Legal
Privacy policy
How we collect, use, and protect your personal data. This policy complies with the EU General Data Protection Regulation (GDPR) and the ePrivacy Directive.
Last updated: 5 April 2026
1. Data controller
IntrinsicAge (“we,” “us,” or “our”) operates the website intrinsicage.com. We are the data controller responsible for your personal data processed through this website.
For any privacy-related questions or to exercise your rights, contact us at: privacy@intrinsicage.com
2. Data we collect
We collect the minimum data necessary to operate the site:
- Technical data automatically collected by your browser when you visit (IP address, browser type, operating system, referring URL, pages visited, timestamps). This data is processed for legitimate interest in maintaining site security and performance.
- Contact data you voluntarily provide if you sign up for our newsletter (email address) or contact us directly.
- Preference data stored locally on your device (cookie consent choice, display preferences). This data never leaves your browser.
We do not collect health data, biometric data, or any special category data as defined under GDPR Article 9. IntrinsicAge is an educational resource — we do not process biological age test results or medical records.
3. Legal basis for processing
We process your personal data on the following legal bases:
- Consent (Article 6(1)(a) GDPR) — for newsletter subscriptions and any optional cookies beyond strictly necessary ones. You may withdraw consent at any time.
- Legitimate interest (Article 6(1)(f) GDPR) — for server logs and security monitoring necessary to keep the website operational and secure.
5. How we use your data
We use collected data exclusively for:
- Operating, maintaining, and improving the website
- Sending newsletter communications (only if you subscribe)
- Responding to your inquiries or feedback
- Ensuring website security and preventing abuse
- Complying with legal obligations
We never sell your personal data. We never use your data for automated decision-making or profiling.
6. Data sharing and transfers
We may share your data with service providers who help us operate the website (e.g. hosting providers, email delivery services). These processors act only on our instructions and are bound by data processing agreements.
Our hosting infrastructure may be located outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure adequate safeguards are in place, such as EU Standard Contractual Clauses or an adequacy decision by the European Commission.
We may disclose data where required by law or to protect our legal rights.
7. Data retention
- Server logs are retained for a maximum of 90 days, then automatically deleted.
- Newsletter subscriber data is retained until you unsubscribe. You can unsubscribe at any time via the link in every email.
- Contact form data is retained for as long as needed to resolve your inquiry, then deleted.
- Local storage data (consent preference) remains on your device until you clear it.
8. Your rights under GDPR
If you are in the European Economic Area, you have the following rights regarding your personal data:
- Right of access (Article 15) — obtain a copy of the personal data we hold about you.
- Right to rectification (Article 16) — correct inaccurate personal data.
- Right to erasure (Article 17) — request deletion of your personal data (“right to be forgotten”).
- Right to restriction of processing (Article 18) — request that we limit how we use your data.
- Right to data portability (Article 20) — receive your data in a structured, machine-readable format.
- Right to object (Article 21) — object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at privacy@intrinsicage.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority if you believe your data has been processed unlawfully.
9. Children's privacy
This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encrypted connections (HTTPS), access controls, and regular security reviews.
11. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated through a notice on the website. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact
For any questions about this privacy policy or your personal data, contact us at: privacy@intrinsicage.com