Data Processing Agreement (GDPR)

Last updated: 30 June 2026

This Data Processing Agreement ("DPA") supplements our Privacy Policy and Terms of Service. It describes how Whale DNA ("Processor") handles personal data on behalf of users ("Controller") in accordance with the EU General Data Protection Regulation 2016/679 ("GDPR").

1. Nature of processing

Whale DNA processes personal data solely for the purpose of generating the health report the Controller has requested. Processing ends upon delivery of the report and deletion of raw uploads.

2. Types of data and data subjects

3. Sub-processors

Whale DNA runs on Amazon Web Services (AWS) in the eu-central-1 (Frankfurt) region.

Any change of sub-processors will be posted with 30 days notice; you may object and close your account.

4. Security measures

5. Data subject rights

As the Controller, you may exercise your rights (access, rectification, erasure, portability, restriction, objection, withdrawal of consent) directly through your dashboard or by emailing privacy@cleanwhale.se.

6. International transfers

Primary data storage is exclusively in AWS eu-central-1 (Frankfurt, Germany). Where transfers occur (e.g., to Anthropic in the United States), they are covered by the EU–US Data Privacy Framework and Standard Contractual Clauses as adopted by the European Commission.

7. Data breach notification

In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by Art. 33 GDPR.

8. Deletion on termination

Upon closure of your account, all personal data is irreversibly deleted within 30 days, except where retention is legally required (e.g., payment metadata for tax law).

9. Audit rights

You may request evidence of our security controls once every 12 months. Organizational customers may request a dedicated DPA and audit under separate agreement.

10. Acceptance

Ticking the consent box when uploading data constitutes acceptance of this DPA by both parties.