Index
GDPR Website Policy
1. Introduction
Gene Keys Ltd (“we”, “us”, “our”) is committed to protecting personal data and respecting the privacy rights of individuals who visit our website, use our services, or otherwise interact with us. This Policy explains how we comply with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and, where applicable, the EU General Data Protection Regulation (EU GDPR) (together referred to in this Policy as “Privacy Laws“).
All references to “GDPR” in this Policy refer to the UK GDPR, and where applicable, the EU GDPR. We maintain appropriate technical and organisational measures to protect personal data, including information security controls aligned with recognised industry standards. Gene Keys maintains appropriate policies, procedures and records to designed to support compliance with applicable Privacy Laws. This Policy explains our approach to the collection, use, storage, security, retention, transfer and protection of personal data, as well as the rights available to individuals under applicable data protection laws.
2. Applicability
This Policy applies to all individuals whose personal data is collected, used or otherwise processed by Gene Keys in connection with our website, products, services and related activities.
3. Data Protection Principles
We process personal data in accordance with the following principles:
1. Lawfulness, Fairness and Transparency: We process personal data lawfully, fairly and in a transparent manner.
2. Purpose Limitation: We collect personal data only for specified, explicit and legitimate purposes.
3. Data Minimisation: We limit the personal data we collect to what is relevant and necessary for those purposes.
4. Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date.
5. Storage Limitation: We retain personal data only for as long as necessary for the purposes for which it was collected and to comply with applicable legal and regulatory requirements.
6. Integrity and Confidentiality: We implement appropriate security measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage.
7. Accountability: We are responsible for, and able to demonstrate, compliance with applicable data protection laws and these principles.
8. Data Subject Rights: We respect and facilitate the exercise of individuals’ rights under applicable data protection laws, including rights relating to access, correction, deletion, restriction, objection and complaints.
9. Responsible Use of Technology: We seek to ensure that any use of automated technologies is consistent with applicable data protection laws, transparency requirements and our commitment to the responsible handling of personal data.
4. Data Collection and Puposes
We collect only the personal data that is reasonably necessary to provide our products and services, process transactions, administer user accounts, respond to enquiries, and support the operation and security of our website and services. The categories of personal data we may collect for the purposes described in this Policy include:
1. Identification and Contact Information: Such as your name, email address, billing address, shipping address (where applicable), and any information you choose to provide when creating an account, making an enquiry, requesting support, subscribing, or purchasing products and services.
2. Birth and Profile Information: Where required to generate a Gene Keys Profile or related services, this may include your date of birth, time of birth, place of birth and other information voluntarily provided by you for the purpose of generating personalised profile outputs.
3. Payment Information: Such as payment card or other payment method information required to process transactions. Payment information is processed securely through approved payment service providers and is not stored by Gene Keys except as necessary to maintain transaction records.
4. Technical and Usage Information: Such as IP address, device and browser information, website usage information, log data, and other technical information generated through your use of our website or services. This information is used for security, service operation, diagnostics, performance monitoring and service improvement. We
5. Legal Basis for Processing
We process personal data only where we have a lawful basis to do so under applicable data protection laws. The lawful bases on which we rely under Article 6 UK GDPR include:
Performance of a Contract (Article 6(1)(b) UK GDPR): We process personal data where necessary to provide our products and services, create and manage user accounts, generate Gene Keys Profiles and related outputs, process orders and payments, provide customer support, and otherwise fulfill our contractual obligations.
Legal Obligations (Article 6(1)(c) UK GDPR):
We process and retain certain data where necessary to comply with legal, regulatory, tax, accounting, reporting and record-keeping obligations.
Legitimate Interests (Article 6(1)(f) UK GDPR):
We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the rights and freedoms of individuals. This may include maintaining the security of our systems, preventing fraud, responding to enquiries, improving our services, and administering our business operations.
Consent (Article 6(1)(a) UK GDPR):
Where required by law, we rely on consent to process personal data, including for marketing communications and certain cookies or analytics technologies.
Marketing communications are sent only to individuals who have subscribed or otherwise consented to receive them. We use a double-opt in process for email subscribers and individuals may withdraw consent at any time by contacting support@genekeys.com or by clicking the “unsubscribe” link in the email. Where consent is withdrawn, will not affect the lawfulness of any processing carried out prior to withdraw.
- Children’s Privacy
Our website, products and services are not intended for use by children under the age of 16. We do not knowingly collect personal data from children under the age of 16. If we become aware that a child under the age of 16 has provided us with personal data without appropriate parental consent or other lawful basis where required by applicable law, we will take reasonable steps to delete that information promptly.
