CirrusDx (“CirrusDx,” “we,” “our,” or “us”) respects the privacy of your information. This Privacy Notice is designed to assist you in understanding how we collect, use, and safeguard the information you provide to us via our website (the “Site”), provider app, any of our online services, or, where applicable, other CirrusDx services where your information is collected (collectively, the “Services”).
THE SERVICES ARE OFFERED FROM THE UNITED STATES (“U.S.). For individuals located outside of the U.S., please note that CirrusDx is a U.S. based company. If you use the Site or Services, all information, including personal information, will be transferred to CirrusDx in the U.S., and as described in this Privacy Notice. Please see Section 9 of this Privacy Notice for more information.
NOTE ON HIPAA: CirrusDx is considered a covered entity under the Health Insurance Portability and Accountability Act (“HIPAA”). As part of engaging with the Site and Services, you may engage with the Site and Services in a manner regulated by HIPAA. In those cases, our collection, creation, maintenance, use and disclosure of protected health information (“PHI”) will be in accordance with our HIPAA Notice of Privacy Practices. This Privacy Notice is not intended for compliance with HIPAA, nor should you take such notice as a reflection of your rights under HIPAA, and it does not apply to PHI. If you are a patient with questions regarding the use and disclosure of your PHI, refer to our HIPAA Notice of Privacy Practices.
From time to time, we may change this Privacy Notice. If we do, we will post an amended version on this webpage. If required by applicable data protection laws, we will obtain your consent to any material changes. Please review this Privacy Notice periodically.
Through your use of the Site and Services, we will collect personal information from you. For purposes of this Privacy Notice, “personal information” (also commonly referred to as “personal data” or “personally identifiably information (PII)”) refers to any information relating to an identified or identifiable natural person that we maintain in an accessible form.
Information You Provide
When you use the Site or Services, you may voluntarily provide us with the following types of personal information:
Information as You Navigate Our Site and Services
We automatically collect certain personal information through your use of the Site and Services. We will automatically collect certain personal information, such as the following:
Third Party Information
We may receive certain personal information from you about a third party. For example, we may receive information about you from a provider if you have been referred to us for laboratory testing. Such sharing may be subject to an agreement with additional protections for your personal information. If you submit any personal information about another individual to us, you are responsible for making sure that you have the authority to do so and to allow us to use their personal information in accordance with this Privacy Notice.
We use the personal information we collect to provide the Services to you, to improve our Services and Site, and to protect our legal rights. In addition, we may use the personal information we collect to:
Given the nature of CirrusDx’s Services, some personal information may be shared with your provider. In other instances, we may share the information that we collect about you in the following ways:
The Site currently collects very limited information via cookies or other tracking technologies. However, like many other companies, we may use cookies and other tracking technologies (such as pixels and web beacons) (collectively, “Cookies”) in the future. We may use Cookies to:
Some Cookies may be set by us, while separate entities set other Cookies. We use Cookies other entities set to provide us with useful information, to help us improve our Site and Services, to conduct advertising, and to analyze the effectiveness of advertising.
We use Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses Cookies to help us analyze how users interact with the Site and Services, compile reports on their activity, and provide other services related to their activity and usage. The technologies used by Google may collect information such as your IP address, time of visit, whether you are a returning visitor, and any referring website. The information generated by Google Analytics will be transmitted to and stored by Google and will be subject to Google’s privacy policies. To learn more about Google’s partner services and to learn how to opt out of tracking of analytics by Google, click here.
Browser Settings
You can block Cookies by changing your Internet browser settings to refuse all or some Cookies. If you choose to block all Cookies (including essential Cookies) you may not be able to access all or parts of the Site.
You can find out more about Cookies and how to manage them by visiting www.AboutCookies.org or www.allaboutcookies.org.
Platform Controls
You can opt out of Cookies set by specific entities by following the instructions found at these links:
Advertising Industry Resources
You can understand which entities have currently enabled Cookies for your browser or mobile device and how to opt out of some of those Cookies by accessing the Network Advertising Initiative’s website or the Digital Advertising Alliance’s website. For more information on mobile specific opt-out choices, visit the Network Advertising Initiative’s Mobile Choices website. Please note these opt-out mechanisms are specific to the device or browser on which they are exercised. Therefore, you will need to opt out on every browser and device that you use.
To the extent we engage third-party processors to provide the Services, we have put in place appropriate procedures with the service providers we share your personal information with to ensure that your personal information is treated by those service providers in a way that is consistent with, and which respects the applicable laws on data security and privacy.
Some internet browsers incorporate a “Do Not Track” feature that signals to websites you visit that you do not want to have your online activity tracked. Given that there is not a uniform way that browsers communicate the “Do Not Track” signal, the Site does not currently interpret, respond to, or alter its practices when it receives “Do Not Track” signals.
The Site may contain links that will let you leave the Site and Services and access another website. Linked websites are not under our control. This Privacy Notice applies solely to personal information that is acquired on this Site and Services. We accept no responsibility or liability for third-party websites and encourage you to review third-party privacy practices via each respective website.
We maintain commercially reasonable security measures to protect the personal information we collect and store from loss, misuse, destruction, or unauthorized access. However, no security measure or modality of data transmission over the Internet is 100% secure. Although we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.
The Site and Services are not intended for children under 16 years of age. We do not knowingly collect, use, or disclose personal information from children under 16.
We do not disclose personal information obtained through our Site or Services to third-parties for their direct marketing purposes. Accordingly, we have no obligations under California Civil Code § 1798.83.
If you are in a country in the European Economic Area (EEA), the United Kingdom, or other jurisdictions with similar privacy rights, you may be entitled to the following explanation of the legal bases we rely on to process your personal information and a description of your privacy rights.
In certain circumstances, you have the following data protection rights:
Even if you make a request for deletion, we may need to retain certain information for legal or administrative purposes, such as record keeping, maintenance of opt-out requirements, defending or making legal claims, or detecting fraudulent activities. We will retain information in accordance with the “How Does CirrusDx Retain Your Personal Information? Section below. If you do exercise a valid right to have your personal data deleted, please keep in mind that deletion by third parties to whom the information has been provided might not be immediate and that the deleted information may persist in backup copies for a reasonable period (but will not be available to others).
In order make a request regarding your personal information, please contact info@cirrusdx.com.
If you have a comment, question, or complaint about how we are handling your personal information, we hope that you contact us as described herein to allow us to resolve the matter. In addition, if you are located in the EEA, you may submit a complaint regarding the processing of your personal information to a regulatory authority.
The following links may assist you in finding the appropriate regulator:
Legal Basis for Processing
If you are located in the EEA or a jurisdiction that requires a similar legal basis for processing, our legal basis for collecting and using the personal information described in this Notice depends on the personal information we collect and the specific context in which we collect it.
We may process personal information because:
Where certain sensitive personal information is processed based on your explicit consent, you may have the right to withdraw such consent at any time. To do so, please contact us as described in this Privacy Notice. If there is a different legal basis that would permit us to continue processing your personal information after withdrawing consent, we will notify you of that legal basis at the time of your request.
How Does CirrusDx Retain Your Personal Information?
We will retain your personal Information for as long as necessary to fulfill the purposes for which we collect it and as set out in this Privacy Notice and for the purpose of satisfying any legal, accounting, or reporting requirements that apply to us.
For questions or concerns about our privacy policies or practices, please contact us at:
Cirrus Dx, Inc.
9901 Belward Campus Drive, Suite 300
Rockville, Maryland 20850
Phone: 240-813-8801
General Email Inquiry: info@cirrusdx.com
Last Updated: July 30, 2025