Privacy Information
Information about local DNA analysis and contract and payment processing.
Version: 1 September 20261. Controller
Linus Ammer, trading as Abakos-Systeme, Schönrain 10, 84152 Mengkofen, Germany. Telephone: +49 152 27640571. Email: gggeogens.eu. For Canadian customers, Linus Ammer is also the individual designated as Privacy Officer under PIPEDA; privacy requests and complaints may be sent to the same postal and email address.
2. Core design
Genetic raw data is particularly sensitive personal data. GeoGens processes the selected genome file, variants, genetic markers and scientific results only locally in the user's browser. These data are not transmitted to Abakos-Systeme, the payment provider or another server for product analysis.
Local processing starts with format, genome-build, marker-coverage and genetic-person matching checks and takes place only after explicit consent.
3. Data processed only locally
- genome file and filename
- variants, alleles, genotypes and marker coverage
- local identity proof and licence matching
- personal scientific results, traits and similarity values
- chosen map position
- imported or generated local result package
4. Local storage
IndexedDB stores GeoGens licences, a random non-genetic order-recovery capability, temporarily where needed the blinded local licence-issuance state, an optional browser file handle, location and visibility settings, and the finished analysis result. The stored result is the same evaluation file the purchased product package contains; it holds no raw calls and no SNP list, but it does hold results derived from genetic data. It is kept locally only, so that the embedded genome reappears after the browser is closed without transferring the reference package again, and it is deleted by “Deselect genome” or by removing the licence it belongs to. Intermediate results stay in memory while an analysis is running. The encrypted reference package may remain in the browser cache.
The downloaded `.gga` result package is unencrypted. It contains results derived from genetic data but no raw call or SNP list. The user controls its storage, backup, disclosure and deletion.
5. Server-side data
- internal order, product and release IDs
- for Canadian orders: purchaser name for the contract copy
- the payment provider's transaction, payment and webhook identifiers
- amount, currency, billing market and payment status
- versions and exact wording of accepted legal documents and declarations
- hash of the blinded signing request and idempotent response
- hash of a random non-genetic package credential
- for abuse prevention on selected order, licence and withdrawal routes: an immediately shortened, secret-keyed HMAC of the network prefix; the application does not store the raw address
- for an electronic withdrawal: name, email address, order or contract reference, statement, language, receipt time and processing status
- refund, revocation and support status
6. Data not stored on the server
Abakos-Systeme does not store genome files, filenames, raw calls, SNPs, marker counts, scientific results, map positions or plain genetic identity-block hashes for the analysis. The server receives only a cryptographically blinded signing request and cannot link its local identity proof to the order.
7. Purposes and legal bases
- Local genetic analysis in the EEA and United Kingdom: performance of the contract under Article 6(1)(b) GDPR or UK GDPR together with explicit consent under Article 9(2)(a) GDPR or UK GDPR. The analysis is the main contractual obligation. Article 9 contains no contract exception of its own, so explicit consent is obtained in addition and not instead.
- United Kingdom: based on the expected low volume of UK orders, analysis being performed only on the user's device and Abakos-Systeme receiving neither the genome file nor genetic results, the operator currently assesses the relevant processing as occasional and unlikely to pose a risk within Article 27(2)(a) UK GDPR. Special-category genetic data is not processed on the server on a large scale. No UK representative is therefore currently appointed. This assessment will be repeated if UK activity becomes materially larger or regular, or if the data flow changes.
- Australia and New Zealand: analysis likewise begins only after express consent. Where the Australian Privacy Principles or New Zealand Privacy Act 2020 apply, their rules for sensitive information, transparency, access, correction, complaints and overseas disclosures are observed in addition.
- Canada: PIPEDA principles of accountability, identified purposes, consent, data minimisation, safeguards, openness, access, correction and complaint handling are observed for cross-border order, contract and licence data. The purchaser name is collected only because the Canadian contract copy requires it. The genome file and analysis results remain local and are not disclosed to the provider.
- Ordering, licence supply and support: contract performance under Article 6(1)(b) GDPR.
- Tax and commercial retention: Article 6(1)(c) GDPR.
