Effective Date: October 1, 2025

1. Introduction

Welcome to Pedigree Tool. This Privacy Policy explains how the owners of Pedigree Tool (“we,” “us,” or “our”) collect, use, and protect your personal data when you use our web-based pedigree drawing and visualization tool (the “Service”).

We are committed to protecting your privacy and handling your data in an open and transparent manner. We strive to follow General Data Protection Regulation (GDPR) requirements in all our processes, although we are still in beta and not yet GDPR-certified.

2. Who is Responsible for Your Data?

Pedigree Tool, owned by Ezgi Yavuz and Bastian Schuele, is “data controller” and responsible for your personal data. If you have any questions about this policy or your data protection rights, please contact us at: info@pedigreetool.com .

3. What Information We Collect

We collect the following types of information:

a) Data You Provide to Us:

When you register for an account, we collect your first name, last name, and email address.

b) Data We Collect Automatically:

Usage Analytics: We may collect aggregated and anonymized data about your interactions with the Service, such as features used, actions taken, and error logs. This data helps us improve the Service and is not used to personally identify you.

c) What We Explicitly Do Not Collect:

We do not collect and you agree not to upload any sensitive personal data, including personal health information (PHI) or any data that could directly identify a patient. The Service is not designed to store this type of information.

4. How and Why We Use Your Data (Legal Basis)

We only use your personal data when the law allows us to. Our legal bases for processing your data is:

To Provide and Manage the Service:

We use your Account Information to create and manage your account, authenticate you, and provide access to your saved work. Legal Basis: Performance of a contract with you.

To Improve Our Service:

We use anonymized Usage Analytics to understand how our Service is being used, identify bugs, and improve its functionality and user experience. Legal Basis: Our legitimate interests to develop and grow our business.

To Communicate With You:

We use your email address to send important service-related notices, such as updates to our terms, security alerts, or information about the expiration of your beta access. Legal Basis: Performance of a contract and our legitimate interests.

5. Data Sharing and Third Parties

We do not sell your personal data. We only share it with trusted third-party service providers who act as data processors on our behalf:

Infrastructure: We use Supabase as our backend service provider for database management and user authentication. The data you save in the application, including pedigree information and your account details, is stored with Supabase and secured with Row Level Security (RLS). You can view their privacy policy for more details.

We use Vercel for hosting our web application. Vercel may collect technical data (like IP addresses) to provide their services and ensure security. You can view their privacy policy for more details.

Analytics: We may use privacy-focused, GDPR-compliant analytics providers to process usage data on our behalf. These third parties are contractually obligated to safeguard your data and are prohibited from using it for any other purpose.

6. Data Security

We implement modern technical and organizational measures to protect your personal data, including the use of encryption for data in transit and at rest. While we take data security seriously, no system is 100% secure, and we cannot guarantee the absolute security of your information.

7. Your Data Protection Rights

Under GDPR a user in the EU, you have the following rights regarding your personal data:

The Right to Access: You can request a copy of the personal data we hold about you.

The Right to Rectification: You can request that we correct any inaccurate or incomplete data.

The Right to Erasure (The “Right to be Forgotten”): You can request that we delete your personal data.

The Right to Restrict Processing: You can ask us to suspend the processing of your personal data in certain situations.

The Right to Data Portability: You can request that we transfer your data to you or another service in a machine-readable format.

The Right to Object: You can object to our processing of your data where we are relying on a legitimate interest.To exercise any of these rights, please contact us at info@pedigreetool.com . You also have the right to lodge a complaint with a data protection authority.

8. Cookies

We may use essential cookies for session management (to keep you logged in) and for basic analytics. You can control or disable cookies through your browser settings, but doing so may affect the functionality of the Service.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and, where appropriate, by email.

10. Contact Us

If you have any questions, comments, or concerns about this Privacy Policy, please contact us at: info@pedigreetool.com