Privacy Policy

General Metabolics

Privacy Policy

Effective date: June 29, 2026

Last updated: June 29, 2026

1. Introduction

General Metabolics (“General Metabolics,” “GMet,” “we,” “us,” or “our”) is a fee-for-service metabolomics and lipidomics profiling company serving life sciences researchers and organizations. We respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights available to you.

This Policy applies to generalmetabolics.com and any other websites, forms, and online services that link to this Policy (collectively, the “Services”), and to our offline interactions with prospects, customers, vendors, and other business contacts. By using our Services or providing us with personal information, you acknowledge the practices described in this Policy.

2. Scope: website data and research data

This Policy primarily addresses personal information we collect as a business when you interact with our website, request a quote, or communicate with us. It is helpful to distinguish two categories of data:

  • Business and website personal information – information about you as a researcher, customer contact, prospect, or website visitor (for example, your name, work email, employer, and how you use our site). For this information, General Metabolics acts as the “controller” (or “business” under U.S. law). This Policy governs that information.
  • Client research data and biological samples – samples (such as plasma, cells, or culture media) and associated study data that our customers send us for analysis. When we process this material on a customer’s instructions, we generally act as a “processor” (or “service provider”). See Section 11. The terms of our service agreements and any data processing agreement govern this category.

Please do not submit patient names, direct patient identifiers, protected health information, or other sensitive personal information through our public website forms unless we have specifically directed you to an approved secure channel and appropriate contractual terms are in place.

3. Information we collect

3.1 Information you provide to us

  • Contact and quote requests. When you complete our “Request a Quote” or “Contact Us” forms, we collect your first and last name, email address, job title, company or institution name, and details about your project (such as sample type, estimated number of samples, desired analysis type, and any message you include).
  • Client portal accounts. If you access our client portal to view results and analytics, we collect account registration and authentication data, such as your name, email address, and account activity. Your use of the portal may be governed by separate portal terms and a separate privacy notice, which control for portal-specific processing.
  • Communications. When you email us, call us, or otherwise correspond with us, we keep a record of that correspondence and any information you choose to provide.
  • Marketing and events. If you subscribe to updates, download resources, or interact with us at conferences and events, we collect the contact details and preferences you provide.

3.2 Information we collect automatically

When you visit our website, we and our service providers automatically collect certain information using cookies and similar technologies, including:

  • Device and usage data – IP address, browser type, operating system, device identifiers, referring/exit pages, pages viewed, links clicked, and the dates and times of your visits.
  • Analytics data – information about how you interact with our site, collected via tools such as Google Tag Manager and associated analytics services.
  • Security data – information collected by Google reCAPTCHA to distinguish humans from automated abuse and to protect our forms.

We provide a notice of collection at or before the point at which we collect personal information through our forms, with a link to this Policy. See Section 6 for cookie detail and your choices.

3.3 Information from third parties

We may receive information about you from third parties, such as our analytics and security providers, email and marketing platforms, event organizers, publicly available professional sources, and our customers (for example, where a customer identifies you as a project contact).

3.4 Sensitive information

Our website is directed at business and research contacts, and we do not intentionally collect special categories of personal data (such as health, racial or ethnic, or biometric data) about website visitors. Biological samples and study data submitted by customers are addressed separately in Section 11.

4. How we use your information

We use personal information to operate our business and provide our Services, including to:

  • Respond to your inquiries, prepare quotes, and provide and administer our metabolomics services;
  • Create and manage client portal accounts and deliver results and analytics;
  • Operate, maintain, secure, and improve our website and Services;
  • Send administrative communications, and – where permitted – marketing communications about our services, publications, and events;
  • Conduct analytics to understand how our Services are used and to improve them;
  • Detect, prevent, and address fraud, security incidents, and misuse;
  • Comply with legal obligations and enforce our agreements; and
  • Establish, exercise, or defend legal claims, and for other purposes with your consent.