- Abuse prevention, idempotency and IT security: legitimate interests under Article 6(1)(f) GDPR where no more specific basis applies.
8. Payment processing through Paddle
Depending on the purchase country, the sale is processed through Paddle.com Market Limited, Paddle.com Inc. or Paddle.com (Canada) Ltd. as reseller. That entity processes payment details, billing address, country or region, payment method, tax data and transaction-related device and security information as its own controller — not as a processor for Abakos-Systeme. It is also the customer's contracting party for the purchase.
Paddle is loaded only when the user reaches the payment stage. No connection to Paddle takes place before that.
Abakos-Systeme receives the transaction identifier, amount, currency, payment status and the country and, where applicable, state of the billing address from Paddle. Those details are required for contract documentation, tax allocation and the check against the enabled markets. Abakos-Systeme does not receive full payment details.
The responsible Paddle entity, international transfers and retention periods are described in Paddle's privacy information at https://www.paddle.com/legal/privacy and in the buyer terms at https://www.paddle.com/legal/checkout-buyer-terms. Both are linked immediately before checkout.
9. Recipients
Recipients of server-side contract data are limited to providers required for operation, hosting, database, backup, payment, legal and tax obligations. Their roles, contracts, locations and transfer safeguards are documented in an up-to-date list available on request. Genetic raw data and scientific results are not disclosed to those recipients.
10. Cookies and browser storage
GeoGens sets exactly two cookies. “geogens-locale” stores the chosen language for one year. “__Host-geogens-order” stores the signed order reference for 24 hours; it is httpOnly, sent over HTTPS only and restricted to the same origin. There is no cookie for cross-site request forgery protection: that protection stores nothing and instead checks the request origin and a dedicated request header.
Additional browser storage is used: IndexedDB for the licences, settings and finished analysis result described above, localStorage for the acknowledgement of the notice dialog, and the browser cache for public or encrypted reference data.
All of this storage is strictly necessary to provide the service the user explicitly requested, within the meaning of section 25(2) no. 2 TDDDG. None of it is used for advertising profiles.
The basemap, map typeface and reference data are served by GeoGens itself. Opening the application transmits no data to third-party providers. Paddle is loaded only when the user opens the payment section.
11. Retention
Tax-relevant records are normally retained for eight years. Contract, consent and withdrawal evidence is kept at least until relevant claim and evidence periods expire. Support cases are normally deleted three years after closure unless another duty or legal defence requires longer retention. Webhook idempotency data and voluntary package access have separately documented deletion periods. Short-lived HMAC rate-limit counters are removed after their minute window by the daily deletion job, normally within 24 to 48 hours. New database backups from 1 September 2026 exclude these counter data; encrypted backups created before that date may contain them until the respective backup is deleted under controlled procedures.
Browser-local data remains until the user removes it through “Deselect genome”, browser controls or deletion of external files.
12. Deselect genome
“Deselect genome” ends the active local session and removes in-memory results, the locally stored analysis result, active genome and result file handles, local map position and visibility. Paid licences and files stored outside the application remain. This is not a retrospective withdrawal of processing that has already taken place.
13. Data-subject rights
Where Abakos-Systeme processes personal contract data, applicable privacy law provides rights of access, correction and, where applicable, erasure, restriction, portability or objection. Contact gggeogens.eu. Consent may be withdrawn for future processing without affecting processing already carried out lawfully.
Abakos-Systeme has no technical access to genome and result data stored only locally and therefore cannot retrieve or delete those data server-side.
14. Complaints
You may complain to a data-protection supervisory authority. The provider's lead local authority is generally the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de. People in the United Kingdom may also contact the Information Commissioner's Office at ico.org.uk.
15. Automated decisions
The scientific display makes no legal or similarly significant automated decision about the user. There is no profiling for advertising, insurance, employment, creditworthiness or medical care.
16. Security and changes
GeoGens separates genetic browser data from contract data, minimises server logs, encrypts backups and uses blind-signed personal licences. Security controls, incident process and deletion process are documented.
Each purchase retains the privacy version recorded in its contract confirmation. This general information may be updated for future processing.
Additional regional privacy information
Additional procedures and response periods apply to purchasers from California, Washington, Nevada and Canada.
