Introduction and Scope
Curehub (“we,” “us,” or “our”) offers genetics‑based wellness insights by analyzing users’ DNA and methylation data. Our Service is designed for general well‑being and is not a medical diagnosis or treatment. This Privacy Policy explains how we collect, use, store, share and protect your personal information and genetic data when you visit the Curehub website or use our associated services (the “Services”). By using our Services, you acknowledge that you have read and agree to this policy.
If you do not agree with any part of this policy, discontinue use of the Services.
We take privacy seriously. Industry best‑practice guidance for direct‑to‑consumer genetic testing recommends that companies provide clear information about data collection, consent, use, onward transfer, access, security and retention/deletion practices, and we have drafted this policy with that standard in mind. Genetic and methylation data are inherently sensitive because they may reveal health risks or family information, so our policy reflects heightened protections.
Types of Information We Collect
1. Registration and Account Information
When you create an account, place an order or contact customer support, you provide details such as your name, date of birth, billing and shipping addresses, payment information, email address, phone number and account password. We also collect any information you submit through contact forms or surveys (for example, fitness goals or lifestyle information).
2. Genetic and Methylation Data
If you purchase a Curehub kit or upload data, we receive your DNA or methylation sample and associated raw data. Your DNA sample and data remain your property; they are stored on secure, encrypted systems, may be destroyed at your request and will never be shared without your explicit consent. The laboratory processing your sample collects identifiers (sample number, date of birth and, in most cases, your name) needed to meet quality standards.
3. Self‑Reported and Lifestyle Information
You may choose to provide additional information through questionnaires, such as nutrition goals, exercise preferences or other health‑related details. Participation in research surveys is optional and subject to separate informed consent.
4. Device and Usage Information
We automatically collect technical data when you visit our website or use our mobile application. This includes IP addresses, device identifiers, browser type, operating system, pages visited and usage patterns. Cookies and similar technologies help us understand how users interact with the site, diagnose technical issues and improve the user experience. For example, we use analytics services like Google Analytics, but we do not share genetic or personal health information with advertisers.
5. Information from Third Parties
Our laboratories and service providers may send us data necessary to provide the Services (e.g., sample barcodes or test results). We may also receive demographic or health information from authorized healthcare partners, but such data is treated as protected health information (PHI) and is processed under strict confidentiality.
How We Use Information
We use your personal information and genetic data to:
1. Provide our Services. We use your data to process orders, ship kits, create accounts, authenticate log‑ins, analyze DNA and methylation samples, generate wellness reports and display results to you. Our analysis is limited to the markers we report; we do not test for diseases, and results cannot identify you or be used by insurers.
2. Improve and develop our products. We may use aggregated or anonymized data to enhance existing reports, develop new insights and improve the performance of our website and applications. De‑identified information is not subject to this policy.
3. Communicate with you. We send transactional messages (order confirmations, account notices) and may send marketing emails about new products or updates. You can unsubscribe from promotional communications at any time.
4. Conduct optional research. We may invite you to participate in research studies. Such studies require separate informed consent describing the purpose, risks, benefits and confidentiality provisions. You are not required to participate, and participation (or refusal) does not affect your access to our core Services.
5. Comply with legal obligations and enforce our rights. We may process data to meet legal requirements, protect against fraud, enforce our Terms and defend against claims.
We do not use personal information for automated decision‑making that produces legal or similarly significant effects. We also do not sell your individual-level genetic or health data, and we do not share it with insurers, employers or public databases.
Sharing and Disclosure of Information
We share personal and genetic data only as described below:
1. Service providers and contractors. We use vetted laboratories, payment processors, cloud hosting providers and customer support vendors. They act under our instructions and are contractually bound to process data only to provide services to Curehub.
2. Authorized third parties with your explicit consent. We will not transfer your individual‑level genetic or personal data to any third party (other than our service providers) unless you explicitly agree. Separate consent is required for research partnerships and other secondary uses.
3. Aggregated or de‑identified information. We may share summary statistics or anonymized insights that no longer identify individuals.
