Privacy Policy

GDPR Website Policy

1. Introduction

Gene Keys Ltd (“we”, “us”, “our”) is committed to protecting personal data and respecting the privacy rights of individuals who visit our website, use our services, or otherwise interact with us. This Policy explains how we comply with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and, where applicable, the EU General Data Protection Regulation (EU GDPR) (together referred to in this Policy as “Privacy Laws“).

All references to “GDPR” in this Policy refer to the UK GDPR, and where applicable, the EU GDPR. We maintain appropriate technical and organisational measures to protect personal data, including information security controls aligned with recognised industry standards. Gene Keys maintains appropriate policies, procedures and records to designed to support compliance with applicable Privacy Laws. This Policy explains our approach to the collection, use, storage, security, retention, transfer and protection of personal data, as well as the rights available to individuals under applicable data protection laws.

2. Applicability
This Policy applies to all individuals whose personal data is collected, used or otherwise processed by Gene Keys in connection with our website, products, services and related activities.

3. Data Protection Principles
We process personal data in accordance with the following principles:
1. Lawfulness, Fairness and Transparency: We process personal data lawfully, fairly and in a transparent manner.
2. Purpose Limitation: We collect personal data only for specified, explicit and legitimate purposes.
3. Data Minimisation: We limit the personal data we collect to what is relevant and necessary for those purposes.
4. Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date.
5. Storage Limitation:  We retain personal data only for as long as necessary for the purposes for which it was collected and to comply with applicable legal and regulatory requirements.

6. Integrity and Confidentiality: We implement appropriate security measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage.
7. Accountability: We are responsible for, and able to demonstrate, compliance with applicable data protection laws and these principles.
8. Data Subject Rights: We respect and facilitate the exercise of individuals’ rights under applicable data protection laws, including rights relating to access, correction, deletion, restriction, objection and complaints.
9. Responsible Use of Technology: We seek to ensure that any use of automated technologies is consistent with applicable data protection laws, transparency requirements and our commitment to the responsible handling of personal data.

4. Data Collection and Puposes

We collect only the personal data that is reasonably necessary to provide our products and services, process transactions, administer user accounts, respond to enquiries, and support the operation and security of our website and services.  The categories of personal data we may collect for the purposes described in this Policy include:

1. Identification and Contact Information: Such as your name, email address, billing address, shipping address (where applicable), and any information you choose to provide when creating an account, making an enquiry, requesting support, subscribing, or   purchasing products and services.

2. Birth and Profile Information: Where required to generate a Gene Keys Profile or related services, this may include your date of birth, time of birth, place of birth and other information voluntarily provided by you for the purpose of generating personalised profile outputs.

3. Payment Information: Such as payment card or other payment method information required to process transactions. Payment information is processed securely through approved payment service providers and is not stored by Gene Keys except as necessary to maintain transaction records.

4. Technical and Usage Information: Such as IP address, device and browser information, website usage information, log data, and other technical information generated through your use of our website or services. This information is used for security, service operation, diagnostics, performance monitoring and service improvement. We 

5. Legal Basis for Processing

We process personal data only where we have a lawful basis to do so under applicable data protection laws. The lawful bases on which we rely under Article 6 UK GDPR include: 

Performance of a Contract (Article 6(1)(b) UK GDPR): We process personal data where necessary to provide our products and services, create and manage user accounts, generate Gene Keys Profiles and related outputs, process orders and payments, provide customer support, and otherwise fulfill our contractual obligations. 
 
Legal Obligations (Article 6(1)(c) UK GDPR):
We process and retain certain data where necessary to comply with legal, regulatory, tax, accounting, reporting and record-keeping obligations.

Legitimate Interests (Article 6(1)(f) UK GDPR):
We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the rights and freedoms of individuals. This may include maintaining the security of our systems, preventing fraud, responding to enquiries, improving our services, and administering our business operations. 

Consent (Article 6(1)(a) UK GDPR):
Where required by law, we rely on consent to process personal data, including for marketing communications and certain cookies or analytics technologies. 
Marketing communications are sent only to individuals who have subscribed or otherwise consented to receive them. We use a double-opt in process for email subscribers and individuals may withdraw consent at any time by contacting [email protected] or by clicking the “unsubscribe” link in the email. Where consent is withdrawn, will not affect the lawfulness of any processing carried out prior to withdraw. 

  1. Children’s Privacy

Our website, products and services are not intended for use by children under the age of 16. We do not knowingly collect personal data from children under the age of 16. If we become aware that a child under the age of 16 has provided us with personal data without appropriate parental consent or other lawful basis where required by applicable law, we will take reasonable steps to delete that information promptly.

