[NEW] Privacy Policy
Introduction
ELSI Skin Health, Inc. (hereinafter, the “Company”, “HelloBiome”, “Dr. Elsa Jungman”, “DR-EJ”, “we”, “us”, “our”) is a legal entity incorporated under the laws of the State of Delaware (USA), file number 6784855. This Privacy Policy (the “Privacy Policy”) applies to the websites listed below (collectively, the “Websites”), as well as other online products and services that fall under this Privacy Policy (collectively, the “Services”) or when you otherwise interact with us, and explains how HelloBiome collects, processes, and discloses personal information in the following use cases:
(i) “Dr. Elsa Jungman Brand” through:
- https://dr-ej.com/, an e-commerce website that sells cosmetic products under Dr. Elsa Jungman brand, as well as the microbiome test kits; and
- https://my.dr-ej.com/, a microbiome test website on which the user registers their account to activate microbiome tests and complete quizzes that accompany each test and, as a result, receives reports with Dr. Elsa Jungman’s brand product recommendations for each test.
(ii) “HelloBiome White-Label Platform” through the websites the particular domains of which shall be defined by the clients of the HelloBiome White-Label Platform (the “Client(s)”). For example, such Clients’ client-branded microbiome test websites can be located either on one of HelloBiome sub-domains (*.hellobio.me) or the Client’s own domain/sub-domain. In any case, such HelloBiome White-Label Platform websites shall contain references to this Privacy Policy.
Clients may also integrate with HelloBiome through the “HelloBiome Client API” — a server-to-server interface that lets a Client access some of our services data programmatically. This integration takes two forms: (a) as an add-on service to a branded White-Label website, where the Client’s branded White-Label platform remains the interface with its users; and (b) API-only (headless), where the Client operates its own software application and the end-user never interacts with a HelloBiome Websites directly.
(iii) “Claim Study & Research and Analysis” through:
- https://hellobio.me/, a B2B focused website, explaining different services of HelloBiome; and
- https://my.hellobio.me (or other subdomains under the main Domain Name, *.hellobio.me), a microbiome test website on which the research study participants register their account to activate microbiome tests and complete quizzes that accompany each test and receive reports for each test.
Your privacy is important to us. This Privacy Policy outlines how we collect, process, manage the personal data we collect from your use of our Services, through your interaction with us on social media or your other dealings with us.
Should you have any questions or concerns regarding your personal data, please contact us at the contact details provided in Section 11 of the Privacy Policy.
Scope
This Privacy Policy applies to all Websites and Services operated by ELSI Skin Health, Inc. (“HelloBiome”), across the Dr. Elsa Jungman Brand, the HelloBiome White-Label Platform, and the Claim Study & Research and Analysis use cases described above, and to every Data Subject whose personal data HelloBiome processes as a Data Controller or as a Data Processor.
This Privacy Policy does not apply to third-party websites, products, or services that HelloBiome does not control, or to the independent privacy practices of Clients acting as their own Data Controllers. Where HelloBiome acts only as a Data Processor on behalf of a Client, the Client’s own privacy notice governs its relationship with its users.
Where a Data Subject interacts via Client interface, HelloBiome receives no direct identifiers and, in the API-only case, holds no information that lets it resolve a kit to a natural person.
Objectives
This policy aims to:
- explain what personal data HelloBiome collects and the lawful bases on which it is processed
- describe how HelloBiome uses, shares, protects, and retains personal data
- set out the privacy rights available to Data Subjects, including EEA and California residents, and how to exercise them
- provide clear contact channels for privacy questions and data subject requests
Table of Contents
1. Definitions
- Company / HelloBiome: ELSI Skin Health, Inc., a company incorporated under the laws of the State of Delaware (USA), file number 6784855, together with the “Dr. Elsa Jungman” and “DR-EJ” brands operated by it. Referred to in this policy as “we”, “us”, or “our”.
- Websites: the websites listed in the Introduction to which this Privacy Policy applies, including
dr-ej.com,my.dr-ej.com,hellobio.me,my.hellobio.me, other*.hellobio.mesubdomains, and Client-branded microbiome test websites that reference this Privacy Policy. - Services: the online products and services offered through the Websites, together with any other interactions covered by this Privacy Policy.
- Data Subject (also “you”, “your”): an identified or identifiable natural person whose Personal Data HelloBiome processes, including website visitors, customers, website users, and research study participants.
- Personal Data: any information relating to an identified or identifiable natural person.
