Cepheid values your privacy and the protection of your personal data. This notice (“Notice”) explains how Cepheid and its affiliates, subsidiaries and related companies under its control (each a "Cepheid Entity”) (together, “Cepheid”, “our”, “us” or “we”), collects, uses, shares, transfers, discloses and processes data collected from or about you. If you are an associate (employee) of Cepheid or another Danaher Entity (as defined below), your privacy rights are outlined in the Danaher Associate Privacy Notice provided by your local HR team and available on Danaher Connect.
The particular Company Entity with which you interact is, where applicable, the data controller (or equivalent under applicable law(s)) responsible for the processing of your Personal Data (as defined below). We are part of the Danaher corporate organization and may process data from, or make data available to, other Danaher subsidiaries, affiliates, or other entities under common ownership (“Danaher Entities”), as appropriate under law and for the purposes described below. Please note that Cepheid is legally separate from and does not control the Danaher Entities other than the Company Entities. You can find a list of relevant Danaher Entities (including the Company Entities) that act as data controllers in Appendix 1 to this Policy.
This Notice is divided into sections to help you find information more easily. If you are after specific information, please click on the relevant section in the list below to navigate directly to it:
This Notice describes the types of Personal Data that we may collect, process or disclose about you and how you may govern this processing by exercising applicable legal rights. This Notice applies to both online and offline information collection, including through your use of websites or subdomains operated by us or any mobile applications, when we provide products and/or services to you, when we notify you about prospective items of interest or regulatory notices, and in other situations where you interact with us in person, by telephone or by mail where this Notice is posted or referenced.
There may be occasions where you have been provided with a circumstance-specific privacy notice that is separate from this Notice, such as privacy notices for specific activities such as recruitment. To the extent you were provided with a different notice, that notice shall apply and govern our interactions with you. If you provide Personal Data about parties other than yourself, you are responsible for ensuring their knowledge of how we will process their Personal Data, and, where applicable, obtaining any necessary consent(s) required in advance.
We are committed to processing Personal Data in accordance with applicable laws. Please note that if you do not wish to provide your Personal Data to us, some products and/or services may become unavailable to you. Personal Data that is mandatory is indicated on relevant forms that you complete or is communicated by us separately. Your use of any or all of our online platforms indicates that you have been notified of our collection, use, sharing, transfer, processing and disclosure of your Personal Data, as described in this Notice and to the extent permitted by applicable law(s).
We connect with individuals for many different reasons. Those interactions may result in us directly or indirectly gaining access to Personal Data about you. The below tables summarize how we may collect, process, and use Personal Data, our legal basis for processing your Personal Data, and the potential recipients of your Personal Data. The described instances may not be applicable in all circumstances.
The table below sets out the categories of Personal Data that may be processed under this Notice. We collect and process Personal Data about you when you interact with us and our websites, and when you purchase goods and services from us.
“Personal Data” is any information that can be used to directly or indirectly identify an individual or that can be reasonably expected to link to an individual. This can include items such as name, address, telephone number, credit card details, email address, ID number, Internet Protocol (“IP”) address of an electronic device used by an individual, or other identifying codes (even absent of other identifying information). Statistical and metric data that are not identifiable to an individual are not considered Personal Data.
