Newsletter Privacy Notice
Last updated: July 31, 2026
About this notice
This notice covers one thing: the Model Organism newsletter. It explains what happens to your personal data when you sign up for the weekly email, while you are subscribed, and after you leave. It is written by Aunova OÜ, which publishes the newsletter.
It does not cover the rest of aunova.net, which has its own privacy policy.
We send the newsletter using beehiiv, a hosted newsletter platform. beehiiv handles your data for us and on our instructions. Its own privacy policy describes what beehiiv does on its own behalf, and it does not answer for us. This notice does.
The newsletter is written for a professional and scientific readership. It is not directed at children.
Who is responsible, and how to reach us
The controller of your personal data for this newsletter is:
Aunova OÜ, Ahtri tn 12, 15551 Tallinn, Harju maakond, Estonia (VAT: EE102670613)
You can reach us by email at info@aunova.net, through our contact page, or by post at the address above.
We have not appointed a Data Protection Officer, and we are not required to have one. Data protection is handled internally, and the email address above reaches the person responsible for it.
What we collect, and where it comes from
From you, when you subscribe: your email address. That is the only thing the signup form asks for. We do not ask for your name.
Recorded automatically by the platform, when you sign up and when you read an issue:
- your IP address, and the approximate location it indicates;
- information about your device and your email client;
- how you arrived at the signup form, such as the referring page and similar attribution data;
- the date and time you submitted the form, and the date and time you confirmed your subscription;
- whether you open an issue, and which links in it you click. See Open and click tracking below, because this is the part most people do not expect.
We do not buy email addresses and we do not add anyone from any other source. The only route onto this list is the signup form followed by your own confirmation.
The platform is also able to handle subscriber names, avatar images and survey answers. We do not use any of those for this newsletter. If that changes, this notice changes first.
What we use it for
One purpose: to send you the Model Organism newsletter, and to keep the list working. Keeping it working means confirming your subscription, honouring your unsubscribe, and stopping delivery to an address that no longer accepts mail.
We do not use your address for anything else. We do not sell it, rent it, or share it with other publishers or advertisers. The platform's advertising network and audience-data features are not switched on for this publication, and switching them on would change what your consent covered, so we would have to come back and ask you again rather than quietly rely on the consent you already gave.
No decision is made about you automatically.
Our lawful basis, and why it is consent
Our lawful basis is your consent, GDPR Article 6(1)(a).
We say that plainly because the usual alternative is not open to us. The ePrivacy Directive 2002/58/EC, Article 13(1), transposed in Estonia by the Electronic Communications Act (Elektroonilise side seadus), requires prior consent before marketing email is sent to an individual. Where consent is required for the message itself, we cannot then fall back on a legitimate interest for the processing that is the message. So the basis is consent, and under Article 7(1) the burden of showing that we have it sits with us, not with you.
Consent has to be a real choice, so: you never have to subscribe to read anything of ours, we do not make you accept terms and conditions in order to subscribe, and the consent box on the form is not ticked for you.
How we know that you consented
The list uses confirmed opt-in, often called double opt-in. Two separate things have to happen before you receive an issue.
- First, the form. You submit the signup form, having ticked the consent box yourself. The wording shown to you is versioned. The version in force since 31 July 2026 is MO-CONSENT-v1.0, and it reads: "Yes, email me the Model Organism newsletter. Aunova OÜ will use my email address only to send this weekly newsletter and will not sell it or share it with anyone else. I can unsubscribe from any issue, and I can withdraw this consent at any time. See the privacy notice for how Aunova OÜ handles your data."
- Second, the confirmation. We send a confirmation email to that address and you click the link in it. Until you do, nothing else is sent to you.
The second step is what turns the record into evidence rather than an assertion. It shows that whoever controls the mailbox took a deliberate, timestamped action, which a typed address on its own does not. We keep that record so that we can demonstrate your consent if we are ever asked to.
How to withdraw your consent
At any time, and withdrawing has to be as easy as giving (Article 7(3)). Either way works:
- Click the unsubscribe link at the bottom of any issue. It takes effect immediately. No login, no explanation, and no reply from us needed.
- Or email info@aunova.net and ask to be removed.
Withdrawing stops the newsletter going forward. It does not make what we sent before unlawful, and you never have to give a reason.
Open and click tracking
This deserves its own section, because a subscriber would not guess at it.
Every issue we send contains a small tracking image, and the links in it pass through the platform's click tracking. So our subscriber record shows whether an issue was opened and which links in it were clicked, with the time and the technical data listed above. Open tracking is not as reliable as it sounds: many email clients block or pre-load remote images, so the figures are an indication and not a measurement.
We use it for one thing, and at the level of the list rather than the person: to see whether the newsletter is worth reading. We do not build a profile of you, we do not disclose this data to anyone, and nothing about you is decided on the strength of it.
If you would rather not be counted, most email clients can be set to block remote images, which prevents open tracking. If we ever turn open tracking off altogether, we will say so here.
Who else handles your data
beehiiv Inc., 228 Park Avenue S. # 29976, New York, New York 10003, is our processor for this newsletter. It stores the subscriber list, sends the emails, and hosts the signup form and the web archive of past issues. It does that under a data processing addendum with us, which requires it to act on our instructions, forbids it from selling your data, and forbids it from using your data for its own purposes.
beehiiv uses subprocessors of its own, such as infrastructure and email delivery providers. The current list is published at subprocessors.beehiiv.com.
