(spx® — 01)
Privacy & Data Use
How SignalPGx collects, uses, and protects data —
including the genetic and health information we process for clinical laboratories.
How SignalPGx collects, uses, and protects data — including the genetic and health information we process for clinical laboratories.

This page explains how SignalPGx collects, uses, shares, and protects personal, patient, and genetic data.
What you can expect from our data protection, and how we safeguard the patient and genetic data laboratories entrust to us. If anything here is unclear, email info@signalpgx.com
1. Who we are
SignalPGx LLC ("SignalPGx", "we", "us", "our") provides a white-label pharmacogenomics (PGx) reporting platform that clinical laboratories use to generate branded, physician-reviewed medication reports. This Privacy Policy explains how we handle information across our website and platform. When a laboratory uses SignalPGx to process patient data, the laboratory is the data controller and, for HIPAA purposes, the covered entity responsible for that patient and genetic data, and SignalPGx acts as its processor and HIPAA business associate under a separate business-associate/data-processing agreement.
Contact: info@signalpgx.com
2. Information we collect
From lab and website users we collect information you provide directly, such as your name, work email, and account details. On behalf of laboratories, we process the genetic and genotype data and limited patient identifiers a lab submits so our platform can generate pharmacogenomic reports. Technical data, including IP addresses and usage patterns, may be collected automatically via cookies.
3. How we use your data
We use account information to operate and improve the platform, process payments, and send service updates. Patient and genetic data submitted by a laboratory is used only to generate that lab's pharmacogenomic reports and deliver them into clinical workflows, under the lab's instructions. We process account information to perform our contract with laboratories and their users and for our legitimate interest in operating and securing the platform; genetic and health data is processed on behalf of, and under the instructions and lawful authority of, the instructing laboratory as its processor. We do not sell personal, patient, or genetic data.
4. Genetic data & AI training
We do not use patient, genetic, or genotype data to train AI models. SignalAI supports interpretation using trusted, published pharmacogenomic evidence, and every report stays under medical-director review and the laboratory's control. Limited, de-identified operational metadata may be used to maintain and secure the platform.
5. Data sharing & disclosure
We may share data with vetted subprocessors that help us run the platform, such as payment processors and cloud infrastructure (e.g., Amazon Web Services), under contracts requiring appropriate safeguards and, where applicable, HIPAA business-associate terms. We may also disclose information if required by law or to protect our legal rights. We never share patient or genetic data for advertising.
6. Data retention
We retain account and report data for as long as an account or laboratory agreement is active, or as needed to provide the service and meet legal, clinical, and audit obligations. Patient and genetic data are retained and deleted according to the instructing laboratory's agreement; you may request deletion of your account and associated data at any time.
7. Security
We protect data with encryption in transit and at rest, role-based access controls, tenant isolation, and audit logging on secured cloud infrastructure, following HIPAA-aligned safeguards. If we become aware of a security incident affecting patient or genetic data we process for a laboratory, we will notify that laboratory without undue delay in accordance with our business-associate agreement so it can meet its notification obligations; for personal data of our own account holders and website users, we will provide notice as required by applicable law. No method of transmission over the internet or electronic storage, however, is 100% secure.
8. User rights
Depending on your location, you may have the right to access, correct, or delete your personal data. If you are in the EEA or UK, you have specific GDPR rights, including access, rectification, erasure, restriction of processing, data portability, and the right to object; you may also withdraw consent where processing relies on it, and you have the right to lodge a complaint with your local data protection supervisory authority. Patients whose data a laboratory processes through SignalPGx should contact that laboratory, which controls the data; we will support the lab in honoring such requests.
9. Cookies & tracking
Our website uses cookies to enhance your browsing experience and analyze site traffic. You can manage cookie preferences through your browser settings, though some features of the platform may not function properly without them.
10. Third-party links
Our website and platform may contain links to third-party websites. We are not responsible for the privacy practices or content of these external sites, and we encourage you to read their privacy policies.
11. Children’s privacy
SignalPGx is a business-to-business platform for clinical laboratories and is not directed to children or offered directly to individuals. Any pediatric patient data is submitted and controlled by the ordering laboratory under its own authorizations. We do not knowingly collect information directly from children and will delete it if we become aware of it.
12. International data transfers
Your information may be transferred to and processed in countries other than your own, subject to appropriate safeguards. Where a laboratory directs cross-border processing of patient data, we support the transfer mechanisms required by applicable law.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in regulations, technology, or our practices. Updates will be posted on this page with a revised "Last updated" date.
14. Contact
Questions about this Privacy Policy?
info@signalpgx.com
If email isn’t an option, write to us at the registered address listed in our website footer.
