Data Processing Agreement (GDPR)
Last updated: 30 June 2026
This Data Processing Agreement ("DPA") supplements our Privacy Policy and Terms of Service. It describes how Whale DNA ("Processor") handles personal data on behalf of users ("Controller") in accordance with the EU General Data Protection Regulation 2016/679 ("GDPR").
1. Nature of processing
Whale DNA processes personal data solely for the purpose of generating the health report the Controller has requested. Processing ends upon delivery of the report and deletion of raw uploads.
2. Types of data and data subjects
- Categories of data: genetic data, health data, contact data (email), payment metadata.
- Data subjects: the Controller (the user uploading their own data).
- Special categories (Art. 9 GDPR): genetic data and health data, processed under explicit consent.
3. Sub-processors
Whale DNA runs on Amazon Web Services (AWS) in the eu-central-1 (Frankfurt) region.
- Amazon Web Services EMEA SARL — infrastructure provider (Amplify Hosting, DynamoDB, S3, Cognito, SES, SQS, Lambda). AWS DPA and EU SCCs executed.
- Anthropic PBC — AI inference in zero-retention mode. SCCs in place.
- Stripe Payments Europe Ltd — payment processor.
Any change of sub-processors will be posted with 30 days notice; you may object and close your account.
4. Security measures
- TLS 1.3 for data in transit.
- AES-256 encryption at rest.
- Automatic deletion of raw uploaded data within 24 hours.
- Principle of least privilege in engineering access.
- Quarterly internal security reviews and an annual external penetration test.
- Audit logs on administrative access, retained 12 months.
5. Data subject rights
As the Controller, you may exercise your rights (access, rectification, erasure, portability, restriction, objection, withdrawal of consent) directly through your dashboard or by emailing privacy@cleanwhale.se.
6. International transfers
Primary data storage is exclusively in AWS eu-central-1 (Frankfurt, Germany). Where transfers occur (e.g., to Anthropic in the United States), they are covered by the EU–US Data Privacy Framework and Standard Contractual Clauses as adopted by the European Commission.
7. Data breach notification
In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by Art. 33 GDPR.
8. Deletion on termination
Upon closure of your account, all personal data is irreversibly deleted within 30 days, except where retention is legally required (e.g., payment metadata for tax law).
9. Audit rights
You may request evidence of our security controls once every 12 months. Organizational customers may request a dedicated DPA and audit under separate agreement.
10. Acceptance
Ticking the consent box when uploading data constitutes acceptance of this DPA by both parties.