  1. Retention of Personal Data

We retain personal data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, provide requested services, comply with legal, regulatory, accounting and reporting obligations, resolve disputes, and enforce our agreements.

For example, we may retain order-related, contractual and transaction records for up to seven (7) years following the end of the relevant customer relationship or transaction in order to comply with legal, tax, accounting, audit and record-keeping requirements, establish or defend legal claims, and resolve disputes.

When personal data is no longer required for these purposes, we securely delete, anonymise or otherwise dispose of it in accordance with our retention practices.

Marketing subscription data is retained until an individual unsubscribes or requests deletion, unless a longer retention period is required by law.

  1. Data Minimisation and Accuracy

We adhere to the principles of data minimisation and accuracy under GDPR. This means that we:

  1. Collect only the personal data that is reasonably necessary to provide our products and services, generate Gene Keys Profiles and related outputs, administer user accounts, respond to enquiries, comply with legal obligations, and send marketing communications where you have provided your consent.
  2. Take reasonable steps to ensure that personal data is accurate, complete and kept up to date.
  3. Provide individuals with the opportunity to access, correct, update or request deletion of their personal data by contacting us.
  1. Analytics and Site Usage Data

We collect limited website and application usage information to understand site performance, identify technical issues, maintain security, improve functionality and enhance the user experience.

For website visitors, we use Google Analytics to collect information about website usage, including page visits, session activity, device and browser information, and general usage patterns. This information is used to generate aggregated statistical reports and to help us improve our website and services.

Gene Keys does not use website analytics information for targeted advertising, marketing profiling or customer segmentation.

Where personal data is provided directly by a user, such as when creating an account, making an enquiry or subscribing to communications, that information may be associated with the relevant user account and used to provide the requested services.

For customers using our applications and services, limited technical and operational information may be processed to support service delivery, security, troubleshooting, maintenance and product improvement. This information is not used for automated decision-making, behavioural profiling or marketing purposes.

The Gene Keys Profile and related outputs are generated using information provided by the user as part of the requested service. These outputs are not used for marketing profiling, customer segmentation or automated decision-making.

Where analytics or technical identifiers are used, they are used solely for operational, security and analytical purposes and not to identify individuals or build behavioural profiles.

Where cookies or similar technologies are used for analytics, they are used in accordance with our Cookie Policy and, where required, your cookie preferences.

  1. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our website, improve functionality, understand how our services are used, and enhance the user experience.

Some cookies are necessary for the operation of the website and cannot be disabled. Other cookies are used for analytics purposes to help us understand website performance, identify technical issues, and improve our services.

We use Google Analytics to collect information about how visitors use our website. Google Analytics uses cookies and similar technologies to collect information such as pages visited, time spent on the site, device and browser information, and general usage patterns. This information is used in aggregated and statistical form to help us improve our website and services.

Analytics information is not used by Gene Keys for behavioural profiling, targeted advertising, or marketing segmentation of website visitors.

Where required by law, visitors are provided with a cookie consent mechanism that allows them to manage their cookie preferences. You can also manage cookies through your browser settings. Further information is available in our Cookie Policy.

Marketing communications are sent only to individuals who have provided their consent or where otherwise permitted by applicable law. We use a double opt-in process for email subscriptions, requiring subscribers to confirm their subscription via an email verification link. Individuals may unsubscribe from marketing communications at any time using the unsubscribe link included in our emails or by contacting us directly.

For users of our applications and services, we may collect limited technical and operational information to maintain, secure, troubleshoot, and improve the performance of our services. This information is not used for automated decision-making, behavioural profiling, or targeted advertising.

  1. Automated Decision-Making and Profiling

Gene Keys does not engage in automated decision-making that produces legal or similarly significant effects on individuals.

Gene Keys Profiles and related outputs are generated using information provided by users as part of the requested service. These outputs are not used for automated decision-making, marketing profiling, customer segmentation or behavioural profiling, or the generation of inferred characteristics for marketing or commercial purposes.

  1. Artificial Intelligence

Gene Keys does not currently use third-party artificial intelligence providers to process personal data or user-generated content, nor does it use such data to train artificial intelligence models.

Should our use of artificial intelligence technologies change in the future, we will review and update our privacy and data protection disclosures accordingly. Please refer to our AI Policy for further information.