4. Legal compliance. We may disclose information when required to comply with a valid court order, subpoena or legal process. We will assess each request and challenge overbroad or inappropriate demands.
5. Business transitions. In the event of a merger, acquisition or sale of assets, your data will remain subject to this policy; material changes will not occur without notice and your consent.
Curehub will never sell, lease or rent your individual-level genetic data or personal information , and we do not share customer data with public databases or insurers.
Data Security
We employ administrative, technical and physical measures to protect personal and genetic data against unauthorized access, disclosure and destruction. These measures include:
• Anonymization, encryption and data segmentation: Identifiers (name, contact details) are stored separately from genetic and phenotypic data and are assigned random IDs to prevent re‑identification.
• Access controls: Access to sensitive data is limited to authorized personnel based on job role.
• Secure facilities and networks: Laboratories storing DNA samples follow international quality and access control standards, and we employ intrusion detection and prevention systems to detect threats.
• Regular audits and assessments: We review our security practices and update them as technology evolves. De‑identification and aggregation methods are applied to reduce the risk of re‑identification.
No system is completely secure. However, we implement and regularly review safeguards designed to protect your data. If we become aware of a data breach, we will notify affected individuals as required by law.
Data Retention and Sample Destruction
We retain personal information only for as long as necessary to provide the Services and fulfill the purposes outlined in this policy, or as required by law. Your DNA sample and data can be destroyed at any time at your request. When you delete your Curehub account, we will delete or de‑identify your personal information unless retention is required for legal reasons (e.g., accounting or compliance).
Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
• Access: You can request a copy of the data we hold about you.
• Rectification: You can correct inaccurate or incomplete information.
• Deletion: You can request deletion of your account and data at any time.
• Restriction and objection: You can restrict or object to certain processing activities, including marketing.
• Data portability: You can request that we transfer your data to another organization (where technically feasible).
• Complaint: You have the right to lodge a complaint with a data protection authority. EU residents can contact their local supervisory authority.
You also choose when and with whom to share your information (e.g., family members or healthcare professionals). You may update preferences, withdraw consent or delete your account through the Curehub account settings or by contacting us.
International Data Transfers
Curehub is based in the European Union but may use service providers located in other countries. When we transfer personal data outside the European Economic Area (“EEA”), we rely on adequate safeguards such as European Commission approved standard contractual clauses or the recipient’s certification under an approved framework. We take steps to ensure that your data receives a level of protection equivalent to that afforded in your home jurisdiction.
Cookies and Tracking Technologies
We use cookies, pixels and similar technologies to collect usage data and improve our Services. Some cookies are necessary for the site to function, while others help us analyze traffic and personalize content. You can manage cookie preferences through your browser settings or by using cookie‑management tools on our website.
Third‑Party Links and Services
Our website may contain links to third‑party websites or services. We do not control and are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external sites you visit.
Children’s Privacy
Our Services are intended for adults. You must be at least 18 years old to purchase a kit or create an account, or have legal authority to act on behalf of a minor. If we learn that we have collected personal information from a child without appropriate consent, we will delete the information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will not be made without first providing prominent notice and obtaining your consent if data will be used in any manner inconsistent with the terms initially provided. For example, we will post a notice on our website and, where appropriate, send email notifications before changes take effect. Continued use of the Services after the effective date of an updated policy constitutes acceptance of the changes.
Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or wish to request deletion of your genetic sample or data, please contact our Team:
Email: info@curehub.eu
Postal mail: Curehub Lab Kft., Alispán utca 8 C/D. Fsz. 5. ajtó 2030 Érd, Hungary
Governing Law
To the extent permitted by applicable law, this Privacy Policy is governed by the law of the jurisdiction that has the most significant connection to the Services and your use of them, without regard to conflict‑of‑laws principles. Mandatory local laws and consumer protections in your country of residence will take precedence where required. Any disputes arising under this Privacy Policy will be handled in accordance with the dispute resolution procedures described in our Terms and Conditions.
CONTACT US
CONTACT US