Privacy Policy
This policy describes what personal data the geno.ac website collects, how it is used, and the rights available to data subjects under applicable law.
1. Overview and Data Controller
Category One Limited, a Business Company incorporated in the British Virgin Islands (BVI Business Company No. 2208440), operating the geno.ac website under the trade name “Geno Project” (hereinafter, “we” or “us”), is the data controller responsible for the processing of personal data described in this Privacy Policy. The Site is designed to minimize personal data collection. This Privacy Policy describes what data is collected incidentally through standard web infrastructure, what the data is used for, and your rights as a data subject.
For any matters relating to data protection, you may contact us at legal@geno.ac.
2. Data We Collect
The Site collects only the data necessary to operate the website and to protect it from abuse. Specifically:
Server logs. When you visit the Site, our content delivery network (Cloudflare) automatically collects and stores information in server log files that your browser transmits. This includes the IP address from which the request originated, the date and time of the request, the URL requested, the HTTP response code, the user-agent string of the browser, and the referring URL if applicable. These logs are used to operate the Site, diagnose technical issues, detect and prevent abuse, and ensure system security and stability. IP addresses may be evaluated, together with other data, in case of attacks on the network infrastructure or other unauthorized use of the Site, and if appropriate, used for identification in legal proceedings.
Essential cookies. The Site uses essential technical cookies set by the content delivery network for security, caching, and load-balancing purposes. These cookies do not track you across other websites and are not used for advertising or profiling. You may prevent the setting of cookies through your browser settings and may delete previously set cookies at any time. If you disable cookies, some functions of the Site may not operate correctly.
Correspondence. If you contact us through any of the email addresses listed in our Legal Notice, we receive and retain the content of your correspondence, including your email address and any personal information you include in your message. We use this data only to respond to your inquiry.
The Site does not use Google Analytics, Matomo, or any other web analytics platform. The Site does not use advertising trackers, third-party analytics, social media pixels, or similar profiling technologies. The Site does not require or collect account registration, newsletter subscription, or any other voluntary personal data submission beyond correspondence.
3. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), where applicable to visitors from the European Economic Area, we process personal data on the following legal bases:
- Legitimate interests (Article 6(1)(f) GDPR) — for server logs and essential cookies necessary to operate and secure the Site, and to continuously ensure system security and stability;
- Consent (Article 6(1)(a) GDPR) — for any voluntary correspondence you initiate with us;
- Legal obligation (Article 6(1)(c) GDPR) — where processing is required by applicable law.
4. How We Use Data
We use collected data to:
- Operate, maintain, and secure the Site;
- Continuously ensure system security and stability;
- Diagnose and resolve technical issues;
- Detect, prevent, and respond to abuse, unauthorized access, and security threats;
- Respond to your correspondence if you initiate it;
- Comply with legal obligations and enforce our rights.
We do not sell personal data. We do not use personal data for advertising. We do not share personal data with third parties for marketing purposes. We do not use personal data to identify individuals unless we become aware of specific indications of illegal use or misuse of the Site.
5. Data Sharing and International Transfers
With the exception of our content delivery network and hosting provider, we do not make your personal data available to third parties unless you have expressly consented to it, we are legally obligated to do so, or it is necessary to enforce our rights.
Personal data collected through server logs is processed by Cloudflare as our content delivery network and hosting provider. Cloudflare’s processing is governed by its own privacy policy and data processing agreements. Cloudflare may store and process data in the United States and other jurisdictions. Where the level of data protection in a given country does not correspond to the level required by GDPR or equivalent laws, we rely on standard contractual clauses and other transfer mechanisms to ensure that the protection of your personal data corresponds to applicable requirements at all times.
Beyond the content delivery network, we do not share personal data with third parties except where required by law, compelled by valid legal process, or necessary to protect our rights, the rights of third parties, or public safety.
6. Data Retention
Category One Limited will process and store personal data only for the period necessary to achieve the purpose of storage, or as permitted by applicable law. Server logs are retained by the content delivery network for the period specified in its retention schedule, typically not more than 90 days for raw logs. Correspondence is retained for as long as necessary to respond and for a reasonable period thereafter to maintain a record of the interaction. If the storage purpose is no longer applicable, or if a retention period prescribed by applicable law expires, personal data is routinely erased in accordance with legal requirements.
7. Your Rights
Under GDPR and similar laws, you have the following rights regarding personal data we hold about you:
- Right of access — to obtain confirmation of whether we process your data, a copy of that data, and information about the purposes of the processing, the categories of data concerned, and the recipients or categories of recipients;
- Right to rectification — to obtain without undue delay the correction of inaccurate or incomplete personal data;
- Right to erasure — to request deletion of your data where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent, where the data has been unlawfully processed, or where erasure is required by applicable law;
- Right to restriction — to request that we limit how we process your data, for example while the accuracy of the data is being verified;
- Right to data portability — to receive your data in a structured, commonly used, and machine-readable format;
- Right to object — to object, on grounds relating to your particular situation, to processing based on legitimate interests;
- Right to withdraw consent — where processing is based on consent, at any time, without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, contact us at the address provided in Section 13 below. We will respond within the timeframe required by applicable law, typically within one month. You also have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe your data protection rights have been violated.
8. Automated Decision-Making and Profiling
Category One Limited does not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. No decisions regarding your access to the Site or the Work are made by automated means.
9. Security
We use appropriate technical and organizational security measures to protect your stored personal data against manipulation, partial or complete loss, and unauthorized access by third parties. Our security measures are continuously improved in line with technical developments.
Please note that any data transmission on the Internet (e.g., communication by email) is generally not secure, and we accept no liability for data transmitted to us via the Internet. Unfortunately, absolute protection is not technically possible. You should use particular caution when transmitting personal information to us via email.
10. Children
The Site is not directed to children under 16. We do not knowingly collect or use any personal data from children. If a child provides us with personal information without the consent of their parent or guardian, we will ask the parent or guardian to contact us for the purpose of deleting that information. If you believe a child has submitted personal data to us, contact us and we will take appropriate steps to delete it.
11. Third-Party Data
If you provide us with the personal data of third parties (for example, by forwarding correspondence that includes another person’s contact information), you should ensure that those persons are familiar with this Privacy Policy and that you have their permission to share their data. You are responsible for ensuring that any third-party personal data you provide to us is accurate and lawfully shared.
12. Applicable Data Protection Regulations
For more information on the data protection regulations applicable to the processing described in this Privacy Policy, you may refer to:
- EU General Data Protection Regulation (GDPR): Regulation (EU) 2016/679
13. Contact
For privacy-related inquiries, data subject rights requests, or complaints, contact Category One Limited at legal@geno.ac. We will respond within the timeframe required by applicable law (see Section 7). You also have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe your data protection rights have been violated.
14. Changes to This Policy
Category One Limited may update this Privacy Policy from time to time. The current version is always available at this URL. With each update, we will note which sections have been updated. Material changes will be noted prominently on the Site. Your continued use of the Site following the posting of a revised Privacy Policy means that you accept and agree to the changes.