Privacy policy
Effective date: 06/19/2026
Nucleus Genomics, Inc. and its affiliated entities (collectively, “Nucleus,” “we,” or “us”) are committed to respecting your privacy and protecting your personal data. This Privacy Policy (“Policy”) explains the types of personal data (defined below) we may collect when you: visit our websites, including www.mynucleus.com and app.mynucleus.com, and all related websites, mobile applications, and web-based services (our “Sites”); interact with us by email, mail, or phone, or otherwise; or access use our products or services. We refer to our Sites, interactions with you, and products and services as “Services” throughout this Policy.
This Policy also describes how and why we collect, use, and disclose personal data, how we protect it, and your available rights and choices associated with it. For the purposes of many privacy laws, we are the data controller of personal data subject to this Policy. Please note that we are providing the following disclosures and rights in the interest of transparency. Such disclosures and rights are not intended to waive any applicable exemptions under applicable law.
We may collect, store, and use personal data that is linked or reasonably linkable to you and that identifies your past, present, or future health status or mental health status, as may be applicable (“consumer health data”). If you are a resident of Connecticut, Nevada, or Washington, we provide information about consumer health data collected about you, as well as the rights you may have related to this data, in our Consumer Health Data Privacy Notice.
Some of the information we collect, use, and disclose is done so for purposes of providing healthcare and are regulated by the federal Health Insurance Portability and Accountability Act (HIPAA) and similar federal and state laws, including the privacy and security protections of those laws (collectively, “protected health information” or “PHI”). This Policy does not apply to PHI, and any overlapping coverage of PHI in this policy is incidental and provided to enhance your understanding of our data collection and use practices, and should not be construed as an acknowledgment of the applicability or inapplicability of certain privacy laws, including HIPAA and/or the state and other privacy laws that may apply to Nucleus. You can find more information about our collection and use of PHI in our HIPAA Notice of Privacy Practices.
This Policy also does not apply to third-party websites, products, or services, even if they link to our Sites or our Sites link to them. We recommend you review the privacy practices of those third parties before connecting, accessing third-party websites, and sharing any personal data.
We also encourage you to review our Terms of service to understand how your personal data will be treated as you make full use of our Sites. Unless otherwise defined in this Privacy Policy, capitalized terms used in this Privacy Policy have the same meanings as in our Terms of service.
01
Collecting Personal Data
Personal data you provide to us
Information we automatically collect
Aggregated, anonymized, and de-identified information
Information we receive from our healthcare and other service providers
Summary of Nucleus Data Use
CATEGORY OF PERSONAL DATA
SOURCES
PROCESSING PURPOSES
CATEGORIES OF THIRD PARTY RECIPIENTS (EXCLUDING OUR SERVICE PROVIDERS)
Identifiers, including:
Name
Address
Email address
Phone number
Date of birth
Account username
IP address
Unique device identifiers
Mobile app identifiers
You, including via your use of our Sites.
Our service providers, such as companies who help us provide Services to you.
Contact you and provide information
Provide customer service
Perform identity and age verification as required under applicable law
Provide, maintain, and improve the Services
Facilitate interactive features
Internal analytics
Market our products and Services
Market the products and services of others
Promotions and sweepstakes
Internal business purposes, including general business administration
Audit, compliance, legal, policy, procedure, and regulatory obligations
Customer claims and fraud investigation and prevention
Systems and data security
Protecting the safety of our employees and others
Profiling
For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy or for any other legal purpose not inconsistent with this Privacy Policy
For any purpose consistent with your consent/expressed preferences
N/A
Commercial information, including:
Information about your interests and preferences, (e.g., Services you have purchased, obtained, or considered)
Same sources as noted for “Identifiers”
Same purposes as noted for “Identifiers”
N/A
Financial information, including:
Bank account number
Credit card number
Debit card number
Any other financial information
Same sources as noted for "Identifiers"
Provide, maintain, and improve the Services
Internal business purposes, including general business administration
For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy or for any other legal purpose not inconsistent with this Privacy Policy
For any purpose consistent with your preferences/consent
N/A
Internet or other electronic network activity information, including:
Browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages
Content and information about your communications through the Services
Information using cookies and tracking technologies
Mobile operating system information
Mobile internet browser type
Diagnostic data
Same sources as noted for "Identifiers"
Same purposes as noted for “Identifiers”
N/A
Geolocation Data, including:
Global Positioning System (“GPS”) data
Locational information based upon your IP address
Cell network data
Locational data collected from various devices including your mobile device(s) or vehicle(s)
Same sources as noted for "Identifiers"
Provide, maintain, and improve the Services
Internal business purposes, including general business administration
Customer claims and fraud investigation and prevention
Systems and data security
Protect the safety of our employees and others
Internal analytics
For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy or for any other legal purpose not inconsistent with this Privacy Policy
For any purpose consistent with your consent/expressed preferences
N/A
Audio, electronic, visual, or similar information, including:
Any original text, audio recordings, photos, videos, music, and other media you may share on the Services.
