Privacy Policy


BioSam is committed to protecting our customer's privacy. Please take the time to review this notice which explains what information we collect about you, how we use it, and your rights. BioSam Limited (“Biosam”, “we” or “us”) is the data controller of the personal data collected via or in connection with Biosam and any associated App (the “Site”).


  1. What personal data we collect and how


    Personal data, or personal information, means any information about an individual from which that person can be identified.

    Personal data we collect directly. We collect personal data from you when you provide it to us directly and through your use of the Site, including:


  2. How we use personal data


    Depending on how you use our Site, your interactions with us, and the permissions you give us, the purposes for which we use your personal data include:


  3. Who do we share personal data with?


    We may share your personal data with third parties, for the purposes described above, in the following circumstances:


  4. Cookies and Personalisation


    Cookies and tracking technologies. We and our third party service providers use cookies, pixels, local storage objects, log files, APIs, and similar technologies to automatically collect browsing activity, device and similar information within our Site.

    We use this information to provide functionality on the Site, to understand and measure Site performance, to understand how users access, use and interact with others, and to deliver targeted advertising and content on our Site and third party sites.

    We also use it to identify and resolve bugs and errors in our Site and to assess, secure, protect, optimise and improve the performance of our Site. Personalised advertising. We work with third parties, such as ad networks, social media platforms, analytics and measurement services and others to personalise content and display advertising within our Site, and to manage our advertising on third party sites, mobile apps and online services.

    For example, you may see ads for our Site on third party websites, including on social media. These ads may be tailored to you using cookies and similar technologies which track your web activity on our Site and across other websites and online services, to enable us to serve ads to customers who have visited our Site.

    We may also engage third parties, including social networks to show ads to our customers, or users who match the demographic profile of our customers. This may involve sharing information, such as your name, email address, and other contact and purchase information with these third parties so that we can better target ads and content to you across third party sites, platforms and services. These third parties may also help us to enhance our customer lists with additional demographic or other information, so we can better target our advertising and marketing campaigns.

    If you do not want to see personalised ads you can change your cookie

    preferences using the tool available on our Site, as explained below, and by adjusting your privacy settings on third party websites and platforms.

    Manage your preferences. You can manage your preferences for cookies and personalisation used by us as explained below.


    Please note that opting out of cookies and trackers on our Site does not mean that you will no longer see ads from us. You may continue to see generic or “contextual” ads.


    Please see our Cookie Policy here for further information about the use of cookies on our Site and the choices you have.

  5. Marketing


    We love to communicate with our customers. Depending on your marketing preferences, we may use your personal data to send you marketing messages by email, SMS, phone and post. Some of these messages may be tailored to you, based on your previous browsing or purchase activity, and other information we hold about you.


    If you no longer want to receive marketing communications from us (or would like to opt back in!), you can change your preferences at any time by contacting us (details below), clicking on the ‘unsubscribe’ link in any email, or updating your settings in your account. If you unsubscribe from marketing, please note we may still contact you with service messages from time to time (e.g. order and delivery confirmations, and information about your legal rights).


  6. Transfers of personal data to other countries


    We use service providers, and have group companies, in countries around the world. Your personal data may therefore be processed in countries outside of Europe, including in countries where you may have fewer legal rights in respect of your data than you do under local law. If we transfer personal data outside the UK/European Economic Area we will ensure that your privacy rights are adequately protected by appropriate safeguards, which may include

    the European Union’s standard contractual clauses and UK equivalent. Please contact us if you would like more information about these safeguards.


  7. Retention


    We will keep your personal data in line with our data retention policy, for as long as we need it for the purposes set out above, so this period will vary depending on your interactions with us. For example, where you have made a purchase with us, we will keep a record of your purchase for the period necessary for invoicing, tax and warranty purposes. We may also keep a record of correspondence with you (for example if you have made a complaint about a product) for as long as is necessary in connection with any legal claim.


  8. Security


    We implement appropriate technical and organisational security safeguards to protect your data from loss, misuse, and unauthorised access, disclosure, alteration and destruction. We also maintain ISO 27001 and PCI DSS (Payment Card Industry - Data Security Standard) security certifications.

    However, please be aware that it is impossible for any company to guarantee the absolute security and integrity of the information that has been transmitted to its website.


  9. Children


    Our Site is not intended for, and should not be used by, children under the age of 18. We do not knowingly collect personal data from children under 18.


  10. Your Rights


    You have choices regarding our processing of your personal data as described in this section. Your rights under data protection laws: You have the right to:


  11. Changes to this Notice


    This Notice is current as of the Effective Date stated above. We may change this Notice from time to time, so please be sure to check back periodically. If we make material changes we will alert you e.g. by posting a prominent notice on the Site or via email.