- Retention of Personal Data
We retain personal data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, provide requested services, comply with legal, regulatory, accounting and reporting obligations, resolve disputes, and enforce our agreements.
For example, we may retain order-related, contractual and transaction records for up to seven (7) years following the end of the relevant customer relationship or transaction in order to comply with legal, tax, accounting, audit and record-keeping requirements, establish or defend legal claims, and resolve disputes.
When personal data is no longer required for these purposes, we securely delete, anonymise or otherwise dispose of it in accordance with our retention practices.
Marketing subscription data is retained until an individual unsubscribes or requests deletion, unless a longer retention period is required by law.
- Data Minimisation and Accuracy
We adhere to the principles of data minimisation and accuracy under GDPR. This means that we:
- Collect only the personal data that is reasonably necessary to provide our products and services, generate Gene Keys Profiles and related outputs, administer user accounts, respond to enquiries, comply with legal obligations, and send marketing communications where you have provided your consent.
- Take reasonable steps to ensure that personal data is accurate, complete and kept up to date.
- Provide individuals with the opportunity to access, correct, update or request deletion of their personal data by contacting us.
- Analytics and Site Usage Data
We collect limited website and application usage information to understand site performance, identify technical issues, maintain security, improve functionality and enhance the user experience.
For website visitors, we use Google Analytics to collect information about website usage, including page visits, session activity, device and browser information, and general usage patterns. This information is used to generate aggregated statistical reports and to help us improve our website and services.
Gene Keys does not use website analytics information for targeted advertising, marketing profiling or customer segmentation.
Where personal data is provided directly by a user, such as when creating an account, making an enquiry or subscribing to communications, that information may be associated with the relevant user account and used to provide the requested services.
For customers using our applications and services, limited technical and operational information may be processed to support service delivery, security, troubleshooting, maintenance and product improvement. This information is not used for automated decision-making, behavioural profiling or marketing purposes.
The Gene Keys Profile and related outputs are generated using information provided by the user as part of the requested service. These outputs are not used for marketing profiling, customer segmentation or automated decision-making.
Where analytics or technical identifiers are used, they are used solely for operational, security and analytical purposes and not to identify individuals or build behavioural profiles.
Where cookies or similar technologies are used for analytics, they are used in accordance with our Cookie Policy and, where required, your cookie preferences.
- Cookies and Tracking Technologies
We use cookies and similar technologies to operate our website, improve functionality, understand how our services are used, and enhance the user experience.
Some cookies are necessary for the operation of the website and cannot be disabled. Other cookies are used for analytics purposes to help us understand website performance, identify technical issues, and improve our services.
We use Google Analytics to collect information about how visitors use our website. Google Analytics uses cookies and similar technologies to collect information such as pages visited, time spent on the site, device and browser information, and general usage patterns. This information is used in aggregated and statistical form to help us improve our website and services.
Analytics information is not used by Gene Keys for behavioural profiling, targeted advertising, or marketing segmentation of website visitors.
Where required by law, visitors are provided with a cookie consent mechanism that allows them to manage their cookie preferences. You can also manage cookies through your browser settings. Further information is available in our Cookie Policy.
Marketing communications are sent only to individuals who have provided their consent or where otherwise permitted by applicable law. We use a double opt-in process for email subscriptions, requiring subscribers to confirm their subscription via an email verification link. Individuals may unsubscribe from marketing communications at any time using the unsubscribe link included in our emails or by contacting us directly.
For users of our applications and services, we may collect limited technical and operational information to maintain, secure, troubleshoot, and improve the performance of our services. This information is not used for automated decision-making, behavioural profiling, or targeted advertising.
- Automated Decision-Making and Profiling
Gene Keys does not engage in automated decision-making that produces legal or similarly significant effects on individuals.
Gene Keys Profiles and related outputs are generated using information provided by users as part of the requested service. These outputs are not used for automated decision-making, marketing profiling, customer segmentation or behavioural profiling, or the generation of inferred characteristics for marketing or commercial purposes.
- Artificial Intelligence
Gene Keys does not currently use third-party artificial intelligence providers to process personal data or user-generated content, nor does it use such data to train artificial intelligence models.
Should our use of artificial intelligence technologies change in the future, we will review and update our privacy and data protection disclosures accordingly. Please refer to our AI Policy for further information.
- Third-Party Data Sharing and Transfers
We may share personal data with carefully selected third-party service providers who support the operation of our website, products and services, including hosting providers, payment processors, customer communication platforms, analytics providers and customer support services.
