Exact Labs website privacy policy

This Privacy Policy is part of and incorporated into the terms and conditions found at http://www.exactsciences.com/terms-use (collectively, this “Agreement”). Exact Sciences Corporation, together with its wholly owned subsidiaries Exact Sciences Laboratories, LLC; Exact Sciences Development Company, LLC; Exact Sciences Europe, Ltd.; Biomatrica, Inc.; Genomic Health, Inc.; Genomic Health Italy, S.r.l.; Exact Sciences France SAS; Exact Sciences UK, Ltd.; Exact Sciences Ireland, Ltd.; Exact Sciences Deutschland GmbH; together with its other U.S. affiliates and subsidiaries with the brand name “Exact Sciences” (collectively, “Exact Sciences,” “we,” “us,” or “our”) offers that website, including its content and site functionality, and related media and services that are or may become available through this website (the “Website”) to you, the user, subject to and conditioned on your acceptance of this Agreement.

By using the Website, you agree that you have read, understand, and are bound by this Agreement. We may, in our sole discretion, revise the Agreement from time to time by updating the Agreement, with the new terms taking effect on the date of posting. You should review the Agreement every time you use this Website, as it is binding on you. IF YOU DO NOT INTEND TO ACCEPT THIS AGREEMENT, PLEASE DO NOT USE THIS SERVICE.

By using the Website, you signify your consent to the collection, use, and disclosure of your personal information in accordance with this Policy, which may be revised from time to time, with new terms taking effect on the date of posting. IF YOU DO NOT CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION IN ACCORDANCE WITH THIS POLICY, PLEASE DO NOT USE THE SERVICE. You must be 18 years or older to use the Website.

The information provided on the page is intended solely for US visitors.


This policy applies to the information you provide to Exact Sciences through the Website. This policy does not apply to information collected by third parties linked in any way to the Website. We have no control over, and no responsibility or liability for, any third party’s collection, use, disclosure, or retention of the personal information that is provided directly to them, and that collection, use, disclosure, and retention is not subject to this policy.

Information Automatically Collected

The Website automatically collects certain information from users through the use of “cookies” and other tracking mechanisms. Information automatically collected may include, but is not limited to: your domain name and host for Internet access; the Internet address of the site from which you came; the date and time you access the Website; your computer or device’s IP address and information about its operating system, browser and host; and your geographic location. We may use this information for any lawful purpose, including, for example, using your IP address to help diagnose problems with our server, to administer the Website, to help identify you and to gather broad demographic data.

Information That You Manually Provide

It is your choice whether to provide personal information to Exact Sciences. Some information must be provided in order to participate in certain services, features, programs or activities, so the decision not to provide information might limit or eliminate certain functions of the Website or the ability to participate. The types of personal information that Exact Sciences tends to request about you include, but are not limited to: your first and last name, email address, mailing address, information about your interest in Exact Sciences (for example, your profession), and the types of information and updates you wish to receive from us. There may be other opportunities to provide information on the Website that will be available to other users of the Website; these opportunities require your good judgment. It is your responsibility not to provide personal information about yourself that could be misused by others in a chat room, bulletin board, blog or similar forum. Do not provide personal information about others without their permission.

Do Not Provide Information About Others

Do not provide personal information about others unless you are authorized or required to do so by applicable law or contract. Before supplying personal information about others, you and the person about whom you supply the information must review and consent to the Agreement. By submitting any personal information about others, you represent and warrant that you are authorized to do so and that you have made the Agreement available to the person about whom you supply the information. If applicable law allows you to supply the information without doing the foregoing, you represent and warrant that you have abided by that law and that it allows us to receive and disclose the information under this Privacy Policy without any further action on our part. You agree to indemnify, defend and hold harmless Exact Sciences, its affiliates, parents, subsidiaries, officers, directors, employees and agents, sponsors and supporting artists, licensors, suppliers, and associates for any failure by you to comply with this paragraph. 

Use of Information

Exact Sciences may use information collected on the Website, which may include information gathered about you, for various purposes. Exact Sciences uses personal information it collects to pursue our mission and operations, including the management of our Website and to engage in related activities. You should assume that we will use all information for all lawful purposes, including, without limitation, to provide you with information you request, to allow users to interact with social networks and platforms, and to enable Exact Sciences to monitor and analyze web traffic.

