TuringDNA

§ Privacy

Privacy Policy

Effective: 2026‑07‑08 · Updated: 2026‑06‑08 · Version: 2.0

What changed in v2.0 (effective 2026‑07‑08). We have updated how we improve our models. To make the Service better for everyone, we now derive aggregated, de-identified signals from how the Service is used — including from Sequences and their outcomes — and use those aggregated signals to calibrate and improve our models. Your individual Sequences are still never shared, exposed, or reproduced, and are never used in isolation or verbatim to train a model. Only anonymous, aggregated insights are used. See "Submitted to the engine" below. This is a material change; we are giving at least 30 days' notice before it takes effect.

This Policy explains what personal data TuringDNA ("TuringDNA", "we", "us") collects through turingdna.com and the directed-evolution engine (the "Service"), why we collect it, who we share it with, and what choices you have. Plain language, no surprises.

Who we are

TuringDNA, Tbilisi, Georgia, is the controller of personal data processed through the Service. Contact: info@turingdna.com.

EU/UK Article 27 representative. Once we have a meaningful number of EU or UK users, we will appoint a representative under Article 27 GDPR / UK GDPR and update this Policy.

Data Protection Officer. A DPO is not required under GDPR Article 37 based on our current processing (we do not engage in large-scale processing of special-category data or large-scale systematic monitoring). If our processing changes, we will appoint a DPO and update this Policy.

Scope

This Policy applies to anyone who visits turingdna.com, uses the engine, places a synthesis order, or contacts us. It does not apply to third-party websites or services we link to (synthesis vendors' own portals, NCBI BLAST, AlphaFold-DB, etc.), which have their own policies.

What we collect

We collect only what we need to run the Service.

You give us directly

Collected automatically

Submitted to the engine

From third parties

We do not knowingly collect personal data of anyone under 18. If you believe a minor has provided us personal data, contact us at info@turingdna.com and we will delete it.

Why we use it (purposes and legal bases)

PurposeData usedGDPR legal basis
Provide the Service (run engine, deliver results)Account, usage, SequencesContract (Art. 6(1)(b))
Process synthesis orders (when live)Account, order, payment, Sequences (to selected vendor)Contract (Art. 6(1)(b))
Secure the Service, prevent abuse, enforce TermsAccount, technical, usageLegitimate interest (Art. 6(1)(f))
Comply with legal/biosecurity obligationsAs neededLegal obligation (Art. 6(1)(c)); public interest (Art. 6(1)(e))
Service emails (order updates, security notices)Account, orderContract
Product analytics, error monitoringUsage, technical (minimized)Legitimate interest
Improve the Service and our modelsAggregated, de-identified signals derived from usage and SequencesLegitimate interest (Art. 6(1)(f)); anonymized outputs fall outside the GDPR (Recital 26)
Marketing emailsAccountConsent (Art. 6(1)(a)); opt-out anytime

We do not use personal data for automated decision-making with legal or similarly significant effects (Article 22 GDPR).

Sharing

We share personal data only as follows:

We do not sell personal information and we do not "share" personal information for cross-context behavioral advertising as those terms are used under California law (CCPA/CPRA) or comparable U.S. state laws.

International transfers

We process personal data in the United States and other countries where our sub-processors operate. If you are in the EU, UK, Switzerland, or another country with data-transfer restrictions, we rely on:

You may request a copy of the relevant transfer mechanisms by emailing info@turingdna.com.

Retention

We keep personal data only as long as needed:

After the retention period we delete, anonymize, or aggregate the data.

Security

We use administrative, technical, and physical safeguards designed to protect personal data, including:

No system is perfectly secure. If we learn of a personal-data breach, we will notify affected users and regulators as required by law (within 72 hours of awareness under Article 33 GDPR; on the timelines required by U.S. state breach-notification laws).

Cookies and similar technologies

We use a small number of cookies and similar technologies:

CategoryPurposeCan disable?
Strictly necessaryAuthentication, session security, load balancingNo
FunctionalRemember preferences (UI theme, host organism)Yes
AnalyticsAggregate product usage (privacy-friendly, no advertising cookies)Yes (consent required in EU/UK)

We do not use cookies for cross-site advertising or targeting. EU/UK visitors will see a consent banner for non-essential cookies; you can change your choices at any time via the analytics preferences link below.

