Pages
Get full access to Figma after the purchase
Buy
legal page

Privacy Policy

1. Introduction

MolMart Ltd (“we,” “us,” or “our”) is committed to protecting the privacy and security of your

personal data. This Privacy Policy explains how we collect, use, share, and protect your

information when you use our genetic screening services, including SureMart, and our

associated patient-facing application.

This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data

Protection Act 2018, and other relevant data protection laws.

2. Data Controller and Data Protection Officer

MolMart Ltd is the data controller responsible for your personal data.

Data Protection Officer Markella Mikkelsen (CEO & Founder)

Email mmikkelsen@molmart.co.uk

Address The Renold Building, 32a Altrincham St, Manchester M1 7JR, UK

Given that MolMart processes special category data (genetic and health data), Markella

Mikkelsen acts as Data Protection Officer in this capacity. If you have any questions or

concerns about how your data is handled, please contact us at the details above.

3. What Data We Collect

We collect and process the following categories of personal data:

a. Personal Identification Data

• Full name

• Date of birth

• Contact details (email address, postal address)

b. Health and Genetic Data (Special Category Data)

• Relevant family history

• Any previous genetic test results provided by you

• Genomic data generated through the SureMart carrier screening process

• Where applicable, donor genetic data used for donor–recipient matching

c. Transaction and Payment Data

Payment transactions are processed securely by Stripe, our third-party payment provider.

MolMart does not retain card details, billing addresses, or other financial credentials. Once a

transaction is complete, Stripe retains the relevant payment data in accordance with their

own privacy policy and applicable financial regulations. We retain only a record of the

transaction (date, amount, and service purchased) for accounting and legal compliance

purposes.

4. Purpose and Legal Basis for Processing

Under UK GDPR, we must have a lawful basis for processing your data. We process your

personal data as follows:

Purpose Legal Basis

Providing genetic screening services Performance of a contract (Article 6(1)(b))

Processing health and genetic data Explicit consent (Article 9(2)(a))

Communicating with you about your results Performance of a contract (Article 6(1)(b))

Donor–recipient genetic matching Explicit consent from both parties (Article 9(2)(a))

AI-assisted analysis and report generation

(MIRS algorithm)

Explicit consent (Article 9(2)(a)) and legitimate

interests (Article 6(1)(f))

Genetic counselling referral and support Explicit consent (Article 9(2)(a))

Complying with legal and regulatory

obligations

Legal obligation (Article 6(1)(c))

Improving our services using anonymised

data

Legitimate interests (Article 6(1)(f))

Your genetic and health data will only be processed with your explicit consent, which you

may withdraw at any time. Withdrawal of consent does not affect the lawfulness of

processing carried out prior to that withdrawal.

5. How We Use Your Data

We use your personal data to:

• Provide genetic carrier screening and deliver your results securely

• Perform donor–recipient genetic matching where you are using a sperm or egg donor

• Support you through our AI-enhanced patient application before and after testing

• Facilitate access to genetic counselling via our partner counsellors

• Conduct anonymised research and continuously improve our services

• Ensure compliance with healthcare regulations

• Respond to enquiries and provide customer support

6. Automated Processing and AI-Assisted Analysis

MolMart uses a proprietary bioinformatic pipeline and pathogenic scoring algorithm (MIRS —

MolMart Interpretation and Reporting System) to analyse your genomic data. This system

uses AI-augmented gene–disease matching to identify clinically relevant variant

combinations between partners or between a donor and recipient.

The output of this automated analysis directly informs the clinical report delivered to you and

your healthcare provider. This constitutes automated processing that may have a significant

effect on you within the meaning of Article 22 of the UK GDPR.

In accordance with your rights under UK GDPR, you have the right to:

• Request human review of any automated analysis or report

• Express your point of view regarding any automated finding

• Contest any decision based solely on automated processing

To exercise any of these rights, please contact us at mmikkelsen@molmart.co.uk. All clinical

reports are reviewed by a qualified molecular geneticist before delivery, providing a layer of

human oversight.

7. Data Sharing and Third Parties

We do not sell your data. We may share it with the following categories of recipients, all of

whom operate under Data Processing Agreements (DPAs) with MolMart:

Recipient Purpose

Accredited sequencing

laboratories

Processing of genetic samples and generation of raw genomic

data

Amber Gardiner, Evolve

Genetics

Genetic counselling services provided to patients

Clair Engelbrecht, CKE Genetics Genetic counselling services provided to patients

Stripe (payment processor) Secure processing of payment transactions; card data is not

retained by MolMart

Cloud storage and IT service

providers

Secure hosting and storage of data

Regulatory authorities Where required by law

8. International Data Transfers

MolMart processes and stores all patient data within the UK and European Economic Area

(EEA). We do not transfer your personal or genetic data to countries outside the UK or EEA

as part of our standard operations.

Where MolMart uses third-party accredited laboratories for customers based in the United

States, those arrangements are governed by separate agreements with those laboratories,

which hold relevant US accreditations (including CLIA and CAP). In all such cases,

appropriate contractual safeguards are in place, including Standard Contractual Clauses

(SCCs) or UK International Data Transfer Agreements (IDTAs) where applicable.