Your name, voice, and/or likeness when you participate in sweepstakes, contests, promotions, and other Company programs
Same sources as noted for "Identifiers"
Same purposes as noted for “Identifiers”
N/A
Characteristics or protected classifications, including:
Age
Date of birth or age range
Gender or gender identity
National origin
Racial or ethnic origin
Sexual orientation
Same sources as noted for "Identifiers"
Provide, maintain, and improve the Services
For internal business purposes, including general business administration
Customer claims and fraud investigation and prevention
Systems and data security
Protecting the safety of our employees and others
Internal analytics and product improvements.
For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy or for any other legal purpose not inconsistent with this Privacy Policy
For any purpose consistent with your consent/expressed preferences
N/A
Professional or employment-related information, including:
Professional licenses or registrations
Same sources as noted for "Identifiers"
Same purposes as noted for “Identifiers”
N/A
Sensitive information or sensitive data, including:
Account login information
Mental or physical health condition or diagnosis
Personal data collected and analyzed concerning health
Genetic information
Consumer health data, as further described in our Consumer Health Data Privacy Notice.
Same sources as noted for "Identifiers"
Provide customer service
Provide, maintain, and improve the Services
Internal analytics
Market our products and services
Market the products and services of others
Internal business purposes, including general business administration
Audit, compliance, legal, policy, procedure, and regulatory obligations
Profiling
For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy or for any other legal purpose not inconsistent with this Privacy Policy
For any purpose consistent with your consent/expressed preferences
N/A
Inferences about you using any of the above, including:
Results from our genetic analysis services such as our genetic risk reports.
Same sources as noted for "Identifiers"
Any of the above purposes
N/A
02
Using Personal Data
Our Services
Digital marketing communications
Other purposes
03
Disclosing Personal Data
Our service providers
Our business partners
Our affiliates
Third parties related to a change of ownership
Third parties related to law, harm prevention, and public interest
Other third parties consistent with your consent and expressed preferences
04
Data Retention
05
Data Security
06
International Data Transfers
07
Cookie Policy
08
Children’s Information
09
Legal Bases for Processing
Legitimate business interests
10
Your Privacy Rights and Choices
Opting out of receiving electronic communications from us
View or change your account personal data
U.S. privacy rights
European privacy rights
Mexico privacy rights
Canada privacy rights
Jordan privacy rights
India privacy rights
Individuals located in India have certain rights with respect to our collection, use, and sharing of their personal data under applicable Indian law. Please review our India Privacy Notice for more information about those rights.
11
Exercising Your Privacy Rights
How to submit a request
How we verify and respond to requests
Data Protection Officer
12
California Privacy Notice
Personal Information We Collect and Why We Collect It
Sources of Collected Personal Information
To Whom We Disclose Personal Information
Sensitive Personal Information
Retention of Personal Information
Your California Privacy Rights
13
Nevada Privacy Notice
14
Privacy Notice for Residents of Other States
Our Personal Data Practices
Your Privacy Rights
15
Consumer Health Data Privacy Notice
Consumer Health Data We Collect
Categories of Sources of Consumer Health Data
How We Use Consumer Health Data
To Whom We Disclose Consumer Health Data
Your Consumer Health Data Privacy Rights
16
European Privacy Notice
Your privacy rights
17
Mexico Privacy Notice
Your privacy rights
18
Canada Privacy Notice
Your privacy rights
19
Jordan Privacy Notice
20
India Privacy Notice
This India Privacy Notice applies to individuals located in India about whom we may collect personal data from any source, including through your use of our Sites, products, and Services. This India Privacy Notice supplements the information contained in the rest of our Policy and is intended to comply with applicable Indian data protection laws, including the Information Technology Act, 2000 (“IT Act”), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Digital Personal Data Protection Act, 2023 (“DPDP Act”), together with the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) notified thereunder (collectively, the “India Data Protection Laws”). Any capitalized term used and not otherwise defined below has the meaning assigned under India Data Protection Laws.
