Privacy Policy
Last modified: September 9th, 2026
INTRODUCTION
VistaPath Biosystems, Inc. (“VistaPath,” “Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it through our compliance with this policy.
This policy describes the types of information we may collect from you or that you may provide when you visit our website, Home (our “Website”), when you or your organization use or receive support for the Sentinel tissue/specimen measurement and pathology grossing station (“Sentinel”), and when you correspond with us as a current or prospective customer. This policy applies to information we collect:
-
On this Website;
-
In email, text, and other electronic messages between you and VistaPath;
-
Through your organization’s use of, and our support and implementation activities related to, the Sentinel; and
-
When you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this policy.
It does not apply to information collected by us offline through any other means not described above, or by any third party, including through any application or content (including advertising) that may link to or be accessible from the Website.
Please read this policy carefully to understand our practices regarding your information. By accessing or using this Website or the Sentinel, you agree to this privacy policy. This policy may change from time to time; your continued use after we make changes is deemed acceptance of those changes.
A note on employment-related information: VistaPath’s workforce is based solely in the United States, and VistaPath does not process human resources data relating to individuals in the European Union, United Kingdom, or Switzerland. VistaPath’s certification under the Data Privacy Framework described in this policy applies only to non-human-resources data and does not cover employment-related information.
CHILDREN
Our Website and Sentinel are intended for business use and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us at info@vistapathbio.com and we will delete it.
INFORMATION WE COLLECT AND HOW WE COLLECT IT
We collect several types of information, including:
-
Personal information — such as name, e-mail address, employer name, telephone number, and any other identifier by which you may be contacted online or offline.
-
Customer and end-user data — contact, account, and support-interaction information for laboratory personnel and other authorized users of the Sentinel, including information submitted through our support ticketing system.
-
Patient- and specimen-associated data — data generated through operation of the Sentinel in connection with tissue and specimen measurement and grossing workflows in customer laboratories.
-
Technical and usage information — information about your internet connection, the equipment you use to access our Website, and usage details, including IP addresses and information collected through cookies, web beacons, and other tracking technologies.
We collect this information directly from you when you provide it (for example, by filling in forms on our Website, requesting a demo, contacting support, or corresponding with us), and automatically as you navigate the Website or as generated through use of the Sentinel.
INFORMATION YOU PROVIDE TO US
The information we collect may include:
-
Information provided by filling in forms on our Website, including requests for a demo or reports of Website problems;
-
Records and copies of your correspondence (including email addresses), if you contact us;
-
Your responses to surveys we might ask you to complete for research purposes; and
-
Information generated through your organization’s implementation, use, and support of the Sentinel.
INFORMATION WE COLLECT THROUGH AUTOMATIC DATA COLLECTION TECHNOLOGIES
As you navigate through and interact with our Website, we may use automatic data collection technologies to collect information about your equipment, browsing actions, and patterns, including traffic data, location data, logs, IP address, operating system, and browser type. This may include:
-
Cookies (browser cookies) — small files placed on your device’s hard drive. You may refuse browser cookies through your browser settings, though this may limit access to parts of the Website.
-
Web Beacons — small electronic files on Website pages and in our e-mails that allow us to count visitors or track email opens and related statistics.
The information we collect automatically is generally statistical, but we may associate it with personal information collected in other ways.
HOW WE USE YOUR INFORMATION
We use information that we collect about you or that you provide to us, including any personal information, to:
-
Present our Website and its contents to you;
-
Provide, maintain, and support the Sentinel and related services;
-
Administer customer accounts, implementation, and support requests;
-
Investigate and resolve product complaints, and fulfill associated medical device reporting and vigilance obligations under applicable regulatory frameworks (including FDA, EU, and UK medical device regulations);
-
Provide you with information, products, or services you request from us;
-
Fulfill any other purpose for which you provide information;
-
Carry out our obligations and enforce our rights under contracts entered into with you, including for billing and collection;
-
Notify you about changes to our Website, Sentinel, or the services we provide;
-
Allow you to participate in interactive features of our Website; and
-
Communicate with you about goods and services that may be of interest to you, unless you have opted out as described below.
DISCLOSURE OF YOUR INFORMATION
We may disclose aggregated or de-identified information about our users without restriction.
