Last updated: 14/07/2026

1. Introduction

This Privacy Policy explains how Genial (operated by Genial Compliance Systems Ltd and Genial Genetic Solutions Ltd — “Genial”, “we”, “us” or “our”) collects, uses, discloses and protects personal information when you visit our website, https://www.genialcompliance.com/ (the “Site”), use our services, communicate with us, or otherwise interact with us (the “Services”). This Policy describes our practices for the personal information for which we are a “data controller” under applicable law.

Genial is part of Harris Health Alliance, a subsidiary of Harris Computer.

This Privacy Policy should be read together with our Cookies and Similar Technologies Policy, which explains how we use cookies and similar technologies.

2. Personal Information We Collect

Contact and Business Information – such as name, job role, employer, address, telephone number, and email address, for example when you contact us, request a demo, or engage with us in a commercial or contractual context.

Location and Technical Information – such as IP address, device identifiers, browser type, operating system, and information about how you use our Site. This information may be collected through cookies and similar technologies.

Health and Genetic Information – where we provide quality and information management or genetic solutions to healthcare providers, we may process health or genetic data on behalf of those providers. Much of this information is handled as a service provider/processor and may be subject to separate laws (for example HIPAA in the United States). See Section 6.

Information from other sources – we may receive information from affiliates, service providers, business partners, or publicly available sources, where permitted by law.

3. How We Use Your Personal Information

  • to provide and administer our Services and Site;
  • to manage our relationship with you and respond to enquiries and demo requests;
  • to operate, maintain, and improve our Services; to ensure security, fraud prevention, and system integrity;
  • to communicate with you, including marketing communications where permitted;
  • to comply with legal, regulatory, and compliance obligations; and
  • to exercise or defend legal rights.

4. Legal Bases for Processing (UK/EU GDPR)

Where the GDPR applies, we process personal information on one or more of the following legal bases: performance of a contract; compliance with a legal obligation; our legitimate business interests (where these do not override your rights); your consent (e.g. for marketing or cookies); protection of vital interests; or public interest, where applicable.

5. Automated Decision-Making

We do not use personal information to make automated decisions that produce legal or similarly significant effects on you. If this changes, we will provide the notices, opt-out, and appeal mechanisms required by applicable law (including the CCPA/CPRA rules on automated decisionmaking technology) before doing so.

6. Sensitive, Health and Genetic Data

Health and genetic data are treated as sensitive personal information. Where we process such data on behalf of healthcare providers, we do so as a service provider/processor under the provider’s instructions and applicable law. Protected Health Information governed by HIPAA, and certain other regulated data, may fall outside the scope of the CCPA. For personal information that is in scope, you may exercise the rights described in Section 9, including the right to limit the use and disclosure of sensitive personal information.

7. Disclosure of Personal Information

We may disclose personal information to: affiliates and subsidiaries within our corporate group; service providers who support our operations (e.g. IT, hosting, analytics, marketing); business partners, where you request their services; authorities or courts, where required by law; and third parties in corporate transactions such as mergers or acquisitions.

We do not sell personal information for monetary consideration, and we do not share personal information for cross-context behavioural advertising.

8. Data Retention & Security

We retain personal information only as long as necessary for the purposes described in this Policy, or as required to meet legal, regulatory, accounting, or reporting obligations, and we maintain records of privacy requests and responses for at least 24 months. We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the personal information to protect it from unauthorised or unlawful access, destruction, use, modification, or disclosure.

9. Your Rights

UK / EU / EEA (GDPR) – you may have the right to: access your personal data; correct inaccurate data; request erasure (deletion); restrict or object to processing; request data portability; and withdraw consent at any time, without affecting processing carried out before withdrawal. You also have the right to complain to the UK Information Commissioner’s Office (ICO, www.ico.org.uk) or your local supervisory authority.

California residents (CCPA / CPRA) — California residents have the right to:

  • know and access the categories and specific pieces of personal information we have collected;
  • request deletion of personal information;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information (we do not sell or share personal information, so no action is required);
  • limit the use and disclosure of sensitive personal information; and
  • not be discriminated against for exercising privacy rights.

We honour Global Privacy Control (GPC) signals where required by law. Requests may be submitted using the contact details in Section 11. We may verify your identity before responding and will respond within the timeframes required by applicable law. You may use an authorized agent to submit a request on your behalf.

10. Cross-Border Transfers & Children

Personal information may be transferred outside the UK, EU or EEA; where required, we use approved safeguards such as Standard Contractual Clauses. Our Services are not directed to children, and we do not knowingly collect personal information from children.

11. Updates and Contact

We may update this Privacy Policy from time to time. The “last updated” date above reflects the most recent revision, and we review this Policy at least once every 12 months. To exercise your rights or ask questions:

Email: [email protected]
Phone: (EU) +44 (0)1244 757 155

Phone: (US) +1 972-200-4433

Address: Unit 62 Coworkz Business Centre, Minerva Avenue, Off Sovereign Way, Chester, Flintshire, Wales, CH1 4QL

© Genial Compliance Systems Ltd, Company reg no: 08776173 Genial Genetic Solutions Ltd, Company reg no: 04314936