This includes:
Catergoy | Details |
Identity and Contact Information |
First and last name, email address, postal address, phone number, job title, research interests, professional license numbers, account username and password, IP address, and national provider identifier and/or state license number. |
Demographic Information | Age, gender, accessibility requirements and date of birth. |
Visual and Audio Information |
Still images, recordings of your calls with our customer service representatives, and video (including via CCTV). |
Commercial and Financial Information | Transaction records, products and services that were purchased, obtained or considered, requested documentation, customer service records (including meeting details, call logs and feedback), financial transaction history, transfers of value, and financial account numbers. |
Professional and Educational Information | Job title or position, employer, office location, work skills and experience, employment history, graduate degree, certification, specialized training, responses to surveys and questionnaires, enrolment history for our education and training events, LinkedIn profile, research, areas of interest, grants and funding awards. |
Technical Information | IP address, user ID or account number (for Danaher account), browser type, browser language, device type, advertising IDs associated with your device (such as Apple’s Identifier for Advertising (IDFA) or Android’s Advertising ID (AAID)), the date and time you use our products and services, Uniform Resource Locators, or URLs (i.e., website addresses) visited prior to arriving and after leaving our products and services, activity on our products and services and referring websites or applications (such as visits and downloads), data collected from cookies or other similar technologies such as pixels, web beacons and tags, log files and geolocation information. |
Health Information | Information regarding your treatment, including your date of birth, sex/gender, treatment dates, medical history, treatment information, patient-reported outcome measures (e.g., responses to questionnaires and surveys), X-rays, test results, magnetic resonance imaging images, medical scans, pictures and videos of treatment activities and communications with your health care provider and/or patient. |
Sometimes we receive information about you from third parties. In particular:
We will only use your Personal Data for the purposes and legal bases set out below:
Puropose | Legal Basis |
We will collect, use and store Identity and Contact Information, Commercial and Financial Information, Professional and Educational Information, and Technical Information to register and create an account on our website, offer and provide you with services (including events) and to deliver requested products to you. | It is necessary for us to process your Personal Data in order to perform our contract with you, or to take steps at your request prior to entering into a contract with you.We have a legitimate interest in managing our business and offering goods and services to our customers. |
We will collect, use and store Identity and Contact Information and Visual and Audio Information to verify your identity and authenticate you. | We have a legitimate interest in ensuring the security of our services and data. We have a legal obligation under EU, member state and/or UK laws. Where the legal obligation applies to us under laws which are not EU, member state or UK, we have a legitimate interest in ensuring compliance with global laws that apply to our business. |
We will collect, use and store Identity and Contact Information, Visual and Audio Information, Commercial and Financial Information and Professional and Educational Information to manage our relationship with you, including communicating with you and for administrative purposes (including customer service). | We have a legitimate interest in managing our business and providing services to our customers. |
We will use all Personal Data mentioned in this Notice to monitor our products, services and customer accounts to detect, prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents and malicious or illegal activities, in accordance with applicable laws and to ensure the appropriate use of our products and services. | We have a legal obligation under EU, member state and/or UK laws. Where the legal obligation applies to us under laws which are not EU, member state or UK, we have a legitimate interest in ensuring compliance with global laws that apply to our business. We have a legitimate interest in preventing and detecting fraud or other wrongdoing. Your consent. |
We will use all Personal Data mentioned in this Notice to investigate concerns (including reports made via our whistleblowing hotline) relating to breaches of laws, our policies and/or our standards. | We have a legal obligation to do this when a report is made which is protected by whistleblowing laws in the EU, member states and/or the UK. For other investigations, we have a legitimate interest in ensuring compliance with global laws, policies and/or standards that apply to our business. |
We will collect and use Identity and Contact Information, Commercial and Financial Information, Professional and Educational Information and Technical Information to send you direct marketing in relation to our relevant products and services, or other products and services provided by Danaher Entities. | Your consent. We have a legitimate interest in promoting our and Danaher Entity services to our customers. |
We will use your Identity and Contact Information, Commercial and Financial Information, Professional and Educational Information and Technical Information to customize and improve the communications you receive, e.g. by offering you specific events, other activities, products and services of Danaher Entities | Your consent. We have a legitimate interest in promoting our and Danaher Entity services to our customers. |
We will collect and analyze Identity and Contact Information, Commercial and Financial | Your consent. |
Information, Professional and Educational Information and Technical Information in order to manage and operate our services, websites and apps, including to keep them updated and relevant, to develop our business and to inform our sales and marketing strategy. We also collect data concerning whether any email communication you have received from us has been opened and if you have clicked on any links within the email. This helps us make our communications useful for you. |
We have a legitimate interest in operating our websites, apps and services, and improving their operations. |
We will collect, use and store your Identity and Contact Information, Commercial and Financial Information to complete our financial reporting and disclosure obligations to the Danaher Entities, tax agencies and regulators. | We have a legal obligation under EU, member state or UK laws. Where the legal obligation applies to us under laws which are not EU, member state or UK, we have a legitimate interest in ensuring compliance with global laws that apply to our business. |
