Helisoma

Legal

Privacy Policy

Effective date: [EFFECTIVE_DATE] · Last updated: [EFFECTIVE_DATE]

This document processes genetic data, which is a special category of personal data under Article 9 of the EU GDPR and UK GDPR. It is provided as a starting draft and must be reviewed by a qualified data-protection lawyer, with every [PLACEHOLDER] replaced, before you rely on it.

1. Who we are

This Privacy Policy explains how [COMPANY_LEGAL_NAME] (“Helisoma”, “we”, “us”), the data controller, collects and uses your personal data when you use the Helisoma website and application (the “Service”).

Controller: [COMPANY_LEGAL_NAME], [REGISTERED_ADDRESS]. Contact: hello@helisoma.com. Data protection contact: [DPO_OR_PRIVACY_CONTACT].

2. The data we collect

3. How we use your data and our legal bases

Under the GDPR we rely on the following legal bases:

4. Connecting AI assistants (Claude, ChatGPT, Gemini)

Helisoma lets you connect AI assistants to your account so they can read your genome report and answer your questions. When you authorize such a connection, the third-party AI platform you choose (for example Anthropic’s Claude, OpenAI’s ChatGPT, or Google’s Gemini) receives your genome report data at your direction and processes it under its own privacy policy and terms, as an independent controller. We do not control how those platforms use data once it reaches them. You can revoke a connection at any time from your account settings.

5. Who we share data with

We do not sell your personal data. We share it only with:

A current list of processors is available on request at hello@helisoma.com.

6. Cookies and analytics

We use strictly necessary cookies to run the Service (e.g. your login session); these do not require consent. We also use Google Analytics 4 to understand how the Service is used. Analytics and any other non-essential cookies load only after you accept them in our cookie banner. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer.

7. International transfers

Some providers (such as Google Analytics) may process data outside the European Economic Area / United Kingdom, including in the United States. Where this happens, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

8. How long we keep your data

We keep your account and genetic data for as long as your account is active. If you delete your genetic data or your account, we delete the raw file, derived markers, and generated reports within [RETENTION_PERIOD, e.g. 30 days], except where we must retain limited records to meet legal obligations.

9. Your rights

Under the EU GDPR and UK GDPR you have the right to:

To exercise any right, email hello@helisoma.com. You can delete your genetic data and account yourself at any time in the app’s account settings.

10. Security

We use technical and organizational measures to protect your data, including encryption in transit, hashed passwords, and access controls. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authority of any breach as required by law.

11. Children

The Service is not directed to, and may not be used by, anyone under [MINIMUM_AGE, e.g. 18]. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy. We will post the new version here and update the “Last updated” date, and for material changes we will notify you by email or in the app.

13. Contact

Questions about this policy or your data? Email hello@helisoma.com.