Privacy policy.
We take your privacy seriously. This policy explains what data we collect, why we collect it, and how you can exercise your rights.
1. Data Controller
GeneDance GmbH ("GeneDance", "we", "us", "our") is the data controller responsible for processing personal data collected through this website (genedance.com) and the GeneDance portal (portal.genedance.com).
GeneDance GmbH
Switzerland
Email: privacy@genedance.com
For any privacy-related enquiries, please contact us at privacy@genedance.com.
2. Data We Collect
We collect personal data in the following contexts:
2.1 Website visitors
- Log data: IP address, browser type, pages visited, referrer URL, time and date of visit. This data is collected automatically by our web server.
- Analytics data: Aggregated usage statistics (page views, session duration, geographic region) collected via privacy-respecting analytics tools. No cross-site tracking is performed.
- Cookie data: See the Cookies section below.
2.2 Contact and enquiry forms
- Name, email address, and any information you voluntarily include in a message when contacting us via email or contact forms.
2.3 Platform users (portal accounts)
- Account data: Name, email address, organisation name, role, billing address.
- Usage data: Login timestamps, actions performed within the portal, project and sample metadata.
- Sequencing data: Raw FASTQ files, sample metadata, and analysis results submitted through the platform. This data is processed solely to deliver the services you have contracted.
- Billing data: Payment method information, processed by our payment provider. We do not store full card details on our servers.
3. How We Use Your Data
We use personal data for the following purposes:
- To operate, maintain, and improve the GeneDance platform and website.
- To create and manage your account and process your sequencing orders.
- To deliver and communicate analysis results, QC notifications, and project status updates.
- To process payments and issue invoices.
- To respond to support requests and general enquiries.
- To send service-related communications (e.g. platform updates, maintenance notices). We do not send marketing emails without your explicit consent.
- To comply with applicable legal obligations.
- To detect and prevent fraudulent or abusive activity.
We do not sell, rent, or trade your personal data to third parties. We do not use your sequencing data for internal research, model training, or any other purpose beyond service delivery.
4. Legal Basis for Processing
Under the GDPR and Switzerland's revised Federal Act on Data Protection (nFADP), we process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): Processing your account data, sequencing submissions, and billing data is necessary to fulfil the services you have contracted with us.
- Legitimate interests (Art. 6(1)(f) GDPR): We process website log data and analytics data to maintain the security and performance of our platform. Our legitimate interest does not override your fundamental rights.
- Legal obligation (Art. 6(1)(c) GDPR): We may process data to comply with applicable laws, such as tax record-keeping requirements.
- Consent (Art. 6(1)(a) GDPR): Where we collect optional analytics cookies or send marketing communications, we do so only with your explicit, freely given consent. You may withdraw consent at any time.
5. Cookies
We use cookies and similar tracking technologies on this website. You can manage your cookie preferences at any time using the cookie banner or by contacting us.
5.1 Essential cookies
These cookies are strictly necessary for the website and portal to function. They cannot be disabled.
- Session cookies: Maintain your authenticated portal session. Expire when you close your browser.
- Security cookies: CSRF tokens to protect against cross-site request forgery attacks.
- Cookie preference cookie: Stores your cookie consent decision so you are not asked again on every visit. Expires after 12 months.
5.2 Analytics cookies
With your consent, we use privacy-respecting analytics tools to understand how visitors use our website. These tools are configured to anonymise IP addresses and do not track you across other websites. Analytics cookies expire after 12 months.
5.3 Managing cookies
You can withdraw your consent for analytics cookies at any time by clicking "Manage Cookies" in the footer, or by adjusting your browser settings. Note that disabling essential cookies will affect the functionality of the portal.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Website log data: 30 days, then deleted or anonymised.
- Analytics data: 14 months in aggregated, anonymised form.
- Account data: For the duration of your account plus 3 years thereafter (to comply with contract and financial record-keeping obligations).
- Sequencing data: Retained according to your plan (Free Trial: 30 days; Starter: 6 months; Growth: 12 months; Professional: 24 months; Enterprise: custom). You can export your raw data at any time. Extended retention can be arranged.
- Billing records: 10 years, as required by Swiss accounting law.
- Support correspondence: 3 years after the resolution of the enquiry.
7. Third-Party Processors
We work with a limited number of carefully selected third-party service providers who process personal data on our behalf. All processors are bound by data processing agreements that meet GDPR requirements.
- Cloud infrastructure: Our platform and data are hosted on ISO 27001-certified cloud infrastructure with servers physically located in Switzerland.
- AI and model processing: All AI model inference runs on dedicated, secured servers located in Switzerland. We do not send your data to third-party AI providers, and no data is retained by the model layer.
- Payment processing: Payment data is processed by a PCI-DSS-compliant payment provider. We do not store card details.
- Email delivery: Transactional emails (notifications, reports) are sent via a reputable email service provider.
- Customer support: Support tickets are managed through a secure helpdesk platform.
We do not use third-party advertising networks, social media pixels, or cross-site tracking technologies.
8. International Data Transfers
All personal data and sequencing data is stored on servers physically located in Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection for the purposes of the GDPR.
Where any of our third-party processors are located outside Switzerland or the European Economic Area, we ensure appropriate safeguards are in place, such as the EU Standard Contractual Clauses (SCCs), prior to any transfer.
We will never transfer your sequencing data outside Switzerland without your explicit written agreement.
9. Your Rights
Under the GDPR and the Swiss nFADP, you have the following rights regarding your personal data:
Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Request correction of inaccurate or incomplete personal data.
Right to erasure
Request deletion of your personal data where we have no lawful basis to retain it.
Right to restriction
Request that we restrict processing of your data in certain circumstances.
Right to portability
Receive your personal data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests or for direct marketing.
Withdraw consent
Withdraw consent at any time where processing is based on consent.
Right to complain
Lodge a complaint with a supervisory authority (FDPIC in Switzerland, or your local DPA).
To exercise any of these rights, please contact us at privacy@genedance.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure:
- All data is encrypted in transit using TLS 1.2 or higher.
- Data at rest is encrypted using AES-256.
- Data is hosted on ISO 27001-certified infrastructure with servers located in Switzerland.
- Access to personal data is restricted to authorised personnel on a need-to-know basis.
- We maintain a documented quality management system covering our data handling processes.
- Security incidents are investigated promptly. Where required by law, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of a breach.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email of any material changes at least 30 days before they take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.
Continued use of the website or platform after a policy change constitutes acceptance of the updated policy.
12. Contact Us
For any questions about this Privacy Policy, to exercise your data rights, or to raise a privacy concern, please contact us:
Privacy enquiries
privacy@genedance.com
General enquiries
info@genedance.com
If you are not satisfied with our response, you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or with the data protection authority in your country of residence.