Privacy policy
Updated: July 2023
Introduction
This Privacy Policy (hereinafter: “Policy”) is used by THE NU B.V., a company with limited liability under the laws of the Netherlands with its registered offices in Amsterdam, the Netherlands, having offices at (2333 CH) J.H. Oortweg 21, Leiden, the Netherlands and registered in the register of the Chamber of Commerce under registration number 78739152 (“THE NU” or “we”). THE NU’s Data Protection Officer can be reached by email at dpo@thenu.com.
This Policy applies to all processing of data that identifies you or may be used to identify you with (“Personal Data”) by THE NU such as but not limited to the processing in relation to the provision of Services provided by THE NU (“Services”) and the processing via the website located at [thenu.com] (“Website”). “Services” shall mean the provision of any online or offline services or offerings by THE NU, including via its app. Other capitalized terms shall have the meaning ascribed to them in the THE NU Terms of Service (“Terms”) unless otherwise defined here. This Policy also applies to other situations where THE NU processes personal data, such as in cases of employment, subcontracting, or business partnerships, where a separate notice is not provided.
THE NU is responsible for determining the purpose and the means of the processing of the Personal Data processed in relation to its Services and is therefore considered Data Controller under the General Data Protection Regulation (“GDPR”) and the UK GDPR.
Data on minors The use of the Website is not permitted for children under the age of 18. Children under 18 must not place orders or create an account. THE NU therefore does not consciously process data pertaining to minors. If, as a parent or legal representative, you suspect that THE NU is processing data from your child or a minor entrusted to your care, please contact us using the contact details mentioned above. However, you should contact us if you wish to provide consent on behalf of a person as their parent or guardian.
For what purposes do we process Personal Data?
To fulfil your order and perform the Services: this seems obvious, but we need certain Personal Information about you to process and fulfil your order. Our Services are based on artificial intelligence-based profiling of your Personal Data, which may include special categories of data and is therefore based on your explicit consent. We are using health and genetic data to optimize our AI models, which are used for personalized life-style design and for personalized supplement formulas. Our Services use machine learning– which is explained below.
For machine learning purposes: we may use your Personal Data for improving our artificial intelligence engine, which provides the core of our longevity Services. Our machine learning models will selectively use small parts of genetic data obtained from your DNA, plus other personal data. Once part of our models, such data will no longer be able to identify you after your personal data, including your genetic, health, and biometric data has been deleted following your withdrawal of consent.
To personalize the Website: you have the option of adapting the Website experience to your needs, for example by changing the language of the Website. To remember your changes, we may process Personal Data about you, such as your IP address. If you have created an account, your preferences may be linked to your account.
To improve our Website and our Services: we are constantly working to improve our Website, our Services and your user experience and add new functionality. Processing analytical data (in an aggregated form) is essential for this.
To secure our Website: in order to offer you the best possible user experience, it is necessary to keep malicious third parties (e.g. hackers) out. We therefore constantly monitor our Services and the use of our Services. When we identify a potential threat, we can take immediate action to prevent disruption or unauthorized use of our Services.
To communicate with you: when you contact us, we process your contact information such as your name and e-mail address and any other Personal Data that you provide to us.
For marketing purposes: your Personal Data can be used to provide you with newsletters and offers for our products and services.
To comply with a legal obligation: we may be required by law or by a court order to process and / or transfer certain Personal Data.
For Research: we may use your Personal Data for research and development, clinical research studies, and identifying candidates for optional Research Participation, subject to your consent.
Who can receive Personal Data?
How long do we retain your Personal Data?
5.1.1
We will retain your data until you withdraw your consent. In some cases, Account Details and other data may be retained, for example in case of non-payment of your obligations or where you are involved in a dispute with us.
5.1.2
Please note that keeping your data enables us to restart the provision of our Services to you at any time, without you being required to provide your samples and your answers to our questions once again. We therefore encourage you not to withdraw your consent and erase your data even if you have not been using our Services for a while. We may from time to time remind you of the existence of your account with us to give you the opportunity to withdraw your consent if you have firmly decided not to order any of our Services again.
5.1.3
When you are referred to us by another person, such as a family member e.g. as a gift or as part of a package, we will use the email address that we receive from them to invite you to use our Services. We may send you one or more reminders within a reasonable time frame. However, if you fail to register, your email address will typically be held 1-2 months and will be deleted from our system the latest after 2 months.
5.1.4
Where you have not completed your sign-up process, we may send you a reminder to complete the process. We will typically delete your email address if you do not complete your sign-up process after 2 months.
5.1.5
When you have applied for a position at THE NU, we retain your personal data no longer than 4 weeks after the end of the application process, unless you give us permission to retain your personal data longer, in which case we will retain your personal data no longer than for 1 year after the end of the application process.
How do we secure your Personal Data?
Your rights
Objection: Depending on the situation, you have the right to consent or object to the processing of your Personal Data and the conditions under which this processing takes place. This is particularly the case for us contacting you with any matters that are not strictly linked to the provision of Services. Please note that objecting to the use of some of your data, notably the information from the Biology Testing and Longevity Report, will result in the termination of the Services at your request. This is because the processing of such data is necessary for entering into, or performance of, a contract between you and us (Article 22(2)(a) GDPR), whereas the data has been held securely and your interests are protected by your right to withdraw consent at any time and erase the data.
Access: You have the right to receive, in an intelligible form, a copy of the Personal Data being processed.
Rectification: You, where appropriate, have the right to request the rectification of your Personal Data.
Restriction and data portability: under some circumstances specified by the GDPR, you have the right to request restriction of your data, plus you have the right to port your data to another provider.
The right to withdraw consent and request erasure: where we are processing personal data relating to you on the basis of your prior consent to that processing, you may withdraw your consent at any time. Please note that your withdrawal of consent and the erasure of data will result in the termination of the Services at your request.
Complaint with relevant authority: You have the right to file a complaint with the relevant data protection authorities, e.g. the Autoriteit Persoonsgegevens in the Netherlands.
What else is important to know?