DNA Privacy and Cookie Policy
Last updated: April 2026
We value your privacy and do not sell your personal information to any third party, ever. This Privacy and Cookie Policy outlines our commitment to protecting your privacy and explains how we collect, use, disclose, and secure your personal information.
In this Privacy Policy, “we,” “us,” or “our” refers to DNA Men Nexus Pty Limited (ABN 11 159 058 796) (“DNA”). This policy applies to all personal information collected offline or online, including through this website and the DNA app (the “Site”).
1. Compliance with Privacy Laws
We handle your personal information in accordance with applicable privacy laws and regulations, including:
- The Australian Privacy Act 1988 (Privacy Act);
- The General Data Protection Regulation (EU GDPR);
- The United Kingdom General Data Protection Regulation (UK GDPR);
- The California Consumer Privacy Act (CCPA) and other applicable US state privacy laws (e.g., Virginia’s CDPA, Colorado’s CPA, Connecticut’s CTDPA).
1A. Special category data
DNA is an LGBTQ+ media organisation. Subscription records, purchase history, and content interaction data we process may, by their nature, be capable of inferring your sexual orientation. Sexual orientation is a special category of personal data under Article 9 of the EU GDPR and UK GDPR.
Where we process data that may indicate or infer your sexual orientation, we do so on the basis of your explicit consent (Article 9(2)(a) GDPR/UK GDPR). You may withdraw that consent at any time by contacting us using the details in Section 10 below.
Where you have chosen to make information about your sexual orientation or identity publicly available, we may also rely on Article 9(2)(e) GDPR (data manifestly made public by the data subject).
2. Types of Personal Information We Collect
We may collect the following types of personal information from you directly or through third parties:
- Personal Identifiers: Name, email address, mailing address, date of birth, and contact information.
- Transactional Data: Payment details, transaction history, and any inquiries about products and services.
- Device and Usage Information: Browser session details, device and network information, IP address, and interactions with our Site.
- Demographic Information: Age, gender, location, and preferences or opinions.
- Additional Information: Information you provide through customer surveys, and interactions via associated applications and social media platforms.
3. How We Use Your Information
We may collect, hold, use, and disclose personal information for purposes including:
- Allowing access to our Site and related applications [Lawful basis: contract performance – Art. 6(1)(b) GDPR];
- Processing and fulfilling orders, including payments [Lawful basis: contract performance – Art. 6(1)(b) GDPR; legal obligation for tax/financial records – Art. 6(1)(c)];
- Contacting you with customer service or account-related information [Lawful basis: contract performance – Art. 6(1)(b) GDPR];
- Conducting analytics, market research, and business development to improve our services [Lawful basis: legitimate interests – Art. 6(1)(f) GDPR. You may object to this processing; see Section 6];
- Running competitions and offering additional benefits [Lawful basis: consent – Art. 6(1)(a) GDPR or contract performance where benefits are part of a subscription];
- Advertising and marketing, including to send you promotional information about our products and services [Lawful basis: consent – Art. 6(1)(a) GDPR; and consent under the Australian Spam Act 2003 for email marketing. You may withdraw consent at any time];
- Complying with legal obligations and resolving disputes [Lawful basis: legal obligation – Art. 6(1)(c) GDPR].
4. Data Sharing and International Transfers
We share personal information with selected third parties to support our services. This includes:
Service Providers
To provide our services, we may share data with the following third-party service providers:
- Payment Processing: Stripe – Privacy Policy
- Communications and CRM: The Magazine Manager (Mirabel Technologies) – Privacy Policy
- Customer Support: FreshWorks (FreshDesk, FreshCaller, FreshChat) – Privacy Policy
- Analytics: Google Analytics – Privacy Policy
- Shipping and Fulfilment: D&D Mailing Services for monthly subscription mailings – Privacy Policy
- Digital Editions: Pocketmags – Privacy Policy
- Website Security and Features: Jetpack (Automattic) – Privacy Policy
- Website Hosting: Pressable Inc. (a subsidiary of Automattic), which hosts dnamagazine.com.au on servers in the United States – Privacy Policy
Additional Data Processors
- Blog Comments: Disqus, for managing comments on the DNA website – Privacy Policy
- Subscriptions and Memberships: WooCommerce for processing purchases and managing subscriptions on DNAstore – Privacy Policy
- SMS Notifications: Twilio Inc., which delivers SMS order and subscription notifications to subscribers who provide a mobile phone number – Privacy Policy
- Transactional Email Delivery: Microsoft Corporation (Microsoft 365 / Exchange Online), which delivers transactional emails including order confirmations, subscription notices, and renewal alerts – Privacy Policy
Where applicable, third parties are required to handle data according to our instructions, ensuring compliance with privacy laws. For transfers outside the EU/UK, we use Standard Contractual Clauses (SCCs) or other appropriate mechanisms to protect personal data.