We reserve the right, but do not undertake a duty, to notify you of court orders, subpoenas or other legal process if allowed. If you do not want us to respond to legal process compelling us to disclose your information, you need to seek a valid order permitting us to refuse to disclose it and serve the order on us at least three (3) business days before the response deadline.

We reserve the right to use, disclose, retain, share, sell and otherwise deal with all information collected via the Website internally or to third parties, for any lawful purpose or to prevent harm to us or others. For example, and without limitation, in our discretion we may:

  • Disclose information to service providers and others in order to deal with requests and questions from you; to personalize or enhance transactions; to verify, process, store, enforce, investigate and/or collect actual or potential transactions; and to assist or respond to our consultants (including auditors and lenders);
  • Disclose information to government regulators, law enforcement authorities or alleged victims of identify theft, as well as voluntary disclosures; and
  • Disclose any matter relating to the Website or your account not listed in this Privacy Policy, but which is not prohibited by law from being disclosed.

We do not purport to have listed all possible disclosures that we might make. This Privacy Policy is intended to help you understand our general practices. This Privacy Policy is not a promise that your information will never be disclosed except as described above. For example, third parties may unlawfully intercept or access information transmitted to or contained on the Website, technologies may malfunction or not work as anticipated, or someone might access, abuse or misuse information, despite a lack of permission. Although we use what we believe to be commercially reasonable practices to protect your privacy, that does not mean, and you should not expect it to mean, that your information or communications will always be private or protected.

We generally will retain information for as long as required, allowed or for as long as we believe it useful. If you cease using the Website, or your permission to use the Website is terminated, we may continue to use and disclose your personal information in accordance with this Policy as amended from time to time. We do not undertake retention obligations through this Privacy Policy. We may dispose of information in our discretion without notice, subject to applicable law. 


We may place a “cookie” on the browser of your computer. Cookies are a technology that installs a small amount of information on the computer of a website user to permit the website to recognize future visits using that computer. Cookies may enhance the convenience and use of the Website. For example, the information provided through cookies may be used to recognize you as a previous user of the Website (so you do not have to enter your personal information every time), offer personalized information for your use, and otherwise facilitate your experience using the Website. You may choose to decline cookies if your browser permits you to do so, but doing so may affect your ability to access or use certain features of the Website. We may also use clear gifs and log file information to store user information, customize content, or monitor Website activity.

Other Websites

The Website may contain hyperlinks to other websites or Internet resources. When you click on one of those links you are contacting another website. We have no control over, and no responsibility or liability for, other websites or their collection, use and disclosure of your personal information. You may encounter third-party advertisements in connection with your use of the Website through, for example, hyperlinked websites and advertisements. We have no control over, and no responsibility or liability for, the cookies or other technologies used in those advertisements or for the use and disclosure of information collected through advertisement cookies or other technologies that you may encounter in connection with your use of the Website.

Privacy Policy Incorporated in Terms and Conditions of Website

Your use of the Website is governed by the Exact Sciences Terms and Conditions of Use, available at http://www.exactsciences.com/terms-use. The Terms and Conditions of Use contain important provisions, including provisions disclaiming, limiting, or excluding the liability of Exact Sciences for your use of the Website and provisions determining the applicable law and exclusive jurisdiction for the resolution of any disputes regarding your use of the Website. Each of those provisions applies to any disputes that may arise in relation to this Privacy Policy and the collection, use and disclosure of your personal information and are of the same force and effect as if they had been reproduced directly in this Privacy Policy.

What Steps Are Taken To Keep Personal Information Secure?

Keeping secure the personal information that we collect is of great concern to us. We exercise care in providing secure transmission of your information from your computer to our servers in connection with the Website. Personal information collected by the Website is stored in secure operating environments that are not available to the public. While Exact Sciences has mechanisms in place to safeguard your personal information once we receive it, no transmission of data over the Internet or any other public network can be guaranteed to be 100% secure.

Special Notice to California Residents 


This section only applies to individuals who are residents of California under the California Consumer Privacy Act of 2018 (“CCPA”), where the resident is acting in their own capacity and not acting on behalf of a company or organization in the context of business activities.


  • Notice of Information Processed

The below chart provides an overview of our Personal Information collection practices for California residents, and includes terms defined under the CCPA, including but not limited to the categories of information listed.