5. Legal bases for processing (EEA and UK)

If you are in the European Economic Area (EEA) or the United Kingdom, we process your personal information only where we have a valid legal basis under the EU and UK General Data Protection Regulation (GDPR). Depending on the context, our legal bases are:

Purpose Legal basis
Responding to inquiries, quotes, and providing services Performance of a contract or steps taken at your request before entering a contract
Account management and service delivery Performance of a contract
Website operation, analytics, security, and improvement Our legitimate interests in running and improving a secure, effective website
Marketing communications Your consent, or our legitimate interests where permitted by law (you may opt out at any time)
Compliance with legal obligations Compliance with a legal obligation to which we are subject

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, you have the right to object as described in Section 12.

6. Cookies and similar technologies

We use cookies, pixels, tags, and similar technologies to operate our website, remember your preferences, measure performance, and protect our Services. We use the following general categories:

  • Strictly necessary – required for the website to function and to keep it secure (for example, Google reCAPTCHA).
  • Analytics and performance – help us understand how visitors use our site (for example, tools deployed through Google Tag Manager).
  • Functional – remember your choices and enable embedded content such as YouTube videos and forms hosted by our email and marketing providers.

Where required by law (including for visitors in the EEA and UK), we obtain consent before placing non-essential cookies or similar technologies, and you can change your choices at any time through our cookie preference tool.

The third-party technologies we use may include the following. These providers process information under their own privacy policies:

Provider / technology Purpose More information
Google Tag Manager / Google analytics services Tag management and website analytics policies.google.com/privacy
Google reCAPTCHA Bot protection and form security policies.google.com/privacy
YouTube (Google) Embedded video content policies.google.com/privacy
Constant Contact Email marketing and landing pages constantcontact.com/legal/privacy-statement

You can control cookies through your browser settings and our cookie preference tool. You can also opt out of Google Analytics via the Google Analytics opt-out browser add-on. For more on Google’s practices, see policies.google.com/privacy.

7. How we share your information

We do not sell your personal information for money. We share personal information only as described below:

  • Service providers and processors. We share information with vendors who perform services on our behalf, such as website hosting, analytics, email and marketing platforms, and security providers. They may use the information only to provide services to us. We maintain an internal list of these providers.
  • Legal and safety. We may disclose information to comply with law, regulation, legal process, or governmental request, and to protect the rights, property, or safety of General Metabolics, our customers, or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy.
  • With your direction or consent. We share information with other parties when you ask us to or otherwise consent.

8. International data transfers

General Metabolics is based in the United States, and we and our service providers may process your personal information in the United States and other countries that may have data protection laws different from those in your jurisdiction. Where we transfer personal information from the EEA, the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of protection, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable). You may request more information about these safeguards using the contact details in Section 17.

9. Data retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Our general retention periods are:

When personal information is no longer needed, we delete or anonymize it. Retention of client research data and samples is governed by our service agreements (see Section 11).

10. How we protect your information

We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include access controls, authentication measures, encryption in transit where appropriate, and secure facilities. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for protecting your account credentials and for using approved secure channels when submitting confidential information.

11. Client research data and samples

Our customers send us biological samples (such as plasma, cells, or culture media) and associated study data for metabolite profiling and analysis. When we process this material on a customer’s behalf and under its instructions, we act as a “processor” (under GDPR) and “service provider” (under U.S. privacy laws), and our customer is the controller or business responsible for it.

In that role:

  • We process samples and study data only to provide the agreed services and as instructed by the customer;
  • We do not use customer research data for our own marketing or to build commercial profiles of individuals;
  • We require customers to avoid submitting directly identifying personal information (such as patient names, contact details, Social Security numbers, medical record numbers, or full dates of birth) with samples or study data unless expressly agreed in writing through an approved secure channel; and
  • Where human-derived samples or data are coded, pseudonymized, or otherwise capable of being associated with an individual by the customer or another party, that data may still constitute personal data, and our processing is governed by the applicable service agreement, data processing agreement, and the customer’s documented instructions.

