Privacy Policy
Last update: 08/19/2024
This “Privacy Policy” explains how we collect, use, protect, and treat the personal information and user data of people using https://www.massivebio.com website and its affiliate websites (“Website”),and services provided there, Synergy-AI Clinical Trial Finder and Cancer Quiz mobile applications (“Mobile Apps”), Clinical Trial Matching, Virtual Tumor Board, Clinical Network, Drug Utilization Optimizer (“DUO“) , Real World Data and other online and off-line applications (“Platforms”), including cancer patients (“you” / “your”), your oncologists, referring physicians, primary investigators and clinic staff, expert oncologists who evaluate your case history and identify options for treatment or clinical trials. From now on, collectively, Website, Mobile Apps, and Platforms are noted as “Solutions”
The Solutions is operated by Massive Bio (“Company”, “we”, “us” or “our”). Massive Bio is a data analytics firm that provides a medical second opinion and clinical trial matching by evaluating a cancer patient’s existing clinical information, leveraging our proprietary artificial intelligence platform, and providing consulting services to patient’s oncologists by identifying and explaining treatment options that best fit the patient’s medical profile, treatment objectives, and resources (collectively, the “Services”).
This Privacy Policy covers only information and data collected or processed through the Solutions and not any other information or data collected or processed by third parties who provide products and services in connection with our Solutions, and Services such as health plan administrators, patient assistance administrators (“Service Providers”), or to third-party web pages, or websites, solutions, products, or services to which we link that do not display this Privacy Policy. We are not responsible for the content or privacy practices of other websites, solutions, or online or mobile services. Each user signifies the data practices described in this Privacy Policy and our Terms of Use by using the Solutions.
We have revised our Privacy Policy to comply with the GDPR, HIPAA, PIPEDA, Data Protection Act, LGPD and local, state, provincial, territorial, and national legislations where the company conducts an activity informing individuals whose personal information, we process on why we need it, how it is used, what their rights are, who the information is disclosed to and what safeguarding measures are in place to protect their data.
THE COMPANY IS NOT A MEDICAL PROVIDER, NOR IS IT A “COVERED ENTITY” SUBJECT TO STATE OR FEDERAL LAWS GOVERNING THE PRIVACY OF MEDICAL RECORDS OR INFORMATION, INCLUDING THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996, COMMONLY REFERRED TO AS “HIPAA”.
I. INFORMATION WE COLLECT
1. Personally identifiable information
Our Solutions and our Service Providers only collect personally identifiable information (“PII”, also referred to as personal data or personal information in some jurisdictions) for our purposes as set out in the next section II. THE CATEGORIES OF PII WE COLLECT FOR OUR PURPOSES AND THE APPLICABLE LEGAL BASIS FOR OUR DATA PROCESSING. Collection of PII occurs if you register for an appointment on the Solutions, subscribe to a newsletter, tweet to us, or use other features and resources on the Solutions. You may visit our Site anonymously, but that may prevent you from accessing certain features or Services or Solutions.
A. Your patient profile
B. Health provider profiles
C. Service Provider profiles
Medical Information Released to Company:
- Through EMR platforms APIs
- Through the EMR platform, online pages shared by you
- Through EMR platform online pages accessed by Company’s corporate accounts with your authorization to see your PII
- Through emails, SMS, any chat application, Whatsapp or other means of communication channels
2. Protected Health Information and Sensitive Personal Information
We will collect and store sensitive personal information and data about you.
3. Non-Personally Identifiable Information
Our Website, Solutions, and Service Providers may also collect non-personally identifiable (anonymous) information (“Non-PII”) from visitors, including cancer patients, health care providers, staff, clinical staff, oncology experts, data analysts, and health plan administrators. Non personally identifiable information is any information that cannot be directly or indirectly associated with you.
4. Cookies
“Cookies” are short computer codes known as cookies, web beacons, and other technologies that collect and store both PII and Non-PII when you visit our Solutions, or share Website content or solutions through a social media account. The following are examples of information we or third-party service providers collect with cookies:
- Cookies that may uniquely identify your browser session and the other website, solutions
you have visited - Browser type and operating system
- Hardware settings
- Date and time of visit
- Website pages you visited
- Web page that referred you to Company
- Web pages your visit after leaving the website
5. Social Media
We may collect information through our presence on social media and networking platforms. You may use social networks or other online services to sign into the Solutions. When you do so, information from those services may be made available to us. By associating a social network account with the Solutions, we may collect your PII, such as your username and email address.
6. Patient Representatives
A patient can give written, verbal or SMS authorization for a person (for example, a solicitor or relative) to make an application on their behalf. We may withhold access if it is of the view that the patient authorizing the access has not understood the meaning of the authorization. The authorization is only good for 90 days and requires a recording.
Next of kin
Despite the widespread use of the phrase ‘next of kin,’ this is not defined, nor does it have formal legal status. A next of kin cannot give or withhold their consent to sharing information on a patient’s behalf. A next of kin had no right of access to medical records.
Court Representatives
A person appointed by the court to manage the affairs of a patient who is incapable of managing her experiences may make an application. Access may be denied where the General Practitioner opinion thinks that the patient underwent relevant examinations or investigations to expect the information would not be disclosed to the applicant.
7. Information about You from Other Sources
We collect personal information about you on the Solutions, and from other sources, including data from your oncologists, oncology practice staff, clinical staff, health claims administrators, and patient benefits organizations. We may combine all information we collect about you to provide Services to you, including data analysis for identifying testing and treatment options and, when de-identified, for our research efforts and to improve our Services and Solutions.
II. THE CATEGORIES OF PII WE COLLECT FOR OUR PURPOSES AND THE APPLICABLE LEGAL BASIS FOR OUR DATA PROCESSING
1. Depending on where you live, how you interact with us, and how we may interact with certain Service Providers, we may collect personal information (PII) about you as set out in the ‘personal information’ column below. You will also find below the purpose of the processing and (for the EEA, UK, Canada, and other countries) the legal basis we rely on for each type of PII that we process about you