Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how Whale DNA ("we", "our", "us") collects, uses, protects and deletes personal data when you use our website and services. It is written to comply with the EU General Data Protection Regulation (GDPR) and applies to all users, wherever located.

1. Who we are

The data controller is Whale DNA Sp. z o.o. (placeholder for registered entity), contactable at privacy@cleanwhale.se. A Data Protection Officer (DPO) can be reached at the same address.

2. Data we collect

We deliberately collect the minimum viable data:

3. Legal basis

4. How long we keep it

5. Who sees your data

Whale DNA is hosted entirely on Amazon Web Services in the EU (Frankfurt) region (eu-central-1). Only the following sub-processors, strictly on a need-to-know basis:

We never share, sell or rent your data to advertisers, insurers, data brokers, research consortia or law enforcement unless legally compelled by an EU court order.

6. Your rights

Under GDPR you have the right to:

7. International transfers

All primary data storage is within the European Economic Area (EEA) — specifically AWS eu-central-1 (Frankfurt). API calls to Anthropic may transit to servers in the United States under Standard Contractual Clauses (SCCs) and the EU–US Data Privacy Framework.

8. Security

Data in transit is secured by TLS 1.3. Data at rest is AES-256 encrypted. Access is limited to a small number of engineers under a strict need-to-know policy. We conduct quarterly security reviews and an annual external penetration test.

9. Children

Whale DNA is not intended for anyone under 18. We do not knowingly collect data from minors. If we learn we have, we delete it immediately.

10. Changes

If we materially change this policy we will email registered users 30 days in advance and post a version history on this page.

11. Contact

Questions: privacy@cleanwhale.se. Supervisory authority for Poland: UODO (uodo.gov.pl).