Please note that we are providing the following disclosures and rights in this Privacy Policy in the interest of transparency. Such disclosures and rights are not intended to waive any applicable exemptions under applicable law.
The India Data Protection Laws are in a period of structured transition. The IT Act and the SPDI Rules presently govern the processing of sensitive personal data in India, and will continue to apply until the relevant provisions of the DPDP Act and DPDP Rules are brought into full force, which is expected to be phased in through May 2027. Upon full commencement, Section 43A of the IT Act and the SPDI Rules will be repealed and the DPDP Act will constitute the primary data protection framework in India. We are committed to complying with applicable requirements at each stage of this transition and to updating our practices as the regulatory framework is progressively operationalized. This Notice is drafted to be consistent with both the current framework and the DPDP Act as it comes into force.
Our Role as Data Fiduciary
For the purposes of the DPDP Act, Nucleus acts as a Data Fiduciary in respect of personal data collected from individuals in India. Where Nucleus processes personal data on behalf of another Data Fiduciary, Nucleus acts as a Data Processor. In either capacity, Nucleus processes personal data in accordance with applicable India Data Protection Laws and the purposes described in this Policy.
Personal Data We Collect
For the purposes of this India Privacy Notice, “personal data” means any data about an individual who is identifiable by or in relation to such data. The personal data we collect is described in the Collecting Personal Data section of this Policy.
A significant portion of the personal data we collect in connection with our genetic testing and embryo analysis services constitutes sensitive personal data under both the SPDI Rules (which include medical records and health data, biometric data, and genetic information) and will constitute personal data requiring heightened handling under the DPDP Act once fully in force. We collect this data only for the purposes described in this Policy, with your consent, and in accordance with applicable law.
Consent and Lawful Basis for Processing
Under the DPDP Act, consent is the primary basis on which we process your personal data. Consent under the DPDP Act must be free, specific, informed, unconditional, and unambiguous, and must be expressed through a clear affirmative action. Where you click “I Accept,” “I Agree,” or any equivalent confirmation button or checkbox on our Sites or in our Services, that action constitutes a clear affirmative action and, together with the notice presented to you at that time, forms your valid consent to the processing described in that notice.
Where we rely on your consent to process personal data, we will provide you with a separate notice prior to or at the time of collection. That notice will be presented in clear and plain language and will describe the personal data to be processed, the purpose for which it is processed, how you may exercise your rights as a Data Principal, and how to raise a complaint with the Data Protection Board of India. This Privacy Policy does not constitute that notice. Consent will not be obtained through pre-ticked boxes, bundled terms, or any mechanism that does not require a deliberate and affirmative act on your part.
You may withdraw your consent at any time by contacting us using the information in the Contact Us section. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Upon withdrawal, we will cease processing your personal data for the relevant purpose and will erase such data, except to the extent that retention is required or permitted under applicable law.
In addition to consent, the DPDP Act recognises certain “legitimate uses” for which personal data may be processed without consent, including compliance with a court order or other legal obligation, medical emergencies, and processing by employers in connection with employment. Where we process your personal data on a legitimate use basis, we will identify the applicable ground at the time of collection or use.
How We Use Personal Data
The purposes for which we collect and process personal data are described in the Using Personal Data section of this Policy. Under the DPDP Act, we are required to use your personal data only for the specified purpose for which it was collected. We will not process your personal data for any purpose that is incompatible with the purpose disclosed to you at the time of collection, without first obtaining your fresh consent.
Cross-Border Transfer of Personal Data
As described in the International Data Transfers section of this Policy, some personal data collected from individuals in India may be transferred to, stored, and processed in the United States, including for the purpose of whole-genome sequencing at our CLIA-certified laboratory. Such transfers are made in accordance with applicable India Data Protection Laws.