If you are an individual whose sample or data was submitted to us by a customer (for example, a research participant), please contact that organization to exercise your rights. We will assist our customers in responding to such requests as required by our agreements and applicable law.

12. Your privacy rights

12.1 EEA and UK rights

If you are in the EEA or the UK, you have the right, subject to certain conditions, to: request access to your personal information; request correction of inaccurate data; request erasure; restrict or object to processing; request data portability; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority, although we encourage you to contact us first.

12.2 U.S. state privacy rights

Depending on your state of residence (for example, California, and other states with comprehensive privacy laws such as Colorado, Connecticut, Virginia, and others), you may have the right to: know and access the personal information we have collected; request correction; request deletion; opt out of the “sale” or “sharing” of personal information and of targeted advertising; and be free from discrimination for exercising your rights. Where applicable law provides, you may also appeal a decision we make about your request.

We do not sell personal information for money, and we do not knowingly “share” personal information for cross-context behavioral advertising. To the extent our use of analytics or advertising technologies is considered a “sale” or “share” under California or other state law, you may opt out by adjusting your cookie settings and by enabling a Global Privacy Control (GPC) signal in a supported browser, which we will treat as a valid opt-out request for the browser or device from which it is sent.

12.3 How to exercise your rights

To exercise any of these rights, contact us at [email protected] or using the details in Section 17. We will verify your request (which may require confirming information we already hold about you) and respond within the timeframes required by applicable law. You may use an authorized agent where permitted by law. We will not discriminate against you for exercising your rights.

13. Additional disclosures for California residents

This section provides additional information required by the California Consumer Privacy Act, as amended (CCPA/CPRA), and applies to the extent the CCPA applies to General Metabolics and to the personal information at issue. In the preceding 12 months, we may have collected the categories of personal information below. Retention for each category is described in Section 9.

Category Sources Purposes Disclosed to service providers? Sold / shared? Retention
Identifiers You; your device; your employer Respond to inquiries; provide services; security Yes No See §9
Customer & professional records You; your employer; clients Service delivery; account management; billing Yes No See §9
Commercial information You; clients Provide and administer services Yes No See §9
Internet / network activity Automatic, via website Operate, secure, and improve site; analytics Yes No* See §9
Geolocation (approx., from IP) Automatic, via website Security; analytics Yes No See §9
Inferences (limited) Derived from the above Improve our services Yes No See §9
Sensitive PI (account credentials) You Portal authentication and security Yes No See §9

*To the extent the use of analytics or advertising cookies is deemed a “sale” or “share” under California law, you may opt out as described in Section 12.2 (including via Global Privacy Control).

We do not sell personal information, and we do not use or disclose sensitive personal information for purposes that would require a right to limit under the CCPA. We do not knowingly sell or share the personal information of individuals under 16. California residents may also use California’s “Shine the Light” law to request information about disclosures for third parties’ direct marketing purposes; we do not make such disclosures.

14. Children’s privacy

Our Services are intended for businesses and professionals and are not directed to children. We do not knowingly collect personal information from children. Consistent with applicable law, we treat individuals under 16 as protected for purposes of any “sale” or “sharing” of personal information. If you believe a child has provided us personal information, please contact us so we can delete it.

15. Third-party websites and services

Our website may link to third-party websites and services that we do not operate or control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

16. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date above indicates when it was last revised. If we make material changes, we will provide notice as required by applicable law, which may include posting the updated Policy or providing additional notice. The updated Policy applies from the effective date stated above.

17. How to contact us

If you have questions about this Policy or our privacy practices, or wish to exercise your rights, contact us at:

General Metabolics

100 Beaver St., Suite 306

Waltham, MA 02453, USA

Privacy inquiries: [email protected]

General inquiries: [email protected]

EEA/UK individuals: you may also contact your local supervisory authority.