Legal
Privacy policy
How we collect, use, and protect your personal data. This policy complies with the EU General Data Protection Regulation (GDPR) and the ePrivacy Directive.
Last updated: 30 August 2026
1. Data controller
IntrinsicAge (“we,” “us,” or “our”) operates the website intrinsicage.com. We are the data controller responsible for your personal data processed through this website.
For any privacy-related questions or to exercise your rights, contact us at: privacy@intrinsicage.com
2. Data we collect
We collect the minimum data necessary to operate the site:
- Technical data automatically collected by your browser when you visit (IP address, browser type, operating system, referring URL, pages visited, timestamps). This data is processed for legitimate interest in maintaining site security and performance.
- Contact data you voluntarily provide if you sign up for our newsletter (email address) or contact us directly.
- Preference data stored locally on your device (cookie consent choice, display preferences). This data never leaves your browser.
- If you accept analytics, public page paths (without query strings), referring page, device and browser information, and limited interaction events are processed by Google Analytics and Microsoft Clarity to help us improve the website.
We do not collect health data, biometric data, or any special category data as defined under GDPR Article 9. IntrinsicAge is an educational resource — we do not process biological age test results or medical records.
The Find Your Best Test quiz runs in your browser. Its answers are encoded in the results-page URL so the result can be shared, but quiz, private editorial, admin, and provider-submission routes are excluded from our analytics events. We also redact the quiz query keys q1–q7 in Google Analytics as an additional safeguard.
3. Legal basis for processing
We process your personal data on the following legal bases:
- Consent (Article 6(1)(a) GDPR) — for newsletter subscriptions and any optional cookies beyond strictly necessary ones. You may withdraw consent at any time.
- Legitimate interest (Article 6(1)(f) GDPR) — for server logs and security monitoring necessary to keep the website operational and secure.
5. How we use your data
We use collected data exclusively for:
- Operating, maintaining, and improving the website
- Understanding how consented visitors use public pages
- Sending newsletter communications (only if you subscribe)
- Responding to your inquiries or feedback
- Ensuring website security and preventing abuse
- Complying with legal obligations
We never sell your personal data. We never use your data for automated decision-making or profiling.
6. Data sharing and transfers
We may share your data with service providers who help us operate the website (e.g. hosting providers, email delivery services). These processors act only on our instructions and are bound by data processing agreements.
If you consent to analytics, Google processes measurement data for Google Analytics and Tag Manager, and Microsoft processes session-interaction data and visible page text from included public routes for Clarity. We do not permit either service to receive quiz answers through our analytics implementation.
Our hosting infrastructure may be located outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure adequate safeguards are in place, such as EU Standard Contractual Clauses or an adequacy decision by the European Commission.
We may disclose data where required by law or to protect our legal rights.
7. Data retention
- Server logs are retained for a maximum of 90 days, then automatically deleted.
- Newsletter subscriber data is retained until you unsubscribe. You can unsubscribe at any time via the link in every email.
- Contact form data is retained for as long as needed to resolve your inquiry, then deleted.
- Local storage data (consent preference) remains on your device until you clear it.
- Consented analytics data is retained according to the retention settings in our Google Analytics and Microsoft Clarity accounts, subject to any earlier deletion request or legal requirement.
8. Your rights under GDPR
If you are in the European Economic Area, you have the following rights regarding your personal data:
- Right of access (Article 15) — obtain a copy of the personal data we hold about you.
- Right to rectification (Article 16) — correct inaccurate personal data.
- Right to erasure (Article 17) — request deletion of your personal data (“right to be forgotten”).
- Right to restriction of processing (Article 18) — request that we limit how we use your data.
- Right to data portability (Article 20) — receive your data in a structured, machine-readable format.
- Right to object (Article 21) — object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at privacy@intrinsicage.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority if you believe your data has been processed unlawfully.
9. Children's privacy
This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encrypted connections (HTTPS), access controls, and regular security reviews.
11. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated through a notice on the website. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact
For any questions about this privacy policy or your personal data, contact us at: privacy@intrinsicage.com