Under the DPDP Act and DPDP Rules, cross-border transfers of personal data are permitted subject to any restrictions or conditions that the Central Government of India may notify from time to time. We will comply with any such conditions as and when notified. We will update this Notice if any material restrictions on cross-border transfers affect our data flows involving India-sourced personal data.
Data Retention
Our retention practices are described in the Data Retention section of this Policy. Under the DPDP Act, we will not retain personal data beyond the period necessary for the specified purpose, or as required by applicable law. Where the purpose for which personal data was collected is no longer served and no legal obligation requires its retention, we will erase the data. Where we are required to notify you prior to erasure, we will do so in accordance with the DPDP Rules.
Children’s Data
Under the DPDP Act, a child is any person below eighteen years of age. Where we process personal data of a child in connection with our Services, we will obtain verifiable consent from the child’s parent or legal guardian prior to such processing, as required under the DPDP Act and DPDP Rules. We do not process children’s personal data for purposes of behavioral monitoring or targeted advertising.
Security Safeguards
We implement reasonable security safeguards to protect personal data against unauthorized access, disclosure, alteration, or destruction. Our security practices are described in the Data Security section of this Policy. Under the IT Act and SPDI Rules, we maintain security practices and standards consistent with reasonable security practices and procedures as defined under applicable Indian law. As the DPDP Act is phased into force, we will maintain security safeguards meeting the standards required under that Act and the DPDP Rules.
In the event of a personal data breach that is likely to affect your rights or interests, we will notify the Data Protection Board of India and, where required, affected individuals, in accordance with the timelines and procedures prescribed under the DPDP Act and DPDP Rules.
Your Rights as a Data Principal
Under the DPDP Act, individuals whose personal data is processed by a Data Fiduciary are referred to as Data Principals. Subject to applicable exceptions and to the phased commencement of the DPDP Act, individuals located in India are entitled to exercise the following rights in relation to their personal data:
Right to access information. You have the right to obtain a summary of the personal data we process about you and the processing activities we carry out in relation to that data, as well as details of the Data Processors and other Data Fiduciaries with whom we may have shared your personal data.
Right to correction and erasure. You have the right to request that we correct inaccurate or incomplete personal data, update personal data that is no longer current, and erase personal data that is no longer necessary for the purpose for which it was collected, subject to any applicable legal obligation to retain such data.
Right to withdraw consent. You have the right to withdraw your consent to the processing of your personal data at any time. Withdrawal of consent does not affect the lawfulness of processing undertaken before the withdrawal.
Right to grievance redressal. You have the right to raise a complaint or grievance with us regarding the processing of your personal data or our compliance with applicable India Data Protection Laws. We will respond to your grievance within the period required under applicable law. If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India in the manner prescribed under the DPDP Act and DPDP Rules.
Right to nominate. You have the right to nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity.
Grievance Officer and Consent Manager
We have designated a point of contact for Data Principals to raise grievances relating to our data processing practices. You may contact our grievance officer using the information provided in the Contact Us section of this Policy. We will respond to grievances within the period prescribed by applicable India Data Protection Laws.
The DPDP Act introduces a Consent Manager framework under which a registered intermediary may assist Data Principals in managing, reviewing, and withdrawing consent on their behalf across multiple Data Fiduciaries. As the Consent Manager registration process is operationalized under the DPDP Rules, we will update our practices to support Data Principals who wish to exercise their rights through a registered Consent Manager.
How to Exercise Your Rights
You may exercise any of the rights described in this India Privacy Notice by submitting a written request using the information in the Data Protection Officer (privacy@mynucleus.com) section of this Policy. We may ask you to verify your identity before we respond to your request. We will respond within the period required under applicable India Data Protection Laws, and will not charge a fee for processing a request unless it is excessive or manifestly unfounded. If we are unable to fulfill your request, we will provide reasons and inform you of your right to escalate to the Data Protection Board of India.
Data Protection Board of India
The Data Protection Board of India (“DPBI”) is the regulatory authority constituted under the DPDP Act to adjudicate complaints from Data Principals and enforce compliance by Data Fiduciaries. If you are not satisfied with our response to a grievance or a rights request, you may file a complaint with the DPBI in accordance with the procedures prescribed under the DPDP Act and DPDP Rules. Details of the DPBI and the complaints procedure are available at the official Ministry of Electronics and Information Technology website.
21
Links to Other Websites
22
Changes to This Privacy Policy
23
Contact Us
