Habit Privacy Notice for California Residents
Last Updated: September 15, 2023
This California Consumer Privacy Act Notice ("Notice"), effective as of September 15, 2023, supplements the Habit Privacy Policy (“Privacy Policy”) and the Habit Terms of Services (“Terms”). Habit LLC (“Habit”) is an affiliate of Viome Life Sciences, Inc. (“Viome”). Habit Privacy Policy describes the Personal Information (“PI”) that we collect, the sources from which we collect it, the purposes for which we use it, the limited circumstances under which we share PI, and with whom we share it. These additional Notices are required by the California Consumer Privacy Act (“CCPA”). This Notice is applicable only to California Consumers.
1) Categories of PI Collected and the Source
The type of PI that Habit collects, or has collected from Consumers and study participants in the twelve (12) months prior to the effective date of this Notice, and sources from which they were collected:
Identifiers, such as name, email, address, phone numbers, IP address, credit card details, birthdate, etc. (Redcap, website, webforms, or mobile app)
Personal Information, such as name, address, date of birth, IP address, credit card details, birthdate, medical records, etc. (Redcap, website, webforms, or mobile app)
Biometric Information, such as your Biological Samples (provided by Consumer, study participant and third-party vendors), as defined in the Terms and Privacy Policy.
Registration Information, such as name, email address, address, country of residence, biological sex, date of birth, phone, password, etc. (Registration)
Self-Reported Information, such as answers to research and study questionnaires, age, race, color, gender, biological sex, ethnic origin, height, weight, sample collection date, health history, current health state, lifestyle, dietary and other habits (e.g., tobacco use), food sensitivities, sleep data, health data, or exercise data, allergies, physical health conditions, mental health conditions, family history of known health conditions, medications used, surgeries, etc. (questionnaires, Customer Service, feedback, Study Participations, and Research questionnaires)
Protected Classification Characteristics, such as age, biological sex, ethnicity, parent or legal guardian of a child, disability related health conditions, marital status, disabilities, pregnancies, etc. (questionnaires, Research, surveys, Registration)
Sensory Data, such as audio, electronic, visual, or similar information health conditions (Consumer or Consumer’s physician)
Commercial Information, such as purchase activity, credit card details, shipping address, billing address, interactions with Customer Service, purchase history, previous tests, etc. (web server that hosts the order system and Customer Service)
Geolocation Data, such as physical location of mobile device or computer (web server)
Professional, Education, or Employment Data, such as highest education received, field of employment or occupation (Registration, Initial questionnaire, study questionnaires, Consent Forms, and Customer Service)
Tracking Technology Data, such as cookies, web beacons, tags, scripts and device identifiers, behavior data on our website (web server and external parties)
User Content, such as profiles, posts, emails, feedback, suggestions, notes, messages, photos, and videos uploaded by Consumer (company servers and social and marketing media platforms)
Internet or Electronic Network Activity, such as accessing Habit website use and interactions with its content, Account activity, content on social media, feedback, contests, sweepstakes, etc. (web server and sales and order system)
Web-Behavior Information, such as your device ID, IP address, Google analytics, purchase activity, Customer Service interactions, web traffic Consumer use of website, sign up to Account, data generated from Services, collected through log files, browser type, domains, page views, etc. (web server and external parties)
Inferences and Derived Data, such as Sample Data, Test Data, Test Results, analytics on Consumer data, recommendations (Viome artificial intelligence database and Viome proprietary technology)
Other Types of Information, as identified in Viome Privacy Policy:
2) Business or Commercial Purpose(s) of PI Collection
Allow Consumer to place orders and make payments for the Service
To fulfill Consumer’s Service orders including shipping
Data analysis to provision the Services and send Test Results
Improve the analytics and AI technology used to generate recommendations
Recruit Consumers for external Study Participations
Allow Consumer to be part of Viome Research
Allow Consumer to participate in Study Participations
To send questionnaires, surveys, study notifications
Provide Consumer with marketing communications
Allow Consumer to share their experience and feedback with others
Quality assurance on Service
Provide Customer Service Support
To obtain a Test requisition approval from a licensed physician
To obtain an approval for Test Result release from a licensed healthcare professional
3) Categories of PI Disclosed to Third Parties for Business Purposes
Habit may share certain PI collected as stated above in this Notice with third parties such as service providers, collaborators, and consultants, for business operation purposes including:
Audit: Audits related to orders, confirmations, verifications, returns, payment processing, data privacy and security, and accounting and finance
Provisioning: For delivery of orders by shipping carriers (local and international) and payment processors transactions
Security: Protect Consumer and company data against malicious, deceptive, fraudulent, or illegal activity, detect security incidents, provide general IT service and security, data encryption, de-identification, assure data safety, accuracy, privacy, and integrity, access control and reporting. Please see Privacy Policy on Information Security Measures
Inventory Management: Manage inventory, order system, and fulfilling Consumer orders
Research: Scientific research by Viome Research Institute with the intent to improve Service and publish discoveries in peer-reviewed scientific journals
Customer Service: Optimize Customer Service, automate routine inquiries, improve quality and efficiency
Product Improvement: Systems used for improving data analytics, minimal or negligible exposure to outside vendors
Quality assurance: Enhance the quality of Sample collection process, minimize sample collection errors and test failures, reduce Sample return turn-around time, and provide data relevant to process improvements
Study Participations: Study specific collaborations with collaborators on disease conditions, clinical trials, and treatments
Test Request Approval: Approval of a Test Request by a licensed physician from our physician oversight and support service partner (“EHS”) or another licensed healthcare provider
Test Result Review and Approval: Review and approval for release of Test Result
Pre and Post Test Consultations: For conducting pre-test and post-test consultations with a licensed healthcare provider, an EHS healthcare professional or counselor
EHS Post Consultation Survey: Conduct surveys on post-test consultations after and obtain feedback on the consultation
4) Request Access
Subject to the following limitations, you may request access to the specific pieces of PI collected about you:
i) It should be limited to your Personal Information only.
