Online Privacy Policy
Last Updated: November 12, 2024
This Online Privacy Policy (“Policy”) reflects My Labs Direct, LLC’s commitments and obligations under the General Data Protection Regulation (“GDPR”). Your privacy is important to us, so the goal of this policy is to be transparent about what information MLD collects, uses, and shares.
This Policy explains your rights with regards to that information. It also explains how to access and update your information, and how you can object to its use.
When we refer to “MLD”, “we”, or “us”, we mean the My Labs Direct, LLC, a limited liability company based in Texas that acts as the controller or processor of your information. When we refer to the “Website”, we mean http://www.mylabsdirect.com and any successor, associated, or affiliated website and/or application (i.e., app).
Any personally identifying information you provide is voluntary. If you have any questions about this Privacy Policy, please e-mail us at support@mylabsdirect.com.
This Policy Covers:
What information we collect and how we use it
How we share information
How we store, secure, and transfer information
Your data rights and choices
Advertising List of data sub-processors
Other
Contacting MLD
When we make changes to our Policy, we will revise the date at the top of this page.
MLD collects the following information about you when you provide it to us and use our services:
Account and Profile Information
When you sign up, create a profile, set your preferences, or pay for any product or service, if any, MLD collects the information you voluntarily provide in communications and transactions with MLD, such as your name, username, password, email, credit card information, and any profile pictures, avatars, or digital images you choose to upload. We also collect the following:
We may collect and process the following types of information about you:
- Purchase and assistance information. We collect information when you purchase our products and services, when you phone our support team, or otherwise contact us for support. This information will include name, gender, contact information, billing address, delivery address and any further information you volunteer to provide to us.
- Health-related data. When you purchase or use our products and services, we will collect and process data concerning your health, including samples, test information or any other information we might receive from you, a medical practitioner, your insurance company, or Accredited Laboratory. When you activate a service or product, we will collect and process information relating to your personal health as well as a suitability questionnaire to confirm that the Service or Product is appropriate to your needs. You may also provide information to us if you connect a wearable device to one of our products or services.
- Biometric Data. In connection with certain products and services, we may collect your biometric data, such as a face scan, for the purposes of verifying your identity.
- We will collect and maintain your contact details when you communicate with us, sign up for promotional material, participate in special promotions, or connect with us through social media. If you contact us by email, we may keep a record of that correspondence. If you make a request with regard to the handling of your personal information, we may retain information regarding the request and any actions we take or correspondence we provide in response to such request.
- Website and device information. We collect information about your browser or device, including, where available, your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. We also collect details of your visits to our Site and Apps including, but not limited to, traffic data, location data, the resources that you access, web logs and other communication data. Our Site and Apps also use cookies; for detailed information on the cookies we use and the purposes for which we use them, see our Cookies Policy. We may also ask you for information when you report a problem with the Website.
- Survey information. If you respond to any surveys that we might request, which are completely voluntary, we will process your responses.
We use this information to correctly identify you, communicate with you, and provide you with customer support. We also use this contact information for accounting and administrative purposes, for transactional emails and to notify you about new features, releases and blog posts.
Device Information and Log Data
We collect information about the type of device you use to access the Website, as well as your device settings, operating system, browser information, connection type, IP address, and the URLs of referring pages. Additionally, we log the date and time you access our services, as well as any error or crash data.
We use device and location information to help us optimize your display and performance, understand user demographics, and improve overall user experience. Your log data helps us troubleshoot errors, analyze performance, resolve reliability issues, perform security audits, and investigate potential service fraud or abuse.
Service Metadata
This data is generated automatically, when you visit MLD. It provides us with information about how you browse our website and use our app. That includes the links you click, the search terms you use, and the features you access.
We use this metadata to help us understand how our users work, and what they find most valuable at MLD. We also use this information to measure the efficiency of our product, enhance our services and guide our future development.
Support Information Cookie Information
MLD and our third-party advertising and analytics partners use cookies and similar technologies for tracking across different devices, websites and online services.