  1. Third-Party Data Sharing and Transfers

We may share personal data with carefully selected third-party service providers who support the operation of our website, products and services, including hosting providers, payment processors, customer communication platforms, analytics providers and customer support services.

These service providers process personal data only on our instructions, are contractually required to maintain appropriate security and confidentiality measures, and may not use personal data for their own purposes except where permitted by law.

Some of our service providers may process personal data outside the United Kingdom or European Economic Area. Where international transfers occur, we take appropriate steps to ensure that personal data remains protected in accordance with applicable data protection laws, including the use of recognised transfer mechanisms and contractual safeguards where required.

  1. International Data Transfers

Our primary application infrastructure is hosted using Amazon Web Services (AWS).

We use carefully selected third-party service providers to support the delivery of our products and services, including customer communication and engagement platforms, email delivery services, payment processors, analytics providers and customer support tools. This includes Braze, a customer engagement and communications platform, which we use to support customer communications and engagement.

These providers may process personal data in the United Kingdom, the European Economic Area, the United States and other jurisdictions in which they operate.

Where personal data is transferred outside the United Kingdom or European Economic Area, we implement appropriate safeguards in accordance with applicable data protection laws. Such safeguards may include adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other legally recognised transfer mechanisms.

We select service providers that maintain appropriate technical and organisational measures to protect personal data and require them to process personal data in accordance with applicable data protection laws.

Further information regarding our service providers and international data transfers is available on request.

  1. Data Security Measures

We take data security seriously and implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration or disclosure.

These measures include, where appropriate:

  1. Encryption: the use of encryption and secure transmission technologies to protect personal data and payment-related information.
  2. Access Controls: restricting access to personal data to authorised personnel and service providers who require access for legitimate business purposes.
  3. Security Monitoring and Testing:  maintaining security procedures, monitoring systems and undertaking periodic testing and reviews to identify and address potential vulnerabilities.
  4. Information Security Controls: implementing information security practices aligned with recognised industry standards and security frameworks.
  5. Payment Security: using approved payment service providers and secure payment processing measures designed to protect payment information.

Personal data may be stored and processed by Gene Keys and its approved service providers in accordance with this Policy and applicable data protection laws.

Although no method of transmission over the internet or electronic storage can be guaranteed to be completely secure, we take reasonable steps to protect personal data and to maintain appropriate security safeguards.

In the event of a personal data breach, we will respond in accordance with applicable legal requirements, including notification to relevant supervisory authorities and affected individuals where required by law.

  1. Data Breach Notification Procedures

In the event of a personal data breach we will:

  1. Assess the Breach: Determine the nature, scope and potential impact of the incident.
  2. Contain and Mitigate: Take appropriate steps to contain the breach, prevent further unauthorised access, and minimise any adverse effects.
  3. Notify Relevant Authorities: Where required by law, notify the Information Commissioner’s Office (ICO) without undue delay and, where applicable, within 72 hours of becoming aware of the breach.
  4. Inform Affected Individuals: Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  5. Review and Improve: Investigate the cause of the incident, implement corrective measures, and review our policies, procedures and security controls to reduce the risk of recurrence.
  1. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data. You may:

  1. Right of Access: Request confirmation of whether we process your personal data and obtain a copy of that information.
  2. Right to Rectification: Request correction of inaccurate or incomplete personal data.
  3. Right to Erasure (“Right to be Forgotten”): Request under certain circumstances deletion of your personal data.
  4. Right to Restrict Processing: Request that we restrict the processing of your data in certain circumstances.
  5. Right to Data Portability: Receive personal data that you have provided to us in a structured, commonly used and machine-readable format and, ask us to transfer that data  to another controller, where technically feasible.
  6. Right to Object: Object to certain data processing activities, including processing for direct marketing communications.
  7. Right to Withdraw Consent: Withdraw, where processing is based on your consent, that consent at any time. Such withdrawal will not affect the lawfulness of any processing carried out before consent was withdrawn.
  8. Rights Relating to Automated Decision-Making:  Have rights in relation to certain automated decision-making and profiling activities where these produce legal or similarly significant effects. Gene Keys does not currently use personal data for automated decision-making that produces legal or similarly significant effects.
  1. Data Protection Complaints

If you have concerns about how we collect, use, store or otherwise process your personal data, we encourage you to contact us in the first instance using the contact details set out in this Policy.

We will investigate complaints in accordance with our internal procedures and applicable Privacy Laws.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that your personal data has been processed in a manner that does not comply with applicable data protection laws. Further information is available at www.ico.org.uk.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that your personal data has been processed in a manner that does not comply with applicable data protection laws. Further information is available at www.ico.org.uk.

