ATTAYN LIVE– Privacy Statement

Introduction

At Attayn Live, we make your privacy a central part of our Services. This privacy statement explains our collection, use, and disclosure of Personal Information.


This privacy statement applies to Attayn Live. and our controlled affiliates and subsidiaries. References to our “Services” in this statement include our websites, apps, software, and related services. This statement applies to our products that display or reference this statement. You’ll also find information about how you can exercise your privacy rights. By using our Services, you agree to Attayn Live using your personal information as described in this Privacy Notice.


This Privacy Notice is incorporated into our Terms of Use. By using the Site, you acknowledge that you have read, understand, and accept the Terms of Use, including this Privacy Notice. If you use this site as an employee or member of an organization, this site may also be operated pursuant to any agreement we may have with your employer, association or group sponsor, or benefit program sponsor.

This statement however does not apply to any third-party products that display or reference a different privacy statement.

Summary

  • How we collect information

    We collect your personal information when you interact with us or use our services, such as when you use our Sites to place an order. We also look at how visitors use our Sites, to help us improve our services and optimize the customer experience.


  • Information we collect from you and why

    The personal data we collect depends on how you interact with us, the products you use, and the choices you make. We collect information about you from different sources and in various ways when you use our products, including information you provide directly, information collected automatically from third- party data sources and data we infer or generate from other data.


    A. Information you provide directly and voluntarily.

    We collect the personal data you provide to us. For example, we collect your contact information including name, email address, phone number, username, and password when you create an account or purchase a Service from us. If you make a purchase, we also collect credit card numbers and other payment information through our payment processor.

    B. Contacting Us

    You may also provide us with other information when interacting with us by email, phone call, via Attayn Live Support, or through other methods of communication. This may include feedback and customer support inquiries. This also includes your preferences for receiving communications about our activities, events, and publications.

    C. Surveys

    We also collect voluntary information through surveys. Basic information surveys may collect personal traits and characteristics such as sex, age, ethnicity, weight, and height. This may also include behavioral and social information such as your occupation, commute, diet, alcohol consumption, and tobacco use, fitness and exercise, and sleep behavior. Health surveys may collect more detailed information about your present or past physical or mental health, medical conditions, diseases, and symptoms, and other medical information.

    D. Genetic Information

    Through your use of the services, you may voluntarily submit saliva and/or blood sample. DNA is then extracted from your blood and/or saliva at one of our partner labs and is converted to a machine-readable code (“DNA Data”) which is used to provide our Gene Sequencing Services. DNA test kit code, year of birth, and sex may also be collected for activation purposes.

    Information Categories

    Information CategoryDescription
    Registration Information
    • Your Name
    • Your Email
    • Account Password
    • Phone Number (optional)
    Payment Information
    • Shipping and Billing address
    • Credit card information
    Feedback and CorrespondenceInformation you provide when interacting with us by email, phone call, via Attayn Live Support, or through other methods of communication. This also includes your preferences for receiving communications about our activities, events, and publications.
    Survey Information (self-reported)
    • Basic Information Survey: This includes personal traits and characteristics such as sex, age, ethnicity, weight, and height.
    • This also includes behavioral and social information such as your occupation, commute, diet, alcohol consumption, and tobacco use, fitness and exercise, and sleep behavior.
    • Health Surveys: Information about your present or past physical or mental health, medical conditions, diseases and symptoms, and other medical information.
    Genetic InformationDNA extracted from your saliva at one of our partner labs is converted to a machine-readable code ("DNA Data") which is used to provide our Gene Sequencing Services.
    DNA Kit Activation Information
    • DNA test kit code
    • Year of birth
    • Sex

    E. Information collected automatically

    When you use our products, some information is collected automatically. For example, when you visit our websites and interact with us, our web servers automatically log your device's operating system, Internet Protocol (IP) address, access times, browser type and language, the website you visited before our site, and your activity on our websites.


    Depending on your device and app settings, we use various tools to enhance your user experience when you use our apps or online services. Our websites and online services store retrieve data using cookies and similar tracking technologies set on your device. We may also use cookies and web beacons to collect information from third parties (such as Google) to help advertise our products and services, to analyze the effectiveness of our marketing or the performance of our websites, and to determine whether you may be interested in other products or services. You can refuse to accept and delete cookies by adjusting your browser setting. Please note that refusing or deleting cookies may impact your browsing experience on our websites, or prevent you from using some of its services, and it may result in the deletion of any preferences you have set. For more information on cookies and how to reject or delete cookies please visit our Cookies Notice.