- Special categories of personal data: personal data revealing health, ethnic origin, or other categories defined in Art. 9(1) GDPR, including microbiome data and skin-, beauty-, and lifestyle-related information.
- Microbiome data: information about the absolute abundance of fungi and bacteria detected in a test sample.
- Client: a business that uses the HelloBiome White-Label Platform to offer microbiome testing to its own users under its own brand and that acts as a Data Controller for those users. A Client is not an individual end-user who takes a test.
- Data Controller: the entity that determines the purposes and means of processing Personal Data.
- Data Processor: the entity that processes Personal Data on behalf of a Data Controller.
- GDPR: the EU General Data Protection Regulation.
- CCPA / CPRA: the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
- EEA: the European Economic Area.
- Cookies: small text files stored on your device that allow the Websites to recognise you and remember your preferences.
- De-identified Data: Personal Data from which identifiers have been removed so that it can no longer be linked to a specific Data Subject without additional information held separately. Distinct from Anonymization, which is irreversible.
- Pseudonymized Data: Personal Data processed so that it can no longer be attributed to a specific Data Subject without additional information that is held separately. Pseudonymized Data remains Personal Data.
- Anonymized Data / Anonymization: the irreversible removal or alteration of identifiers and linkage so that a natural person can no longer be identified from the data by any party, including HelloBiome and the Client. Anonymized Data is not Personal Data and is distinct from De-identified and Pseudonymized Data, which remain re-linkable. Anonymization is carried out in line with the HelloBiome Data Retention Policy and Schedule.
- Kit Identifier (Kit ID): the identifier of a physical test kit. It is not an identifier HelloBiome can resolve to a natural person; in Client API integrations any ability to link a kit to an individual rests solely with the Client.
- Client API: the server-to-server B2B interface (served under secure API gateway) through which a Client can, for example, activates kits, submits quiz answers, and retrieve kit-scoped test results.
- Synthetic Anonymous Account (per-kit): a system-generated account that HelloBiome creates for a single kit where no registered user exists (for example, in the Client API channel). HelloBiome handles each kit under its own such account with no linkage across kits.
- DSR (Data Subject Request): a request by a Data Subject to exercise their rights under Data Protection Laws, handled in accordance with the HelloBiome Data Subject Request Policy.
2. Information We Collect About You
HelloBiome is responsible for the protection of privacy and safeguarding of the personal data of the following categories of Data Subjects (hereinafter, each separately or collectively referred to as “you”, “your” or the “Data Subject(s)”):
| https://dr-ej.com/ | • website visitors • customers |
• email • first name • last name • password • address • age • location • non-identifying information about website visits • payment event data |
|
• website visitors • website users |
• email • first name • password • year of birth • health, beauty, and skin-related information • data revealing ethnic origin • location (zipcode) |
| client-branded microbiome test websites | • other special categories of personal data (as defined in Art. 9(1) GDPR) depending on the set of questions of a particular client • quiz questions about the lifestyle and conditions of the specific body area • microbiome data (containing information about the absolute abundance of fungi and bacteria detected in the test sample) |
|
| client-branded microbiome test websites | • website visitors • website users |
additional data specified by the Client, collected directly from users or from 3rd party systems and authorized to be accessed – as part of custom development (e.g., heart rate variability (HRV) from the fitness bracelet) |
| HelloBiome Client API | • end-users of a Client that integrates through the API, who do not interact with any HelloBiome Website | • kit identifier (Kit ID) • quiz answers about the lifestyle and conditions of the specific body area • microbiome data (containing information about the absolute abundance of fungi and bacteria detected in the test sample) • other special categories of personal data (as defined in Art. 9(1) GDPR) depending on the Client’s quiz • no email, or other direct identifiers are received by HelloBiome; each kit is handled under a separate synthetic anonymous account with no linkage across kits |
| https://hellobio.me/ | • website visitors • website users |
• email • company name • first name • last name • automatically check if returning visit |
3. Purposes For Which We Use Personal Data
HelloBiome, as a Data Controller, may only use your personal data if there is a lawful basis for such use.
The most common lawful bases used by HelloBiome are:
-
- consent: in some cases, we may process your personal data only if we obtain your prior consent;
-
- performance of a contract: we will require your personal data to be able to offer you the Services in accordance with the contract terms between you and us;
-
- compliance with a legal obligation: due to the nature of the Services we provide, the laws applicable to our activities require us to collect and store certain data about you;
-
- legitimate interests: sometimes we rely on our legitimate interests to process your data (e.g., to improve our Services) and we will do so except where such interests are overridden by your interests or fundamental rights and freedoms.