We use this information both for secure authentication and for the maintenance of your active sessions. Our third-party partners use cookies for the purposes of marketing, ad targeting, and performance analytics.
Integrations and Linked Services
Whenever you or your account owner links to a third-party service, MLD is authorized to connect and transfer information as specified by our agreement with that linked service.
We use this information to authenticate, connect, or link your third-party accounts to MLD. However, we do not receive or store passwords for any of these third-party services.
To understand what data may be shared with MLD when you enable these integrations, please check the settings, permissions and privacy policies of these third-party services.
Accounts, Subscriptions, Webpages
Payment information is never given or sold to third-parties for any purpose, except to MLD and to third-party service providers acting on its behalf.
Personally Identifiable Information (“PII”) may be collected in order to process payments. This information is never made public nor given or sold to third parties for any purpose, except to MLD and to third-party service providers acting on its behalf or the purpose it was given.
Demographic and profile data are also collected at our site. This data is necessary for promotion of a player or team and for statistical purposes and is used solely for that purpose. This non PII information is publicly available to visitors to our site.
MLD may disclose your personal information among its affiliated businesses and with third-party service providers acting on MLD’s behalf.
The personal information you provide may be transmitted, used, stored and otherwise processed outside of the country where you submitted that information, including jurisdictions that may not have data privacy laws that provide equivalent protection to such laws in your home country.
Disclosure of your information
We share personal information with service providers, healthcare providers, affiliates, partners, and other third-parties where it is necessary to provide the Products and Services, or for any other purposes described in this Policy.
Your personal information may be provided as necessary to the following categories of recipients: Accredited Laboratories, healthcare providers, pharmacies, service providers (such as couriers, communications and marketing service providers, IT-related service providers, analytics providers, legal or financial advisors, contractors and vendors), and other trusted third-parties with whom we have an agreement for the protection of your information, or government/regulatory/law enforcement agencies pursuant to legally binding order.
We may disclose and transfer your personal information to our Accredited Laboratory for the purpose of (i) accepting and processing an accepted order by us, (ii) in order to procure the product is delivered to you by it, and (iii) to test any sample provided and make your test information available to you on our secure account on our Website. To process a request for a product and for our Accredited Laboratory to test the Sample and send you the Test Information, we need to disclose personal information within and outside our company including to healthcare providers, to our Accredited Laboratory and our IT services providers.
We may disclose and transfer your personal information to healthcare providers, such as contracted or other medical practitioners for purposes of review, quality assurance, prescribing of tests, review of results and other purposes.
We may disclose and transfer your personal information to pharmacies as directed by our contracted or medical practitioners and/or on your behalf.
We may share your personal information with certain third-party suppliers and service providers to help us operate, provide, improve, understand, customize, support, and market our Products and Services. We will take all steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this Policy by imposing obligations of security and confidentiality on such service providers.
In instances where our business is subject to a re-organization, such as a merger or acquisition of some or all of its assets, we may, in accordance with our legitimate interests, share information in the course of the transaction. In such circumstances, your personal information may be disclosed, where permitted by applicable law, in connection with a corporate restructuring, sale, or assignment of assets, merger, or other changes of control or financial status of MLD.
If you send offensive or objectionable content or otherwise engage in any disruptive behavior on the Site, we can use your personal information to stop such behavior and pursue our legitimate interest to prevent such behavior on our Site. This may involve informing relevant third parties, such as law enforcement agencies, about the content and your behavior.
Equally, we may retain, preserve, or disclose your personal information if we have a good-faith belief that it is reasonably necessary to (i) respond, based on applicable law, to a legal request (such as a subpoena, a search warrant, court order, or other request from government or law enforcement); (b) detect, investigate, prevent, and address fraud and other illegal activity, security, or technical issues; (c) protect our rights, property, or safety; (d) enforce the agreements we have with you; (e) prevent physical injury or other harm to any person or entity, including yourself and members of the general public. For example, your IP address may be supplied to regulatory authorities in connection with fraud or other formal investigations.