  1. Related Policies

To understand the terms and conditions of using our website and services, please review our Terms of Service.

  1. Links to Other Websites

Our Service may contain links to other websites that are not operated by Gene Keys. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

  1. Policy Updates

We may update this Policy to reflect changes in our data handling practices, services, or legal requirements. Updated versions will be posted on our website, and we encourage you to review this Policy periodically.

Updated on 19th June 2026

Contact Us

For any questions, concerns, or to exercise your GDPR rights, please contact us:

  1. Email: [email protected]

  2. Mail: Gene Keys Ltd, 13 Freeland Park, Wareham Road, Poole, BH16 6FA, United Kingdom

The Gene Keys App – Data Collection and Storage

1. What data we collect, how, and how we use it

When you create an account in the Gene Keys app, we collect:

  1. Email address — entered at sign-up; used for account creation, magic-link authentication, and transactional and lifecycle emails.

  2. Name — entered during profile creation; used to personalize your experience and communications.

  3. Birth data (date, time, and city) — entered during profile creation; required to generate your Gene Keys profile.

  4. Sign-in identifier — if you choose sign in with Apple or sign in with Google, we receive your email and a unique provider ID from that service.

  5. Subscription / purchase data — if you subscribe, your purchase events and a user identifier are processed by our payments provider (RevenueCat together with Apple or Google).

  6. Device identifier and push token — generated on first launch; used for session security and to deliver push notifications.

  7. App engagement events — screens viewed, features used, and notification interactions; collected via our messaging provider (Braze, Inc.) to deliver relevant in-app, push, and email messages.

We do not collect location, contacts, photos, or browsing data, and we do not use advertising software developer kits (SDKs) in the app.

2. Third parties and equal protection

We share user data only with the processors listed below. Each is bound by a Data Processing Agreement requiring them to protect user data to a standard equal to or greater than this Privacy Policy and applicable law (GDPR, UK GDPR, CCPA):

  1. Braze, Inc. — in-app messaging, push notifications, magic-link and transactional emails, and lifecycle communications.

  2. Receives: user ID, email, name, push token, device information, and app engagement events.

  3. RevenueCat, Inc. — subscription management.

  4. Receives: user ID and purchase events.

  5. Apple Inc. — Sign in with Apple and App Store payments.

  6. Receives: data per Apple’s own privacy policy.

  7. Google LLC — Sign in with Google and Google Play payments.

  8. Receives: data per Google’s own privacy policy.

We do not sell user data and do not share data with advertising networks, data brokers, or any parent, subsidiary, or related entity outside the protections above.

3. Retention, deletion, and revoking consent

Retention: We keep your account data (email, name, birth data, generated profile) for as long as your account is active. Billing records are retained for 7 years to meet tax and accounting obligations. After you delete your account, all personally identifying data is purged within 30 days, except where retention is legally required.

Deleting your account: In the app, open Settings → Account → Delete Account. This permanently deletes your account, profile, and birth data within 30 days. You can also email [email protected] for assistance regarding deletion.

Revoking consent: You can disable push and in-app notifications in your device settings, and unsubscribe from marketing emails via the link in any email. To withdraw any other consent, or to exercise your rights under GDPR / UK GDPR / CCPA (access, correction, portability, restriction, deletion, and — for California residents — “Do Not Sell or Share”), please email [email protected]

Triple Flame App – Data Collection and Storage

The Triple Flame app may collect some data for analytics, app testing, crash-logging (henceforth referred to as ‘crashlytics’), and core app functionality. This data is not linked to you, and is anonymously submitted.

Submitted data pertaining to the correct working of the “live counter” feature within the app consists of the following fields:

  • pause start date (ISO GMT)
  • pause end date (ISO GMT)
  • pause length
  • anonymous id (to count unique number of people)
  • pause timezone

Submitted data pertaining to app analytics are anonymous and not linked to you, nor your device. Anonymous data gathering is enabled by default, and can be disabled in the settings of the app. Disabling anonymous data gathering also disables all services related to anonymous data analytics, including the aforementioned “live counter” feature of the app.