Our role depends on the arrangement. When we deliver the testing Service for a Client — including through the Client API — we act as a Data Processor on that Client’s documented instructions, and the Client is responsible for the lawful basis (such as consent) for its end-users; our obligations in that role are set out in the HelloBiome Personal Data Protection Policy. When we anonymize data and use the anonymized result to develop and train our models and to conduct research, we act as a Data Controller for that purpose, on the basis of our legitimate interests and where our Client contracts permit.
Below you will find a table describing how we may use your personal data and which of the legal bases are used by the Company to ensure lawful data processing.
| Purpose/activity | Personal Data Categories | Lawful Basis for Processing |
|---|---|---|
|
|
|
|
|
|
To communicate with you To contact you with information about:
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you fail or refuse to provide your personal data, we need to provide the Services to you, you will not be able to access the Services.
4. Cookies
We may use cookies for various purposes when you access or use the Services:
-
- to recognise you whenever you use the Website (this speeds up your access as you do not have to log in each time);
-
- to prevent fraud on our Website;
-
- remember your preferences and your device so the Website works as expected;
-
- to provide visitors with the relevant version of the Website;
-
- to assist with our promotional and marketing efforts;
-
- to carry out research and statistical analysis to help improve our content, products, and services and to help us better understand our users’ requirements.
For further information on cookies generally, visit www.aboutcookies.org or www.allaboutcookies.org.
You can adjust your cookie choices using the cookie banner on the Websites, which will appear during your first visit to the Websites.
We will ask for your consent for the use of all non-essential cookies, for instance, functional cookies, targeting cookies or analytical/performance cookies.
Strictly necessary cookies are essential cookies, and they cannot be disabled on the Websites. Unless you choose otherwise, we can store and process only those cookies that are necessary for the operation of our Websites without obtaining your consent. If you don’t want to be tracked by other types of cookies, you can refuse to give your initial consent or opt out later.
5. Sources Of Personal Data
Most of the personal data we process about you is received directly from you. For example, when you register to use the Services or communicate with us, we may receive your account data from you.
In other cases, we may receive personal data about you from various third parties and publicly accessible sources, including, but not limited to, laboratories, banks, payment service providers, advertising networks, analytics providers, etc. Where a Client integrates through the Client API, we receive kit-scoped data from the Client through the API rather than directly from you, and that data does not include your email, or other direct identifiers.
When you use the Services, we may also automatically collect usage data through the use of cookies and similar technologies.
6. How Do We Protect Your Personal Data?
We take all reasonable and appropriate technical and organisational measures to protect all personal data collected by us from loss, theft, misuse, unauthorised access, disclosure, alteration, and destruction.
6.1. Security
Security implemented by design: is realized from the very beginning by controlling all layers of data exchange and storage.
From the Client side, we:
-
- ensure customers access to the reports with strong passwords and secure authentication;
-
- transmit data over HTTPS with up-to-date SHA-256 with RSA Encryption;
-
- minimize security flaws, by implementing the highest security settings as defaults for each user;
-
- avoid Cross-Site Scripting (XSS) attacks by validating all the data input from the users to our servers.
From the server side, we:
-
- strictly separate data and control instructions, and never process control instructions received from untrusted sources;
-
- ensure all data are explicitly validated before processing and storage;
-
- identify sensitive entries in the customer data and how they should be handled;
-
- never store passwords and access credentials in plain;
-
- never track access credentials in code versioning;
-
- avoid SQL injection (SQLi) attacks by validating and formatting all the data input from the client-side request to our servers before using it in a database query.
In our team, we:
-
- work with reliable partners who value privacy and security of the customer data;
-
- ensure all members of our team are well-instructed;
-
- conduct cybersecurity self-assessment regularly;
-
- perform regular software updates and code refactoring as a part of our product development lifecycle;
-
- enforce 2-factor Authentication on key corporate resources.
6.2. Privacy & Confidentiality
-
- we implement a strict policy towards who can access personal data;
-
- we minimize personal data collection to only allow the provision of the service;
-
- we keep personal data confidential and never share it with any third party without the user’s consent;
-
- we only use personal collected information for the purpose we collect it;
-
- provide transparent, clean, user-friendly, and understandable Privacy Policy;
-
- only designated members of our team have access to customer data.
