Privacy Policy
Genpath.ai, LLC d/b/a HelixaHealth.ai
Effective Date: August 01, 2026
Version: 1.0
This Privacy Policy explains how Genpath.ai, LLC d/b/a HelixaHealth.ai (“Helixa,” “we,” or “us”) collects, uses, discloses, and protects your information, with particular attention to genetic data. It supplements the Genetic Testing Informed Consent and Data Authorization (the “Consent”), which governs your specific authorizations. Where the Consent and this Policy address the same subject, the Consent controls as to the authorizations you gave.
1. Who We Are
Helixa sells genetic testing kits and delivers results and related insights. The laboratory analysis is performed by Dynamic DNA Laboratories, an independent laboratory. After analysis, your genetic raw data and results are returned to Helixa for further processing to produce your reports. Because Helixa offers this service directly to consumers and is not acting as a HIPAA-covered healthcare provider or health plan in this transaction, the information you provide is protected under this Policy and applicable consumer-privacy and genetic-privacy laws rather than under HIPAA, based on Helixa's current business model. If Helixa's role changes in a way that would make HIPAA applicable, we will update this Policy and the Consent accordingly.
2. Information We Collect
- Account and contact information, such as your name, email, shipping address, and password.
- Order and payment information, processed through our payment provider.
- Intake information required for testing, such as age, sex, and the fields required by the laboratory.
- Genetic data - the raw genetic data and test results returned to Helixa by Dynamic DNA.
- Usage and device information collected automatically when you use the platform, including cookies and similar technologies.
3. How We Use Information
We use your information to fulfill and support your order; to generate, interpret, and deliver your results; to provide customer service; to secure and improve the platform; to communicate with you about your order and results; and to meet legal, tax, and audit obligations. We use your genetic data only to provide the services you requested and as otherwise described in this Policy and the Consent.
4. Consent
We rely on the consents you provide in the Consent to collect, use, and disclose your genetic data. Where applicable law requires separate, express consent before genetic data is transferred to certain third parties, retained beyond initial testing, or used for research or marketing, we obtain that consent separately, and you may withdraw it at any time without affecting testing already performed.
5. How We Share Information
We share information only as needed to operate the service and as required by law:
- With Dynamic DNA, to fulfill and process your order;
- With service providers who operate parts of our platform under contract (for example payment processing, hosting, and shipping), limited to what each needs and bound by confidentiality and data-protection obligations;
- Where legally compelled by valid legal process, or to protect rights, safety, or security; and
- In a business transfer, subject to Section 13. With a healthcare provider or genetic counselor of your choosing, but only at your direction. We do not share your genetic data or results with any corporate affiliate; if this changes, we will update this Policy and, where required by law, obtain your consent first.
We do not sell your genetic information, do not use it for advertising, do not share it for cross-context behavioral advertising, and do not disclose it to data brokers. We do not disclose your genetic data to insurers or employers, and we do not provide it to law enforcement absent valid legal process.
6. Automated Processing; No Model Training
We use automated systems, which may include machine-learning models, to generate and interpret your results. We do not use your genetic data to train or improve machine-learning models. This commitment applies regardless of whether you have opted in to the optional research use described in the Consent; de-identified genetic data contributed under that opt-in is not used to train or improve machine-learning models absent a separate, specific disclosure and opt-in for that purpose. Your genetic data is used only to produce the results and insights you purchased and as otherwise described in this Policy.
7. Data Retention and De-Identification
We retain your information for as long as your account remains active and as needed to meet legal, tax, and audit obligations, and thereafter we delete or de-identify it. When we de-identify data, we use measures reasonably designed to prevent its association with you using a methodology consistent with recognized frameworks such as the HIPAA Safe Harbor or Expert Determination methods, adapted to our context; de-identified data may retain a low residual risk of re-identification, and we do not attempt to re-identify de-identified data except as permitted by law to test our de-identification. The laboratory’s retention of your physical sample is governed by the laboratory’s consent. We retain account and order information for the life of your account and up to seven (7) years thereafter for tax and audit purposes; genetic raw data and results are retained for the life of your account unless you request earlier deletion. “Anonymize” or “anonymization” means processing data so that re-identification is not reasonably possible by any party, including us, and anonymized data is not personal information under applicable law.
8. Data Security and Breach Notification
We maintain administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and access controls limiting who may view genetic data. No system is perfectly secure. If a breach affecting your information occurs, we will notify you and the authorities as required by applicable law. Because our services may involve genetic and other health-related information, we comply with the FTC’s Health Breach Notification Rule (16 C.F.R. Part 318) in addition to applicable state breach-notification laws, including notifying affected individuals without unreasonable delay and in any event within sixty (60) calendar days of discovery, and notifying the Federal Trade Commission within the timeframe the Rule requires.
9. Your Rights
Subject to applicable law and legitimate recordkeeping obligations, you may access, correct, delete, and (where applicable) port your information; withdraw consent; and request that the laboratory destroy your sample. When we receive a deletion request we can verify, we will complete it within forty-five (45) days, with one permitted extension of up to an additional forty-five (45) days for complex requests where the law allows, and we will confirm when it is done. To exercise these rights, contact privacy@helixahealth.ai.