We may pass aggregate information on the usage of our Site and Apps to third parties.
Security and Protection of Information
MLD uses encryption and authentication tools to protect your personal information. The information you may provide through our website is secured using industry-standard security matters to protect the loss, misuse, or alteration of the information under our control. While there is no such thing as perfect security on the Internet, we will take all reasonable steps to ensure the safety of your personal information. In addition, our employees are instructed that such information is to be used only in accordance with the principles of this Privacy Policy and the laws applicable to each specific business. Employees who misuse customer information are subject to disciplinary action.
External Links
This site may contain links to other sites not monitored by or controlled by MLD. MLD shall not be responsible for the privacy practices or the content of such non-controlled linked websites.
Changes in Business
If MLD engages in a merger, acquisition, reorganization, bankruptcy, dissolution, sale of company assets, financing, public offering of securities, or due diligence and other steps in contemplation and negotiation of such activities, we may share or transfer information that we collect under this privacy policy, subject to standard confidentiality agreements.
Data Security
MLD takes data security very seriously and implements the industry’s best practices and policies. We take all reasonable measures to protect your information, and to prevent any kind of unauthorized access, misuse, loss, or disclosure.
While no system is infallible, we strive to keep our systems secure and constantly updated.
Data Retention
MLD may also retain certain information for as long as necessary in order to support business operations, or as required by law.
International Data Transfers
MLD collects information internationally and uses hosting and cloud computing infrastructure located primarily in the United States to transfer, process and store information. In order to provide you with our service, we may also transfer your data to third-party services. Please refer to the list of data sub-processors for more information about why we use those third-party services, and where they are located.
Right to be forgotten
You have the right to be forgotten which means that, at any time, you can request that MLD permanently delete all applicable data records, including your profile information, along with any user-created content. In some cases, we may need to retain partial information to fulfil our legal responsibilities.
Data Portability
You have the right, at any time, to request and receive the information that you have provided to MLD. We will provide you with your information, in a machine-readable format, so that you can make use of it in other contexts, or with other service providers.
Access Under 18 Years of Age
MLD services are not directed at children. Furthermore, we do not knowingly collect personal information from individuals under 18 years of age, unless consent is given or authorized by the holder of parental responsibility over the child. If we become aware that someone under 18 has provided us with personal details, we will take steps to delete such information. If you become aware that a child has unlawfully or unwittingly provided us with personal data, please contact our Support team.
Online Privacy Policy Only
This privacy policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in www.mylabsdirect.com. This policy is not applicable to any information collected offline or via channels other than this website.
MLD Privacy Policy does not apply to other advertisers or websites. Thus, we are advising you to consult the respective Privacy Policies of these third-party sites for more detailed information.
NOTICE TO CALIFORNIA RESIDENTS – YOUR CALIFORNIA PRIVACY RIGHTS
This section is applicable to residents of California. If you are a resident of California, you have certain rights described below. The following do not apply to individuals who do not live in California on a permanent basis.
RIGHTS PROVIDED BY CALIFORNIA CIVIL CODE SECTION 1798.83
A California resident who has provided personal information to a business with whom he/she has established a business relationship for personal, family, or household purposes (a “California Customer”) may request information about whether the business has disclosed personal information to any third parties for the third-parties’ direct marketing purposes. In general, if the business has made such a disclosure of personal information, upon receipt of a request by a California Customer, the business is required to provide a list of all third parties to whom personal information was disclosed in the preceding calendar year, as well as a list of the categories of personal information that were disclosed. California Customers may request further information about our compliance with this law by mailing us at 610 Coit Road, Unit 2, Plano, Texas 75075, or emailing us at support@mlabsdirect.com. You may also contact us via toll free phone number at (888) 919-6465 Please note that we are only required to respond to one request per California Customer each year under Code Section 1798.83.