Personal Information We Collect

Information Automatically Collected

Categories of Information

  • Electronic Data, such as geolocation, IP address, and analytics data
  • Inferred Data, including information derived from Personal Information or a profile or segment attribution 

Purposes for Collection of Personal Information

We collect this information for the operation of our services, auditing, security, internal research and development, analytics, and quality and safety business purposes.

Sources of Personal Information

We collect this information directly from the individual, through cookies and other tracking technologies, and from service providers acting on our behalf. 

Types of Third Parties with Whom We Share Personal Information

We share this information with our service providers. 

Personal Information We Collect

Information That You Manually Provide

Categories of Information

  • Identifiers such as name, email address, and postal address.
  • Electronic Data, such as geolocation, IP address, and analytics data.
  • Commercial Information, such as products considered or purchasing tendencies.
  • Employment and Education Information, such as from health providers.
  • Inferred Data, including information derived from Personal Information or a profile or segment attribution.

Purposes for Collection of Personal Information

We collect this information for the operation of our services, auditing, security, internal research and development, analytics, and quality and safety business purposes.

Sources of Personal Information

We collect this information directly from the individual, through cookies and other tracking technologies, and from service providers acting on our behalf. 

Types of Third Parties with Whom We Share Personal Information

We share this information with our service providers and other third parties at the direction of the individual. 


  • California Residents Rights 

Under California laws including the CCPA, California residents have the following rights (“Rights”) listed below. Your Right to Access and Right to Deletion are not absolute and are subject to certain exceptions. For instance, we cannot disclose specific pieces of Personal Information if the disclosure would create a substantial, articulable, and unreasonable risk to the security of the Personal Information, your account with us, or the security of the business’s systems of networks.

  • Disclosure & Access Rights: California residents have the right to request in writing from a business, (i) a list of the categories of Personal Information, such as name, address, e–mail address, and the type of services provided to the customer, that a business has disclosed to third parties (including Independent Affiliates that are separate legal entities) during the immediately preceding calendar year for the third parties' direct marketing purposes, and (ii) the names and addresses of all such third parties. In addition, California residents have the right to request that we disclose to them (i) the categories of Personal Information we have collected about them, (ii) the categories of sources from which Personal Information is collected, (iii) the business or commercial purpose for the information collection, (iv) the categories of third parties with whom we have shared Personal Information, and (v) the specific pieces of Personal Information we hold about an individual.

  • Deletion Rights: California residents have the right to have their Personal Information deleted, unless the Personal Information is necessary for the business or service provider to:
  • complete a transaction for which the Personal Information was collected, provide a good or service requested by the resident or otherwise perform a contract between the business and the resident;
  • detect security incidents;
  • protect against malicious, deceptive, fraudulent or illegal activity (or prosecute those responsible);
  • debug to identify and repair functionality errors;
  • exercise or ensure the right of another to exercise free speech or another legal right;
  • comply with the California Electronic Communications Privacy Act, which compels the production of or access to electronic communication information or electronic device information with a search warrant;
  • engage in research in the public interest (if the resident has provided informed consent);
  • to enable solely internal uses aligned with the resident's expectations given their relationship with the business;
  • comply with a legal obligation;
  • otherwise use the information internally in a lawful manner compatible with the context in which the resident provided it.

    • Do Not Sell: Californian residents have the right to opt-out of having their Personal Information sold. Californian residents acting on behalf of a company or organization in the context of business activities will also have the right to opt-out.  


Californians can exercise their privacy rights by contacting us at the address below.  

Response Time.  We will handle request under applicable law in California. When a request is made, we may verify your identity to protect your privacy and security. We will respond to written rights requests within 45 days following receipt at the e–mail or mailing address listed. If we receive your request at a different e–mail or mailing address, we will respond within a reasonable period of time. Please note that we are only required to respond to each customer twice per calendar year.

Special Notice for Individuals Located in the EEA, UK, or Switzerland

This section applies to individuals using or accessing our Website while located in the European Economic Area, the United Kingdom, or Switzerland (collectively, the “Designated Countries”) at the time of data collection. 

We may ask you to identify which country you are located in when you use or access some parts of the Website, or we may rely on your IP address to identify which country you are located in. When we rely on your IP address, we cannot apply the terms of this section to any individual that masks or otherwise hides their location information from us so as not to appear located in the Designated Countries. If any terms in this section conflict with other terms contained in this Policy, the terms in this section shall apply to individuals in the Designated Countries.