15. Compliance
SignalPGx supports HIPAA- and GDPR-aligned workflows and processes protected health information as a business associate on behalf of laboratories. SignalPGx provides decision-support and reporting tools and is not a diagnostic device or a substitute for clinical judgment. This Policy is provided for transparency and general information, not as legal advice; please consult a qualified professional about your specific obligations.
1. Who we are
SignalPGx LLC ("SignalPGx", "we", "us", "our") provides a white-label pharmacogenomics (PGx) reporting platform that clinical laboratories use to generate branded, physician-reviewed medication reports. This Privacy Policy explains how we handle information across our website and platform. When a laboratory uses SignalPGx to process patient data, the laboratory is the data controller and, for HIPAA purposes, the covered entity responsible for that patient and genetic data, and SignalPGx acts as its processor and HIPAA business associate under a separate business-associate/data-processing agreement.
Contact: info@signalpgx.com
2. Information we collect
From lab and website users we collect information you provide directly, such as your name, work email, and account details. On behalf of laboratories, we process the genetic and genotype data and limited patient identifiers a lab submits so our platform can generate pharmacogenomic reports. Technical data, including IP addresses and usage patterns, may be collected automatically via cookies.
3. How we use your data
We use account information to operate and improve the platform, process payments, and send service updates. Patient and genetic data submitted by a laboratory is used only to generate that lab's pharmacogenomic reports and deliver them into clinical workflows, under the lab's instructions. We process account information to perform our contract with laboratories and their users and for our legitimate interest in operating and securing the platform; genetic and health data is processed on behalf of, and under the instructions and lawful authority of, the instructing laboratory as its processor. We do not sell personal, patient, or genetic data.
4. Genetic data & AI training
We do not use patient, genetic, or genotype data to train AI models. SignalAI supports interpretation using trusted, published pharmacogenomic evidence, and every report stays under medical-director review and the laboratory's control. Limited, de-identified operational metadata may be used to maintain and secure the platform.
5. Data sharing & disclosure
We may share data with vetted subprocessors that help us run the platform, such as payment processors and cloud infrastructure (e.g., Amazon Web Services), under contracts requiring appropriate safeguards and, where applicable, HIPAA business-associate terms. We may also disclose information if required by law or to protect our legal rights. We never share patient or genetic data for advertising.
6. Data retention
We retain account and report data for as long as an account or laboratory agreement is active, or as needed to provide the service and meet legal, clinical, and audit obligations. Patient and genetic data are retained and deleted according to the instructing laboratory's agreement; you may request deletion of your account and associated data at any time.
7. Security
We protect data with encryption in transit and at rest, role-based access controls, tenant isolation, and audit logging on secured cloud infrastructure, following HIPAA-aligned safeguards. If we become aware of a security incident affecting patient or genetic data we process for a laboratory, we will notify that laboratory without undue delay in accordance with our business-associate agreement so it can meet its notification obligations; for personal data of our own account holders and website users, we will provide notice as required by applicable law. No method of transmission over the internet or electronic storage, however, is 100% secure.
8. User rights
Depending on your location, you may have the right to access, correct, or delete your personal data. If you are in the EEA or UK, you have specific GDPR rights, including access, rectification, erasure, restriction of processing, data portability, and the right to object; you may also withdraw consent where processing relies on it, and you have the right to lodge a complaint with your local data protection supervisory authority. Patients whose data a laboratory processes through SignalPGx should contact that laboratory, which controls the data; we will support the lab in honoring such requests.
9. Cookies & tracking
Our website uses cookies to enhance your browsing experience and analyze site traffic. You can manage cookie preferences through your browser settings, though some features of the platform may not function properly without them.
10. Third-party links
Our website and platform may contain links to third-party websites. We are not responsible for the privacy practices or content of these external sites, and we encourage you to read their privacy policies.
11. Children’s privacy
SignalPGx is a business-to-business platform for clinical laboratories and is not directed to children or offered directly to individuals. Any pediatric patient data is submitted and controlled by the ordering laboratory under its own authorizations. We do not knowingly collect information directly from children and will delete it if we become aware of it.
12. International data transfers
Your information may be transferred to and processed in countries other than your own, subject to appropriate safeguards. Where a laboratory directs cross-border processing of patient data, we support the transfer mechanisms required by applicable law.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in regulations, technology, or our practices. Updates will be posted on this page with a revised "Last updated" date.
14. Contact
Questions about this Privacy Policy?
info@signalpgx.com
If email isn’t an option, write to us at the registered address listed in our website footer.
15. Compliance
SignalPGx supports HIPAA- and GDPR-aligned workflows and processes protected health information as a business associate on behalf of laboratories. SignalPGx provides decision-support and reporting tools and is not a diagnostic device or a substitute for clinical judgment. This Policy is provided for transparency and general information, not as legal advice; please consult a qualified professional about your specific obligations.