We will collect, use and store your Identity and Contact Information, Demographic Information, Visual and Audio Information, and Professional and Educational Information to invite you to take part in and manage customer surveys, reviews and other market research activities carried out by us and other organizations on our behalf. | Your consent. We have a legitimate interest in managing our business and providing services to our customers. |
We will collect, analyze and store your Identity and Contact Information, Demographic Information, Professional and Educational Information, Technical Information, and Health Information to conduct research, develop and promote new products and/or services, and improve or modify our existing products and services. | Your consent. We have a legitimate interest in managing our business and providing products and services to our customers. Processing is necessary for scientific research. |
We will process your Identity and Contact Information and Health Information to ensure the quality and safety and continued effective performance of medical products, services and devices (including for quality assurance purposes). | We have a legitimate interest in ensuring we offer safe services and products to our customers. We have a legal obligation under EU, member state and/or UK laws. Where the legal obligation applies to us under laws which are not EU, member state and/or UK, we have a legitimate interest in ensuring compliance with global laws that apply to our business. Your consent (as provided to your healthcare provider). |
We will use all Personal Data mentioned in this Notice to establish, exercise and/or defend our legal rights, and/or comply with court orders, subpoenas and/or other legal obligations. | We have a legitimate interest in protecting our business interests and legal rights, including in connection with legal claims, compliance, regulatory, auditing, investigative and/or disciplinary purposes (including in relation to the disclosure of information in connection with legal procedures or litigations) and/or other ethics and compliance reporting requirements. |
We will use Identity and Contact Information, Demographic Information, and Professional and Educational Information to manage our relationships with healthcare professionals (who work with us as investigators on clinical trials, on health outcome research and/or market research) and/or to identify healthcare professionals with whom we may wish to work with on such research in the future. | We have a legitimate interest in improving healthcare products and services, and in conducting scientific research. Some of our processing in connection with clinical studies is also necessary when we have legal obligations under laws relating to the safety of healthcare and medical products, and/or medical devices. |
There are instances where we have a legitimate interest to use your data. Our legitimate interest will vary depending on what we are using your data for, and we explain above what the interest is and how it relates to the processing operation(s) we carry out. You can obtain further information about our legitimate interests by using the contact details at the end of this Notice.
When we process Health Information, we do so in connection with our services for business customers and pursuant to separate privacy notices provided to you by our customer or otherwise provided at the time of data collection. This Notice does not apply to such Health Information, which is governed by the relevant notices provided to you and by our customer agreements. For example, if you are a patient based in the United States of America, this Notice is distinct from your healthcare provider’s HIPAA Notice of Privacy Practices, which describes how your healthcare provider uses and discloses the protected health information that it collects, as well as any other privacy practices it applies to that information.
Cepheid may process anonymized/de-identified data. This is data for which the characteristics that can identify you, directly or indirectly, have been removed such that you are no longer identifiable. This information is no longer considered Personal Data under data protection laws. This includes, in the United States, the removal of identifiers from protected health information required under HIPAA (45 CFR § 164.514(b)(2)) or another permissible method for such data to be considered de-identified. We rely on our legitimate business interests, scientific or historical research and/or statistical purposes, consent or other purposes that may be required or allowed by law as the legal basis to anonymize Personal Data.
We may also obtain and use certain types of combined datasets (such as demographic data) for any purpose (“Aggregated Data”). Aggregated Data may be derived from your Personal Data but does not directly or indirectly reveal your identity. For example, we may aggregate certain information technology-related data of yours with others’ data to calculate the percentage of users accessing a specific feature on our website. We may use Aggregated Data for any purpose without restriction. However, if we re-combine or re-connect Aggregated Data with your Personal Data so that it can directly or indirectly identify you, we then treat the combined data as Personal Data (which will be used in accordance with this Notice).
We combine information we collect on the website with information we receive from you in person, by email, or by other forms of communication. We also combine information you provide with information we obtain from third parties, service providers, publicly available sources and Danaher Entities.
We do not knowingly collect Personal Data from minors without the permission of such minors’ parents or legal guardians.
We may transfer your Personal Data to recipients (including our affiliates or third-party service providers) in countries other than the country in which your Personal Data was originally collected. When we transfer your Personal Data in such a manner, we take steps to ensure your Personal Data is protected in a way that is consistent with the laws and requirements in your country (including any requirements that apply to cross-border data transfers). Where Personal Data is transferred outside the EEA and/or UK, and where this is to a stakeholder or vendor in a country that is not subject to an adequacy decision by the EU Commission, does not fall under the UK government adequacy regulations, or is not considered adequate under applicable data protection laws, we take steps to require that your Personal Data is adequately protected. This includes using the EU Commission approved standard contractual clauses, the UK Information Commissioner approved standard contractual clauses, or a vendor's Processor Binding Corporate Rules. We implement appropriate technical and organizational measures to provide a level of security appropriate to the risk of protecting your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
A copy of the relevant mechanisms can be obtained for your review on request by using the contact details below.
