GenePlanet places particular emphasis on the security of your personal information. All transmitted personal data is handled confidentially and is used only for the legitimate purpose for which it was transmitted. We handle your personal data with utmost care, bearing in mind the applicable legislation and the highest standards of processing. In order to protect your personal data as effectively as possible, we use appropriate organizational measures, work procedures and advanced technology solutions, as well as external experts. We also use an appropriate level of protection and reasonable physical, electronic and administrative measures to protect the collected data from unintentional or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access to personal data that has been downloaded, stored or otherwise processed.
The General Data Protection Regulation (EU) 2016/679 ("GDPR") is a regulation in EU law on data protection and privacy for all individuals citizens of the European Union (EU) and the European Economic Area (EEA). It also addresses the export of personal data outside the EU and EEA areas. The GDPR aims primarily to give control to individuals over their personal data collection, storage and processing.
Any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
The following personal data is considered ‘sensitive’ and is subject to specific processing conditions:
If you are only a visitor to a website, we only collect your data using cookies. If you are a service user or a subscriber to a service provided by GenePlanet, we also collect other personal information that we need to provide the services you use or are subscribed to. This data is:
The Website provides direct to customer services only to persons who are legally competent to enter into a valid contract or have a written signature of a parent/legal guardian or as otherwise provided by the rules of a member state or other Applicable Law.
In the context of the execution of contractual rights and the fulfilment of contractual obligations, GenePlanet processes your personal information for the following purposes:
When calculating the services, based on the tax regulations, we obtain and process your address for the correct issue of accounts.
On the basis of legitimate interest, we use your personal information to detect and prevent the fraudulent use and misuse of services, in the context of ensuring the stable and safe operation of our system and services, and also for the purpose of implementing information security measures, meeting the requirements regarding quality of services, and detecting technical system and service failures.
In accordance with the GDPR, in the event of suspected abuses, GenePlanet may process personal data in an appropriate and proportionate manner for the purpose of identifying and preventing any fraud or misuse, and may, if appropriate, also forward this information to other providers of such services, business partners, the police, the Public Prosecutor's Office, or to other competent authorities. For the purpose of preventing future abuse or fraud, data on the history of identified abuses or fraud in connection with an individual, including data on the subscription and, for example, IP address, can be kept for another five years after the termination of the business relationship.
We may also Process your Information on the basis of our legitimate interests to inform you about new products and Services, related products and Services, about any upcoming events, invite you to participate in relevant GenePlanet Research, obtain testimonials for promotional purposes, perform quality control checks and to conduct R&D. Where we rely on a legitimate interest to Process your Information, you have the right to object to such Processing and this can be stopped at any time via your GenePlanet account settings.
We will not rely on our legitimate interests to Process your Information where such Processing overrides your fundamental rights, interests or freedoms or where we have another legal justification for Processing your Information.
On the basis of legitimate interest, we also use your personal information for the purposes of potential enforcement, judicial and extra-judicial recovery.
Data processing can also be based on your consent, which you have provided to GenePlanet.
The revocation or alteration of consent refers only to data processed on the basis of your consent. The most recent consent that has been received from you is valid. The possibility of revoking your consent does not constitute a resignation from the business relationship of the individual with GenePlanet.
The data for which your consent is given shall be processed, in the absence of cancellation, for up to two years after the termination of the business relationship with GenePlanet.
Processing of your Sensitive Personal Information:
Processing to create Information:
Processing for GenePlanet Research and R&D:
GenePlanet depends on other companies and individuals to perform certain tasks that complement our services. Therefore GenePlanet may also transfer personal data to carefully selected external processors who will enter into a contract for the processing of personal data with GenePlanet, or into an agreement or other binding document (hereinafter: "Processing contract") with the same substance as the contract. For external processors, such data will only be transmitted or made accessible to the extent required by a specific purpose. Such data may not be used by external processors for any other purpose, and the external processor must meet at least all the standards for the processing of personal data provided for in the applicable law. External processors are contractually committed to GenePlanet to respect the confidentiality of your personal information.
On the basis of a reasoned request, companies also provide personal data to the competent state authorities on a legal basis. GenePlanet will, for example, respond to requests from courts, law enforcement and other state authorities, which could also involve the state authorities of another EU Member State.
The data retention period is determined according to the category of the individual data. We keep the data for as long as necessary to achieve the purpose for which it was collected or further processed, or until the expiration of the limitation period for the fulfilment of the obligation or the statutory retention period.
