VUO legal
VUO Privacy Notice
This notice explains how VUO Labs AB processes personal data when you request access, apply to VUO Founding Members, use an application or Members account, enter a candidate room, accept membership, pay, or receive a personalized membership. It also explains the strict boundary between VUO and supplier-hosted DNA, blood, and NorthStream questionnaire systems.
1. Controller and contact
VUO Labs AB, Swedish organization number SE 559577-5684, Hälsingegatan 51, 113 68 Stockholm, Sweden, is the controller for the VUO processing described here. Contact privacy@vuolabs.com to ask a privacy question or exercise a data-protection right. Contact support@vuolabs.com for application, membership, or billing support.
2. Who and what this notice covers
This notice covers visitors who request access, applicants, selected candidates, members, authorized account users, and people who contact VUO. It covers the public site and waitlist, access emails, authentication, Members and application accounts, application questionnaires and review, candidate rooms, legal acceptance, payments, customer-safe recommendations, fulfillment, support, security, and audit records.
3. Data VUO collects
Depending on how you interact with VUO, we process:
- identity and contact data, such as name, email, age confirmation, country, delivery details, and account identifiers;
- application data, such as professional or performance identity, habits, readiness answers, goals, open-text answers, submission state, selection status, and internal review records;
- membership and transaction data, such as invitations, room and plan identifiers, accepted legal versions, consent evidence, payment method and status, invoices, cancellation or withdrawal records, orders, deliveries, and support history;
- permitted customer outputs, such as answer-free workflow status, opaque supplier references, allowlisted recommendation results, review and edit records, and customer-safe result projections; and
- technical and security data, such as timestamps, device or browser information, IP address where approved and necessary, authentication events, audit records, error logs, and abuse-prevention signals.
Application answers may reveal health-related or other sensitive information. VUO saves those questionnaire answers only after asking for explicit consent for application review. VUO does not use an application consent as membership consent.
4. Data VUO does not receive or store
VUO does not receive or store your saliva sample, raw DNA file, genetic-variant data, blood-test file or values, blood results used by NorthStream, NorthStream customer health questionnaire sessions, raw answers, answer labels, free text, exports, or answer history. Omicron stores non-customer scientific rules, questionnaire definitions, question and answer-option codes, and condition mappings; those records are not your answers.
5. Sources
We collect data directly from you, from an authorized VUO administrator acting on your application or membership, from payment and fulfillment providers, and from approved supplier-controlled workflows. Suppliers disclose only the coordination status, opaque references, and allowlisted recommendation outputs authorized for VUO—not the raw inputs listed above.
6. Purposes and legal bases
VUO processes personal data to:
- create, secure, and administer access requests, applications, candidate rooms, accounts, memberships, payments, orders, delivery, support, cancellation, and withdrawal—before a contract at your request or to perform a contract;
- review founding-member applications and operate, improve, and protect controlled application and membership processes—based on VUO’s legitimate interests, balanced against your rights;
- meet tax, accounting, consumer, product-safety, data-protection, and other legal obligations;
- detect abuse, secure accounts and systems, investigate incidents, establish or defend legal claims, and maintain reliable audit evidence—based on legal obligations and legitimate interests; and
- process health-related, genetic, or other special-category data for the specific application-review or personalized-membership purpose only after explicit consent, unless another basis is required or permitted by law.
Where processing is necessary for a contract or requested pre-contract step, not providing required data may prevent VUO from opening an application, activating a membership, taking payment, delivering an order, or providing a dependent feature. Marketing is not bundled into application or membership consent.
7. Supplier-hosted health and recommendation workflows
SelfDecode is the current Genetic Testing Supplier and NorthStream Runtime Supplier. It handles DNA testing and DNA-result custody and hosts the NorthStream customer health questionnaire surface, sessions, answers, answer-set storage, and result-state capture in its supplier-controlled environment. Its privacy information is available at selfdecode.com.
The Blood Testing Supplier has not been selected. Blood coordination is disabled and VUO does not provide a blood-result upload, entry, parsing, or storage path. Before the recurring blood-test benefit is enabled, VUO will name the approved supplier and publish the reviewed processing path. When enabled, VUO will receive only permitted coordination status, opaque references, and recommendation results—not blood values or files.
8. Recipients
Access within VUO is limited to personnel and authorized administrators who need the data for their role. VUO also uses contracted providers for hosting, database, authentication, email, payments, security, customer support, testing, recommendation runtime, manufacturing, fulfillment, and professional advice. They may process data only for their assigned purpose and under applicable contractual, confidentiality, security, and data-protection controls. VUO may disclose data where law requires it or to protect legal rights. VUO does not sell personal data.
9. International transfers
Some providers, including SelfDecode, may process data outside your country. When personal data is transferred outside the EEA or another territory requiring transfer safeguards, VUO uses an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary measures where required. Contact privacy@vuolabs.com for information about the safeguard relevant to your data.
10. Retention
An incomplete application is kept for up to one year after its last activity. A submitted application that is not selected is kept for up to two years after the decision so VUO can administer the round and answer follow-up questions. Selected applications, contractual records, legal acceptances, payments, orders, complaints, and audit evidence are retained for the membership and then only as long as needed for contractual, product-safety, accounting, limitation-period, legal, or security obligations. Security logs use shorter risk-based periods where possible. VUO deletes or anonymizes data when the applicable purpose and retention duty end.
11. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, portability, or objection to processing based on legitimate interests. Where VUO relies on consent, you may withdraw it at any time without affecting earlier lawful processing. Withdrawal may mean VUO cannot continue a feature or personalized service that depends on those data. You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority. VUO may need to verify your identity before completing a request.
12. Automated decisions
VUO uses structured eligibility answers to identify applications that do not meet a founding-round readiness rule. VUO does not use solely automated processing to make a legal or similarly significant membership decision. Selection, scientific rules, recommendation review, customer-specific edits, supplier ordering, and final service decisions remain subject to the governed human and system controls described by VUO. Contact privacy@vuolabs.com if you want information or human review of a decision.
13. Security
VUO uses administrative, technical, and organizational safeguards designed to limit access, separate roles and suppliers, encrypt data in transit and where appropriate at rest, authenticate users, maintain audit evidence, control production changes, and respond to incidents. No system is risk-free, but VUO minimizes the sensitive data it receives and keeps raw DNA, blood, and NorthStream questionnaire data out of VUO systems by design.
14. Changes to this notice
VUO may update this notice when its service, suppliers, or legal obligations change. The published notice shows its version and effective date. Material changes are presented through the relevant application, candidate, or Members surface before a new consent or agreement is requested. An earlier processing event remains associated with the notice and consent versions recorded for it.