Gene Keys gathers anonymous app data to know what resources (like text, videos, audio files) app users listen to and read, allowing Gene Keys to optimize app content, such that it maximises value to the community and purpose of the app. Gathered data is also used to measure conversion rates, user journey mapping, and infrastructure management. In the name of transparency, anonymous app event types are listed which may be gathered during app operation:

  • Pause audio listen
  • Resource view & call-to-action view
  • Schedule setting
  • Privacy setting & privacy policy page visit
  • Chosen notification sound
  • App credit page visit
  • App support page visit
  • Coarse Approximate Location when pausing
The app may gather anonymous coarse approximate location gathering during pausing, if the user has explicitly allowed this in the settings of the app. The coarse approximate location is gathered to empower future feature development, like showcasing pausing people on a globe-like structure, or map, in real-time. Further, coarse approximate location data may be used for analytics purposes.
 
Submitted data pertaining to crashlytics is not linked to you, and is being gathered by a third party provider: Firebase Crashlytics Services. Crashlytics allows Gene Keys to gather device info right as crashes happen, which give insight to the nature of crashes, empowering Gene Keys with adequate insights towards fixing bugs, and building the best possible app for the users. Gene Keys has no insight nor control over how Firebase Crashlytics Services uses gathered device information, and hence the reader is reffered to the privacy policy of Firebase Crashlytics Services. The app provides the capability to disable crashlytics in the settings of the app.
 
Gene Keys’ anonymous data gathering services operate on the basis of randomly generated identifiers, which are not linked to you, nor your device. We have no capability of linking these randomly generated identifiers to you, nor your device. Gene Keys provides the user the option to fully reset the Triple Flame App, which generates new anonymous identifers, which are not contingent on previous versions of the app, nor on previously generated anonymous identifiers.
  •  

This privacy policy sets out how Gene Keys Ltd (herein referred to as ‘Gene Keys’) uses and protects any information that you give Gene Keys when you use this website.

Gene Keys is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.

Gene Keys may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from 1st May 2019.

The Gene Keys App – Data Collection and Storage

1. What data we collect, how, and how we use it

When you create an account in the Gene Keys app, we collect:

  1. Email address — entered at sign-up; used for account creation, magic-link authentication, and transactional and lifecycle emails.

  2. Name — entered during profile creation; used to personalize your experience and communications.

  3. Birth data (date, time, and city) — entered during profile creation; required to generate your Gene Keys profile.

  4. Sign-in identifier — if you choose sign in with Apple or sign in with Google, we receive your email and a unique provider ID from that service.

  5. Subscription / purchase data — if you subscribe, your purchase events and a user identifier are processed by our payments provider (RevenueCat together with Apple or Google).

  6. Device identifier and push token — generated on first launch; used for session security and to deliver push notifications.

  7. App engagement events — screens viewed, features used, and notification interactions; collected via our messaging provider (Braze, Inc.) to deliver relevant in-app, push, and email messages.

We do not collect location, contacts, photos, or browsing data, and we do not use advertising software developer kits (SDKs) in the app.

2. Third parties and equal protection

We share user data only with the processors listed below. Each is bound by a Data Processing Agreement requiring them to protect user data to a standard equal to or greater than this Privacy Policy and applicable law (GDPR, UK GDPR, CCPA):

  1. Braze, Inc. — in-app messaging, push notifications, magic-link and transactional emails, and lifecycle communications.

  2. Receives: user ID, email, name, push token, device information, and app engagement events.

  3. RevenueCat, Inc. — subscription management.

  4. Receives: user ID and purchase events.

  5. Apple Inc. — Sign in with Apple and App Store payments.

  6. Receives: data per Apple’s own privacy policy.

  7. Google LLC — Sign in with Google and Google Play payments.

  8. Receives: data per Google’s own privacy policy.

We do not sell user data and do not share data with advertising networks, data brokers, or any parent, subsidiary, or related entity outside the protections above.

3. Retention, deletion, and revoking consent

Retention: We keep your account data (email, name, birth data, generated profile) for as long as your account is active. Billing records are retained for 7 years to meet tax and accounting obligations. After you delete your account, all personally identifying data is purged within 30 days, except where retention is legally required.

Deleting your account: In the app, open Settings → Account → Delete Account. This permanently deletes your account, profile, and birth data within 30 days. You can also email [email protected] for assistance regarding deletion.

Revoking consent: You can disable push and in-app notifications in your device settings, and unsubscribe from marketing emails via the link in any email. To withdraw any other consent, or to exercise your rights under GDPR / UK GDPR / CCPA (access, correction, portability, restriction, deletion, and — for California residents — “Do Not Sell or Share”), please email [email protected]

Triple Flame App – Data not linked to you

The Triple Flame app may collect some data for analytics, app testing, crash-logging (henceforth referred to as ‘crashlytics’), and core app functionality. This data is not linked to you, and is anonymously submitted.

