Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how Whale DNA ("we", "our", "us") collects, uses, protects and deletes personal data when you use our website and services. It is written to comply with the EU General Data Protection Regulation (GDPR) and applies to all users, wherever located.
1. Who we are
The data controller is Whale DNA Sp. z o.o. (placeholder for registered entity), contactable at privacy@cleanwhale.se. A Data Protection Officer (DPO) can be reached at the same address.
2. Data we collect
We deliberately collect the minimum viable data:
- Account data: email address (and only email address).
- Uploaded data (temporary): genetic raw data files, lab result documents, wearable exports, self-reported symptoms and goals.
- Derived data (stored): structured insights generated from your uploads (e.g. "MTHFR C677T: heterozygous", "Vitamin D: 28 ng/mL").
- Payment data: processed by Stripe. We never see your card details; we only receive a transaction ID.
- Technical data: minimal server logs (IP, user agent, URL) kept 14 days for abuse prevention.
3. Legal basis
- Contract performance — to deliver the report you requested (Art. 6(1)(b) GDPR).
- Explicit consent — for processing genetic and health data, a special category under Art. 9(2)(a) GDPR. Consent is collected with a granular, unticked checkbox before any upload.
- Legitimate interest — for fraud prevention and product security (Art. 6(1)(f)).
4. How long we keep it
- Raw uploads: deleted within 24 hours after successful processing, irreversibly.
- Derived reports: kept in your dashboard until you delete them, or automatically after 24 months of account inactivity.
- Account email: deleted when you close your account.
- Payment records: retained 7 years as required by tax law (minimum metadata only — no health data linked).
5. Who sees your data
Whale DNA is hosted entirely on Amazon Web Services in the EU (Frankfurt) region (eu-central-1). Only the following sub-processors, strictly on a need-to-know basis:
- AWS Amplify Hosting (eu-central-1) — web application hosting & CDN.
- Amazon DynamoDB (eu-central-1) — structured user & report metadata.
- Amazon S3 (eu-central-1) — ephemeral file storage with 24-hour lifecycle deletion, and long-term report archive (encrypted AES-256).
- Amazon Cognito (eu-central-1) — user authentication.
- Amazon SES (eu-central-1) — transactional email.
- Amazon SQS + Lambda (eu-central-1) — background analysis workers.
- Anthropic — AI language model. Only structured, anonymized insights are sent, never raw files. Zero-retention API mode used.
- Stripe Payments Europe Ltd — payments. We pass only an anonymous customer ID.
We never share, sell or rent your data to advertisers, insurers, data brokers, research consortia or law enforcement unless legally compelled by an EU court order.
6. Your rights
Under GDPR you have the right to:
- Access all data we hold about you (Art. 15).
- Rectify any inaccurate data (Art. 16).
- Erase all your data (Art. 17) — available as a one-click action in your dashboard.
- Port your data (Art. 20) — export available as JSON.
- Restrict or object to processing (Art. 18, 21).
- Withdraw consent at any time (Art. 7).
- Lodge a complaint with a supervisory authority.
7. International transfers
All primary data storage is within the European Economic Area (EEA) — specifically AWS eu-central-1 (Frankfurt). API calls to Anthropic may transit to servers in the United States under Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework.
8. Security
Data in transit is secured by TLS 1.3. Data at rest is AES-256 encrypted. Access is limited to a small number of engineers under a strict need-to-know policy. We conduct quarterly security reviews and an annual external penetration test.
9. Children
Whale DNA is not intended for anyone under 18. We do not knowingly collect data from minors. If we learn we have, we delete it immediately.
10. Changes
If we materially change this policy we will email registered users 30 days in advance and post a version history on this page.
11. Contact
Questions: privacy@cleanwhale.se. Supervisory authority for Poland: UODO (uodo.gov.pl).