For the purpose of fulfilling contractual obligations, the accounting data and the associated contact details of individuals may be kept until the full payment for the service or at the latest until the expiration of the limitation period in respect of an individual claim, which may legally last from one to five years. Invoices are kept for 10 years after the expiration of the year the invoice relates to in accordance with the law governing value added tax.
Other information that we have obtained on the basis of your consent is kept for the duration of the business relationship and for 2 years after the termination, unless the law provides for a longer retention period. If an individual who has given consent to the processing of personal data has not entered into a business relationship with us, their consent is valid for 2 years from its delivery or until its revocation.
After the expiry of the retention period, the data is deleted, destroyed, blocked or anonymised if the law does not specify otherwise for the particular type of data.
We guarantee the exercise of your rights regarding the processing of your personal information without undue delay. We will decide on your request within one month of receiving it. In case of complexity and a greater number of requests, the deadline may be extended by up to two additional months. If we extend the deadline, we will notify you of any such extension within one month of receiving the request along with the reasons for the delay.
We accept requests regarding the exercise of your rights at firstname.lastname@example.org, or by post at genEplanet d.o.o., Cesta na Poljane 24, 1210 Ljubljana-Šentvid. When submitting an application by electronic means, we will, whenever possible, provide you with information electronically, unless you request otherwise.
Where there is reasonable doubt as to the identity of the individual who submits a claim relating to one of their rights, we may request the provision of additional information necessary to confirm the identity of the data subject.
Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, GenePlanet may:
You have the following rights regarding the processing of your personal information:
You are always entitled to know whether personal data is processed in relation to you and, if so, you are also entitled to access your personal information, as well as the following information:
You have the right to have any correction of inaccurate personal information relating to you performed without undue delay and, considering the purposes of the processing, the right to complete any incomplete personal data, including the submission of a supplementary statement.
You have the right to have your personal information deleted without undue delay, if one of the following reasons applies:
You have the right to limit the processing of your personal information when one of the following applies:
If the processing of your personal data has been restricted in accordance with the preceding paragraph, such personal data, with the exception of its storage, shall be processed only with your consent or for the establishment, enforcement or defence of legal claims or for the protection of the rights of another natural or legal person.
Before cancelling the processing limit of your personal information, we are obliged to inform you of this.
You have the right to receive your personal information, which you have provided us, in a structured, widely used and machine-readable form, and the right to forward this information to another controller without GenePlanet hindering you from doing so, when the processing is based on your consent and the processing is carried out using automated means. At your request, when technically feasible, personal data may be transferred directly to another controller.
Whenever your data is processed on the basis of a legitimate interest for marketing purposes, you may object to such processing at any time.
We will stop processing your personal data unless we prove necessary grounds for processing that prevail over your interests, rights and freedoms, or to establish, enforce or defend legal claims.
We make Our Site and Services available to Users across the world, and similarly, make use of service providers in jurisdictions outside the European Economic Area ("EEA"). Therefore, your Information may be transferred outside the EEA to Processors for various Processing Purposes.
Where we transfer Information to countries outside the EEA, the Processors who Process the Information will be required to enter into a data processing agreement setting out how they may Process the Information and further requiring them to comply with the GDPR and other relevant Applicable Laws to protect your individual rights.
We require all Processors to have appropriate technical and security safeguards and measures to protect that Information.
Any complaint regarding the processing of your personal data may be sent to the e-mail address email@example.com or by post to the address of genEplanet d.o.o., Cesta na Poljane 24, 1210 Ljubljana.
If we do not decide on your request within the legal deadline or if we reject your request, you have the option to lodge a complaint with the Information Commissioner.
You also have the right to lodge a complaint directly with the Information Commissioner if you believe that the processing of your personal data violates Slovenian or EU regulations in the field of personal data protection.
If you have exercised the right of access to the information and if, after receiving the decision, you believe that the personal data you received is not the personal information you requested or that you did not receive all the required personal information, you can lodge a reasoned complaint before submitting a complaint to the Information Commissioner with GenePlanet within 15 days. We need to decide on your complaint as a new request within five business days.
All connections to Our Site and our mobile applications are encrypted using Secure Socket Layer (SSL) technology and internal systems protected with anti-virus software.
Only authorised personnel of GenePlanet and contracted third parties have access to Information that is necessary for them to perform their jobs or services.
Sharing Self-Reported Information through surveys, or other features on Our Site, is voluntary and done at your sole risk. GenePlanet cannot take responsibility for Information that you release or that you request us to release publicly.
In the event of a security incident, GenePlanet's internal procedures and those prescribed by the GDPR will be followed. You will be notified of any material impacts or direct consequences to you as a User without undue delay.
Contact us and we will help you find the answers.