RIGHTS UNDER THE CALIFORNIA CONSUMER PRIVACY ACT
You may exercise your privacy rights where these are applicable to you at any time, by contacting us at support@mlabsdirect.com or via toll free phone number at (888) 919-6465. This includes if you wish to exercise any of the privacy rights as set out below, and/or as applicable to you in relation to your access to and use of (i) our products and services, or (ii) physician groups providing you with virtual health services.
This section of our Policy provides California residents with a description of our online and offline practices regarding the collection, use, disclosure, and sale of personal information and the rights of California consumers regarding their personal information under the California Consumer Privacy Act (“CCPA”). This section applies to all California residents (but not including legal entities, such as companies). The section will not apply, however, if we do not collect any personal information about you or if all of the information we collect is exempt from the statute (for example, the CCPA does not protect information that is already protected by certain other privacy laws such as HIPAA, and it does not protect information that is already publicly available).
“Personal information,” for purposes of this section regarding the rights of California residents, is to be understood in a manner consistent with the CCPA and does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights
You have a right not to receive discriminatory treatment by us for exercising any of your privacy rights conferred by the CCPA. We will not discriminate against any California consumer because such person exercised any of the consumer’s rights under CCPA, including, but not limited to:
- Denying goods or services.
- Charging different prices or rates for goods and services, including through the use of discounts or other benefits or imposing penalties.
- Providing a different level or quality of goods or services.
- Suggesting that the consumer will receive a different price or rate for goods or services or a different level or quality of goods or services.
We may, however, charge a different price or rate, or provide a different level or quality of goods or services, if that difference is related to the value provided to you by your data.
NOTICE TO VIRGINIA RESIDENTS
This notice is provided in accordance with the Virginia Consumer Data Protection Act (“CDPA”) and describes how we collect, use, and share your personal data and the rights that you have with respect to your personal data, including sensitive personal data. For purposes of this section, “personal data” and “sensitive data” have the meanings given in the CDPA and do not include information excluded from the CDPA’s scope. In general, personal data is information reasonably linkable to an identifiable person.
The personal data we collect about you will depend upon how you interact with our site and the information you voluntarily provide us. Accordingly, we may not collect all of the below information about you. In addition, we may collect and/or use additional types of information after providing notice to you and obtaining your consent to the extent such notice and consent is required by the CDPA.
To the extent that we collect personal data that is subject to the CDPA, that information, our practices, and your rights are described below. Persons with disabilities may obtain this notice in alternative format by contacting MLD at support@mylabsdirect.com.
Notice of Privacy Practices
This Notice of Privacy Practices applies to MLD and all of its subsidiaries and business units (collectively referred to as “MLD” in this Notice), except to the extent that a subsidiary, division, or business unit of MLD performs occupational screening, forensic tests, paternity/identity tests, clinical trials tests or other services that do not involve standard electronic transactions for which the Department of Health and Human Services (“HHS”) has adopted standards.
Under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), MLD is required by law to maintain the privacy of health information that identifies you, called protected health information (“PHI”), and to provide you with notice of our legal duties and privacy practices regarding PHI. MLD is committed to the protection of your PHI and will make reasonable efforts to maintain the confidentiality of your PHI, as required by statute and regulation. We take this commitment seriously and will work with you to comply with your right to receive certain information under HIPAA. This Notice describes how PHI may be used and disclosed and how you can get access to this information. Please review it carefully. For more information see: https://www.hhs.gov/hipaa/for-individuals/notice-privacy-practices/index.html.
Your Rights
When it comes to your PHI, you have certain rights. This section explains your rights and MLD’s responsibilities. You have the following rights:
- Receive an electronic or paper copy of your PHI
- Ask to correct your PHI
- Request confidential communications
- Ask to limit the PHI MLD uses or discloses
- Receive a list of certain disclosures of your PHI by MLD
- Receive a copy of this privacy Notice
- Choose someone to act on your behalf as it relates to your PHI
- Notify MLD or file a complaint regarding MLD’s privacy practices
Get an Electronic or Paper Copy of your Medical Records
You can ask to see or obtain an electronic or paper copy of the portions of your medical record and other PHI we have about you. With certain exceptions, we will provide a copy or a summary of your PHI, usually within 30 days of your request. We may charge a reasonable, cost-based fee.
