Legal

Privacy policy

How DNA Layer collects, uses, protects, and gives you control over personal and genetic data.

Last updated 10 August 2026

Scope and responsibility

This policy explains how DNA Layer handles personal data when you visit our website, create an account, upload a DNA file, purchase or use our services, or contact us. DNA Layer is the controller for the processing described here unless another notice says otherwise.

Genetic and health-related information can be especially sensitive. We treat it as special-category data where applicable and process it only with an appropriate legal basis, including your explicit consent where required.

Data we collect

Depending on how you use DNA Layer, we may collect:

  • Account and contact data, such as your name, an email address entered to start onboarding, authentication details, and support messages.
  • Genetic and health data, including supported markers from your uploaded DNA file, derived genetic findings, information you add, and the personalised guidance generated for you.
  • Purchase data, such as your selected product, transaction status, and billing records. Payment card details are handled by our payment provider and are not stored by DNA Layer.
  • Technical and usage data, such as IP address, browser and device type, security events, pages viewed, and diagnostic information.
  • Preferences and communications, including consent choices, email preferences, feedback, and correspondence.

How your DNA file is handled

In our browser-based upload flow, your raw DNA file is read on your device. DNA Layer sends the supported marker data and technical metadata needed to build your personalised layer, rather than intentionally retaining the original raw file in that flow. If a future upload method works differently, we will explain that before collection.

We store derived genetic data, evidence records, and generated guidance so you can access and improve your layer over time. These records remain sensitive personal data even when they do not contain your original file.

How we use personal data

We use personal data to:

  • provide, personalise, secure, and maintain DNA Layer;
  • process supported DNA markers and create your findings, action guidance, and downloadable artefacts;
  • manage accounts, purchases, customer service, and service communications;
  • remember an email submitted through “Get started” so you can continue onboarding; this alone does not subscribe you to marketing;
  • detect abuse, troubleshoot faults, measure reliability, and improve the service;
  • comply with law, enforce our terms, and protect users and the service; and
  • send optional product news when you have asked to receive it.

Our legal bases may include performing our contract with you, your consent, compliance with legal obligations, and our legitimate interests in operating a secure and useful service. You may withdraw consent at any time, but withdrawal does not affect earlier lawful processing.

AI-assisted guidance and improvement

DNA Layer uses automated systems and specialist service providers to organise evidence and draft personalised explanations. We apply deterministic safety and evidence checks around that synthesis. Generated guidance can still be incomplete or wrong and is not a medical diagnosis.

We do not use your genetic data to make solely automated decisions that produce legal or similarly significant effects about you.

We may use aggregated or de-identified information to evaluate and improve DNA Layer. We do not sell your genetic data, and we do not share identifiable genetic data with advertisers or data brokers.

Who receives personal data

We disclose personal data only where needed to operate DNA Layer or meet legal obligations, including to:

  • hosting, database, authentication, communications, analytics, security, and AI infrastructure providers;
  • payment processors for purchases, refunds, fraud prevention, and required financial records;
  • professional advisers, auditors, insurers, and authorities where lawfully required; and
  • a buyer or successor if DNA Layer is involved in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and legal safeguards.

These recipients may act as processors under our instructions or as independent controllers for their own regulated functions, such as payment processing.

International transfers

Some providers may process data outside the European Economic Area. Where required, we use recognised safeguards such as adequacy decisions or standard contractual clauses, together with additional technical and organisational measures appropriate to the data.

Retention and deletion

We keep personal data only as long as needed for the purposes described here, including to provide your account and saved layer, meet tax and legal obligations, resolve disputes, and maintain security records. Retention periods vary by data type and legal requirement.

You may request account deletion. We will delete or irreversibly de-identify data that we no longer need, except where retention is required by law or necessary to establish, exercise, or defend legal claims. Backups expire on their normal secure cycle.

Security

We use technical and organisational safeguards designed for sensitive information, including access controls, encryption in transit, separation of production environments, monitoring, and restricted service-provider access. No system is perfectly secure, so we cannot guarantee that unauthorised access will never occur.

Cookies and similar technology

We may use essential cookies and local storage for security, authentication, service continuity, and preferences. If we introduce optional analytics or marketing technologies that require consent, we will provide an appropriate choice before using them. Browser controls can remove or block stored data, although essential features may then stop working.

Your rights

Depending on where you live, you may ask to access, correct, delete, restrict, or receive a portable copy of your personal data. You may also object to certain processing, withdraw consent, and ask for information about safeguards used for international transfers.

Contact us to exercise a right. We may need to verify your identity and may retain a limited record of the request. You may also complain to your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

Children

DNA Layer is for adults aged 18 or older. We do not knowingly collect DNA or other personal data from children. If you believe a child has provided data to us, contact us so we can investigate and delete it where appropriate.

Changes to this policy

We may update this policy as DNA Layer develops or legal requirements change. We will publish the revised version here and update the date above. If a change materially affects how we use sensitive data, we will provide additional notice or seek consent where required.

Contact

Questions, privacy requests, and accessibility requests can be sent to contact@dnalayer.ai.

DNA Layer
Strawinskylaan 1
1077 XW Amsterdam
The Netherlands