Privacy Notice
1. Data controller
Aimosti Oy (Business ID 3630145-4, VAT number FI36301454)
Ristikkotie 16, 90420 Oulu, Finland
2. Contact person for the register
Raine Laurila, [email protected].
3. Purposes and legal bases
- Producing your report from the genomic file you upload: contract (GDPR Art. 6(1)(b)) and explicit consent for special-category data (Art. 9(2)(a)).
- Interpretation and findings: covered by that same explicit processing consent (Art. 9(2)(a)). It authorises interpretation across every report module (clinical findings, carrier status, pharmacogenomics, traits, ancestry, risk factors and the exploratory readings), including sensitive, predictive findings such as APOE, which stay hidden behind a deliberate in-report reveal you control.
- Payments and accounting: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Account: contract (Art. 6(1)(b)).
- Marketing email: consent (Art. 6(1)(a)), withdrawable at any time.
- Service improvement and research using de-identified data: consent (Art. 6(1)(a)).
- Security, logging, fraud and abuse prevention: legitimate interest (Art. 6(1)(f)).
4. Categories of personal data
- Identity: email, password hash (argon2id) or Google sign-in identifier, locale, timestamps.
- Genetic raw data (special category, Art. 9): your uploaded variant file (VCF/gVCF) and, for the Deep Read add-on, an aligned-reads file (BAM/CRAM). Uploaded directly to EU object storage (Helsinki, Finland).
- Normalised variant file: a small, panel-restricted file derived from your upload, retained only while you hold an active re-analysis subscription (so we can re-run the analysis as the science updates); otherwise it is purged after your report is produced.
- Derived health-related findings (Art. 9): clinical findings, carrier status, pharmacogenomics, traits, ancestry and coverage. Stored as a frozen snapshot in your report.
- Consent audit trail: an append-only (immutable) history of every grant and withdrawal, including the consent group, the consent-text version, IP address, user-agent and timestamp.
- Payment metadata: user/analysis reference, SKU, payment rail, transaction id, status and paid-at time. Card and billing data are held by our payment processor, not Aimosti.
- Session: a signed
aimosti_sessioncookie containing only your user identifier. - Aggregate, cookieless analytics (see section 14).
5. Sources of data
Data comes from you (uploads and forms), from Google sign-in (if you use it), and from our payment processor as payment confirmation.
When you upload, you confirm you are 18 or older and that the data is your own or data you are legally authorised to process (see our Terms).
Checking your file before you pay. When you use “See what your DNA unlocks,” your browser sends only the first part of your file: its header, not your genome. We read it in memory to detect the file type, reference build and the report it supports, then discard it: the header is never written to storage, never logged with your data, and no account record is created from it. Your genome itself is only ever uploaded after you choose to buy a report.
6. Recipients and processors
We use the following processors, each under a data-processing agreement (DPA):
- Hetzner: hosting and object storage, Finland (genetic and health data).
- Cloudflare: CDN, WAF, access control, and cookieless web analytics.
- Google: sign-in (OAuth).
- Stripe: card payment processing and tax calculation (we remain the seller and remit the tax ourselves). Receives your card, billing and transaction data, including billing country to calculate the applicable VAT; we never see your full card details. No genetic or health data is ever shared with Stripe.
- Zoho ZeptoMail: transactional email, EU.
- Bunny Fonts: EU-based font delivery, no cookies.
We never sell your personal data and never use your genetic data to train any model.
7. Transfers outside the EU/EEA
Genetic and health-related data is processed and stored in Finland and does not leave the EU. Some providers (Google, Cloudflare, Stripe) are US-parented; any transfers of the limited data they process rely on the EU Standard Contractual Clauses (SCCs) or a valid adequacy decision. As a general rule, your genetic data remains within the EU and is never shared with any of them.
8. Retention periods
- Genetic raw data (VCF/gVCF): deleted after analysis, by default within about 7 days.
- Aligned reads (BAM/CRAM): deleted immediately after the coverage computation, on success or failure.
- Normalised variant file: kept while you hold an active re-analysis subscription — this is what lets us re-run your analysis when sources update. Without a subscription it is purged within about 30 days of your analysis; if you cancel, it is deleted once your paid period ends. Cancelling the subscription is how you end this retention.
- Findings and report snapshot: kept for the life of your account. Even if a re-analysis subscription lapses, we keep your last snapshot: only new updates stop, and your report stays yours. You can request deletion at any time, or delete your account, which erases your data with it.
- Consent audit trail: retained as evidence of compliance.
- Payment and accounting data: retained for the period required by Finnish accounting law (approx. 6 years) even after an erasure request (GDPR Art. 17(3)(b)).
- Account deletion: when you delete your account we erase your genome data, reports, uploaded files, and direct identifiers; we retain a de-identified record of your orders and consents (no genetic data) to defend payment disputes (GDPR Art. 17(3)(e)) and to meet the accounting-retention rules above.
9. Your rights
You have the right to access your data, rectify inaccuracies, request erasure, restrict or object to processing, data portability, and to withdraw consent (withdrawal does not affect the lawfulness of processing before it). You can manage and withdraw your consents in the in-app consent view. Other rights are exercised by emailing [email protected].
10. Right to lodge a complaint
If you have any concern about how we handle your data, please contact us first at [email protected]: we want to put it right. You also retain the statutory right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
11. Automated decision-making and profiling
Automated genomic analysis produces information in the form of attributed literature matches. It is not an automated decision under GDPR Art. 22 producing legal or similarly significant effects on you.
12. Whether providing data is mandatory
Uploading a genome file is necessary to receive a report. If you do not provide it, the service cannot be delivered.
13. Security
Data is encrypted in transit, processed and stored in the EU, access-controlled, and can be deleted on request.
14. Cookies
We use an essential aimosti_session cookie and Cloudflare's cookieless
web analytics (aggregate, no personal data). Optional advertising cookies
are used only with your consent — see our Cookies & consent page, where
you can review or change your choice at any time.
15. Advertising measurement
To measure and improve our advertising we use, with your consent (Art. 6(1)(a) GDPR), a client pixel and a server-to-server conversions API from our advertising partner Reddit (an independent controller for this purpose; see our Cookies & consent page for our current advertising partners). We share a Reddit click identifier, your IP address and user-agent, and the fact that a page view, registration, or purchase occurred — for a purchase, its value and currency only. We never share your email content, your genome, any health data, or the product you bought. You can withdraw consent at any time via Cookies & consent.
Separately, and regardless of your advertising choice, we record in our own systems which campaign or link referred you to us, to measure the effectiveness of our marketing. This first-party record is not shared with any third party; its legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
16. Updates
We will notify you of material changes to this notice. Last updated: 11 Jul 2026.