If we are involved in a sale or transfer of all or some of our business assets or operations via (among other mechanisms) a share or asset transaction, your Personal Data may be transferred to the acquiring organization(s), who will be required to take at least the same or higher standards of care in the treatment of your Personal Data. Should such a sale or transfer occur, if required by law, you will be informed about this and may withdraw your consent to the transfer of your Personal Data (if relevant to the processing) or, as applicable, instigate any other legally-available rights, as detailed in the “Your Rights and Choices” section of this Notice with regards to the processing and use of your Personal Data by the transferee.
As outlined in the table above, your interactions with our websites are an additional source for collecting your information. We may use cookies, web beacons and other technologies to help us evaluate and improve the content or functions of the products or services we provide.
Our Cookie Policy provides more detailed information about this topic and how we use cookies to enhance your experience and better serve you.
On our websites, apps and/or platforms, we may link to other websites, apps and/or platforms that we do not control. If you click on a third-party link, you will be taken to a website, app and/or platform we do not control. This Notice does not apply to the privacy practices of those websites, apps and/or platforms. Read the other companies’ privacy policies carefully as we are not responsible for these third parties. Our websites, apps and/or platforms may also serve third party content that contains their own cookies or tracking technologies. We do not control the use of those technologies.
We may share your Personal Data with the following categories of recipients:
Personal Data Category | Category of Recipient | Why? |
Identity and Contact Information, Commercial and Financial Information, Professional and Educational Information, Technical Information | Danaher Entities and Company Entities | To operate, improve, and develop our products and services. |
Identity and Contact Information, Commercial and Financial Information, Professional and Educational Information, Technical Information | Danaher Entities |
To customize and improve the communications you receive, e.g. by offering you specific events, other activities, products and/or services of Danaher Entities |
All Personal Data mentioned in this Notice | Third-party service providers | We employ other companies and individuals to perform functions on our behalf. Examples include website hosting and maintenance, customer service operations, identity verification, fulfilling orders for products or services, delivering packages, sending postal mail and e-mail and, processing payments. |
All Personal Data mentioned in this Notice | Business partners, including distributors and joint venture partners | To operate, improve, and develop our products and services. |
All Personal Data mentioned in this Notice | Prospective buyers/sellers | In the event that the business is sold, assigned or transferred, or integrated with another business, your Personal Data will be disclosed to our adviser(s) and any prospective purchaser’s adviser(s) and will be passed to the new owner(s) of the business. |
Identity and Contact Information, Demographic Information, Health Information | Customers and healthcare providers | To provide our products and services, carry out clinical trials, healthcare outcomes analysis and market research activities. |
All Personal Data mentioned in this Notice | Courts, law enforcement authorities, regulators, government officials, attorneys and/or other parties | When it is reasonably necessary for: the establishment, exercise or defense of a legal or equitable claim; for the purposes of a confidential alternative dispute resolution process; to respond to complaints and investigations; to comply with any subpoena, court order or other legal obligation; or when data is requested by regulators, government agencies or law enforcement agencies. |
All Personal Data mentioned in this Notice | Auditors and other professional advisors | To request and obtain advice, meet our legal obligations, respond to complaints and investigations and/or (when necessary) in the course of the professional services they provide to us. |
All Personal Data mentioned in this Notice | Credit reference agencies, law enforcement agencies and fraud prevention agencies | To prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crimes (in accordance with applicable laws). |
Identity and Contact Information, Demographic Information, Health Information | Clinical Research Organizations, applicable study sponsors, their corporate affiliates, business partners, and third-party service providers performing services related to the study (e.g. providing services in relation to study data management, clinical research monitoring, safety monitoring, etc.) | To carry out the applicable studies, other study-related services and/or adverse event reporting. |
Identity and Contact Information, Demographic Information, Health Information | Event and webinar organizers (including universities) | To prepare for and host events and webinars. |
Identity and Contact Information, Demographic Information, Health Information | Social media companies | To communicate with you or provide you with relevant advertising related to your interests on those platforms. We use the “custom audiences” services provided by these social media companies. |
We will retain Personal Data for as long as is necessary to carry out the purpose(s) the Personal Data was collected for, or for the period prescribed by applicable laws (whichever is longer). In considering how long to retain your Personal Data, the following are considered:
When the retention of your Personal Data is no longer required, we will delete or anonymize/de-identify the Personal Data as per the details provided above, or, if this is not immediately possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is accomplished.
