Privacy policy

Privacy Policy

Synergistic Labs LLC
Effective date: September 18, 2026

1. Introduction and Scope

Synergistic Labs LLC (“Synergistic Labs,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with our website, laboratory-ordering services, customer support, and administrative support for healthcare services, where offered.

This Policy applies to information handled by Synergistic Labs. Laboratories, licensed healthcare providers, pharmacies, and other independent healthcare organizations may provide separate privacy policies and Notices of Privacy Practices governing information they maintain and services they provide.

This Policy is a notice of our privacy practices. Visiting our website, placing an order, or acknowledging this Policy does not, by itself, constitute authorization for a use or disclosure of health information that requires separate consent or authorization.

2. Information We Collect

The information we collect depends on your interactions with us and the services you request.

Identity and contact information. This may include your name, date of birth, email address, telephone number, billing or mailing address, and demographic information needed to identify you accurately and coordinate requested services.

Order and transaction information. This may include the services or tests ordered, order identifiers, transaction amounts, payment status, billing details, referral codes, and fulfillment information. Payment information submitted during checkout is processed through the applicable payment service providers.

Health-related information. This may include laboratory orders, requisitions, patient identifiers, preliminary and final laboratory results, and information supplied by you or participating healthcare organizations to coordinate your requested services. When relevant to healthcare services actually offered, this may also include intake responses, medical history, medication information, and related clinical communications. All PHI is stored in a HIPAA compliant manner outside of Shopify and directly in Salesforce with the necessary HIPAA compliance and SOC2 protections.

Communications and preferences. This includes information you provide in support requests, emails, forms, attachments, privacy requests, and communication preferences.

Website and device information. Our website and its service providers may collect IP addresses, browser and device information, access times, referring pages, pages visited, cookie identifiers, and information about website functionality and interactions.

We obtain information directly from you, automatically through website interactions, and from laboratories, healthcare providers, payment processors, and other service providers involved in the services you request. We may also receive information from a representative authorized to act for you.

3. How We Use Information

We use information to process orders and payments; verify identity and service eligibility; coordinate laboratory ordering and related healthcare services; deliver requisitions, results, and service communications; provide customer support; maintain records; administer referral and commission arrangements; protect against fraud and unauthorized access; maintain and improve website functionality; and meet legal and regulatory obligations.

When permitted by law and consistent with your choices, we may also use contact information to send news or promotional communications about our services. Marketing communications are subject to the choices described below and any separate authorization requirements applicable to health information.

We limit our collection and use of information to purposes reasonably related to the services requested, purposes disclosed in this Policy, and other purposes permitted by law or separately authorized by you. Identifiable health information is subject to the additional limitations described below.

4. Health Information, HIPAA, and Business Associate Agreements

Certain identifiable health information handled in connection with healthcare services is protected health information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). HIPAA applies according to the information involved and the legal role of the organization handling it; not all website information is PHI.

When we handle PHI subject to HIPAA, our practices must comply with the HIPAA requirements applicable to our role, including relevant Privacy, Security, and Breach Notification Rule requirements. When acting as a business associate of a healthcare organization, we may use or disclose PHI only as permitted by applicable law and the agreement governing that relationship.

Permitted activities may include supporting treatment, laboratory ordering, payment, and healthcare operations. Other uses or disclosures require an appropriate legal basis and, when required, your written authorization. We apply the minimum-necessary standard when it applies to the activity involved.

Business associate agreements. Our policy requires an appropriate written business associate agreement before a vendor or subcontractor creates, receives, maintains, or transmits PHI on our behalf when HIPAA requires such an agreement. These agreements must address permitted uses and disclosures, safeguards, incident reporting, and other applicable obligations. A vendor’s general security certification does not replace a required agreement.

Healthcare providers and laboratories may issue their own HIPAA Notices of Privacy Practices. Those notices describe their clinical privacy practices, legal duties, and patient rights. This website Privacy Policy supplements, but does not replace, any applicable Notice of Privacy Practices. You may contact us for assistance identifying the organization responsible for your records or obtaining its notice.

Some health information may receive additional protection under state or federal law. We will obtain additional consent or authorization and apply additional restrictions when required.