You can Request a Copy of your PHI by:
- Asking for a courtesy copy at MLD’s patient service center,
- Opening a patient portal account to receive your laboratory reports electronically,
- Completing MLD’s HIPAA Patient Request Form, or
- Contacting MLD at support@mylabsdirect.com.
Ask MLD to Correct your Medical Records
You can ask MLD to correct PHI about you in MLD’s records that you think is incorrect or incomplete by making a written request to support@mylabsdirect.com. We may say “no” to your request, but we’ll tell you why in writing within 60 days.
Request Confidential Communications
You can ask MLD to contact you in a specific way (for example, home or office phone) or to send mail to a different address.
Ask MLD to Limit the Information we Use or Disclose
You can ask MLD not to use or disclose certain PHI for treatment, payment, or MLD’s operations. We are not required to agree to your request, and we may say “no” under certain circumstances. If you pay for a service or health care item out-of-pocket in full, you can ask MLD not to disclose that information for the purpose of payment or MLD’s operations with your health insurer. We will say “yes” unless a law requires MLD to disclose that information.
Get a List of those with whom we’ve Shared your Information
You can ask for a list (accounting) of the times we’ve shared your PHI for six (6) years prior to the date you ask, who we shared it with, and why. We will include all the disclosures except for those about treatment, payment, and health care operations, and certain other disclosures (such as any you asked MLD to make). We’ll provide one accounting a year for free but will charge a reasonable, cost-based fee if you ask for another one within twelve (12) months.
Get a Copy of this Privacy Notice
You can ask for a paper copy of this Notice at any time, even if you have agreed to receive the Notice electronically. We will provide you with a paper copy promptly.
Choose Someone to Act for You
If you have given someone medical power of attorney or if someone is your legal guardian, that person can exercise your rights and make choices about your PHI. We will verify that the person has this authority and can act for you before we take any action.
Contacting MLD or Filing a Complaint
You can complain if you feel we have violated your rights by emailing support@mylabsdirect.com, calling MLD at (888) 919-6465 and asking for the MLD Privacy Officer, or sending a written request to: My Labs Direct, LLC, Attn: Privacy Officer, 610 Coit Road, Unit 2, Plano, Texas 75075.
You can file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights by sending a letter to 200 Independence Avenue, S.W., Washington, D.C. 20201, calling 1-877-696-6775, or visiting www.hhs.gov/ocr/privacy/hipaa/complaints/.
We will not Retaliate against you for Filing a Complaint.
For certain PHI, you can tell MLD your choices about what we disclose. If you have a clear preference for how we disclose your information in the situations described below, talk to MLD. Tell MLD what you want MLD to do, and we will follow your instructions.
You have both the right and choice to tell MLD to disclose your PHI in the following ways:
- With your family, close friends, or others involved in your care
- In response to a disaster relief situation
If you are not able to tell MLD your preference, for example if you are unconscious, we may go ahead and disclose your information if we believe it is in your best interest. We may also disclose your information when needed to lessen a serious and imminent threat to health or safety.
MLD will request your written permission before disclosing your PHI for marketing purposes.
How does MLD typically use or disclose your PHI?
MLD uses or discloses PHI in the following ways:
- For treatment purposes
- For MLD’s health care operations
- For billing and payment processing
MLD may further use or disclose PHI, as permitted under HIPAA, in the following ways:
- For public health and safety issues
- For research
- As required by law
- To respond to organ and tissue donation requests
- At the request of a medical examiner or funeral director
- To respond to workers’ compensation, law enforcement, and other government requests
- To respond to lawsuits and legal actions
MLD has in place additional safeguards for your PHI consistent with federal and state laws, for example, relating to mental health, HIV/AIDS, and genetic testing. In addition, federally assisted alcohol and drug treatment programs are subject to additional and separate restrictions on the use and disclosure of alcohol and drug abuse treatment information. Where required, MLD will obtain your permission before disclosing PHI with additional safeguards to other health care providers who are not involved in your treatment program or care.