California residents: your genetic data, health-related information, and certain other information we collect are “sensitive personal information” under the California Consumer Privacy Act, as amended. We use and disclose sensitive personal information only for the limited business purposes described in this Policy and do not use it to infer characteristics about you for unrelated purposes; because we do not use or disclose sensitive personal information beyond these limited purposes, California law does not currently require us to offer a separate “Limit the Use of My Sensitive Personal Information” option, and if this changes we will provide that option. You may use an authorized agent, and where a state law provides a right to appeal a denied request, we will provide an appeal mechanism.
10. State-Specific Disclosures
California
Under the California Genetic Information Privacy Act (GIPA) and the California Consumer Privacy Act, as amended (CCPA/CPRA), California residents have the rights described above, including the right to delete genetic data, to have the biological sample destroyed, and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA.
Illinois
Under the Illinois Genetic Information Privacy Act, we will not disclose your genetic testing information except with your written authorization or as otherwise permitted by that Act, and we obtain the consents that Act requires before disclosure.
Other states
Residents of other states with consumer-privacy or genetic-privacy laws have the rights those laws provide, which we honor where they apply. In addition to the California and Illinois disclosures above, residents of Alabama, Arizona, Florida, Kentucky, Louisiana, Maryland, Montana, Nebraska, South Dakota, Tennessee, Texas, Utah, Virginia, Wyoming, and any other state with a genetic-privacy or comprehensive consumer-privacy statute that applies to Helixa have the rights that statute provides, which we honor regardless of the state in which you reside. If you are a Washington or Nevada resident, or are physically present in Washington or Nevada when you use our services, our collection, use, and sharing of your consumer health data, including genetic data, is additionally governed by Washington’s My Health My Data Act or Nevada’s consumer health data law, as applicable, and by our separate Consumer Health Data Privacy Policy; we do not collect consumer health data beyond what is strictly necessary to provide the product or service you requested without your separate, valid authorization.
11. Genetic Non-discrimination
The federal Genetic Information Non-discrimination Act (GINA) restricts the use of genetic information by health insurers and employers. Its protections are limited and do not cover life, disability, or long-term-care insurance. State law may provide additional protection. Consider these limits before sharing your results with third parties.
12. Health Connect and Apple Health Data
If you turn on "Connect with Health App" in the mobile app, we read the following categories of data from Health Connect (Android) or Apple Health (iOS): heart rate, resting heart rate, heart rate variability, oxygen saturation, steps, sleep, weight, blood pressure, body temperature, and blood glucose. We use this data only to build the trend charts on your Health Metrics screen and, where you have enabled it, to include relevant trends in your generated health reports. This data is transmitted to our servers over an encrypted connection, stored encrypted at rest, and is not sold, used for advertising, or shared with any third party for their own purposes. You can disconnect at any time by turning off "Connect with Health App," and you can revoke Helixa's access directly from the Health Connect or Apple Health app settings on your device. See Section 8 for how we protect this data and Section 9 for how to request its deletion.
13. Business Transfers and Insolvency
If Helixa is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction only to a successor that agrees to be bound by commitments no less protective than those in this Policy and the Consent. We will notify you before your genetic data would become subject to a materially different privacy practice, and you will have the opportunity to delete your data and direct destruction of your sample beforehand. We will not sell or transfer your genetic data as a standalone asset stripped of these commitments.
14. Law Enforcement and Third-Party Requests
We require valid legal process before disclosing personal information or genetic data in response to a government or third-party request, we review requests for legal sufficiency, and we seek to narrow or challenge requests that are overbroad or improper. We do not voluntarily provide genetic data to law enforcement.
15. Children
The services are intended for adults. We test a person under eighteen (18) only with the consent of a parent or legal guardian, and we do not knowingly collect information from a child except through that parent or guardian. The Helixa platform is not directed to children under thirteen (13) and we do not knowingly collect personal information directly from a child under thirteen through the platform, consistent with the Children's Online Privacy Protection Act. Where a minor is tested, the minor does not create their own account or interact directly with the platform; their parent or legal guardian creates and controls the account, provides all information, and receives all results.
16. Cookies and Tracking
We use cookies and similar technologies to operate the platform, remember preferences, and measure usage. You can control cookies through your browser settings. We use essential cookies to operate the platform, functional cookies to remember your preferences, and, where disclosed to you at collection, analytics cookies to measure usage. We also use advertising cookies, and you may opt out through the cookie banner or by using your browser’s controls. We honor Global Privacy Control signals as a valid opt-out request where applicable law requires.
17. United States Only
The services are offered in the United States and are intended for United States residents. Kits are not available to residents of New York, Maryland, Pennsylvania, or Rhode Island, and we do not offer the services where prohibited by law.
18. Changes to This Policy
We may update this Policy. Material changes will be communicated, and the version in effect when you provided your information governs that information unless you agree to an updated version.
19. Contact
Genpath.ai, LLC d/b/a HelixaHealth.ai, 9238 Diamond Pointe Drive, Indianapolis, IN. Email: privacy@helixahealth.ai. Helixa's Privacy Officer is responsible for this Policy and can be reached at the address above.
End of Privacy Policy.