1. Who we are and scope

We are a privately owned Australian company headquartered in Perth, with operations in Australia and New Zealand. This policy applies to personal information we handle as a controller (or APP entity under Australian law), including information provided by clients, website visitors, and prospective clients. If you access our Services from New Zealand, see Section 11 for NZ-specific information.

2. Our compliance framework

We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme. Where relevant, we also take into account applicable state/territory health privacy laws (e.g., NSW Health Records and Information Privacy Act 2002; VIC Health Records Act 2001; ACT Health Records (Privacy and Access) Act 1997).

Given our New Zealand operations, we also comply, where applicable, with the Privacy Act 2020 (NZ) and the Health Information Privacy Code 2020 (NZ).

We do not rely on the lapsed Genetic Privacy and Non-Discrimination Bill 1998. Instead, we treat genetic information as sensitive information under the Privacy Act 1988 (Cth) and apply elevated protections.

3. The information we collect

3.1 Account & Order Information

Name, email, phone, billing and delivery addresses, order details, payment confirmation (processed by our payment providers), communications and support tickets.

3.2 Device & Usage Information

When you visit the Site, we automatically collect technical data (IP address, time zone, browser type/version, referring pages), pages viewed, links clicked, and cookie identifiers. We use cookies, tags, pixels and log files to operate and improve the Site (see Section 8).

3.3 Self-Reported Information (optional)

If you choose, you may provide demographic and health-related details (e.g., age, sex, family medical history, lifestyle, ethnicity) to enhance report precision. This is strictly optional.

3.4 Genetic & Health Information

We do not accept uploads of external genetic data files. Your genetic material is collected using our at-home collection kit (e.g., saliva or cheek swab). Life X DNA performs sequencing and analysis using coded barcodes only (no given names on any sample or instrument run). Once sequencing is complete, the physical sample is irreversibly destroyed by us. We store the resulting Genetic Information (digital data) in encrypted repositories and generate your Life X DNA™ insights.

4. How we collect information

Directly from you: account creation, orders, consultations, forms, email/phone.

Automatically: cookies and similar technologies when you use the Site.

From service providers: e.g., payment processors, analytics, couriers/logistics for kit delivery and return; these providers do not receive your Genetic Information.

5. How we use information

We use personal information to:

  • Provide, personalise and improve the Services and your reports;
  • Process orders and payments; dispatch kits; send confirmations and updates;
  • Provide support and respond to enquiries;
  • Maintain security, prevent fraud and misuse;
  • Operate, test and enhance our analytics and AI systems (using de-identified/aggregated data wherever feasible);
  • Comply with legal/regulatory obligations and maintain business records.

We do not sell your personal information. We never use your Genetic Information for advertising.

Ownership & control of Genetic Information: You retain ownership of your Genetic Information and may request deletion at any time (see Section 9).

6. Sharing and disclosure

We do not sell or rent personal information. We place additional restrictions on Genetic Information:

  • No internal access to sequencing files: Life X DNA does not have access to clients’ raw genetic sequencing files (e.g., FASTQ/BAM/VCF or equivalent). These files are barcoded and blockchain-encrypted. They can only be accessed and decrypted by the client via their secure portal/credentials.
  • Sequencing files cannot be disclosed: We cannot provide sequencing files, even when legally required. Only the client can access/decrypt these files.
  • Pseudonymisation & non-identifiability: Sequencing artefacts and derived datasets are labelled only with barcodes. They contain no names or contact details and cannot be used to identify clients.
  • Processing model: Our systems process barcoded data to generate your Life X DNA™ insights. Our personnel may access operational metadata only (e.g., kit status, barcode, timestamps) to deliver support and fulfilment—not raw sequencing files. We do not disclose Genetic Information to third parties without your explicit consent. If disclosure is mandated by law, see Legal/compliance below; note we cannot provide sequencing files in any circumstances.
  • Operational vendors – non-genetic data only: We use service providers for e-commerce, hosting/backup, email, analytics and logistics for account, order and site usage data only (e.g., name, contact details, delivery address, order ID). These providers are bound by confidentiality and data processing terms. Couriers receive only the details required to deliver and return kits.
  • Payments: Card and other payments are processed by third-party providers; we do not store full card or bank details on our servers.
  • Employers/insurers: We will never share your personal or Genetic Information with an employer, insurer or similar third party.
  • Research & analytics: Any internal research, service improvement or model training uses de-identified and/or aggregated information; no identifiable Genetic Information is disclosed outside Life X DNA.
  • Legal/compliance: We cannot provide sequencing files; only the client can access these.

7. Security

We apply administrative, technical and physical safeguards proportionate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, network segmentation, secure key management, and audit logging. Genetic and health data are stored in encrypted repositories. Where feasible, we maintain offline/cold-storage archives for Genetic Information.

Although no system can be 100% secure, we operate a risk-based security programme and comply with the Notifiable Data Breaches scheme in Australia and comparable obligations in New Zealand where applicable.

We apply administrative, technical and physical safeguards proportionate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, network segmentation, secure key management, and audit logging. Genetic and health data are stored in encrypted repositories. Where feasible, we maintain offline/cold-storage archives for Genetic Information.

Although no system can be 100% secure, we operate a risk-based security programme and comply with the Notifiable Data Breaches scheme in Australia and comparable obligations in New Zealand where applicable.

8. Retention & deletion

Order/Account data: retained for as long as needed for your account, to deliver Services, and to satisfy legal, tax and accounting requirements.

Genetic Information: retained until you ask us to delete it or until it is no longer required to provide the Services.

Sample destruction: physical reference samples are destroyed after sequencing by Life X DNA.

You may request deletion of your account and Genetic Information at any time. We will action deletion subject to lawful retention requirements (e.g., invoices). We will confirm once deletion is complete.

9. Cookies and similar technologies

We use cookies and similar tools to:

  • keep you signed in and remember preferences;
  • analyse Site performance and usage;
  • measure marketing effectiveness.

You can decline cookies in your browser settings. For more on cookies, visit www.allaboutcookies.org. We use Google Analytics; you can learn how Google uses data at policies.google.com/privacy and opt-out via your browser add-on if you wish.

Do Not Track: our Site does not currently respond to browser DNT signals.

10. Children

Our Site and Services are intended for adults (18+). If you are a parent or guardian and believe a minor has provided personal information, please contact us so we can address it promptly. (Where testing for a minor is arranged, we require verifiable parental/guardian consent via our client onboarding process.)

11. Additional information for New Zealand residents

We comply, where applicable, with the Privacy Act 2020 (NZ) and the Health Information Privacy Code 2020 (NZ) for New Zealand clients.

Your rights (NZ): You have rights to access and correct your personal and health information held by us.

12. Your choices and rights (AU)

Under the Australian Privacy Principles, you may request access to the information we hold about you and ask us to correct it if inaccurate.

13. Changes to this policy

We may update this policy from time to time. The latest version and effective date will always be shown at the top. Material changes will be notified via the Site or by email where appropriate.

14. Contact, feedback and complaints

Privacy enquiries/requests:

Post

Privacy Officer, Life X DNA™, L25, Capital Square Tower 3, 1 Spring Street, Perth CBD, WA 6000, Australia

Entity

Life X DNA™ (ABN 12 642 051 563)