5. When We Disclose Information

Laboratories and healthcare organizations. We disclose information to laboratories, ordering clinicians, provider networks, and, where relevant to services you request, pharmacies or other healthcare organizations to arrange and fulfill services, coordinate care, and deliver results. Such disclosures remain subject to applicable health privacy requirements.

Operational service providers. We use vendors that support website hosting, commerce, payments, laboratory coordination, administrative workflows, communications, information technology, and customer support. Shopify supports our online storefront and order-processing functions. Junction supports laboratory-ordering workflows and requisition delivery. Salesforce supports administrative workflows and automated delivery of laboratory-result communications.

Service providers receive information appropriate to the functions they perform. Their handling of that information is subject to applicable legal requirements and contractual restrictions, including business associate agreements when required. Naming a vendor in this Policy does not authorize disclosure of information that the vendor is not permitted to receive.

Authorized recipients. We may disclose information to a person you authorize or to a legally recognized personal representative after appropriate verification. Purchasing a test for someone else or paying for an order does not automatically entitle the purchaser to that individual’s results.

Legal and safety matters. We may disclose information when required or permitted by applicable law, including for legally authorized public health reporting, regulatory oversight, legal proceedings, and fraud prevention. A request for health information is not, by itself, sufficient authority to disclose it; applicable legal conditions must be satisfied.

Business transactions. A merger, acquisition, reorganization, or transfer of business assets may involve information subject to applicable legal restrictions and confidentiality protections. A business transaction does not remove restrictions on PHI or authorize an otherwise prohibited sale or disclosure of health information.

6. Email, Requisitions, and Laboratory Results

Laboratory requisitions are delivered through Junction. Automated laboratory-result communications are sent through Salesforce. These communications may include PDF attachments containing personal and health information, including preliminary or final results.

Email security depends on the sending system, receiving email provider, account settings, devices, and other factors. Ordinary email may not be end-to-end encrypted, and a PDF attachment is not necessarily encrypted or password-protected merely because it is a PDF. Messages may also be accessible to anyone with access to your email account or device.

Provide an accurate email address that you control, notify us promptly of changes, and avoid using a shared or employer-managed address when confidentiality is important. Please contact us before delivery when possible if you need a different communication method or destination.

We will accommodate reasonable requests for confidential communications as required by law. When an unencrypted delivery method requires a risk disclosure and your agreement, we will explain the relevant risks and document your choice before using that method. Your use of our website is not a blanket authorization for unencrypted delivery.

Choosing email does not waive your privacy rights or release us from applicable privacy and security obligations. You may contact us to change future communication preferences, although a change cannot recall messages already delivered.

7. Affiliates, Marketing, and Cookies

Affiliate privacy. We administer an affiliate referral program. Participating marketing affiliates are not given access through that program to customer names, email addresses, specific tests purchased, requisitions, laboratory results, or medical records. Referral and commission administration does not authorize an affiliate to obtain your health information. Using a referral code does not authorize us to share your records with the person who provided it.

Advertising and promotional communications. We do not currently run paid advertising campaigns. We do not sell laboratory results or medical records. We do not use PHI for marketing purposes requiring a HIPAA authorization unless a valid authorization has been obtained.

You may opt out of promotional emails using the unsubscribe instructions in the message or by contacting us. Opting out of promotions does not automatically stop order confirmations, requisitions, results, privacy notices, or other necessary service communications. Contact us separately to discuss the delivery method for those messages.

Cookies and similar technologies. Our website and service providers may use these technologies for functions such as shopping carts, account access, security, preferences, website performance, and referral attribution. The absence of paid advertising does not mean that the website operates without cookies or technical data collection.

You can manage cookies through your browser and any privacy controls made available on the website. Disabling certain cookies may affect website functionality. Where applicable law requires consent or recognition of an opt-out preference signal, we will honor those requirements. Cookie choices or acceptance of this Policy do not substitute for a legally required health-information authorization.

8. Information Security

Our website uses HTTPS/TLS to encrypt browser connections. Our information-security policy requires reasonable administrative, technical, and physical safeguards appropriate to the information involved, including controls over access to sensitive information, credentials, authorized personnel, vendors, and information transfers.

Access to personal and health information must be limited to authorized personnel and service providers with a legitimate need for the information. Where HIPAA applies, security measures must satisfy the requirements applicable to our role and systems.