6.3. Reliability
-
- we use AWS, a trusted and certified cloud computing provider (https://aws.amazon.com/security/?nc1=f_cc);
-
- if the system detects a problem with one of the computing nodes, it proactively launches the application to the new computing node, so they are restored to a running and accessible state;
-
- we guarantee 99.5% availability of the service uptime;
-
- we use automated backup of our customer data.
7. How Long Do We Keep Your Personal Data?
We do not share your personal information with third parties, except as described in this Privacy Policy.
HelloBiome does not share any health-related information (i.e., data concerning health, beauty, skin, lifestyle, conditions of the specific body area), microbiome-related information (i.e., data about the absolute abundance of the fungi and bacteria detected in the test sample), data revealing ethnic origin or other special categories of personal data (as defined in Art. 9(1) GDPR) in association with personal data without the explicit consent of the Data Subject.
All personal data is de-identified before sharing. Consent may be collected when sharing of the data that contains identifiers is required to provide the personalized Services. Sharing of the de-identified test results is happening for the research projects and projects where the Data Subjects provide their consent to improve our Services.
The Clients of the HelloBiome White-Label Platform may have access to the personal data because in this case, the Data Subjects directly interact with the Client’s brand while HelloBiome conducts data processing. The Clients in this case will be the Data Controllers of the data and HelloBiome may be both a Data Processor and a Data Controller of the data.
HelloBiome may engage service providers and partners to assist with the delivery of the Services:
Generally, we will retain your personal data for as long as necessary to fulfil the specific purpose we collected it for, including the purpose of satisfying any legal, accounting, reporting requirements and our legitimate interests. For example, most of your data will be retained up to 3 years after the end of the business relationship with us. However, we may need to keep certain information (e.g., payment information) for longer in order to comply with our legal obligations. In certain cases, the authorities may require us to store the personal data longer if they deem necessary (e.g., in case of an ongoing investigation). You may send us a request to delete your personal data using the form, specified in the Contact Information section. We will consider it and delete your data if none of the above grounds obliging us to keep it longer apply.
When we act on a deletion request, we erase all your personal identifiers. We may retain data that has been anonymized so that it can no longer be re-linked to you by HelloBiome and use it for research and model development. Such anonymized data is no longer Personal Data.
8. Your Rights
How you exercise these rights depends on how you interacted with us. If you used a Client’s White-Label Platform, that Client is your first point of contact. Where HelloBiome acts as the Client’s Data Processor, the Client forwards your request to us and we action it. For example, for a deletion request, we erase your identifiers as described in Section “How Long Do We Keep Your Personal Data?”. Where a Client integrates through the Client API, HelloBiome holds no direct identifiers and handles each kit under a separate Synthetic Anonymous Account, so we cannot identify an individual from the data we hold.
8.1. EEA Residents’ Rights
If you are a resident of the EEA, with regards to our collection and processing of your personal data, under the GDPR you have the right to (subject to applicable exceptions):
- Obtain confirmation from us as to whether we process your personal data.
- Access your personal data processed by HelloBiome.
- Correct your personal data.
- Withdraw consent and remove your personal data we collected on the basis of your consent (e.g., to opt out from marketing communications from us).
- Obtain restriction of processing, for instance, where you contest the accuracy of your personal data for a period enabling us to verify the accuracy of the personal data.
- Have your personal data transmitted directly from one controller to another, where technically feasible and when doing so does not adversely affect the rights and freedoms of others.
- Erasure of your personal data under certain circumstances. See more information about our data retention obligations in section “How long do we keep your personal data” above.
- Object to our processing of your personal data, when the processing is related to the performance of our task, carried in the public interest, or the exercise of official authority vested in us.
If you wish to make use of any of the above rights, please contact us stating your name and question related to any of the above rights at the contact details provided in Contact Section of the Privacy Policy.
HelloBiome will endeavour to provide you with information on the actions it has taken on your request related to your rights, specified above, within 1 (one) month of receipt of the request. That period may be extended by 2 (two) further months if the request is complex, or if HelloBiome is in the process of resolving a large number of requests. We will inform you if any such extension is required within 1 (one) month of receipt of the request, together with the reasons for the delay.
8.2. California Residents’ Privacy Rights
Pursuant to the California Consumer Privacy Act (the “CCPA”) as amended by the California Privacy Rights Act, this section applies to certain personal data collected about California individuals where HelloBiome controls how and why the personal data is processed (which the CCPA calls a “business”) and supplements the rest of our Policy above.