Some jurisdictions have provided individuals with rights in relation to the processing of their Personal Data. These rights are not available to everyone, and they do not necessarily apply in all contexts. Depending on the applicable laws or legal bases, you may have the right to:
To exercise a right that you believe you may be entitled to under applicable law(s), you can contact us directly by submitting a request through this webform. We may need to verify your identity before we fulfill your request. Otherwise, under applicable laws, we may be unable to action your submission. We will notify you in a timely manner of such decisions or requirements, as necessary.
Whenever we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent (before its withdrawal). We may, however, have other legal grounds for processing your data for other purposes (such as those set out above).
California Residents. Our California Consumer Rights Notice provides certain information required by California law and an overview of how consumers in California can exercise certain privacy rights and protections.
Filing a Complaint. If you are not able to resolve a problem directly with us and wish to make a formal complaint, you can contact your local data protection authority or other enforcement authorities.
If you have any questions about this Notice or our data practices, you can write to us at:
Cepheid
Attn: Privacy Officer
904 Caribbean Drive
Sunnyvale, CA 94089 U.S.A.
Alternatively, you can email us directly at privacy.officer@cepheid.com.
From time to time, we may change our privacy policies. The most updated copy will be found on our website. Please check our site periodically for updates.
Your information is controlled by Company Entities and Danaher Entities. The full list of relevant Danaher Entity controllers and their contact details can be found in the table below.
Controller | Contact Details |
For example, if you: a) purchase products and services from, or b) visit the websites of, the following companies, that company will be the data controllers of your Personal Data. They will also act as controllers in respect of sales and marketing activities linked to their business activities. |
|
Abcam | Abcam Limited Discovery Drive Cambridge Biomedical Campus Cambridge CB2 0AX dataprivacy@abcam.com
|
Aldevron | Aldevron LLC Aldevron Fargo Corporate Headquarters 4055 41st Avenue South Fargo North Dakota 58104 United States of America dataprivacy@aldevron.com
|
Beckman Coulter Diagnostics | Beckman Coulter, Inc. |
Beckman Coulter Life Sciences | Beckman Coulter Life Sciences Headquarters |
Cepheid | Cepheid |
Cytiva | Cytiva |
Danaher Life Sciences | DH Life Sciences LLC |
Genedata | Genedata AG |
HemoCue | HemoCue AB
|
IDBS | IDBS Limited |
Integrated DNA Technologies | Integrated DNA Technologies, Inc. |
Leica Biosystems | Leica Biosystems |
Leica Microsystems | Leica Mikrosysteme Vertrieb GmbH |
Mammotome | Mammotome Global Headquarters |
Molecular Devices | Molecular Devices LLC |
Pall | Pall Corporation |
Phenomenex | Phenomenex Global Headquarters |
Radiometer | Radiometer Denmark |
SCIEX | AB SCIEX LLC |
This Appendix applies if you live in Japan or the processing of your Personal Data is otherwise subject to the Act on the Protection of Personal Information of Japan (“APPI”). This Appendix should be read in conjunction with and in addition to the main body of the Privacy Policy to which this Appendix is attached.
The detailed purpose of processing the Personal Data provided in the main body of the Privacy Policy will be as follows:
We may jointly use your Personal Data within Danaher Entities (including the Company Entities) here as described in the main body of the Privacy Policy as follows.
Cepheid GK
703 Burex Toranomon, 2-7-5 Toranomon,
Minato-ku, Tokyo 105-0001 Japan, Japan
Peter Farrell
All Danaher Entities, as included in the link above, have entered into a data protection agreement and will take necessary measures in order to meet the requirements for cross-border data transfer stipulated by the APPI and other applicable laws and ensure that the level of protection of the Personal Data is not undermined.