Your Data Rights
The GDPR grants you comprehensive rights over your personal data. Here is each right explained in plain language, along with how to exercise it.
Right of Access
You have the right to obtain confirmation of whether we are processing your personal data, and if so, to access that data. You can request a complete copy of all personal data we hold about you — including your training history, health records, genetic data, blood work panels, microbiome profiles, wellness data, and any AI-generated analyses.
How to exercise this right
Email dpo@bioforge.science with the subject "Data Access Request". We will verify your identity and provide your data in a structured, machine-readable format within 30 days.
Right to Rectification
If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. This includes your account information, health records, and any other data you have provided to the platform.
How to exercise this right
Most data can be corrected directly within the BioForge app. For data that cannot be edited through the interface, contact dpo@bioforge.science.
Right to Erasure
You can request the deletion of your personal data. We will comply without undue delay unless we have a legal obligation to retain certain records. Deletion is permanent and includes all derived data — risk profiles, AI analyses, pharmacogenomic mappings, and any other data generated from your inputs.
How to exercise this right
You can delete individual records (blood panels, genetic data, health records) directly in the app. To delete your entire account and all associated data, contact dpo@bioforge.science. Deletion is completed within 30 days.
Right to Restriction
In certain circumstances, you can request that we restrict the processing of your data. This means we will store your data but not actively process it. This applies when you contest the accuracy of data, when processing is unlawful but you prefer restriction over deletion, or when you need the data for legal claims.
How to exercise this right
Contact dpo@bioforge.science with the subject "Restriction Request" and specify which data and under what grounds.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You can also request that we transmit this data directly to another controller where technically feasible. This covers all data you have provided to us — training data, health records, blood work, genetic data, and microbiome profiles.
How to exercise this right
BioForge supports data export directly from the app for most data types (JSON format). For a complete export, contact dpo@bioforge.science.
Right to Object
You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis (Article 6(1)(f)). This applies to service improvement and analytics processing. It does not apply to processing based on your consent (health data) or contractual necessity (core service delivery).
How to exercise this right
Contact dpo@bioforge.science with the subject "Objection" and specify which processing you object to.
Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. BioForge does not make such automated decisions. All AI-generated recommendations, analyses, and coaching responses are advisory in nature. No automated decision on BioForge restricts your access, alters your legal rights, or produces similarly significant effects.
How to exercise this right
No action needed. BioForge does not engage in automated decision-making as defined by Article 22.
Right to Withdraw Consent
Where processing is based on your explicit consent (which covers all special category health data), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before you withdrew consent. After withdrawal, the relevant data will be deleted.
How to exercise this right
Delete the relevant data from your account in the BioForge app, or contact dpo@bioforge.science to withdraw consent for specific categories of processing.
Contact
Email dpo@bioforge.science for all data subject requests.
Response Time
We respond to all requests within 30 days, as required by the GDPR. Acknowledgement within 48 hours.
Supervisory Authority
You have the right to lodge a complaint with your local authority. For France: CNIL.
