PRIVACY POLICY
This Privacy Policy (the "Privacy Policy") describes how the Weizmann Institute of Science.
("we", "our" or "us") collects, uses, stores, and protects personal data obtained through our
website https://www.project10k.org.il/ and mobile applications (collectively, the "Platform") in
connection with the Human Phenotype Project Israel ("the Study").
1. Introduction. This Privacy Policy details how we manage personal data that will be collected
during your visit and/or use of the Platform, and the choices you can make regarding how this
data will be collected.
What is personal data? "Data" or "personal data" as defined in the Israeli Privacy Protection
Law, 5741-1981 (hereinafter: the "Privacy Protection Law") including data relating to an
identified person or an identifiable person, including by means of an identifying detail such as
name, ID number, biometric identifier, location data, online identifier, or one or more details
relating to a person's physical, health, economic, social or cultural condition.
2. Consent and Updates. You are not under any legal obligation to provide us with your personal
data, and the provision of data is done on your own free will. However, if you decide not to
provide certain data, you may not be able to participate in the Study.
By using the Platform, you agree to the terms of our Privacy Policy, and to any collection,
processing and sharing of your personal data, for the purposes detailed below. If you do not
agree to the terms of this Privacy Policy, please do not enter or make any use of our Platform.
We reserve the right, at our discretion, to change this Privacy Policy at any time.
3. Type of Personal Data Collected that is Directly Provided by You and Purposes of its Use.
We receive or collect data from you in the following ways:
3.1. Personal Identifiable Data and Contact Details. Full name, phone number, email
address, residential address, ID number, driver's license, passport number, date of birth, gender.
3.2. Health-Related Data . Physiological measurements (e.g., blood pressure, BMI, bone
density); Medical history (e.g., chronic diseases, medications); Disease manifestations and
lifestyle-related health data (e.g., smoking, alcohol consumption); Laboratory test results (e.g.,
blood tests, urine and stool analysis).
3.3. Biological Samples: Blood samples (e.g., for genetic and biochemical analysis); Urine and
stool samples; Continuous Glucose Monitoring (CGM) data; Additional samples for microbiome,
proteome, and metabolome analysis.
3.4. Multi-Omics Data: Genomic data (e.g., whole genome sequencing); Proteomic,
metabolomic, transcriptomic, and microbiomic profiles; Immunological profiling (e.g., antibody
repertoire analysis).
3.5. Lifestyle Data: Fitness and activity levels (e.g., data collected via wearable devices); Diet
and sleep patterns; Data from questionnaires on lifestyle and environment.
3.6. Device and System Data: IP addresses and device identifiers ; Data collected from
wearable devices and smartphone applications used during home monitoring.
4. Type of Personal Data Collected by Us that is Not Directly Provided by You and Purposes
of its Use:
4.2. Log Files. We may use log files. The data appearing in the log files includes IP address,
browser type, date/time stamp, referring/exit pages, filtering actions, clicks and any other data
that may be provided to us from your browser. We may use such data for the purpose of
analyzing trends, managing the Platform, tracking visitor traffic on the Platform and system, and
for collecting demographic data.
4.3. Cookies and Other Tracking Technologies. We may use "cookies", anonymous
identification files and other tracking technologies on the Platform, for data security purposes, as
well as to enhance the efficiency of our operations. A "cookie" is a small text file used, for
example, to collect data about activity on the Platform, save user preferences and authenticate.
Certain cookies and other technologies may be used to retrieve personal data, such as an IP
address.
Some cookies are operated by third parties and data collected through them may be transferred
to those parties, for commercial purposes or for internal purposes related to service
improvement and the like. The ability of those third parties to use the data, including in an
identifiable manner, depends on whether you have registered for the services of those parties
and agreed to their privacy terms.
Most browsers allow you to control cookies, including whether to approve them or not and how
to remove them. You can set most browsers to notify you if you want to approve a cookie, or you
can block cookies in your browser.
4.4. Mobile Device Data. We may collect limited data from the device for operational purposes.
Such data may include the type of device, device identification (ID), date and time stamps of
use of the Platform, browser type, browser language, date and time of your request and the
requested URL. We may also use location-based technology to help us collect aggregate
statistical data, but we will not use personal data that can identify you for these purposes.
4.5. Google Analytics and Additional Analytical Tools. The Platform may use a tool called
"Google Analytics" to collect data about the use of the Platform for various purposes. Google
Analytics collects data such as how often users visit the Platform, which pages they visit and
which sites they use before entering the Site. We use the data received from Google Analytics
to maintain and improve the Site and the Platform. We do not combine the data collected
through the use of Google Analytics with personally identifiable data. Google's ability to use and
share data collected through Google Analytics about your visits and use of the Platform is
limited by the Google Analytics Service Agreement, published at
http://www.google.com/analytics/terms/us.html and Google's Privacy Policy, published at
http://www.google.com/policies/privacy/.
You can read about how Google collects and processes data through Google Analytics at
http://www.google.com/policies/privacy/partners/.
You can prevent the use of your data by Google Analytics by downloading and installing the
Google Analytics Opt-out Browser Add-on, found at https://tools.google.com/dlpage/gaoptout.
5. Use of Artificial Intelligence Systems for the Processing of Personal Data.
5.1. We may use artificial intelligence tools (AI) to process personal data collected about you.
Such processing may include, inter alia, analysis, classification, the generation of predictions,
recommendations, or decisions relating to you, in accordance with the purposes of use set out
in this Privacy Policy.
5.2. Our artificial intelligence systems operate through advanced algorithms designed to identify
patterns in data, learn from historical data, and generate automated insights. Potential risks
associated with the use of this technology include, among others: the possibility of algorithmic
bias, errors in processing or analyzing data, automated decision-making that may affect you, as
well as data security risks relating to the large-scale storage and processing of data.