We may disclose personal information that we collect or you provide:
-
To our subsidiaries and affiliates;
-
To contractors, service providers, and other third parties we use to support our business, including:
-
Cloud infrastructure providers hosting VistaPath’s systems, including infrastructure located in the European Union and, prospectively, the United Kingdom;
-
VistaPath’s outsourced cloud infrastructure management provider;
-
Support ticketing and case management platforms; and
-
Providers of software tools, including AI-assisted tools, used in connection with customer support or product operations;
-
To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of assets;
-
To fulfill the purpose for which you provided the information;
-
To applicable regulatory authorities, where required for medical device reporting, vigilance, or other legal obligations;
-
To comply with any court order, law, or legal process, including government or regulatory requests;
-
To enforce or apply our terms of use and other agreements;
-
If we believe disclosure is necessary to protect the rights, property, or safety of VistaPath, our customers, or others; and
-
With your consent.
Onward transfer accountability: VistaPath remains responsible for personal data it receives under the Data Privacy Framework and subsequently transfers to a third party acting as its agent on our behalf, and will be liable under the DPF Principles if such agent processes the personal data in a manner inconsistent with the Principles, unless VistaPath proves it is not responsible for the event giving rise to the damage.
Cross-border transfers: Personal data relating to VistaPath’s customers located in the European Union, United Kingdom, and Switzerland may be stored in cloud infrastructure located in the European Union and, prospectively, the United Kingdom. VistaPath’s personnel, who are located in the United States, may remotely access this data in the course of providing customer support, implementation, and engineering services, and VistaPath also communicates directly with customers located in the EU, UK, and Switzerland during implementation and support.
CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR INFORMATION
-
Tracking Technologies and Advertising. You can set your browser to refuse browser cookies or alert you when cookies are sent. Disabling cookies may make parts of the Website inaccessible or non-functional.
-
Promotional Offers. If you submit personal information through a demo request or similar feature, you consent to VistaPath using that information to contact you about VistaPath’s products and offers. You may opt out of future marketing emails by replying to any promotional email; this does not apply to information provided in connection with a product purchase, warranty registration, product service experience, or other transaction.
DATA INTEGRITY AND PURPOSE LIMITATION
VistaPath takes reasonable steps to ensure that personal data is reliable for its intended use, and is accurate, complete, and current, limited to the information relevant for the purposes described in this policy. VistaPath will process personal data in a manner compatible with the purposes for which it was collected or subsequently authorized.
ACCESS TO YOUR INFORMATION
Individuals whose personal data VistaPath processes have the right to obtain confirmation of, and access to, the personal data VistaPath holds about them, and to request correction, amendment, or deletion of personal data that is inaccurate or has been processed in violation of the applicable Principles described below. VistaPath may limit or deny such requests where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy, or where doing so would violate the rights of persons other than the individual.
To exercise these rights, contact VistaPath at info@vistapathbio.com.
DATA SECURITY
We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers behind firewalls.
The transmission of information via the internet is never completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of information transmitted to our Website, and any transmission is at your own risk.
The Data Privacy Framework
VistaPath complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union to the United States. VistaPath’s adherence to the EU-U.S. DPF Principles extends to personal data received from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. VistaPath also complies with the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) regarding personal information transferred from Switzerland to the United States.
VistaPath has certified to the U.S. Department of Commerce that it adheres to:
-
The EU-U.S. DPF Principles with respect to personal data received from the European Union in reliance on the EU-U.S. DPF, including personal data received from the United Kingdom in reliance on the UK Extension to the EU-U.S. DPF; and
-
The Swiss-U.S. DPF Principles with respect to personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms of this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework program and to view VistaPath’s certification, please visit Data Privacy Framework .
RECOURSE, ENFORCEMENT, AND LIABILITY
In compliance with the EU-U.S. DPF, its UK Extension, and the Swiss-U.S. DPF, VistaPath commits to resolve complaints about our collection or use of personal data processed in reliance on these frameworks.
EU, UK, and Swiss individuals with inquiries or complaints regarding VistaPath’s handling of their personal data should first contact VistaPath at info@vistapathbio.com.
VistaPath has further committed to refer unresolved complaints under the DPF Principles to JAMS, an independent dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from VistaPath, or if VistaPath has not addressed your complaint to your satisfaction, please contact or visit JAMS EU-U.S. Data Privacy Frameworks for more information or to file a complaint. This service is provided at no cost to you.
Under certain conditions, described on the Data Privacy Framework website, you may invoke binding arbitration for certain residual claims not resolved by other means.
VistaPath is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission with respect to its compliance with the Data Privacy Framework Principles.
CHANGES TO OUR PRIVACY POLICY
It is our policy to post any changes we make to this policy on this page. If we make material changes to how we treat personal information, we will notify you through a notice on the Website home page. The “Last modified” date above reflects the most recent revision.
CONTACT INFORMATION
To ask questions or comment about this privacy policy and our privacy practices, contact us at: info@vistapathbio.com