Submitted data pertaining to the correct working of the “live counter” feature within the app consists of the following fields:

  • pause start date (ISO GMT)
  • pause end date (ISO GMT)
  • pause length
  • anonymous id (to count unique number of people)
  • pause timezone

Submitted data pertaining to app analytics are anonymous and not linked to you, nor your device. Anonymous data gathering is enabled by default, and can be disabled in the settings of the app. Disabling anonymous data gathering also disables all services related to anonymous data analytics, including the aforementioned “live counter” feature of the app.

Gene Keys gathers anonymous app data to know what resources (like text, videos, audio files) app users listen to and read, allowing Gene Keys to optimize app content, such that it maximises value to the community and purpose of the app. Gathered data is also used to measure conversion rates, user journey mapping, and infrastructure management. In the name of transparency, anonymous app event types are listed which may be gathered during app operation:

  • Pause audio listen
  • Resource view & call-to-action view
  • Schedule setting
  • Privacy setting & privacy policy page visit
  • Chosen notification sound
  • App credit page visit
  • App support page visit
  • Coarse Approximate Location when pausing
The app may gather anonymous coarse approximate location gathering during pausing, if the user has explicitly allowed this in the settings of the app. The coarse approximate location is gathered to empower future feature development, like showcasing pausing people on a globe-like structure, or map, in real-time. Further, coarse approximate location data may be used for analytics purposes.
 
Submitted data pertaining to crashlytics is not linked to you, and is being gathered by a third party provider: Firebase Crashlytics Services. Crashlytics allows Gene Keys to gather device info right as crashes happen, which give insight to the nature of crashes, empowering Gene Keys with adequate insights towards fixing bugs, and building the best possible app for the users. Gene Keys has no insight nor control over how Firebase Crashlytics Services uses gathered device information, and hence the reader is reffered to the privacy policy of Firebase Crashlytics Services. The app provides the capability to disable crashlytics in the settings of the app.
 
Gene Keys’ anonymous data gathering services operate on the basis of randomly generated identifiers, which are not linked to you, nor your device. We have no capability of linking these randomly generated identifiers to you, nor your device. Gene Keys provides the user the option to fully reset the Triple Flame App, which generates new anonymous identifers, which are not contingent on previous versions of the app, nor on previously generated anonymous identifiers.

Genekeys.com – Data linked to you

When you subscribe to email lists or purchase a product on our website, we may collect the following information:

    • your name and / or nick-name
    • contact information including email address and mailing address
    • demographic information such as location, postcode / zipcode, preferences and interests
    • other information relevant to customer surveys and/or offers
    • data provided for your hologenetic profile 
    • app usage data logs for improving user experience – this data anonymized and unidentifiable to you as an individual user

  •  

What we do with the information we gather

We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:

    • Internal record keeping.

    • We may use the information to improve our products and services and to customise the website according to your interests.

    • We may periodically send promotional emails (if you have given us your email address or bought a product from us) about new products, special offers or other information which we think you may find interesting using the email address which you have provided.

    • You always have the right to opt-out of receiving these emails.

    • You always have the right to delete your account and request for information from your account to be removed from our records.

Security

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online. 

How we use cookies

A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.

We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.

Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website. We also use cookies to reward affiliates whose link you may have used to get to our website. We offer affiliates a commission of any successful sale of products from our website. This is a way to support our Gene Keys Guides & Network Partners, while also sharing the teachings far and wide. 

Links to other websites

Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question. Where we provide a link to another website or platform that includes a ‘Donate’ button, please note that we are not able to verify the authenticity of the platform nor endorse the recipient. You need to do your own due diligence before you make a decision to donate.

Controlling your personal information

You may choose to restrict the collection or use of your personal information in the following ways:

    • when using the Hologenetic Profile, you do not have to put in your real name. You can use a made-up name or nick-name. 

    • if you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to or emailing us at [email protected]

    • We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting if you tell us that you wish this to happen.

    • You may request details of personal information which we hold about you under the Data Protection Act 1998. A small fee will be payable. If you would like a copy of the information held on you please write to Gene Keys Ltd, 13 Freeland Park, Wareham Road, Poole, BH16 6FA, UK.

    • If you believe that any information we are holding on you is incorrect or incomplete, please write to or email us as soon as possible at [email protected]. We will promptly correct any information found to be incorrect.