No website, email system, or storage method can guarantee absolute security. This limitation does not reduce our responsibility to implement required safeguards or respond appropriately to security incidents. Please promptly report suspected unauthorized access or misdirected communications using the contact details below.

9. Retention and Disposal

We retain information for the periods reasonably necessary to fulfill the purposes described in this Policy and to meet applicable medical-record, legal, tax, accounting, contractual, and regulatory obligations. Relevant considerations include the record type, the services provided, legal retention requirements, and the need to resolve disputes or investigate incidents.

Different records may have different retention periods. Closing an account or requesting deletion does not necessarily permit deletion of laboratory, clinical, transaction, or other records that must be retained. Laboratories and healthcare providers may have their own retention obligations for records they maintain.

When information is no longer needed and retention is not required, our policy is to securely delete, destroy, or lawfully de-identify it, as appropriate. Information retained in backups or archives remains subject to applicable protections and deletion requirements.

10. Privacy Requests and State-Law Rights

You may contact us to request access to personal information, correction of inaccuracies, deletion, a copy in an available portable format, or information about our collection and disclosure practices.

Depending on your state of residence, the information involved, and the law applicable to our business, you may also have rights to withdraw consent, obtain additional information about recipients, opt out of certain sales, sharing, targeted advertising, or profiling, limit certain uses of sensitive information, and appeal a denied request. These rights are subject to applicable exceptions and do not imply that we engage in each listed activity.

Submit requests to the privacy contact below. We may take reasonable steps to verify your identity and an authorized representative’s authority. Please do not include laboratory results or unnecessary sensitive information in an initial privacy request; we will explain any additional verification needed.

We will respond within applicable legal timeframes. If we cannot fulfill a request, we will explain the reason and any available review or appeal process. To appeal, contact the same address and identify your message as a “Privacy Request Appeal.” We will not unlawfully discriminate against you for exercising privacy rights.

Requests involving medical records may need to be handled by the responsible laboratory or healthcare provider. We will assist with identifying or directing your request to that organization as appropriate. Additional state-specific notices and consent procedures will be provided where required.

11. Rights Regarding HIPAA-Protected Information

Where HIPAA applies, you have rights, subject to applicable conditions and exceptions, to access and obtain copies of records; request amendments; request restrictions on certain uses or disclosures; request reasonable confidential communications; receive an accounting of certain disclosures; obtain the applicable Notice of Privacy Practices; and file a privacy complaint.

You may revoke a HIPAA authorization in writing, subject to actions already taken in reliance on it and other applicable exceptions. HIPAA does not provide a general right to require deletion of medical records.

Contact us for assistance exercising a right relating to information we handle. When another healthcare organization is responsible for responding, its Notice of Privacy Practices explains the applicable procedure.

12. Security Incidents and Required Notifications

We will investigate suspected privacy or security incidents involving information under our responsibility and take appropriate responsive action. When notification is required by HIPAA or another applicable law, we will provide the required notices to affected individuals, healthcare organizations, regulators, or other parties within the applicable deadlines and according to our legal role.

13. Children and Minors

Our website is intended for adults age 18 and older. We do not knowingly solicit personal information directly from children through the website. If you believe a child has provided information without appropriate authority or consent, contact us so we can review the situation and take appropriate action, consistent with applicable law and record-retention requirements.

14. Third-Party Services and Processing Locations

Our website may link to services operated by laboratories, healthcare providers, payment processors, or other third parties. Information you provide directly to those organizations may be governed by their own privacy notices. A third party’s separate notice does not remove our obligations for information we disclose to it.

Our services are directed to individuals in the United States. Information may be processed in the United States or in other locations where our service providers operate, subject to applicable legal and contractual safeguards. This Policy does not authorize a transfer prohibited by law or an applicable healthcare agreement.

15. Changes to This Policy

We may update this Policy to reflect changes in our services, practices, or legal requirements. The revised Policy will be posted with an updated effective date. We will provide additional notice and obtain consent or authorization when required before implementing a change. Updating this Policy does not, by itself, authorize a new use of health information that requires separate permission.

16. Contact and Complaints

To ask a privacy question, exercise a privacy right, request confidential communications, or submit a complaint, contact:

Synergistic Labs LLC
Attention: Privacy Contact
15744 Kohut Ln
Westfield, IN 46074
United States
Email: info@synergisticlabs.net