Website analytics

We measure how this website is used — which pages are opened, how far down them people read, which links are clicked, and whether visitors go on to create an account. We do this to find out which pages actually help people and which ones do not. It is first-party: the data goes to our own database, and it is not sold, shared for advertising, or sent to an advertising network.

By default, nothing is stored on your device. Until you choose otherwise, the identifier that groups your page views into a single visit exists only in your browser's memory and is discarded when you close the tab. No cookie is set and nothing is written to local storage. On this basis we do not store any identifier for you at all, and the measurement runs on our legitimate interest in understanding whether our own website works (Article 6(1)(f) GDPR). You can object at any time using the link below.

If you allow storage, we keep a random identifier on your device so we can tell that a return visit is the same browser, and so we can connect a first visit to a later signup. That is the difference between knowing how many visits we had and knowing whether the site actually persuades anyone. This is consent under Article 6(1)(a) GDPR and regulation 6 of PECR, and we record the date and policy version when you give it.

If you decline, we stop measuring you entirely and delete what we had already recorded for that visit. Declining is honoured permanently on that browser, and we treat a Global Privacy Control signal as a decline without asking you.

What is never collected. We do not record the text of anything you type, the contents of form fields, or the text content of the page. Where a click is recorded, we store the structural position of the element (an id or a developer-authored label), never what it said. We store the host a visitor arrived from, never the full referring address, which can carry search terms and identifiers. We never store your IP address; where we need to tell two visitors apart, we use a salted, non-reversible hash that we cannot turn back into an address.

Error reports record the type of error and the script it came from, never the error message, because messages routinely quote whatever was being processed at the time.

Analytics records are deleted after 90 days. The record of your consent decision is kept for longer, because it is the evidence that we asked you and honoured your answer.

Change your analytics choice

Your rights

Depending on where you live, you may have rights to:

EU / UK / Switzerland rights

You may exercise the rights above and also lodge a complaint with your local data-protection authority (e.g., the ICO in the UK, your national DPA in the EU, the FDPIC in Switzerland).

California (CCPA/CPRA) rights

If you are a California resident, you have rights to know, access, delete, correct, and limit use of sensitive personal information, and a right to non-discrimination for exercising your rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, email info@turingdna.com. You may use an authorized agent (we will verify the agent's authority). You may also lodge a complaint with the California Privacy Protection Agency or the California Attorney General.

Other U.S. states

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), and other states with comparable laws may have similar rights (access, correction, deletion, portability, opt-out of targeted advertising / sale / certain profiling). Submit requests via info@turingdna.com and we will route them appropriately. You may also lodge a complaint with your state Attorney General.

How to exercise rights

Email info@turingdna.com with your request. We will verify your identity (typically by confirming control of the account email) and respond within the timeframes required by law — generally 45 days under CCPA/CPRA and U.S. state laws (extendable once by 45 days with notice), and 30 days under GDPR/UK GDPR (extendable by 60 days for complex requests).

Children

The Service is intended for users 18 and older. We do not knowingly collect personal data from anyone under 18, and our Terms prohibit users under 18. Consistent with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal data from anyone under 13. If you believe we have collected data from someone under 18, contact info@turingdna.com and we will delete it.

Sub-processor list

A current list of our sub-processors is published below and kept up to date. EU/UK customers will receive prior notice of new sub-processors as required by Article 28 GDPR, with at least 30 days to object before the new sub-processor is engaged.

Sub-processorPurposeLocation
Hugging FaceHosting and compute for the engine (Spaces, ZeroGPU)United States
HostingerStatic-site hosting for marketing pagesEuropean Union
SupabaseAccount database, authentication (email + password), password reset, and Storage for generated variant librariesEuropean Union (Ireland)
ResendTransactional email delivery (verification, password reset, account notifications)United States
Twist BioscienceDNA synthesis (when you order from Twist)United States
Integrated DNA Technologies (IDT)DNA synthesis (when you order from IDT)United States
GenScriptDNA synthesis (when you order from GenScript)United States / China

Additional sub-processors (analytics, payment processing, customer support) will be added when those services are introduced; we will update this list at the same time.

Changes to this Policy

We may update this Policy. If changes are material, we will notify you (email or in-app notice) at least 30 days before they take effect. The "Updated" date above reflects the most recent revision. Material prior versions are kept available on request.

Contact

TuringDNA
Tbilisi, Georgia
info@turingdna.com