  12. California Privacy Supplement


Consumers residing in California have additional rights in relation to their personal information under California privacy law, including the California Consumer Privacy Act (“CCPA”). If you are a California resident, this section applies to you. This section does not address or apply to our handling of publicly available information or other personal information that is exempt under the CCPA.


Categories of personal information collected and disclosed. Whilst our processing of personal information varies based upon our relationship and interactions with you, the table below identifies, generally, the categories of personal information (as defined by the CCPA) that we may collect, and have in the past twelve months collected, about California residents, as well as the categories of third parties to whom we may disclose this information for a business or commercial purpose


Categories of Personal Information


Categories of Third Party Disclosures


Cat


Identifiers


Includes direct identifiers, such as name, alias, user ID, username, account number or unique personal identifier; email address, phone number, address and other contact information; IP address and other online identifiers.



Customer Records


Includes e.g. name, account name, user ID, contact information, account number, and financial or payment information, that individuals provide us in order to purchase or obtain our products and services. For example, this may include information collected when an individual register for an account, purchases or orders our products and services, or enters into an agreement with us related to our products and services.



Commercial information


Includes records of personal property, products or services purchased, obtained, or considered, or other purchasing or use histories or tendencies. For example, this may include demographic information that we receive from third parties in order to better understand and reach our customers.



Internet and electronic network activity information


Including, but not limited to, browsing history, clickstream data, search history, and information regarding interactions with an internet website, application, or advertisement, including other usage data related to your use of any of our Site or other online services.



Geolocation data


Location information about a particular individual or device e.g., derived from your IP address.



Audio, visual and other electronic data


Includes audio, electronic, visual, thermal or similar information, such as thermal screenings and CCTV footage (e.g., collected from visitors to our stores, offices and premises; photographs and images (e.g., that you provide us or post to your profile) and call recordings (e.g., of customer support calls).



Professional information


Includes professional and employment-related information such as current and former employer(s) and position(s), job application information, business contact information and professional membership(s).



Profiles and inferences


Including inferences drawn from any of the information identified above to create a profile reflecting a consumer’s preferences, characteristics, behavior or attitudes.



Protected classifications


We collect some information that is considered a protected classification under California/federal law, such as your gender, date of birth, citizenship, and marital status.



Sensitive personal information


In limited circumstances, we may collect:


Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account.


Sales and sharing. California privacy laws define a "sale" as disclosing or making available to a third-party personal information in exchange for monetary or other valuable consideration, and “sharing” broadly includes disclosing or making available personal information to a third party for purposes of cross-context behavioral advertising. While we do not disclose personal information to third parties in exchange for monetary compensation, we may “sell” or “share” (as defined by the CCPA): identifiers and internet and electronic network activity information to/with third-party advertising networks, analytics providers, and social networks. We do so in order to improve and evaluate our advertising campaigns and better reach customers and prospective customers with more relevant ads and content. We do not sell or share sensitive personal information, nor do we sell or share any personal information about individuals who we know are under sixteen (16) years old.


Sources of personal information. In general, we may collect personal information from the following categories of sources:


Submitting CCPA requests. California residents may make requests to access/know, correct and delete their personal information maintained by us online by

emailing support@biosam.co.uk or by visiting this page. Once we receive your request, we will take steps to verify it by asking you to provide information related to your account or your recent interactions with us, such as information regarding a recent purchase. We will process your request based upon the personal information in our records that is linked or reasonably linkable to the information provided in your request. In some cases, we may request additional information in order to verify your request or where necessary to process your request. If we are unable to adequately verify a request, we will notify the requestor. If you would like to use an authorized agent to exercise your rights, we may request evidence that you have provided such agent with power of attorney or that the agent otherwise has valid authorization to submit requests on your behalf and we may also require that the relevant consumer directly verify their identity and the authority of the authorized agent.

Opt-out requests. Our Site responds to global privacy control—or “GPC”—signals, which means that if we detect that your browser is communicating a GPC signal, we will process that as a request to opt that particular browser and device out of sales and sharing (i.e., via cookies and tracking tools) on our Site. Note that if you come back to our Site from a different device or use a different browser on the same device, you will need to opt out (or set GPC for) that browser and device as well.

More information about GPC is available. You can also opt out of online tracking on our Site via the cookie preference tool (see Section 5 for details).

California residents may exercise their right to opt out online by submitting an opt out request to support@biosam.co.uk or by visiting this page. We will apply your opt out based upon the personal information in our records that is linked or reasonably linkable to the information provided in your request.


For more information about our privacy practices, you may contact us as set out in the “Contact Us” section above.


Last Revised: 10 December 2023