BYOSOM Privacy Policy
BYOSOM Privacy Policy
Effective Date: 12/18/2025
Your privacy is important to us. This Privacy Policy explains what personal data we collect from you and how we use it. We encourage you to read this policy carefully.
This Privacy Policy applies to all BYOSOM products and services. References to BYOSOM products include BYOSOM DNA testing services, personalized skincare formulations, custom beauty products, skincare consultation services, mobile applications, and websites maintained by BYOSOM.
BYOSOM partners with Gene by Gene, Ltd. for DNA testing services through their FDA-approved Genomics Research Center in Houston, Texas. BYOSOM provides DNA-personalized skincare products, genetic skin analysis, custom formulation services, and related beauty and wellness consultations.
For the purposes of this Privacy Policy, “BYOSOM” (“we”, “us”, “our”, “the Company”) refers to BYOSOM and its affiliated service providers, including Gene by Gene, Ltd. for genetic testing services.
Important Legal Notice
PLEASE READ THIS AGREEMENT CAREFULLY TO ENSURE THAT YOU UNDERSTAND EACH PROVISION.
THIS AGREEMENT CONTAINS A MANDATORY ARBITRATION OF DISPUTES PROVISION THAT REQUIRES THE USE OF ARBITRATION ON AN INDIVIDUAL BASIS RATHER THAN JURY TRIALS OR CLASS ACTIONS TO RESOLVE DISPUTES. IT ALSO LIMITS THE REMEDIES AVAILABLE TO YOU IN THE EVENT OF A DISPUTE.
BYOSOM and International Data Privacy Frameworks
BYOSOM complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce through our partnership with Gene by Gene, Ltd.
BYOSOM has committed to adhere to the EU-U.S. Data Privacy Framework Principles with regard to the processing of personal data received from the European Union and from the United Kingdom (and Gibraltar).
BYOSOM has committed to adhere to the Swiss-U.S. Data Privacy Framework Principles with regard to the processing of personal data received from Switzerland.
If there is any conflict between the terms in this Privacy Policy and the applicable DPF Principles, the Principles shall govern.
DPF Complaints & Dispute Resolution
In compliance with the DPF frameworks, BYOSOM commits to resolve DPF Principles-related complaints about our collection and use of your personal information.
EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data should first contact BYOSOM at:
BYOSOM has committed to refer unresolved complaints related to the DPF frameworks to a U.S.-based independent dispute resolution mechanism, BBB NATIONAL PROGRAMS.
If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit:
www.bbbprograms.org/dpf-complaints
This service is provided free of charge.
Purposes of This Document
This document (the BYOSOM Privacy Policy) explains how BYOSOM manages the privacy of your personal data and other information that can be used to identify you, either alone or in combination with other information, including:
- DNA samples
- genetic test results
- skincare preferences
- purchase history
- consultation records
- custom formulation data
- product usage information
(collectively, “Personal Information”).
We use your Personal Information to provide BYOSOM services, including DNA-personalized skincare products, genetic skin analysis reports, custom formulation development, skincare consultations, product recommendations, subscription services, and personalized beauty guidance.
By using BYOSOM services and websites, you consent to the collection, use, storage, and disclosure of your Personal Information by BYOSOM in accordance with this Privacy Policy. This document should be read in conjunction with the BYOSOM Terms of Use and BYOSOM Consent Agreement.
Our Commitment to You
BYOSOM collects, processes, stores, and shares your Personal Information in a responsible, transparent, and secure environment that fosters our customers’ trust and confidence.
BYOSOM respects your privacy and will not sell or rent your Personal Information without your consent.
Personal Information includes, but is not limited to:
- Names, phone numbers, physical or mailing addresses, email addresses
- Genetic test results and DNA analysis data
- Skincare preferences, concerns, and goals
- Purchase history and subscription information
- Custom formulation specifications and ingredients
- Consultation records and skincare assessments
- Product usage feedback and reviews
- Payment and billing information
- Communication preferences and marketing consents
How We Use Personal Information
BYOSOM collects data to operate effectively and provide you with the best experiences with our DNA-personalized skincare products and services.
You provide some data directly, such as when you:
- Create a BYOSOM account
- Order DNA testing kits or skincare products
- Complete skincare questionnaires and assessments
- Participate in consultations or customer service interactions
- Subscribe to services or newsletters
- Provide feedback or reviews
Additional data is provided when we deliver genetic test results, custom skincare formulations, product recommendations, or other BYOSOM services.
BYOSOM uses the data we collect to:
- Analyze DNA for skincare-relevant genetic markers
- Develop personalized skincare formulations based on your genetic profile
- Provide custom product recommendations and skincare guidance
- Process and fulfill orders
- Manage subscription services and recurring deliveries
- Conduct skincare consultations and provide expert advice
- Improve and personalize skincare experiences
- Communicate test progress, account status, and product updates
- Provide customer support and technical assistance
- Conduct research and development
- Ensure product quality and safety
- Comply with legal and regulatory requirements
We may also use the data to communicate with you about your account and to provide product information, including occasional marketing offers. You may opt out of receiving marketing communications at any time.