Stripe, our payment provider, may process transaction data in jurisdictions outside the UK or

EEA. Stripe’s data transfers comply with UK GDPR requirements. Please refer to Stripe’s

Privacy Policy for further information.

9. Data Retention

We retain your personal data for the following periods, in accordance with applicable UK

clinical and regulatory guidance:

Data Type Retention Period Basis

Family genetic records (test

results, clinical reports)

Minimum 30 years, or longer if

clinically relevant

NHS/UK clinical records

guidance for family genetic

records

Genomic data used for

research (anonymised)

Indefinitely, subject to strict

anonymisation and safeguards

UK GDPR Article 89 —

scientific/public interest

research

Transaction records (date,

amount, service)

7 years HMRC financial records

obligation

Payment data (card details,

billing address)

Not retained by MolMart — held by

Stripe only

Stripe Privacy Policy

App interaction and support

records

Duration of the customer relationship

plus 2 years

Legitimate interests

10. Donor–Recipient Genetic Matching

Where you are using a sperm or egg donor, SureMart offers a genetic matching service that

compares your genomic data against that of the donor to assess shared carrier variants that

may represent a reproductive risk.

This service involves the processing of genetic data from both the recipient and the donor.

Both parties must provide explicit, separate consent before any matching analysis is

performed. Donor data used for matching purposes is processed solely for that purpose and

is not used for any other analysis or stored beyond what is necessary to complete the

matching report.

If you are a donor whose data may be used in a matching service, you will be informed of

this use and your consent will be obtained in advance.

11. The SureMart Application

SureMart includes an AI-enhanced patient application that supports you before and after

testing. The app may collect and process the following:

• Your results and associated clinical information, to provide personalised guidance

• Responses to in-app questions or assessments

• Records of in-app interactions with our AI-supported genetic counselling content

Data collected through the app is subject to the same protections and retention policies

described in this Privacy Policy. The app does not make clinical decisions independently;

any outputs are supportive in nature and are not a substitute for advice from a qualified

genetic counsellor.

You may request deletion of your app data at any time by contacting us at

mmikkelsen@molmart.co.uk, subject to any retention obligations described in Section 9.

12. Cookie Policy

Our website (suremart.uk) and application use cookies and similar tracking technologies.

This section explains what we use and why.

What are cookies?

Cookies are small text files placed on your device when you visit a website. They allow the

site to recognise your device and remember information about your visit.

Cookies we use

Category Purpose Can be declined?

Strictly necessary Essential for the website and app to function

(e.g. maintaining your session, security tokens).

Cannot be disabled.

No

Functional Remember your preferences (e.g. language,

accessibility settings).

Yes

Analytics Help us understand how visitors use the site

(e.g. pages visited, time on site). Data is

anonymised where possible.

Yes

Marketing We do not currently use marketing or

advertising cookies.

N/A

Your cookie choices

When you first visit our website, you will be presented with a cookie consent notice. You may

accept all cookies, accept only strictly necessary cookies, or manage your preferences in

detail. You can update your cookie preferences at any time via the cookie settings link in the

footer of our website.

You may also control cookies through your browser settings. Note that disabling certain

cookies may affect the functionality of our website and app.

We comply with the UK Privacy and Electronic Communications Regulations (PECR) in our

use of cookies.

13. Your Rights Under UK GDPR

Under UK GDPR, you have the following rights:

Right Description

Right to Access Request a copy of your personal data held by us

Right to Rectification Request correction of inaccurate or incomplete data

Right Description

Right to Erasure Request deletion of your data, subject to legal and clinical

retention obligations

Right to Restrict Processing Request that we limit how we use your data

Right to Data Portability Receive your data in a portable, machine-readable format

Right to Object Object to processing based on legitimate interests

Right to Withdraw Consent Withdraw consent at any time without affecting prior lawful

processing

Right to Human Review Request human review of any automated analysis or AIgenerated

output

To exercise any of these rights, please contact mmikkelsen@molmart.co.uk. We will

respond within one calendar month. Where requests are complex or numerous, we may

extend this by a further two months, in which case we will notify you.

14. Security Measures

We take strict measures to protect your personal and genetic data, including:

• Encryption of sensitive data in transit and at rest

• Access controls to limit data access to authorised personnel only

• Secure storage of genetic samples and sequencing results

• Regular security reviews and risk assessments

• Data Processing Agreements with all third-party partners

15. Changes to This Privacy Policy

We may update this policy periodically to reflect changes in our services, legal obligations, or

data practices. The latest version will always be available on our website at suremart.uk.

Where changes are material, we will notify you directly.

16. Contact and Complaints

If you have any concerns about how we process your data, please contact:

Name Markella Mikkelsen, Data Protection Officer

Email mmikkelsen@molmart.co.uk

Address The Renold Building, 32a Altrincham St, Manchester M1 7JR, UK

You also have the right to lodge a complaint with the UK Information Commissioner’s Office

(ICO):

Website https://ico.org.uk/make-a-complaint/

Phone 0303 123 1113