  1. Our relationship to you. Exact Sciences is a data controller with regard to personal information collected from individuals accessing or using its Website. We act as a Processor with regard to personal information collected as part of tests or diagnostics rendered pursuant to a contract with a controller (i.e., a medical professional) in accordance with the GDPR. 


  1. Legal bases for processing your personal information when Exact Sciences is the Controller. We rely on the following Legal Bases under the EU General Data Protection Regulation in processing your personal information:
    • Legitimate interest (for example, to provide and maintain the Website, to maintain the security of the Website, and to attract new customers, to maintain demand for the Website, all of which are described in the “Use of Information” section above).
    • In some cases, we may have a legal obligation to process your personal information to comply with relevant laws (for example, processing payroll and tax information to comply with relevant employment and tax legislation); or processing is necessary to protect your vital interests or those of another person (for example, obtaining health-related information during a medical emergency).
  1. Marketing. If you are in the Designated Countries, we will only contact you by electronic means (including email or SMS) based on our legitimate interests, as permitted by applicable law or your consent. If you do not want us to use your personal information in this way, please click the unsubscribe link at the bottom of any of our email messages to you or contact us at DPO@exactsciences.com. You can object to direct marketing at any time and free of charge.


  1. Individual rights. Individuals located in Designated Countries have the following rights: 
    • You can request access to or deletion of your personal information.
    • You can correct or update your personal information, object to processing or your personal information, ask us to restrict processing of your personal information or request portability of your personal information.
    • If we collected and processed your personal information with your consent, you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of the processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
    • You have the right to complain to ICDR-AAA, under our Privacy Shield certification about our collection and use of your personal information. 

If you would like to exercise your rights under applicable law where Exact Sciences is acting as the Controller (for example, for personal information collected on or Website), please contact us at DPO@exactsciences.com. We may limit your individual rights requests: (a) where denial of access is required or authorized by law; (b) when granting access would have a negative impact on other’s privacy; (c) to protect our rights and properties; or (d) where the request is frivolous or unrealistic.

If we have collected your personal information as a Processor in conjunction with our tests or diagnostics, you must contact the Controller to exercise your individual rights under the GDPR should and refer to the controller’s privacy policy for more information. 

If you believe we have infringed or violated your privacy rights, please contact our Data Protection Officer at DPO@exactsciences.com  so that we may resolve your dispute directly. We will investigate and attempt to resolve complaints regarding use and disclosure of personal information by reference to the principles contained in this Policy.

  1. Privacy Shield.  Exact Sciences participates in and has certified its compliance with both the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the EEA, UK, and Switzerland to the United States, respectively. Exact Sciences is committed to subjecting all personal information received from the EEA, UK, and Switzerland, in reliance on the Privacy Shield Frameworks, to the Framework's applicable Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit the U.S. Department of Commerce's Privacy Shield List at https://www.privacyshield.gov

Exact Sciences is responsible for the processing of personal information it receives, under the Privacy Shield Frameworks, or subsequently transfers to a third party acting as an agent on its behalf. Exact Sciences complies with the Privacy Shield Principles for all onward transfers of personal information from the EEA, UK, and Switzerland to the United States, including the onward transfer liability provisions. 

Exact Sciences commits to resolve complaints about the processing of EEA, UK or Switzerland data subjects’ personal information in compliance with the Privacy Shield Principles. Individuals with inquiries or complaints regarding this Privacy Policy should first contact Exact Sciences at DPO@exactsciences.com.

If you have an unresolved complaint or dispute arising under the requirements of Privacy Shield, we agree to refer your complaint under the Framework to an independent dispute resolution mechanism. Our independent dispute resolution mechanism is ICDR-AAA, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit http://go.adr.org/privacyshield.html for more information or to file a complaint.  The services of ICDR-AAA are provided at no cost to you. You also have a right to lodge a complaint with the appropriate supervisory authority.

With respect to personal information received or transferred pursuant to the Privacy Shield Frameworks, Exact Sciences is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Exact Sciences may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Contacting Us

If you have any questions about this Privacy Policy or other matters that relates to it, you may contact us at:

Exact Sciences Corporation

441 Charmany Drive
Madison, WI 53719


Click the button below to download an order form.


Signing up for our secure Web portal allows you to track patient orders, monitor test compliance, and access reports online.

Our state of the art contact center can assist you and answer your questions.