Specific Use of Genetic Information
Your genetic data is used specifically for:
- Analyzing genes related to collagen production (MMP1, MMP3)
- Evaluating antioxidant system genes (SOD2, GPX1, CAT, NQO1)
- Assessing hydration system genes (AQP3)
- Understanding skin aging patterns and susceptibilities
- Determining optimal ingredients for custom formulations
- Identifying potential sensitivities or contraindications
- Providing personalized skincare recommendations
Your raw genetic data is processed by Gene by Gene, Ltd. at their FDA-approved laboratory in Houston, Texas. BYOSOM receives only analysis results relevant to skincare characteristics, not your complete genetic profile.
Storage and Processing
Personal Information is stored and processed at BYOSOM facilities and partner facilities, including:
- Gene by Gene’s Genomics Research Center in Houston, Texas
- Custom formulation laboratories in France and the United States
If you are located outside the United States, by providing Personal Information you specifically consent to the transfer, storage, and processing of Personal Information in the United States and France.
Data Retention
- Account Information: Retained while active and for 7 years after closure
- Genetic Data: Stored for the lifetime of the account unless deletion is requested
- Custom Formulation Data: Retained for 10 years
- Purchase History: Retained for 7 years
- Communication Records: Retained for 3 years
You may request deletion of data at any time, subject to legal requirements.
Security
BYOSOM places great importance on the security of Personal Information and uses:
- End-to-end encryption
- Secure transmission (SSL/TLS)
- Access controls and authentication
- Regular security audits
- Employee privacy training
- Secure physical facilities
- FDA-approved laboratory partners
Only authorized personnel have access, and all access is logged and monitored.
Use and Disclosure of Personal Information
BYOSOM discloses Personal Information only in limited circumstances to:
- Gene by Gene, Ltd. (DNA testing and analysis)
- Custom formulation laboratories (France and United States)
- Shipping and logistics partners
- Payment processors
- Customer service platforms
Research and Development
With explicit consent, anonymized and aggregated data may be used for:
- Improving genetic algorithms
- Developing new formulations
- Advancing DNA-based skincare science
- Publishing peer-reviewed research
- Academic collaborations
Individual genetic data is never used without explicit consent.
Legal Requirements
We may disclose Personal Information:
- With your knowledge and permission
- As described in this Privacy Policy
- As required by law or legal process
- To protect rights, safety, or property
- To prevent fraud or cybercrime
Non-Personal Information
We may collect non-personal information such as device data, IP address, usage patterns, and analytics data. Aggregated or anonymized information cannot identify individuals.
Consent for Research
Use of BYOSOM services constitutes consent for internal quality control and research. Additional consent may be requested for specific research activities. Participation is voluntary and revocable.
BYOSOM Account and Subscription Services
Account holders may access genetic results, manage subscriptions, update preferences, communicate with experts, and manage privacy settings.
Subscriptions may be modified, paused, or canceled at any time.
Your Data Rights
You have the right to:
- Access
- Correct
- Delete
- Port
- Restrict processing
- Object
- Withdraw consent
Requests can be sent to [email protected]. Responses are provided within 30 days.
Deleting Genetic Data
Deletion requests may take up to 90 days. Aggregated data may be retained. Deletion may limit future services.
Policy Updates
Updates are communicated via website notice, email, app notification, or product shipment. Changes take effect after 30 days.
International Transfers
Data may be transferred to the United States, France, and the European Union under approved safeguards, including SCCs and adequacy decisions.
California Privacy Rights (CCPA)
California residents have rights to know, delete, opt out (BYOSOM does not sell data), and non-discrimination. Requests may require identity verification.
Children’s Privacy
BYOSOM services are not intended for individuals under 18. Any data collected inadvertently will be deleted promptly.
Third-Party Services
Third-party services operate under their own privacy policies.
Enforcement
BYOSOM is subject to oversight by the Federal Trade Commission (FTC).
Biometric Information
Genetic data may be considered biometric information. BYOSOM obtains consent, secures data, limits retention, and does not sell genetic information.
Arbitration & Governing Law
Disputes are resolved by binding arbitration via the American Arbitration Association (AAA) in Houston, Texas. Class actions and jury trials are waived. Texas law governs.
Contact Information
Email: [email protected], [email protected]
Data Protection Officer: [email protected]
Mail:
BYOSOM – A102669
1 rue de Stockholm
75008 Paris
France
This Privacy Policy was last updated on 12/18/2025 and is effective immediately for new users and after 30 days for existing users.