Privacy Policy

Last updated: [10.10.2025]

This Privacy Policy explains how Nomads UAB (“NomadsBio”, “we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use our website nomadsbio.com (the “Site”) and our skin microbiome testing service (the “Service”).

We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other applicable EU and national regulations.

 

1. Data Controller

Nomads UAB
Mokslininkų g. 2, LT-08412 Vilnius, Lithuania
Company code: 302441263
Email: info@nomadsbio.com

Nomads UAB is the data controller for the personal data processed in connection with your use of the Site and the Service.

 

2. Types of Personal Data We Collect

We may collect and process the following categories of personal data depending on your interactions with us:

2.1. Account and Contact Information

  • Full name

  • Email address

  • Phone number (if provided)

  • Delivery and billing address

  • Payment details (processed securely via third-party providers; we do not store full card data)

2.2. Order and Communication Data

  • Order history

  • Customer support communications

  • Consent records and preferences

2.3. Sample and Laboratory Data

  • Unique kit or sample ID (pseudonymized)

  • Biological material (e.g. skin swab)

  • Laboratory results from microbiome sequencing or other analysis

  • Derived microbiome profile data

Important: We do not analyze, store, or interpret genetic (human DNA) data. The Service analyzes microbial DNA from skin samples only.

2.4. Technical and Usage Data

  • IP address

  • Browser type and version

  • Device identifiers

  • Pages visited, session duration, and Site interactions

  • Cookies and analytics data (see Section 10)

 

3. Purposes and Legal Bases of Processing

We process your personal data only when we have a lawful basis under Article 6 of the GDPR. The main purposes and bases are:

Purpose

Legal Basis

To process and deliver your order

Performance of a contract (Art. 6(1)(b))

To collect, receive, and analyze your skin microbiome sample

Performance of a contract (Art. 6(1)(b))

To provide and send you your microbiome Report

Performance of a contract (Art. 6(1)(b))

To manage your account and respond to inquiries

Legitimate interests (Art. 6(1)(f))

To improve our products, algorithms, and scientific research using anonymized data

Legitimate interests (Art. 6(1)(f)) or consent (Art. 6(1)(a))

To comply with tax, accounting, or legal obligations

Legal obligation (Art. 6(1)(c))

To send optional marketing communications (e.g. newsletters)

Consent (Art. 6(1)(a))

You can withdraw your consent at any time by contacting us at info@nomadsbio.com.

 

4. How We Use and Protect Your Data

4.1. We use your data solely to:

  • Fulfil and manage your order and payment;

  • Analyze your microbiome sample and produce your Report;

  • Improve our scientific models and services using anonymized data;

  • Communicate important updates, test results, or customer support responses.

4.2. We apply pseudonymization during laboratory processing: your sample is assigned a unique ID, and laboratory staff do not have access to your identifying information.

4.3. All personal data are stored securely within the European Economic Area (EEA). Access is restricted to authorized staff and processors under confidentiality agreements.

4.4. We will never sell or share your identifiable data with third parties for marketing or unrelated commercial purposes.

 

5. Anonymized and Aggregated Data

We may use fully anonymized or aggregated microbiome data (from which individuals cannot be identified) for:

  • Statistical analysis and product improvement;

  • Internal R&D and algorithm training;

  • Scientific or wellness-related publications;

  • Public communications about population-level microbiome insights.

Such anonymized data are no longer considered personal data under GDPR.

 

6. Data Retention

Data Category

Retention Period

Account and order data

5 years after last purchase (for accounting/legal compliance)

Laboratory and microbiome data

Up to 2 years after your Report is delivered (unless you request earlier deletion)

Anonymized data

Retained indefinitely (not personally identifiable)

Marketing consent records

Until consent is withdrawn

After expiry of the retention period, data are securely deleted or irreversibly anonymized.

 

7. Sharing and Data Recipients

We may share personal data with trusted data processors who act on our behalf and under our instructions:

  • Accredited laboratories conducting microbiome analyses

  • Payment service providers (for secure transactions)

  • Couriers and logistics companies delivering and returning kits

  • IT hosting and data-storage providers within the EEA

  • Customer support and email systems

All processors are bound by data-processing agreements ensuring GDPR compliance.

If data are transferred outside the EEA (e.g. IT cloud providers in the US), we ensure adequate safeguards such as Standard Contractual Clauses approved by the European Commission.

 

8. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Access: obtain a copy of your data.

  • Rectification: correct inaccurate or incomplete data.

  • Erasure (“right to be forgotten”): request deletion of your personal data, unless retention is legally required.

  • Restriction: limit how your data are processed.

  • Data portability: receive your data in a structured, commonly used format.

  • Objection: object to processing based on legitimate interests.

  • Withdraw consent: withdraw consent for marketing or optional processing at any time.

To exercise your rights, contact us at info@nomadsbio.com. We may need to verify your identity before processing your request.

You also have the right to lodge a complaint with the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija):
Website: https://vdai.lrv.lt

 

9. Data Security

We employ appropriate technical and organizational measures to protect data against unauthorized access, loss, misuse, or alteration, including:

  • Encrypted transmission (HTTPS/SSL);

  • Access control and staff confidentiality training;

  • Secure data-storage environments;

  • Regular backups and pseudonymization procedures.

 

10. Cookies and Analytics

Our website uses cookies and similar technologies to improve functionality and analyze user behavior.

10.1. Types of cookies

  • Essential cookies: required for basic site functionality (e.g. checkout).

  • Analytics cookies: help us understand how visitors use the site (e.g. via Google Analytics).

  • Preference cookies: remember your settings and choices.

  • Marketing cookies: only used if you consent.

You can adjust your cookie preferences in your browser or through our cookie banner.

 

11. Marketing Communications

With your explicit consent, we may send you occasional newsletters or product updates.
You can unsubscribe at any time by clicking “Unsubscribe” in our emails or by contacting us directly.

 

12. Children’s Privacy

Our Service is not directed to individuals under 18 years old.
We do not knowingly collect personal data from minors. If we learn we have done so, we will promptly delete such data.

 

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect legal or operational changes.
The latest version will always be available at
nomadsbio.com/privacy.
Material changes will be announced via email or website notice.

 

14. Contact Information

For any questions or requests regarding this Privacy Policy or your data, please contact us:

Nomads UAB
Mokslininkų g. 2, LT-08412 Vilnius, Lithuania
Email: info@nomadsbio.com

 

Summary of Key Points

  • We analyze microbiome, not human DNA.

  • Data are stored securely within the EEA.

  • You retain full control over your personal and sample data.

  • Anonymized data may be used for scientific and wellness research.

  • You can contact us anytime to access, delete, or update your data.