We take the privacy and confidentiality of data subjects and visitors seriously. That is why we pledge to respect the privacy of personal data, to remain transparent and to keep your data safe.
SOPHiA GENETICS SA, which is headquartered at Rue du Centre 172, 1025 Saint-Sulpice, Switzerland and its subsidiaries, including without limitation SOPHiA GENETICS SAS, SOPHiA GENETICS LTD, SOPHiA GENETICS, Inc. and SOPHIA GENETICS EIRELI, process personal data as part of its relations with the visitors, prospects, partners or applicant and more generally any users of the website www.sophiagenetics.com (the “Website”).
2. SOPHiA GENETICS is a global company headquartered in Switzerland
Our headquarter is in Switzerland. You acknowledge and consent that any data you provide or we may collect may be used, processed, and/or transferred to Switzerland or other countries or territories as permitted under applicable law.
This Policy does not cover the following elements of data:
1. The receipt, creation, or analysis of genomic or other data derived from people (such as through customer’s use of SOPHiA® DDM Platform or any other SOPHiA GENETICS’ products or services);
2. Genotyping and sequencing services for research purposes;
3. The receipt and storage of clinical and administrative data;
4. The receipt and storage of radiomics images.
4. Categories of data we collect
We collect various types of data. As used herein, "Personal Data" means any information relating to an identified or identifiable person, who can be identified directly or indirectly.
We may collect the following categories of Personal Data:
1. Personal Data concerning the identity of visitors, prospects or partners contacting SOPHiA GENETICS via the Website's contact form, including: first names, last names, email address, phone numbers, country, contact reason and your message. These Personal Data are necessary to process your request. Each contact form limits the collection of Personal Data to what is necessary and indicates the required information to provide.
2. Personal Data concerning the identity of applicant applying to SOPHiA GENETICS’ job offer including: first names, last names, email address, phone numbers, residence address, photography, birth date, nationality, residence permit, professional and academic background, CVs, cover letter, etc. These Personal Data are necessary to process your application. Each job offer form limits the collection of Personal Data to what is necessary and indicates the required information to provide.
3. Personal Data concerning cookies, connection data and other piece of information generated by a web server of visitors of the Website. Click here for more information relating to the Cookies processing.
5. Legal basis and purposes of processing of your Personal Data
We may process your Personal Data in accordance with the following legal bases:
1. the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, with regard to processing operations for the purpose of performance of contract, of marketing operations, monitoring of relationship between SOPHiA GENETICS and its customer, prospect, partner and applicant;
2. the legitimate interest pursued by SOPHiA GENETICS, with regard to processing operations for the purpose of compiling statistics, marketing, promoting and improving SOPHiA GENETICS’ products and services, the defense of SOPHiA GENETICS’ rights and interests;
3. compliance with legal obligations applicable to SOPHiA GENETICS, with regard to processing for invoicing and accounting purposes or the management of requests for the exercise of rights of the data subject.
6. Sharing of your Personal Data
As a general rule we do not provide, sell, or lease your Personal Data to any third parties for their marketing use without your express consent.
6.1 Service Providers
We may rely on various third-party service providers and contractors to provide services that support the Website and our operations, including, without limitation, maintenance of our databases, distribution of emails and newsletters on our behalf, data analysis, payment processing and other services of an administrative nature. Such third-parties may have access to your Personal Data for the purpose of performing the service for which they have been engaged. However, such third-party providers shall remain under contractual obligations, particularly confidentiality obligations, for as long as they hold Personal Data from us.
6.2 Compliance with Laws and Law Enforcement
SOPHiA GENETICS cooperates with government and law enforcement officials and private parties to enforce and comply with the law. We may be required to disclose an individual’s Personal Data in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
6.3 Business Transfers
We may transfer your Personal Data to a third-party in the event of any corporate reorganization, merger, sale, joint venture, assignment, transfers, or other disposition of all or any portion of SOPHiA GENETICS' business, assets, or stock.
6.4. External transfers of Personal Data in accordance with GDPR
To ensure compliance with the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”) and applicable data protection law, we may not transfer your Personal Data to countries outside the European Union without adequate level of protection. In the event of a transfer to a country whose legislation has not been recognized by the European Commission as providing an adequate level of protection within the meaning of the applicable data protection legislation, we undertake to sign with the recipient a data transfer contract including the standard contractual clauses of the European Commission.
7. Storage of your Personal Data
We may keep your Personal Data for no longer than is necessary for the purposes for which the Personal Data is processed. In this respect, Personal Data relating to our customers and/or partners shall be kept for the entire duration of our contractual relationship, plus an additional three (3) years to promotional use, without prejudice to any retention obligations or limitation periods. Personal Data concerning our prospect shall be kept for three (3) years from the time they are collected or from the last contact sent by the prospect, without prejudice to any retention obligations or limitation periods. Personal Data concerning our applicant shall be kept for two (2) years from the time they are collected or from the last contact sent by the applicant, without prejudice to any retention obligations or limitation periods.
8. Your rights
In accordance with GDPR and applicable data protection laws, you may access, review, update, correct, delete, restrict, object and request data portability pertaining to your Personal Data. You may also file a complaint with a data protection authority, if you consider that any processing of your Personal Data infringes the requirements of the applicable data protection law. However, we invite you to contact us prior to doing so. If you would like to exercise one of your rights, please contact us at privacy(at)sophiagenetics.com, with a copy of your identification card or any valid identification document with a signature.. We may retain an archived copy of your request in accordance with GDPR and applicable data protection laws.
9. Limited use in our email list
If you no longer wish to receive new notices, email newsletters or other future promotional communications from us, you may choose to unsubscribe by clicking on the link at the bottom of any such communication and following the instructions thereto. Alternatively, you may notify us by email at privacy(at)sophiagenetics.com with the word "remove" in the subject header, and we will remove your name from our email recipient list, within five (5) days notice. Opt-out is not possible for necessary service or other administrative and transactional notices.
11. Security of your Personal Data
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk concerning your Personal Data.
The Website is not directed towards persons under the age of 16. We do not knowingly collect Personal Data from minors under the age of 16 that use the Website. If you become aware that a user under the age of 16 has used the Website, please contact SOPHiA GENETICS at privacy(at)sophiagenetics.com. If we become aware that a child under 16 has provided us with Personal Data, SOPHiA GENETICS will take the necessary steps to have that Personal Data irrevocably removed.
13. Your California Privacy rights (for users located in California)
Under California Civil Code Section 1798.83 (known as the “Shine the Light” law), SOPHiA GENETICS customers who are residents of California may request certain information about our disclosure of personal information during the prior calendar year to our affiliates or to third parties their direct marketing purposes. To make such request, please write to us at the following address: SOPHiA GENETICS SA, Rue du Centre 172, 1025 Saint-Sulpice, Switzerland or you may send us an email at privacy(at)sophiagenetics.com.
14. Canada’s CASL (for consumers located in Canada)
15. Your French Privacy rights (for users located in France only)
In accordance with GDPR and Loi Informatique et Libertés, you may define general and specific guidelines defining how you intend to exercise the above-mentioned rights after your death.
16. Contact Us – Data Protection Officer