    We also log information about your use of the Services, including your interactions with the Services and histories of your transactions, and the parties with whom you’ve shared your genetic information.

    F. Information provided by representatives or Third parties

    We may collect information from you, your representative, your employer, association, group, or benefit program sponsor, and/or third parties that have roles in delivering services to you, your employer, association, group, or benefit program sponsor. These may include insurance companies, plan administrators and vendors, brokers or agents, credit agencies, and financial institutions. You might provide this information when you visit this site; apply for insurance coverage; enrol in an association, group, or benefits program; communicate with us through email, chat, and instant messenger; speak to an Attayn Live representative by phone or in a call center, or send mail/faxes to our office. In addition, your employer, association, group, or benefit program sponsor or someone acting on their behalf may provide us with information about you.


    Note: If you supply us with personal information about other people, you represent that you have the authority to provide this information on their behalf. In these instances, you further represent that the individuals to whom this information relates have been informed of and understand the reason(s) for obtaining the information, the manner in which this information will be used and disclosed and have consented to such use and disclosure.

    G. Information created or generated.

    We infer new information from other data we collect, including using automated means to generate information about your likely preferences or other characteristics. For example, Google Analytics aids us in inferring your city, state, and country location based on your IP address. We also generate your DNA sequence from your saliva sample with assistance from our lab partners.

    When you are asked to provide Personal Information, you may decline. But if you choose not to provide or allow information that is necessary for certain products or features, those products or features may not be available or function correctly.

  • Use of Data

    A. Generally: to provide you with our Services and analyze and improve our Services.

    We use your data to provide, personalize, analyze, and improve our Services and as otherwise described in this statement or otherwise disclosed to you. These activities include, among other things, using your information to:

    • Open your account and to your payments. More generally, we use your data to enable the use of our website including the authentication of your site visits, providing personalized content, and personalizing your use of the Services;
    • Build new services and improve existing services;
    • Provide customer support and respond to your questions;
    • Communicate with you about purchases, your account, and any relevant information about our Services (e.g., product updates, policy changes, or security issues).
    • Enforce our Terms of Service or any other agreements between you and Attayn Live;
    • Detect, investigate, and protect against prohibited or illegal behaviors on our Services including combatting spam and other security risks; and
    • Perform research & development activities including but not limited to, conducting statistical data analysis and research.
    • To market new products and offers from Attayn Live and our partners as well as provide personalized advertising to you based on your interests.

    In carrying out these purposes, we combine data we collect from different sources to give you a more seamless, consistent, and personalized experience.

    B. Genetic Results: to process, analyze and deliver your genetic results.

    To receive results from our Services you must first create an Attayn Live account, register your kit, and submit your saliva sample to our contracted laboratories which then analyze your samples and provide us with the resulting data. Attayn Live uses your Genetic Information for these primary purposes:


    • Analyze Genetic Information to provide you with information on:
      • your ancestry and ethnicity
      • the makeup of your oral microbiome
      • other insights into what your DNA reveals about your traits, personal health, and wellness, based on this information we may also invite you to participate in certain surveys which are entirely optional, and
      • customize the Attayn Live Library according to genetic profile.
    • Study aggregated Genetic Information to provide more accurate ancestry results and oral microbiome and polygenic score percentiles.
    • Improve features and functionality in our existing Services, as well as build new products to add to our Services and ultimately better serve you.
    • Conducting scientific, statistical, and historical research.

    C. Blockchain Ledger

    Attayn Live uses blockchain technology to improve transparency and control over genetic data. We are currently in the process of developing our blockchain infrastructure to record user consent settings and requests for access to user data. This will be designed to increase transparency and immutability of data access requests and user consent for sharing data. By storing data requests and consent settings on the blockchain, Attayn Live hopes to enable users to audit any transactions involving their data to ensure that all of the data sharing is acceptable, and no misuse of data has taken place.

  • Who do we share your data with?

    A. Information we share with third parties:

    Attayn Live is committed to transparency in data sharing and giving you certain control over when and how your genetic data is shared. We only share your Personal Information, including your Genetic Information with third parties with your explicit permission, as necessary to complete your transactions or provide the products you have requested or authorized, or as otherwise described in this Privacy Statement. We may share personal data with our subsidiaries and affiliates that share common data systems and process data as needed to provide our products and operate our business. We do and will continue to, develop our Services around these principles. In the spirit of transparency, the circumstances described below explain when sharing might occur.