The CCPA requires that we detail the categories of personal information that we disclose for certain “business purposes”, such as to service providers that assist us with securing our services or marketing our products, and to such other entities. We collect the personal information for business and commercial purposes as described in the “Purposes for which we use personal data” section above. We share this information as described in the “How do we share your personal data?” section below.
We do not knowingly sell or share any personal data of minors under the age of 16. We do not collect or process “sensitive personal information”, as defined by the CCPA, to infer characteristics about you.
Subject to legal limitations, California residents may have the below rights:
-
- Right to know. You have the right to request information about the categories of personal data we have collected about you, the categories of sources from which we collected the personal data, the purposes for collecting the personal data, the categories of third parties to whom we have disclosed your personal data, and the purpose for which we disclosed your personal data. You may also request information about the specific pieces of personal data we have collected about you.
- Right to delete. You have the right to request that we delete personal data that we have collected from you.
- Right to correct. You have the right to request that we correct inaccurate personal data that we maintain about you.
- Right to opt out of sale or sharing. We do not sell personal data to third parties in exchange for money. You may still email us using the information below to exercise your right to opt out of sale under applicable law. California residents may make a request pursuant to their rights under the CCPA by contacting us at the contact details provided in Contact Section of the Privacy Policy. We will verify your request using the information associated with your account, including email address. Government identification may be required. You can also designate an authorized agent to exercise these rights on your behalf. Authorized agents must submit proof of authorization.
9. How Do We Share Your Personal Data?
We do not share your personal information with third parties, except as described in this Privacy Policy. HelloBiome does not share any health-related information (i.e., data concerning health, beauty, skin, lifestyle, conditions of the specific body area), microbiome-related information (i.e., data about the absolute abundance of the fungi and bacteria detected in the test sample), data revealing ethnic origin or other special categories of personal data (as defined in Art. 9(1) GDPR) in association with personal data without the explicit consent of the Data Subject. All personal data is de-identified before sharing. Consent may be collected when sharing of the data that contains identifiers is required to provide the personalized Services. Sharing of the de-identified test results is happening for the research projects and projects where the Data Subjects provide their consent to improve our Services. The Clients of the HelloBiome White-Label Platform may have access to the personal data because in this case, the Data Subjects directly interact with the Client’s brand while HelloBiome conducts data processing. The Clients in this case will be the Data Controllers of the data and HelloBiome may be both a Data Processor and a Data Controller of the data. HelloBiome may engage service providers and partners to assist with the delivery of the Services:
| Category | Purpose |
|---|---|
| Support/communication tools |
|
| Hosting providers |
|
| IT service providers |
|
| CRM |
|
| Analytics |
|
| Payment service providers |
|
| Ad service providers |
|
| Clients |
|
| Fulfilment Partners |
|
| Other |
|
In case your personal data is provided to service providers outside the EEA and where applicable, we will implement appropriate safeguards to protect your personal data, including Standard Contractual Clauses as adopted by the European Commission. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA. Moreover, HelloBiome requires its service providers to implement appropriate security measures to ensure the protection of your personal data in accordance with applicable data protection legislation. In other cases, we may disclose your personal data:
In other cases, we may disclose your personal data:
-
- to the relevant government agencies and regulatory authorities when required by the applicable laws;
-
- with affiliates and subsidiaries within the HelloBiome entities, which includes parent and ultimate holding companies, affiliates, subsidiaries, business units, and other companies that we acquire in the future after they are made part of the HelloBiome entities;
-
- in the event of any merger, acquisition, sale or change of control or a similar transaction or proceeding;
-
- with professional advisors, such as lawyers, accountants, and auditors;
-
- if you have consented to the disclosure;
-
- to establish, exercise or defend legal claims.
10. Privacy Policy Updates
HelloBiome may update this Privacy Policy from time to time. In the event we materially change this Privacy Policy, including how we collect, process, or use your personal information, we will notify you by means of the publication of the updated Privacy Policy on our Website or by any other acceptable means.
11. Contact Information
If you have questions about this Privacy Policy or our privacy practices, or if you are seeking to exercise any of your rights, you may contact us at:
| Mailing Address | HelloBiome ELSI Skin Health, Inc 181 2nd St, San Francisco, CA 94105 USA |
| Email (Dr. Elsa Jungman products & microbiome test kits – *.dr-ej.com) | [email protected] |
| Email (HelloBiome products & services – *.hellobio.me, including client-branded websites) | [email protected] |
| Online form (to exercise your data rights – DSR form) | https://hellobio.me/privacy/data-requests |
If you are a resident of the EEA, you have the right to lodge a complaint with the data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.