MLD typically uses or disclose your PHI in the following ways:
- Treat you: We can use your PHI to treat you and disclose it with doctors, other health care professionals, and pharmacies who are treating you.
- Run MLD’s organization: We can use and disclose your PHI to run MLD’s organization, improve your care, and contact you when necessary.
- Bill for your services: We can use and disclose your PHI to bill and get payment from health plans or other entities.
- Help with public health and safety issues: We can disclose PHI about you for certain situations such as:
- Preventing disease
- Helping with product recalls
- Reporting adverse reactions to medications
- Reporting suspected abuse, neglect, or domestic violence
- Preventing or reducing a serious threat to anyone’s health or safety
- Do research: We can use or disclose your information for health research.
- Comply with the law: We will disclose information about you if state or federal laws require it, including with the Department of Health and Human Services if it wants to see that we’re complying with federal privacy law.
- Respond to organ and tissue donation requests: We can disclose PHI about you with organ procurement organizations.
- Work with a medical examiner or funeral director: We can disclose PHI with a coroner, medical examiner, or funeral director when an individual dies.
- Address workers’ compensation, law enforcement, and other government requests: We can use or disclose PHI about you:
- For workers’ compensation claims.
- For law enforcement purposes or with a law enforcement official, provided MLD is able to confirm notice has been provided to you, as required under applicable laws, when a request from law enforcement is not accompanied by a non-disclosure or gag order.
- With health oversight agencies for activities authorized by law.
- For special government functions such as military, national security, and presidential protective services.
- Respond to lawsuits and legal actions: We can disclose PHI about you in response to a court or administrative order, or in response to a subpoena, provided MLD is able to confirm notice has been provided to you, as required under applicable laws, when a legal request is not accompanied by a non-disclosure or gag order.
We are also allowed or required to disclose your information in other ways – usually in ways that contribute to the public good, such as public health and research. We have to meet many conditions in the law before we can disclose your information for these purposes. For more information see: https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html.
MLD’s Responsibilities
- MLD is required by law to maintain the privacy and security of your PHI.
- MLD will let you know if a breach occurs that has compromised the privacy or security of your PHI.
- MLD is required to comply with this Notice and make this Notice available to you.
- MLD will not sell or license your PHI to third-parties.
- MLD will not use or disclose your PHI other than as described in this Notice unless you tell MLD we can in writing. If you tell MLD we can, you may change your mind at any time by contacting MLD in writing.
Consent
By using our Website, you hereby consent to our Policy and agree to its Terms and Conditions.
Request That We Stop Using Your Information
Even if you have previously consented to our Terms of Service and Privacy Policy, you have the right, at any time, to change your mind and object to the collection, use, and processing of your personal information. Additionally, you are under no contractual obligation to continue to provide any information to MLD. However, we require certain information in order to provide you with our services. Therefore, if you disagree with the terms of this Policy or our Terms of Use, you should stop using MLD, and contact us so that we may delete your information.
MLD may modify this Policy from time-to-time and such modification shall be effective upon posting by MLD on the Website. You agree to be bound to any changes to this Agreement when you use the site services after any such modification is posted. It is therefore important that you review this Policy regularly to ensure you are updated as to any changes.
MLD, reserves the right, in its sole discretion, to reject, refuse to post or remove any posting (including private messages) by you, or to restrict, suspend, or terminate your access to all or any part of the Site Services at any time, for any or no reason, with or without prior notice, and without liability. MLD, expressly reserves the right to remove your profile and/or restrict, suspend, or terminate your access to any part of site services if MLD determines, in its sole discretion, that you pose a threat to MLD and/or its users.
Contacting MLD
If you have any questions about the Policy or want to make a request with regard to your information, please contact MLD at support@mylabsdirect.com.