on where you are located. Otherwise, you may view or update your email notification preferences by visiting your Account Settings or by contacting our Data Manager at email@example.com. You can also click the “unsubscribe” button at the bottom of promotional email communications.
- Sharing outside of the Biomeb Services
You may decide to share your Personal Data with friends and/or family members, doctors or other health care professionals, and/or other individuals outside of our Services These third parties may use your Personal Data differently than we do under this Privacy Statement. Please make such choices carefully and review the privacy statement of all other third parties involved in the transaction.
In general, Personal Data, once shared or disclosed, can be difficult to contain or retrieve. Biomeb will have no responsibility or liability for any consequences that may result because you have released or shared Personal Data with others.
- Account deletion
If you no longer wish to participate in our Services, or no longer wish to have your Personal Data be processed, you may delete your Biomeb account and Personal Data within your Account Settings. This process cannot be cancelled, undone, withdrawn, or reversed. When your account is deleted, all associated Personal Data is deleted and any stored samples are discarded, subject to the following limitations:
- Data previously included in Biomeb Research. As stated in any applicable Consent Document, Metabolomic Data and/or Self-Reported Data that you have previously provided and for which you have given consent to use in Biomeb Research cannot be removed from ongoing or completed studies that use that data.
- Legal Retention Requirements. Biomeb will retain your Metabolomic Data, date of birth, and sex as required for compliance with applicable legal obligations. Biomeb will also retain limited data related to your account and data deletion request, including but not limited to, your email address, account deletion request identifier, and record of legal agreements for a limited period of time as required by contractual obligations, and/or as necessary for the establishment, exercise or defence of legal claims and for audit and compliance purposes.
7. Security measures
Biomeb takes seriously the trust you place in us. To prevent unauthorized access or disclosure, to maintain data accuracy, and to ensure the appropriate use of data, Biomeb implements physical, technical, and administrative measures to safeguard your Personal Data.
- Biomeb produces secure applications by design. Biomeb incorporates explicit security reviews in the software development lifecycle, quality assurance testing and operational deployment.
- De-identification. Registration Data is stripped from Sensitive Data, including Metabolomic and Self-Reported Data. This data is then assigned a randomly generated ID so an individual cannot reasonably be identified.
- Encryption. Biomeb uses industry standard security measures to encrypt Sensitive Data both at rest and in transit.
- Limiting access to essential personnel. We limit access to Personal Data to authorized personnel, based on job function and role. Biomeb access controls include multi-factor authentication, single sign-on, and strict least-privileged authorization policy.
- Managing third party service providers. Biomeb requires service providers to implement and maintain accepted industry standard administrative, physical and technical safeguards to protect Personal Data.
Your Responsibility. Please recognize that protecting your Personal Data is also your responsibility. We ask you to be responsible for safeguarding your password, and other authentication information you use to access our Services. You should not disclose your authentication information to any third party and should immediately notify Biomeb of any unauthorized use of your password. Biomeb cannot secure Personal Data that you release on your own or that you request us to release.
Your data collected through the Service may be stored and processed in Europe or any other country in which our Data Service Providers maintain facilities and, therefore, your data may be subject to the laws of those other jurisdictions which may be different from the laws of your country of residence.
8. Children's privacy
Biomeb is committed to protecting the privacy of children as well as adults. Neither Biomeb nor any of its Services are designed for, intended to attract, or directed toward children under the age of 18. A parent or guardian, however, may collect a blood sample from, create an account for, and provide information related to, his or her child. The parent or guardian assumes full responsibility for ensuring that the information that he/she provides to Biomeb about his or her child is kept secure and that the information submitted is accurate.
9. Linked websites
Biomeb provides links to third party websites operated by organizations not affiliated with Biomeb. Biomeb does not disclose your data to organizations operating such linked third party websites. Biomeb does not review or endorse, and is not responsible for, the privacy practices of these organizations. We encourage you to read the privacy statements of each and every website that you visit. This Privacy Statement applies solely to data collected by Biomeb and our service providers on our behalf.
10. Direct marketing
We will obtain your consent where required to send you marketing communications using electronic means. You may withdraw your consent at any time within your Account Settings or by emailing firstname.lastname@example.org We will only contact you by electronic means (email, push notification, etc.) with information about our Services that are similar to those which were the subject of a previous sale or negotiations of a sale to you.
We will only share your Personal Data with third parties for marketing purposes with your explicit consent. If you do not want us to use your Personal Data in this way, please contact us at email@example.com. You may raise such objection with regard to initial or further processing for purposes of direct marketing at any time and free of charge. The withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
Other marketing activities will happen based on the legitimate interests. E.g. where we tailor marketing communications or send targeted marketing messages via post, phone or social media and other third party platforms; and in providing existing customers with information (via email or other channels) about similar products and services.