Data Processing Agreements
Where we engage third-party processors to handle your personal data on our behalf, we enter into Data Processing Agreements (DPAs) that contractually require those processors to: handle your data only on our documented instructions; implement appropriate technical and organisational security measures; comply with applicable data protection laws; and not engage sub-processors without our prior authorisation.
DPAs are currently in place with the following key processors: Automattic Inc. / Aut O’Mattic A8C Ireland Ltd. (WordPress.com and Jetpack); Pressable Inc. (website hosting); WooCommerce Ireland Ltd. (subscription and payment processing); and FreshWorks Inc. (customer support). For EU/EEA and UK data transfers, these DPAs incorporate the relevant Standard Contractual Clauses.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to collect and store information when you visit our Site, including:
- Essential Cookies: Necessary for basic functionality.
- Analytics Cookies: Used to analyse site usage, provided by services such as Google Analytics.
- Marketing Cookies: Allow us to display targeted ads across social media and online media feeds.
Managing Cookies: You can modify your cookie preferences via your browser settings. EU and UK users will receive a cookie banner to consent to non-essential cookies, which can be adjusted anytime.
6. Your Rights and Controlling Your Personal Information
Depending on your location and applicable privacy laws, you may have rights over your personal information, including:
- Access and Portability: Request a copy of your personal information in a machine-readable format.
- Correction and Deletion: Request updates to inaccurate data or deletion where permissible.
- Object to Processing: Request limitations on processing activities, such as direct marketing.
- Opt-Out: US residents can opt out of the “sale” of personal information as defined by CCPA and other state laws.
If you would like to exercise any of these rights, please contact us using the details below.
Right to complain to a supervisory authority
If you believe we have not handled your personal data in compliance with applicable law, you have the right to lodge a complaint with your relevant data protection authority. Contact details for key jurisdictions are:
- Australia: Office of the Australian Information Commissioner (OAIC) – www.oaic.gov.au
- European Union / EEA: Irish Data Protection Commission (DPC), which acts as our lead supervisory authority for EU/EEA residents – www.dataprotection.ie
- United Kingdom: Information Commissioner’s Office (ICO) – ico.org.uk
- Other jurisdictions: Your national or state data protection regulator.
We encourage you to contact us first (see Section 10) so we can attempt to resolve your concern directly.
7. Data Security and Breach Notification
We employ industry-standard security measures, including data encryption and access controls, to protect your information. While we take all reasonable steps to secure your data, no method of transmission or storage is completely secure. In the unlikely event of a data breach, we are committed to:
- Notifying affected individuals and relevant regulatory authorities as required by law.
- Taking necessary steps to contain and mitigate the breach to prevent further unauthorised access.
To the extent permitted by law, our liability for any data breach is limited to cases of proven gross negligence or intentional misconduct. For uncontrollable circumstances or third-party actions, we disclaim liability. By using our services, you acknowledge and accept these limitations.
8. Data Retention
We retain personal data for as long as necessary to fulfil the purposes outlined in this policy or to meet legal obligations. Data is securely stored and managed according to industry standards.
8A. Profiling and automated decision-making
We use analytics and marketing tools (including Google Analytics and Jetpack Stats) to analyse browsing behaviour and interactions with our Site. This analysis may constitute profiling for the purposes of improving our services and delivering relevant content and advertising.
We do not make automated decisions that produce legal effects or similarly significant consequences about you without human review.
You can limit profiling activities by adjusting your cookie preferences as described in Section 5, or by opting out of Google Analytics at tools.google.com/dlpage/gaoptout. You may also object to profiling based on legitimate interests by contacting us at the details in Section 10.
8B. Age restrictions and children’s privacy
DNA Magazine contains adult content and is intended exclusively for audiences aged 18 years and over. We do not knowingly collect, use, or disclose personal information from individuals under 18 years of age.
If you are under 18, please do not provide us with any personal information or access our Site. If we become aware that we have inadvertently collected personal information from a minor, we will take reasonable steps to delete that information as soon as practicable.
If you believe we may have collected information from or about a person under 18, please contact us immediately using the details in Section 10.
9. Updates to This Policy
This Privacy and Cookie Policy may be updated periodically. We will notify you of significant changes where possible, and you may refer to the “Last Updated” date at the top of this policy for the latest version.
10. Contact Us
For any questions, complaints, or to exercise your rights, please contact our Privacy Officer:
DNA Men Nexus Pty Limited
Email: [email protected]
Postal Address: PO Box 3, COOMA NSW 2630, AUSTRALIA
Change History
Freshworks DPA added (3 Mar 2019) · Amazon removed (22 Mar 2021) · Klaviyo DPA added (2 Apr 2021) · Klaviyo, Mailchimp removed (31 Oct 2024) · The Magazine Manager added (31 Oct 2024) · 27 April 2026: special category data disclosure added, lawful bases added per processing activity, Pressable Inc. added, DPA statement added, supervisory authority complaint pathway added, profiling disclosure added, age restrictions added, Eventbrite removed, Twilio SMS added, Microsoft 365 added as email processor.