The security measures beehiiv commits to are set out in the information security addendum to that agreement, and include role-based access control, multi-factor authentication on administrative access, network segmentation, logging and vulnerability scanning. No arrangement makes a system perfectly secure, and we do not claim otherwise.
Beyond beehiiv and its subprocessors, nobody receives your data. Not an advertiser, not a partner, not another publication. If the law compelled us to disclose it we would, and we would tell you unless we were forbidden to.
Where your data goes, and the safeguard
beehiiv Inc. is in the United States, so your email address and the engagement data described above leave the European Economic Area.
For that transfer we rely on the Standard Contractual Clauses: the controller-to-processor clauses (Module Two) adopted by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into our agreement with beehiiv. Those clauses are the appropriate safeguard under GDPR Article 46(2)(c). We do not rely on an adequacy decision for this transfer.
The clauses as beehiiv incorporates them are public in its data processing addendum, and we will send you a copy of the version we rely on if you ask.
How long we keep it
- While you are subscribed. We keep your subscriber record for as long as your consent stands, which means until you withdraw it or until we stop publishing the newsletter.
- After you unsubscribe. We delete your subscriber record, and we keep one thing: a minimal suppression record, being your email address and the date you unsubscribed. Nothing else. This is the item in this notice that looks wrong at first glance, so here is the reason. To honour a withdrawal we have to remember that it happened. If we forgot, a later import or a re-added address could quietly put you back on a list you had already left. The suppression record exists only to make that impossible. It is never used to send you anything, and it is not kept on the basis of your consent: it rests on our obligation to give effect to your withdrawal and our legitimate interest in not contacting you again, GDPR Article 6(1)(c) and (f).
- If your address stops accepting mail. We stop sending to it at once, and we delete the record once we no longer need it as evidence of your consent.
- If you never open anything for a long time. We will either ask you to confirm that you still want the newsletter, or delete your record. Consent that is never exercised and never refreshed stops being good evidence of what you currently want.
- Consent evidence. The timestamps of your signup and your confirmation are kept while we are sending you the newsletter, and for a period after that, so we can show your consent was valid if it is ever questioned.
- At the platform. If our agreement with beehiiv ends, beehiiv deletes the personal data it holds for us within 30 days of the end of that agreement.
Two of those periods are deliberately not given as numbers yet: how long an address may sit dormant before we re-ask or delete it, and how long consent evidence is kept after a subscription ends. We are settling both with legal counsel and will state them here once they are fixed, rather than publish a figure we have not decided.
Your rights
You have the following rights over the personal data described in this notice. Exercising any of them is free, and you never have to justify asking.
- Access. Ask whether we hold personal data about you, and get a copy of it together with the information in this notice as it applies to you. GDPR Article 15.
- Rectification. Have inaccurate data corrected and incomplete data completed. Article 16.
- Erasure. Have your data deleted, including where you have withdrawn consent and we have no other basis for holding it. The suppression record described above is the narrow exception, and it exists to protect you. Article 17.
- Restriction. Ask us to limit what we do with your data, for example while a correction is being checked. Article 18.
- Portability. Receive the data you gave us in a structured, commonly used, machine-readable form, and have it sent to another controller where that is technically feasible. Article 20.
- Objection. Object to processing, and in particular object to direct marketing. An objection to direct marketing is honoured without exception and without assessment. Article 21.
- Withdraw consent at any time, as described above, without affecting the lawfulness of what we did before you withdrew it. Article 7(3).
- Complain to a supervisory authority, and seek a remedy in court. See the next section.
We make no solely automated decisions about you that have legal or similarly significant effects, so the Article 22 rights do not arise here. If that ever changes, this notice will change before it does.
How to exercise a right
Email info@aunova.net, or write to the postal address above, and tell us what you want. You do not need to cite a law, use particular words, or fill in a form.
- We confirm the request is yours before we act on it. We reply only to the email address named in the request, and we ask the person named to confirm from that address that the request is theirs. An address in a From line proves nothing on its own. It also means that a request made in your name by somebody else cannot cause your data to be disclosed or deleted, because you would see the confirmation instead of us acting.
- Please do not send identity documents. What we hold is an email address, so confirming control of that address is proportionate, and it is all we ask for.
- We answer within 30 calendar days of receiving your request. If a request is complex we may extend that by up to two further months, in which case we will tell you inside the first 30 days, and why.
- Requests are free.
- If we refuse a request, in whole or in part, we will tell you the reason and how to complain about it.
Complaining to a supervisory authority
We would rather hear from you first, but you are not obliged to come to us at all. You can complain directly to our supervisory authority:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia. Telephone +372 627 4135. Website www.aki.ee.
You may also complain to the data protection authority of the EU or EEA country where you live or work, and you may seek a remedy in court.
Changes to this notice
We update this notice when what we do changes, and the version and date change with it.
Two changes would be too significant to make by quietly editing this page. Turning on any advertising or audience-data feature of the platform, and using the list for anything other than sending this newsletter, would both make the consent you gave inaccurate. In either case we would ask you again rather than reinterpret what you had already agreed to.
Version and effective date
Version MO-PRIVACY-v1.0, in force from 31 July 2026. Consent statement in force: MO-CONSENT-v1.0, dated 31 July 2026.
This notice is pending review by qualified counsel. It is not legal advice.