Legal and trust/Privacy Notice

Privacy Notice

Revised 21 August 2026

This Privacy Notice explains how Varosync, Inc. collects, uses, discloses, and retains personal information, and the choices and rights available to individuals.

This Privacy Notice explains how Varosync, Inc. collects, uses, discloses, and retains personal information. It also explains the choices and rights available to individuals.

1. Scope

This Notice applies when Varosync decides why and how personal information is processed. It covers varosync.com, public request and configuration forms, events, business communications, contracting, the private order room, procurement, billing, accounts, and security administration.

This Notice does not govern scientific files, customer datasets, or other Customer Material that Varosync processes on behalf of a customer under an Order. That processing is governed by the customer agreement, Order, and any applicable data processing agreement, business associate agreement, data use agreement, or security addendum. Questions about personal information contained in Customer Material should normally be directed to the organization that provided it.

2. Personal information we collect

Information you provide

We may collect:

  • contact information, including name, business email, telephone number, title, organization, and business address;
  • request and configuration information, including the decision, program, public sources, intended use, scope selections, and institutional requirements you submit;
  • commercial information, including an Order, selected scope, price, invoice, purchase-order number, tax information, billing contact, payment status, refund, and dispute record;
  • account and authority information, including signatory role, procurement role, security-review role, data-owner role, workspace role, invitation, and access status;
  • communications, including inquiries, support requests, meeting records, survey answers, and messages exchanged with us; and
  • event, referral, and marketing preferences.

Do not place patient information, unpublished results, MNPI, data-room material, or other restricted material in a public form, the commercial order room, a payment page, a support request, or ordinary email.

Payment information

Where card or bank payment is offered, payment credentials are entered on the payment provider’s hosted page. Varosync receives transaction identifiers, payment status, billing details, and receipt or invoice information needed to administer the Order. Varosync does not receive complete card or bank-account credentials from the hosted checkout flow.

Information collected automatically

When you use a Varosync site, we may receive an IP address, browser and device information, requested page, referring page, date and time, session events, authentication events, and security logs. The Cookie Notice identifies cookies and similar technologies used in production.

Information from other sources

We may receive business-contact information from your organization, a colleague, an event organizer, a referral source, a public professional profile, or a service provider that helps us prevent fraud or maintain account security. We may receive Order and payment status from contracting, invoicing, payment, and procurement providers.

3. How we use personal information

We use personal information to:

  1. review a request and determine whether Varosync can accept the work;
  2. prepare, route, accept, administer, and change an Order;
  3. verify authority, assign institutional roles, and control access;
  4. process payments, invoices, purchase orders, taxes, refunds, and disputes;
  5. create and administer a project record and authorized workspace access;
  6. communicate about a request, Order, project, event, or support matter;
  7. operate, secure, troubleshoot, and improve our sites and business systems;
  8. prevent fraud, misuse, and unauthorized access;
  9. keep legal, accounting, contract, audit, and compliance records;
  10. establish, exercise, or defend legal claims; and
  11. send business communications where permitted by law and according to your preferences.

We do not use Customer Material to train or fine-tune a shared model, improve a product, perform another customer’s work, or publish research unless the customer gives separate, express written permission for that use.

4. How we disclose personal information

We may disclose personal information to:

  • personnel and advisers who need it for the purposes described in this Notice;
  • the organization for which you act and its authorized scientific, legal, procurement, security, finance, and administrative contacts;
  • providers that support hosting, authentication, databases, communications, contracting, electronic signature, payment, invoicing, security, and customer support;
  • public authorities or other parties where disclosure is required by law or reasonably necessary to protect rights, safety, systems, or evidence of unlawful conduct; and
  • a prospective or completed acquirer, investor, lender, or successor in connection with a financing, merger, reorganization, or sale, subject to appropriate confidentiality restrictions.

Providers may use personal information only to perform the contracted service or as otherwise permitted by their agreement and applicable law.

Varosync does not sell personal information. Varosync does not share personal information for cross-context behavioral advertising and does not use advertising pixels or session-replay tools in the private order room.

5. Retention

We retain records according to their purpose:

  • a configuration or inquiry that does not become an Order: 24 months after the last substantive interaction;
  • customer, Order, contract, authority, procurement, and project-administration records: the term of the customer relationship plus 7 years;
  • invoice, payment, tax, refund, and accounting records: 7 years after the transaction or longer where law requires;
  • account, authentication, access, and security-event records: 12 months after creation, unless a longer period is needed to investigate an incident or establish a legal claim;
  • support and ordinary business communications: 3 years after the matter closes, unless the communication forms part of a contract, dispute, or regulated record;
  • marketing contact information: until you opt out or we determine the information is no longer current; and
  • an opt-out record: for as long as needed to honor the opt-out.

Customer Material follows the retention, return, and deletion terms stated in the applicable Order and data agreement. Backups may persist for a limited cycle after deletion from active systems. Records may be retained longer when required by law, legal hold, audit, fraud prevention, or the establishment or defense of a claim.

6. Security

Varosync uses administrative, technical, and physical safeguards designed for the nature of the information handled. No transmission or storage system is completely secure. The Security and Trust page describes verified controls and the route for institutional diligence.

Do not use this Notice as authorization to send restricted material. The applicable Order and data agreement must approve the material and transfer route before it moves.

7. International processing

Varosync is based in the United States. We and our providers may process personal information in the United States and other countries. Where applicable law requires a transfer mechanism or additional protection, Varosync will use an approved contractual or legal mechanism.

8. Your choices and rights

You may unsubscribe from a marketing email by using its unsubscribe link. You may still receive messages needed to administer a request, Order, account, security matter, or legal obligation.

Subject to applicable law, you may ask Varosync to:

  • confirm whether we process your personal information;
  • provide access to or a copy of that information;
  • correct inaccurate information;
  • delete information;
  • restrict or object to certain processing; or
  • provide portable information where the right applies.

You may also withdraw consent where processing depends on consent. Withdrawal does not affect processing completed before withdrawal. Some requests are subject to exceptions, including contract, security, accounting, legal-hold, and recordkeeping requirements.

Send a request to privacy@varosync.com. State the right you wish to exercise and the context in which you interacted with Varosync. We may ask for information needed to verify your identity and authority. An authorized agent must provide evidence of authority. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.

If local law gives you a right to appeal our response, send “Privacy appeal” in the subject line to privacy@varosync.com. You may also complain to the data-protection authority or regulator with jurisdiction over you.

9. Children

Varosync’s sites and Services are intended for business and professional use by people who are at least 18 years old. We do not knowingly collect personal information from children through these sites. If you believe a child has provided personal information, contact privacy@varosync.com.

10. Other sites

Links to third-party sites are provided for source access or convenience. Their privacy practices are governed by their own notices.

11. Changes to this Notice

We may update this Notice to reflect changes in law, systems, providers, or practices. We will post the revised Notice and change its effective date. We will provide additional notice where required for a material change.

12. Contact

Email: privacy@varosync.com
Varosync, Inc.
712 5th Avenue, New York, NY 10019