These service providers process personal data only on our instructions, are contractually required to maintain appropriate security and confidentiality measures, and may not use personal data for their own purposes except where permitted by law.
Some of our service providers may process personal data outside the United Kingdom or European Economic Area. Where international transfers occur, we take appropriate steps to ensure that personal data remains protected in accordance with applicable data protection laws, including the use of recognised transfer mechanisms and contractual safeguards where required.
- International Data Transfers
Our primary application infrastructure is hosted using Amazon Web Services (AWS).
We use carefully selected third-party service providers to support the delivery of our products and services, including customer communication and engagement platforms, email delivery services, payment processors, analytics providers and customer support tools. This includes Braze, a customer engagement and communications platform, which we use to support customer communications and engagement.
These providers may process personal data in the United Kingdom, the European Economic Area, the United States and other jurisdictions in which they operate.
Where personal data is transferred outside the United Kingdom or European Economic Area, we implement appropriate safeguards in accordance with applicable data protection laws. Such safeguards may include adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other legally recognised transfer mechanisms.
We select service providers that maintain appropriate technical and organisational measures to protect personal data and require them to process personal data in accordance with applicable data protection laws.
Further information regarding our service providers and international data transfers is available on request.
- Data Security Measures
We take data security seriously and implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration or disclosure.
These measures include, where appropriate:
- Encryption: the use of encryption and secure transmission technologies to protect personal data and payment-related information.
- Access Controls: restricting access to personal data to authorised personnel and service providers who require access for legitimate business purposes.
- Security Monitoring and Testing: maintaining security procedures, monitoring systems and undertaking periodic testing and reviews to identify and address potential vulnerabilities.
- Information Security Controls: implementing information security practices aligned with recognised industry standards and security frameworks.
- Payment Security: using approved payment service providers and secure payment processing measures designed to protect payment information.
Personal data may be stored and processed by Gene Keys and its approved service providers in accordance with this Policy and applicable data protection laws.
Although no method of transmission over the internet or electronic storage can be guaranteed to be completely secure, we take reasonable steps to protect personal data and to maintain appropriate security safeguards.
In the event of a personal data breach, we will respond in accordance with applicable legal requirements, including notification to relevant supervisory authorities and affected individuals where required by law.
- Data Breach Notification Procedures
In the event of a personal data breach we will:
- Assess the Breach: Determine the nature, scope and potential impact of the incident.
- Contain and Mitigate: Take appropriate steps to contain the breach, prevent further unauthorised access, and minimise any adverse effects.
- Notify Relevant Authorities: Where required by law, notify the Information Commissioner’s Office (ICO) without undue delay and, where applicable, within 72 hours of becoming aware of the breach.
- Inform Affected Individuals: Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
- Review and Improve: Investigate the cause of the incident, implement corrective measures, and review our policies, procedures and security controls to reduce the risk of recurrence.
- Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data. You may:
- Right of Access: Request confirmation of whether we process your personal data and obtain a copy of that information.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): Request under certain circumstances deletion of your personal data.
- Right to Restrict Processing: Request that we restrict the processing of your data in certain circumstances.
- Right to Data Portability: Receive personal data that you have provided to us in a structured, commonly used and machine-readable format and, ask us to transfer that data to another controller, where technically feasible.
- Right to Object: Object to certain data processing activities, including processing for direct marketing communications.
- Right to Withdraw Consent: Withdraw, where processing is based on your consent, that consent at any time. Such withdrawal will not affect the lawfulness of any processing carried out before consent was withdrawn.
- Rights Relating to Automated Decision-Making: Have rights in relation to certain automated decision-making and profiling activities where these produce legal or similarly significant effects. Gene Keys does not currently use personal data for automated decision-making that produces legal or similarly significant effects.
- Data Protection Complaints
If you have concerns about how we collect, use, store or otherwise process your personal data, we encourage you to contact us in the first instance using the contact details set out in this Policy.
We will investigate complaints in accordance with our internal procedures and applicable Privacy Laws.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that your personal data has been processed in a manner that does not comply with applicable data protection laws. Further information is available at www.ico.org.uk.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that your personal data has been processed in a manner that does not comply with applicable data protection laws. Further information is available at www.ico.org.uk.
- Related Policies
To understand the terms and conditions of using our website and services, please review our Terms of Service.