ii) Collected in the 12-month period preceding the date of your request; and
iii) Access is limited to no more than twice in a 12-month period.
Contact our Customer Service by sending a request using the details below.
Visit https://support.viome.com and request Assistance with CCPA: Access to PI or
Email privacy@viome.com using your Viome account email address to request Assistance with CCPA: Access to PI
5) Request Deletion
You may request deletion of PI we process about you, subject to certain limitations. Your rights under CCPA are not absolute. For additional details regarding account deletion please read our Privacy Policy on Account Closure. Your PI may not be deleted if they are necessary to:
i) Complete the transaction for which they were collected, provide the Service requested, or perform a contract with the Consumer
ii) Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity
iii) Debug products to identify and repair errors that impair existing intended functionality
iv) Ensure the right of another Consumer to exercise his or her right of free speech, or exercise another right provided for by law
v) Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code
vi) Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, and the deletion of the information is likely to render impossible or seriously impair the achievement of such research (if the Consumer has provided informed consent)
vii) To enable solely internal uses that are reasonably aligned with the expectations of the Consumer
viii) To comply with a legal obligation
ix) Otherwise use your PI, internally, in a lawful manner that is compatible with the context in which you provided the information
Contact our Customer Service by sending a request using the details below.
Visit https://support.viome.com and request Assistance with CCPA: Deletion of PI or
Email privacy@viome.com using your account email address to request Assistance with CCPA: Deletion of PI
6) Methods for Submitting Requests
Visit https://support.viome.com and send a request to our Customer Service or
Email privacy@viome.com using your account email address to request (CCPA Right Request)
Submit by mail:
Viome Customer Service
Viome Life Sciences, Inc.
205 108th Ave NE, STE 150
Bellevue, WA 98004
Phone: Call Customer Service at 1-855.958-4663
7) Opt-out of Sale
The CCPA provides you the right to opt-out of having your PI sold.
Please note that Habit has not sold any PI of Consumers. Habit does not sell Consumer PI to third parties.
8) No Discrimination
Habit does not discriminate against any Consumer for exercising their rights under the CCPA.
9) Verifying Consumer Requests
Only you or your authorized representative can act on your behalf to make a verifiable Consumer request on your PI. Your request must:
i) Provide sufficient information to verify that you are a California Consumer
ii) Provide sufficient information that allows us to verify you are the person or the duly authorized representative of the person about whom we collected the PI
iii) Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond
iv) Habit may request additional materials or information for the purposes of validating the authenticity of your request
(Note: We cannot give effect to your request if we are unable to verify your identity or authority to make the request.)
10) Key Definitions
Consumer: natural persons who reside in California, including (1) individuals who are in California for other than a temporary and transitory purpose; and (2) individuals who are domiciled in California, but are outside the state for a temporary or transitory purpose
PI: as defined in the CCPA, and includes information that can be used to identify you, either alone or in combination with other information, and any other information that could reasonably be linked with a particular Consumer or device
11) Conflicts
In the event of any conflict between the terms of this Notice and the Privacy Policy or the Terms, the terms of this Notice shall prevail.
12) How to Contact Us
If you have any questions regarding the information presented on this Notice, please contact us at privacy@viome.com using your account email address with the subject line (Rights under CCPA). Please remember to mention that you are a Habit Consumer.
Viome Life Sciences, Inc.
Attn: Chief Privacy Officer
205 108th Ave NE, STE 150
Bellevue, WA 98004
Email: privacy@viome.com