    B. When you choose to share your information through sharing features:

    As part of our Services, you have the option to share your Genetic Information with others through sharing features in the Services. This includes, but is not limited to, sharing your genetic reports or ancestry information with others on social media platforms such as Facebook.

    Note: If you decide to share details about your ancestry, traits, or any other information through these sharing features, you do so at your own risk. We encourage you to review the privacy statements of these third parties before using these features.

    C. Sharing your Genetic Information for Research Purposes:

    You will have the choice to participate in Attayn Live research. Attayn Live research may be conducted by Attayn Live in partnership with third parties such as non-profit foundations, academic institutions, or pharmaceutical companies; or similar third parties independently performing research with Attayn Live facilitating access to the data. These studies may focus on a specific group or population, identify potential areas or targets for therapeutics and drug discovery, genetic research to help in further understanding the relationship between health and the human genome, and ultimately apply all this knowledge to improve healthcare.

    Attayn Live is not currently engaged in sharing your data with any researchers. In the nearest future, as the opportunity for you to connect with researchers arises, we will ensure either having acquired the proper consent from you for such sharing or in turn will reach out to see if you are interested in engaging in Attayn Live’s research.

    D. Service Providers

    We work with other companies to provide our Services. In turn, we share information with these third-party services providers as necessary for them to provide their services to us and help us perform our contract with you. These third parties support our Services in several ways, including the following areas:

    • Order fulfillment and shipping
    • Payment processing
    • Our gene sequencing and processing labs
    • Customer care support
    • Cloud storage, IT, and security
    • Marketing and analytics

    E. Aggregate Information

    We may use personal data in our possession to create de-identified and aggregated data sets. In other words, some of the data that we collect from you is stripped of all information that may be used to identify an individual and is stored in a data set in combination with other users’ de-identified data. We may then use this aggregate data for any purposes or disclose it to third parties for their purposes in accordance with applicable laws. For example, we use Aggregate Information to provide statistical information such as our users’ Oral Microbiome percentiles.

    F. Law Enforcement

    Attayn Live will not voluntarily share your genetic information with law enforcement. However, under certain circumstances, your genetic information may be subject to processing pursuant to laws, regulations, or judicial or governmental orders, warrants, or subpoenas. In other words, a lawful demand by public authorities may require that we share your Personal Information.

    Attayn Live will not share any other categories of Personal Information, other than to cooperate with law enforcement, protect the safety of persons or property, or in enforcing ours, our affiliates or partners’ legal rights. For example, if a user defrauds our Services, we may share that user’s personal information with law enforcement in an effort to recuperate the defrauded costs.

    If we are compelled to disclose your Personal Information, we will do our best to provide you with advance notice, unless we are prohibited under the law from doing so. In the spirit of transparency, we will produce a Transparency Report to provide disclosure of the number of valid law enforcement requests for user data across all of our Services.

    G. Other Legal Disclosures

    We may share your personal data if we believe it is reasonably necessary to enforce the Attayn Live Terms and Conditions, protect the security and integrity of our Services, or protect the rights, safety, or property of Attayn Live, our employees, or users.

    H. Business Purposes

    In the event that Attayn Live is acquired or transferred including in connection with a corporate transaction, bankruptcy, or similar proceedings (including financing, merger, acquisition, dissolution, or a transfer, divestiture, or sale of a portion or all of our business or assets), we will share your personal data Information with the acquiring or receiving entity as a part of the transaction or negotiation for such a transaction. Nonetheless, the promises of this Privacy Statement will continue to apply to your personal data that is transferred to the new entity.

  • Choice and Control of Personal Data
    • Access, Correction, and Deletion of your Personal Information. Attayn Live will allow you to access and correct your registration information within the account settings and your Self-Reported Information by going to the specific survey page and changing any answers previously reported. This will not delete your prior entry for the specific survey response. To permanently delete any prior response for reasons such as inaccuracy, you may reach out to the Attayn Live team at [email protected] and request to have any health survey responses deleted. You may initiate deletion of certain personal data by emailing [email protected] with your request.  If you would like to request access, correction, or deletion of any other information, contact [email protected] and we will do our best to assist you without undue delay. However, to the extent permitted by applicable law, we reserve the right to charge a fee or decline requests that are unreasonable or excessive, where providing the data would be prohibited by law or could adversely affect the privacy or other rights of another person, or where we are unable to authenticate you as the person to whom the data relates.
    • Communications preferences. You can choose whether to receive promotional communications from us by email. If you receive promotional emails from us and would like to stop, you can do so by following the directions in that message. These choices do not apply to mandatory service communications that are part of certain products, or to surveys or other informational communications that may have their own unsubscribe method.
    • Sale of Genetic Data to Researchers. See the Sharing your Genetic Information for Research Purposes section for choices about selling your data.
    • Choices for Cookies and Similar Technologies. See the Cookies section for choices about cookies and other analytics and advertising controls.
    • Do Not Track. Some browsers have incorporated "Do Not Track" (DNT) features that can send a signal to the websites you visit indicating you do not wish to be tracked. Because there is not a common understanding of how to interpret the DNT signal, our websites do not currently respond to browser DNT signals. Instead, you can use a range of other tools to control data collection and use, including the cookie controls and advertising controls described above.
  • EUROPEAN DATA PROTECTION RIGHTS