5.3. We strive to ensure that the processing of personal data through artificial intelligence tools
is conducted in compliance with applicable law, while maintaining principles of transparency and
protection of your privacy. We implement reasonable data security measures aimed at mitigating
the risks inherent in the use of such technology. However, we cannot guarantee that errors or
inaccuracies in data processing will not occur.
6. For What Purposes We Collect the Data.
In addition to the purposes of use detailed above, we may use personal data collected by us, as
detailed above, also in the following ways and for the following purposes:
6.1. Primary Purposes.
To conduct a long-term observational study that aims to collect multi-omics and
physiological data over a period of up to 25 years.
To investigate the biological, social, and environmental determinants of health and
disease progression.
To establish predictive models for early diagnosis, risk stratification, and personalized
treatment.
6.2. Secondary Purposes.
To develop new diagnostic tools, personalized healthcare solutions, and treatments for
various diseases.
To enable secondary research purposes through data-sharing with authorized research
organizations or commercial partners in anonymized or pseudonymized form.
To contribute to the development of health-related technologies and products in
collaboration with commercial entities.
6.3. Other Purposes.
To comply with legal and regulatory requirements (e.g., data protection laws, health
regulations).
To respond to government or law enforcement requests, if required by law.
For the purpose of communicating with you when needed.
To improve the platform and our operations according to its purposes.
For data security purposes on the platform.
For the purpose of defense in legal proceedings.
7. Research Use of Anonymized Data. We may anonymize personal data collected through our
services and retain such anonymized data indefinitely for secondary research purposes.
Anonymized data cannot be used to identify you and may be used in future research projects
aimed at improving our services and supporting scientific and academic studies. Once data is
anonymized, it is no longer considered personal data, and certain privacy rights (such as access
or deletion) may not apply.
8. How We Share Personal Data.
Apart from the above, we will not transfer or share your personal data with third parties, except
in the following cases:
8.1. Your data may be shared with academic, governmental, and commercial research partners
under the following conditions:
(a) Data will be anonymized or pseudonymized, ensuring that participants cannot be directly
identified;
(b) Access to multi-omics and health data will be granted in secure, controlled environments
such as our Trusted Research Environment (TRE), ensuring no raw data leaves the secure
platform.
8.2. We may engage third-party vendors to process data or provide services (e.g., cloud service
providers, laboratories), to assist us in our activities, including system providers. These vendors
will have limited access to personal data and will be contractually bound to comply with strict
confidentiality and data protection obligations.
8.3. In the event of a violation of the terms of use or this Privacy Policy, or if you perform actions
through the Platform that appear to be contrary to law, or an attempt to perform such actions;
8.4. In the event of any dispute, claim, lawsuit, demand or legal proceedings, if any, between
you and us;
8.5. In any case where we believe that the disclosure of the data is necessary to prevent bodily
harm or property damage (to you or to a third party) or in connection with an investigation into
suspicions of illegal acts;
8.6. In the event that we are required by law, including if we receive a judicial order directing us
to provide data about you to a third party or in response to a request from a law enforcement
authority or other governmental or public authority;
8.7. In the event that we are acquired by a third-party company or merge with a third-party
company.
In certain cases, third parties to whom data will be transferred as stated in this section above,
will be outside of Israel You hereby agree that data relating to you will be transferred and stored
outside the borders of the country, in accordance with the provisions of the law and for the
purposes presented above.
9. Data Security. We implement systems, security measures and procedures for data security on
the Platform. While these measures, systems and procedures reduce the risks of unauthorized
intrusion into our systems, they do not provide absolute security. Therefore, while we make
effort to use appropriate and reasonable measures to protect your personal data, we cannot
guarantee that the Platform will be completely immune from unauthorized access to data stored
on it. If you have any questions regarding the security of the service or concerns about
confidentiality, you may contact us using the contact details provided in the "Contact Us" section
of this Privacy Policy.
10. Data Retention
10.1. Retention of Personal Data. Identifiable data will be retained for five years after the
completion or termination of the Study. After this period, personal data will be securely deleted.
10.2. Retention of Biological Samples. Biological samples will be stored for up to 25 years
after the last follow-up visit. Samples that are no longer required for research will be securely
destroyed.
10.3. Retention for Secondary Use. Data anonymized for secondary research purposes will be
retained indefinitely for future research projects.
11. Children's Privacy. The Platform is not intended for or directed to children under the age of
18. We do not knowingly collect, process, or store personal data from children under 18 years
of age. If we discover that we have collected personal data from a child under 18, we will
promptly delete such data from our systems. If you are a parent or legal guardian and believe
your child has provided us with personal data, please contact us using the details provided at
the end of this Privacy Policy, and we will take steps to remove this data from our systems.
12. Your Rights and Protection of Your Privacy. We respect your right to privacy and are
interested in keeping only required, up-to-date and accurate data. It is important for us that you
know that you have the right to access/review data about you that we hold, and if you find that
this data is not correct, complete, clear or up-to-date, you are invited to contact us with a
detailed request to correct or delete such data, in accordance with the provisions of the
Privacy Protection Law and the Privacy Protection Regulations (Conditions for Reviewing data
and Appeal Procedures on Refusal to Request for Review), 5741-1981. We invite you to
contact us to exercise your rights through the contact details provided in the ‘Contact Us’
section.
13. Compliance With Applicable Laws and Google Health policies. This Privacy Policy is
governed by and complies with Israeli Law, including Privacy protection law.
14. CONTACT US. is the controller of the database containing the data detailed in this policy. If
you have any questions, concerns, requests or complaints regarding this privacy policy or if
you wish to exercise your rights, we invite you to contact us at support10k@project10k.org.il
Last updated: August 2025