GDPR Website Policy

Gene Keys Ltd (“we,” “us,” “our”) is committed to protecting your personal data and respecting your privacy. This policy explains how we adhere to the General Data Protection Regulation (GDPR) and related standards, including ISO 27001:2013 and PCI DSS, to safeguard the personal data of individuals visiting or using our website. It complements our Privacy Policy and outlines our practices regarding data collection, processing, security, and user rights.

Applicability

This GDPR Website Policy applies to all individuals residing in the European Union (EU) and the United Kingdom (UK) who interact with our website, regardless of their nationality or location.

Data Protection Principles

We adhere to the following data protection principles:

  1. Lawfulness, Fairness, and Transparency: Processing data lawfully, fairly, and in a transparent manner.

  2. Purpose Limitation: Collecting data for specified, explicit, and legitimate purposes.

  3. Data Minimization: Ensuring data is adequate, relevant, and limited to what is necessary.

  4. Accuracy: Keeping personal data accurate and up to date.

  5. Storage Limitation: Retaining data only for as long as necessary.

  6. Integrity and Confidentiality: Protecting data against unauthorized access, loss, or damage.

  7. Accountability: Being responsible for and able to demonstrate compliance with these principles.

Data Collection and Purposes

We collect only the personal data that is necessary to provide you with our products and services, process your orders, and ensure a smooth user experience. Specifically, we may collect the following personal data when you interact with our website or place an order:

  1. Identification and Contact Details: Such as your name, email address, dob, laction, billing address, and shipping address. These details are essential for processing orders, delivering products, providing customer support, and communicating updates about your purchase.

  2. Payment Information: Such as credit/debit card details or other payment method information, processed securely to complete your transactions and fulfill your orders.

Legal Bases for Processing

Under GDPR, we rely on the following lawful bases for processing your personal data:

  1. Contractual Necessity (Article 6(1)(b)):

  2. Identification and Contact Details: Processed to fulfill orders, provide customer support, and communicate updates.

  3. Payment Information: Processed to complete transactions securely under PCI DSS Compliance.

  4. Legal Obligations (Article 6(1)(c)):

  5. Order-Related Data: Retained for up to seven years to meet tax and accounting requirements.

  6. Consent (Article 6(1)(a)):

  7. Marketing Communications: Processed when you explicitly opt-in to receive marketing emails or newsletters. You can withdraw this consent at any time by contacting us at [email protected].

Third-Party Data Sharing and Transfers

We may share your personal data with trusted third-party service providers who assist us in operating our website, conducting our business, or providing services to you. These third parties are obligated to protect your data and are restricted from using it for any other purposes.

International Data Transfers

All personal data is stored and processed within the United Kingdom. We do not transfer your personal data to countries outside the UK. If any future data transfers occur, we will ensure appropriate safeguards are in place in compliance with GDPR.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience, analyze site usage, and provide personalized content. Cookies may be essential for website functionality or used for analytics and marketing purposes.

You can manage your cookie preferences through your browser settings. For more detailed information, please refer to our Cookie Policy.

Anonymized Analytics and Site Usage Data

We may collect anonymized usage data from our website to help us understand how users interact with our site, improve our services, and enhance the user experience. This anonymized data cannot identify you personally and therefore does not fall under the scope of GDPR. No personal data is used for analytics purposes, and no data subject rights are impacted by these purely anonymized metrics.

Data Minimization and Accuracy

We adhere to GDPR’s principles of data minimization and accuracy. This means we:

  1. Collect only the personal data we need to fulfill your order, comply with legal obligations, or send you marketing communications if you have consented.

  2. Keep your personal data as accurate and up-to-date as possible.

  3. Offer you the opportunity to correct or update your information at any time by contacting us.

Data Retention

We retain personal data only as long as is necessary to fulfill your order, meet our legal obligations, or provide requested services. For example, we may keep order-related data for up to seven years to meet tax and accounting requirements. When your personal data is no longer needed for these purposes, we securely delete or anonymize it.

Data Security Measures

We take data security seriously and implement technical and organizational measures to protect your personal data from unauthorized access, misuse, alteration, or loss. These measures include, but are not limited to:

  1. Encryption: Encryption of sensitive data, such as payment information, during transmission.

  2. Access Controls: Ensuring that only authorized personnel can access personal data.

  3. Regular Security Audits and Testing: Identifying and addressing potential vulnerabilities.

  4. ISO 27001:2013 Alignment: Ensuring our information security management system follows internationally recognized best practices.

  5. PCI DSS Compliance: Secure handling of payment card information.

All personal data is stored on secure servers located in the UK. We do not transfer personal data internationally. In the event of a data breach affecting personal data, we will notify the appropriate supervisory authority and any affected individuals in accordance with GDPR requirements.