    If the processing of personal data about you is subject to European Union data protection law, you have certain rights with respect to that data:

    • You can request access to, and rectification or erasure of, personal data;
    • If any automated processing of personal data is based on your consent or a contract with you, you have a right to transfer or receive a copy of the personal data in a usable and portable format;
    • If the processing of personal data is based on your consent, you can withdraw consent at any time for future processing;
    • You can object to, or obtain a restriction of, the processing of personal data under certain circumstances; and
    • For residents of France, you can send us specific instructions regarding the use of your data after your death.

    To make such requests or contact our Data Protection Officer, you can follow the directions outlined in this privacy statement or contact us at [email protected] You also have the right to lodge a complaint with a supervisory authority, but we encourage you to first contact us with any questions or concerns.

    We rely on different lawful bases for collecting and processing personal data about you, for example, with your consent and/or as necessary to provide the products you use, operate our business, meet our contractual and legal obligations, protect the security of our systems and our customers, or fulfill other legitimate interests.

  • UK DATA PROTECTION RIGHTS

    If you are resident in the United Kingdom, we guarantee the protection of your data in line with the provisions of the GDPR. As such, we shall observe the following principles;

    • Processing shall be lawful, fair, and transparent to the data subject.
    • We will process your data for the legitimate purposes specified explicitly to the data subject when you collected it
    • We will collect and process only as much data as absolutely necessary for the purposes specified.
    • All personal data shall be kept accurate and up to date.
    • We will only store personally identifying data for as long as necessary for the specified purpose.
    • Our processing shall be done in such a way as to ensure appropriate security, integrity, and confidentiality (e.g. by using encryption) i.e.
      • By implementing appropriate technical and organizational measures including requiring our employees to use two-factor authentication on accounts where personal data are stored to contracting with cloud providers that use end-to-end encryption.
      • Organizational measures such as staff trainings, adding a data privacy policy to our employee handbook, or limiting access to personal data to only those employees in our organization who need it.
      • In the highly unlikely event that there is a data breach, we shall within 72 hours notify the data subjects although we have implemented enough safeguards, including data encryption to render data useless to a hacker or other hostile intruder.
    • We will be responsible for being able to demonstrate GDPR compliance with all of these principles i.e.
      • Designate data protection responsibilities to our team.
      • Maintain detailed documentation of the data we are collecting, how it is used, where it is stored, which employee is responsible for it, etc.
      • Train our staff and implement technical and organizational security measures.
      • Have Data Processing Agreement contracts in place with third parties we contract to process data for us.
      • Appoint a Data Protection Officer where necessary.

    We also recognize your data protection rights to wit:

    • The right to be informed
    • The right of access
    • The right to rectification
    • The right to erasure
    • The right to restrict processing
    • The right to data portability
    • The right to object
    • Rights in relation to automated decision making and profiling.
  • INDIAN DATA PROTECTION RIGHTS

    If you are resident in India, we guarantee the protection of your data in accordance with the following laws;

  • Our Data Retention Policies (FOR THE US AND REST OF THE WORLD)

    We retain personal data for as long as necessary to provide the products and fulfill the transactions you have requested, comply with our legal obligations, resolve disputes, enforce our agreements, and other legitimate and lawful business purposes. Because these needs can vary for different data types in the context of different products, actual retention periods can vary significantly based on criteria such as user expectations or consent, the sensitivity of the data, the availability of automated controls that enable users to delete data, the existing data laws in the relevant region(s) and our legal or contractual obligations. For example, all of the data collected by Google Analytics for the purposes understanding our website usage is automatically deleted after 26 months, all mobile identifiers and cookie identifiers placed by Adroll expire and are then deleted after 13 months, and the Recent User Activity feed collected by Hotjar are retained for 1 year.