- Links to Other Websites
Our Service may contain links to other websites that are not operated by Gene Keys. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
- Policy Updates
We may update this Policy to reflect changes in our data handling practices, services, or legal requirements. Updated versions will be posted on our website, and we encourage you to review this Policy periodically.
Updated on 19th June 2026
Contact Us
For any questions, concerns, or to exercise your GDPR rights, please contact us:
-
Email: support@genekeys.com
-
Mail: Gene Keys Ltd, 13 Freeland Park, Wareham Road, Poole, BH16 6FA, United Kingdom
The Gene Keys App – Data Collection and Storage
1. What data we collect, how, and how we use it
When you create an account in the Gene Keys app, we collect:
-
Email address — entered at sign-up; used for account creation, magic-link authentication, and transactional and lifecycle emails.
-
Name — entered during profile creation; used to personalize your experience and communications.
-
Birth data (date, time, and city) — entered during profile creation; required to generate your Gene Keys profile.
-
Sign-in identifier — if you choose sign in with Apple or sign in with Google, we receive your email and a unique provider ID from that service.
-
Subscription / purchase data — if you subscribe, your purchase events and a user identifier are processed by our payments provider (RevenueCat together with Apple or Google).
-
Device identifier and push token — generated on first launch; used for session security and to deliver push notifications.
-
App engagement events — screens viewed, features used, and notification interactions; collected via analytics tracking (AppsFlyer) and our messaging provider (Braze, Inc.) to deliver relevant in-app, push, and email messages.
We do not collect location, contacts, photos, or browsing data, and we do not use advertising software developer kits (SDKs) in the app.
2. Third parties and equal protection
We share user data only with the processors listed below. Each is bound by a Data Processing Agreement requiring them to protect user data to a standard equal to or greater than this Privacy Policy and applicable law (GDPR, UK GDPR, CCPA):
- Braze, Inc. — in-app messaging, push notifications, magic-link and transactional emails, and lifecycle communications.
- Receives: user ID, email, name, push token, device information, and app engagement events.
- RevenueCat, Inc. — subscription management.
- Receives: user ID and purchase events.
- Apple Inc. — Sign in with Apple and App Store payments.
- Receives: data per Apple’s own privacy policy.
- Google LLC — Sign in with Google and Google Play payments.
- Receives: data per Google’s own privacy policy.
- AppsFlyer LTD – Analytics
- Receives: data ber AppsFlyer’s own privacy policy
We do not sell user data and do not share data with advertising networks, data brokers, or any parent, subsidiary, or related entity outside the protections above.
3. Retention, deletion, and revoking consent
Retention: We keep your account data (email, name, birth data, generated profile) for as long as your account is active. Billing records are retained for 7 years to meet tax and accounting obligations. After you delete your account, all personally identifying data is purged within 30 days, except where retention is legally required.
Deleting your account: In the app, open Settings → Account → Delete Account. This permanently deletes your account, profile, and birth data within 30 days. You can also email support@genekeys.com for assistance regarding deletion.
Revoking consent: You can disable push and in-app notifications in your device settings, and unsubscribe from marketing emails via the link in any email. To withdraw any other consent, or to exercise your rights under GDPR / UK GDPR / CCPA (access, correction, portability, restriction, deletion, and — for California residents — “Do Not Sell or Share”), please email support@genekeys.com.
Triple Flame App – Data Collection and Storage
The Triple Flame app may collect some data for analytics, app testing, crash-logging (henceforth referred to as ‘crashlytics’), and core app functionality. This data is not linked to you, and is anonymously submitted.
Submitted data pertaining to the correct working of the “live counter” feature within the app consists of the following fields:
- pause start date (ISO GMT)
- pause end date (ISO GMT)
- pause length
- anonymous id (to count unique number of people)
- pause timezone
Submitted data pertaining to app analytics are anonymous and not linked to you, nor your device. Anonymous data gathering is enabled by default, and can be disabled in the settings of the app. Disabling anonymous data gathering also disables all services related to anonymous data analytics, including the aforementioned “live counter” feature of the app.
Gene Keys gathers anonymous app data to know what resources (like text, videos, audio files) app users listen to and read, allowing Gene Keys to optimize app content, such that it maximises value to the community and purpose of the app. Gathered data is also used to measure conversion rates, user journey mapping, and infrastructure management. In the name of transparency, anonymous app event types are listed which may be gathered during app operation:
- Pause audio listen
- Resource view & call-to-action view
- Schedule setting
- Privacy setting & privacy policy page visit
- Chosen notification sound
- App credit page visit
- App support page visit
- Coarse Approximate Location when pausing