Data Breach Notification Procedures

In the event of a data breach affecting personal data, we will:

  1. Assess the Breach: Determine the nature and scope of the breach.

  2. Contain the Breach: Implement measures to prevent further unauthorized access.

  3. Notify Authorities: Inform the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach.

  4. Inform Affected Individuals: Communicate with individuals affected by the breach without undue delay if the breach is likely to result in a high risk to their rights and freedoms.

  5. Review and Improve: Analyze the breach to prevent future incidents and update security measures accordingly.

Your GDPR Rights

Under GDPR, you have several rights regarding your personal data. You may:

  1. Right of Access: Request information about whether we hold personal data about you and obtain a copy of that data.

  2. Right to Rectification: Ask us to correct inaccurate or incomplete personal data.

  3. Right to Erasure (“Right to be Forgotten”): Under certain conditions, request the deletion of your personal data.

  4. Right to Restrict Processing: Request that we limit how we process your data in specific circumstances.

  5. Right to Data Portability: Receive your personal data in a machine-readable format and ask us to transfer it to another controller, where feasible.

  6. Right to Object: Object to specific data processing activities, including receiving direct marketing communications.

Exercising Your GDPR Rights

To exercise any of your GDPR rights, follow the steps listed below. We will acknowledge receipt of your request within five business days and respond within one month to confirm the actions taken or provide further information. If you have any difficulties or additional questions, please contact us at [email protected].

Requesting Data Export:

  1. Log in to Your Account: Visit our website and log in using your registered credentials.

  2. Navigate to Account Settings: Go to Account Settings > Export Data to download a copy of your personal data.

Requesting Data Deletion:

  1. Contact Customer Service: Send an email to [email protected] with the subject line “Data Deletion Request.”

  2. Confirmation Process: Once we receive your request, we will send a confirmation email to your registered email address. You must confirm your request to proceed with the data deletion process.

Marketing Communications

We will only send marketing emails or newsletters if you have explicitly agreed to receive them. You can unsubscribe at any time by using the “unsubscribe” link in the email or by contacting us at [email protected]. Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.

Obtaining and Managing Consent

When you opt-in to receive marketing communications, you do so through clear and affirmative actions, such as checking an opt-in box. We record your consent and provide options to manage your preferences at any time. To withdraw consent, you can use the “unsubscribe” link in our emails or contact us directly at [email protected]. Upon withdrawal, we will cease processing your data for marketing purposes promptly.

No Legitimate Interests or Automated Decision-Making

We do not rely on “legitimate interests” as a separate lawful basis for processing your personal data. Additionally, we do not engage in automated decision-making or profiling that would produce significant legal effects for you.

Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that affects your legal rights or significantly impacts you. Our data processing activities for analytics are limited to improving user experience and do not involve profiling individuals.

Anonymized Analytics and Site Usage Data

We may collect anonymized usage data from our website to help us understand how users interact with our site, improve our services, and enhance the user experience. This anonymized data cannot identify you personally and therefore does not fall under the scope of GDPR. No personal data is used for analytics purposes, and no data subject rights are impacted by these purely anonymized metrics.

Children’s Privacy

Our website is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data without parental consent, we will take steps to delete such information promptly.

Accountability and Governance

We maintain records of our data processing activities, perform regular staff training at least annually, and conduct Data Protection Impact Assessments (DPIAs) where necessary. Our training programs cover data protection principles, handling personal data securely, and recognizing potential data breaches. By doing so, we demonstrate accountability and uphold the principles of GDPR, ISO 27001:2013, and PCI DSS. If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK: www.ico.org.uk.

Breach Documentation and Response

We have established documented procedures for responding to data breaches, including roles and responsibilities for our staff. These procedures ensure a swift and effective response to any incidents, minimizing potential harm and ensuring compliance with GDPR requirements.

Related Policies

For more information on how we handle cookies and other tracking technologies, please refer to our Cookie Policy above. To understand the terms and conditions of using our website and services, please review our Terms of Service.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Gene Keys. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Policy Updates

We may update this policy to reflect changes in our data handling practices, services, or legal requirements. Updated versions will be posted on our website, and we encourage you to review this policy periodically.

Contact Us

For any questions, concerns, or to exercise your GDPR rights, please contact us:

  1. Email: [email protected]

  2. Mail: Gene Keys Ltd, 13 Freeland Park, Wareham Road, Poole, BH16 6FA, United Kingdom

Write a Testimonial

Testimonial