    Attayn Live will store your account profile information, including your raw genetic data, health surveys, and related reports and information, as long as your account is open, unless you make a request for us to delete all or any of your information prior to the closing of your Account as described in this privacy statement. If you decide to close your Account, then Attayn Live will automatically destroy this personal data related to your account. In specific circumstances such as by court order, subpoena, or other legal or regulatory obligations, however, Attayn Live may be required by law to store your information beyond the deletion of your Account or request for deletion of Personal Information. Attayn Live may also retain disaster recovery copies for a fixed period following this deletion, although this data will not be used for any purpose other than disaster recovery.

    You may access and delete or change much of your information through your Account Settings. Otherwise, any information that is not accessible in your Account Setting can be accessed and changed or deleted by reaching out to [email protected]

  • Security

    Attayn Live maintains a comprehensive information security program designed to protect your Personal Information through the use of many safeguards. Attayn Live has measures in place designed to protect against inappropriate access, loss, or misuse of Personal Information. For example, we use secure server software to encrypt Personal Information and work with data storage cloud partners that meet our security standards.

    While we cannot guarantee that loss, access, or misuse of data will not occur, we use reasonable efforts to prevent these outcomes. We also undertake to notify you as soon as practicable – usually within 72 hours of the breach – where there has been a data breach. To help us protect Personal Information, we request that you use a strong password and never share your password with anyone or use the same password with other sites or accounts.

  • Data Location and Transfer and Privacy Shield Notice

    The personal data we collect may be stored and processed in your country or region, or in any other country where we or our affiliates, subsidiaries, or service providers maintain facilities. Currently, we primarily use data centers in the United States. The storage location is chosen to operate efficiently and improve performance. We take steps designed to ensure that the data we collect under this statement is processed according to the provisions of this statement and applicable law wherever the data is located.

    Location of Processing European Personal Data We transfer personal data from the European Economic Area and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level of data protection. When we do so, we use a variety of established transfer mechanisms such, as the Privacy Shield or contracts, to help ensure your rights and protections. To learn more about the European Commission’s decisions on the adequacy of personal data protection, please visit: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers- outside-eu/adequacy-protection-personal-data-non-eu-countries_en.

    Privacy Shield Attayn Live participates in and has certified its compliance with both the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred to the United States from the European Union (EU), European Economic Area (EEA), and Switzerland. To learn more about the Privacy Shield program, and to view our certification, please visit the U.S. Department of Commerce’s Privacy Shield List.

    We are committed to subjecting all personal data that we receive from the EU member countries, the EEA, and Switzerland to the Privacy Shield Framework Principles in the European Union Data Protection Rights section above. If third- party agents process personal data on our behalf in a manner inconsistent with the principles of either Privacy Shield Framework, they remain liable unless they prove we are responsible for the event giving rise to the damage. If there is any conflict between the terms of this Privacy Statement and the Privacy Shield Principles, the Privacy Shield Principles shall govern.

    Regarding personal data received or transferred pursuant to the Privacy Shield Frameworks, Attayn Live is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission (FTC). Further, in certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

    If you have a question or complaint related to our participation in the EU-U.S. or Swiss-U.S. Privacy Shield, please contact us as indicated at the bottom of this privacy statement. For any complaints related to the Privacy Shield frameworks that cannot be resolved with us directly, you may refer the matter to your local Data Protection Authority or the Swiss Federal Data Protection and Information Commissioner (FDPIC) if you are located in Switzerland. Finally, under limited circumstances and after other available dispute resolution mechanisms have been exhausted, binding arbitration is available for EU and Swiss individuals to address certain residual complaints not resolved by other means.

  • Changes to this Statement

    We will update this privacy statement when necessary to reflect changes in our products, how we use Personal Information or the applicable law. When we post changes to the statement, we will change the "Last Updated" date at the top of the statement.  If we make material changes to the statement, we will provide notice or obtain consent regarding such changes as may be required by law.

    The Privacy Statement is subject to change at any time. If we make changes to this Privacy Statement, we will update the “Effective date” at the top of this page. Any changes we make to this Privacy Statement become effective immediately, so you should review this Privacy Statement regularly for changes.

  • How to Contact Us

    In compliance with the Privacy Shield Principles, Attayn Live commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Attayn Live at: [email protected]

    Attayn Live has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved Privacy Shield complaints concerning data transferred from the EU and Switzerland.

    Our address is: Attayn Live, 30 N Gould Street, Suite R, Sheridan WY 82801.