11. Privacy rights
You can exercise your privacy rights by following the instructions below or contacting us at firstname.lastname@example.org. We will handle your request under applicable law. When you make a request, we may verify your identity to protect your privacy and security.
- Right to withdraw consent. To the extent Biomeb requests and you provide your consent to the processing of your Personal Data, you can withdraw your consent at any time. Your withdrawal will not affect the lawfulness of our processing based on consent before your withdrawal.
- Right of access to and rectification of your Personal Data. Our site allows you to access and rectify certain Registration Data within your Account Settings, and your Self-Reported Data by going to the surveys page. You can download your raw Metabolomic Data by going to “Tools.” If you would like to access or rectify any other data, contact Customer Care and we will do our best to provide it to you without undue delay. We may reject part or all of your request if responding to your request could adversely affect the rights and freedoms of others.
- Right to erasure (or, “Right to be Forgotten”). we allow our customers to delete their accounts at any time. You can request erasure of Personal Data that: (a) is no longer necessary in relation to the purposes for which it was collected or otherwise processed; (b) was collected in relation to processing to which you previously consented, but later withdrew such consent; or (c) was collected in relation to processing activities to which you object, and there are no overriding legitimate grounds for our processing. If we have made your Personal Data public and we are required to erase such Personal Data, we will, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the Personal Data that you have requested the erasure by such controllers of any links to, or copy or replication of, such Personal Data. Our assistance with your request for erasure is subject to limitations by relevant data protection laws.
- Right to data portability. If we process your Personal Data based on a contract with you or based on your consent, or the processing is carried out by automated means, you may request to receive your Personal Data in a structured, commonly used and machine-readable format, and to have us transfer your Personal Data directly to another “controller”, where technically feasible, unless exercise of this right adversely affects the rights and freedoms of others. A “controller” is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of your Personal Data.
- Right to restriction of our processing. You can restrict our processing of your Personal Data where one of the following applies: (a) you dispute the accuracy of Personal Data processed by Biomeb (for a period enabling us to verify its accuracy); (b) the processing is unlawful and you oppose the erasure of the Personal Data and request the restriction of its use instead; (c) Biomeb no longer needs the Personal Data for the purposes of the processing, but it is required by you for the establishment, exercise or defence of legal claims; and (d) you have objected to certain processing relying on legitimate interest, pending the verification whether Biomeb legitimate grounds override your rights. Restricted Personal Data shall only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest. We will notify you if the restriction is lifted.
- Notification of erasure, rectification and restriction. We will provide notice to each recipient that we disclosed your Personal Data to regarding any rectification or erasure of Personal Data or restriction of processing, unless you initiated the disclosure or providing notice proves impossible or involves disproportionate effort. Upon your request, we will share the list of recipients with you.
- Right to object to processing. Where the processing of your Personal Data is based on consent, contract or legitimate interests described under Legal Bases for Processing heading above, you may restrict or object, at any time, to the processing of your Personal Data as permitted by applicable law. We may continue to process your Personal Data if it is necessary for the defence of legal claims, or for any other exceptions permitted by applicable law.
- Automated individual decision-making, including profiling. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you, except as allowed under applicable data protection laws.
- Retention of your Personal Data. Unless you make a request for us to delete your account or delete certain Personal Data (i.e., User Content, etc.), we will store your Personal Data as long as your account is open. If you request to delete your account, we will take the steps described under “Your Choices – Account Deletion” and delete all your Personal Data, unless a longer retention period is required or permitted by law.
The rights described above may be limited by local laws. Further, your right of access and deletion is not absolute and may not be available if fulfilment of such right would, among other things:
- cause interference with execution and enforcement of the law and legal private rights (such as in the case of the investigation or detection of legal claims or the right to a fair trial);
- breach or prejudice the rights of confidentiality and security of others;
- prejudice security or grievance investigations, corporate re-organizations, future and ongoing negotiations with third parties, the compliance with regulatory requirements relating to economic and financial management; or
- otherwise violate the interests of others or where the burden or cost of providing access would be disproportionate.
If you believe that we have infringed your rights, we encourage you to contact us so that we can try to address your concerns or dispute informally. Our contact information is:
Att. Data Protection Officer
Dietary Molecular Diagnostics SL
Parc Científic i Tecnològic Agrolimentari, núm 23 A
25003 Lleida (Spain)
13. Changes to this privacy statement
Whenever this Privacy Statement is changed in a material way, a notice will be posted to user accounts as part of this Privacy Statement and on our website or by email to existing users if appropriate. Please access your account and/or this page regularly. A continued access to your account or use of the Services after effective date will mean that you agree to any changes.