Privacy Policy
Effective date: April 3, 2026
1. Data controller
The data controller is the platform operator identified on the website. This Policy explains how personal data is collected, used, shared, and protected.
2. Scope
This Policy applies to website, applications, authentication features, subscriptions, billing, and support related to the service, for both individual and institutional accounts.
3. Data we collect
We may collect registration data (first name, last name, email, username), organizational data (institution and role), authentication data (including federated identity provider), technical usage data (logs, IP, device), and transactional data related to subscriptions and payments.
4. Processing purposes
We process data to: (a) create and manage accounts; (b) provide and improve the service; (c) manage security and fraud prevention; (d) process payments and billing; (e) comply with legal obligations; and (f) handle support requests.
5. Legal bases
We process data based on contract performance, legal compliance, legitimate interest (security and service improvement), and, where applicable, consent. For institutional data, the organizational customer may act as an additional controller under its own policy.
6. Data retention
We retain data for as long as necessary for the stated purposes, legal obligations, and claims defense. Data is then securely deleted or anonymized unless a longer retention period is legally required.
7. Sharing and processors
We may share data with technology and payment providers acting as processors under contractual confidentiality and security obligations. We do not sell personal data. Data is disclosed to authorities only when legally required.
8. International transfers
Where international data transfers occur, appropriate safeguards are applied under applicable legal frameworks (for example, standard contractual clauses or other valid mechanisms).
9. Security
We implement reasonable technical and organizational safeguards (access control, encryption in transit, monitoring, and operational best practices). No system is fully invulnerable, so absolute security cannot be guaranteed.
10. Data subject rights
You may request access, rectification, update, deletion, objection, or portability of your data, subject to applicable law. You may also withdraw consent where processing depends on consent, without affecting prior lawful processing.
11. Cookies and similar technologies
We use cookies and similar technologies for session management, security, preferences, and operational analytics. You can manage cookies in your browser, though some features may be affected.
12. Children
The platform is not directed to children without required legal authorization. If unauthorized children data processing is detected, we will take steps to delete data as required.
13. Policy changes
We may update this Policy due to legal, regulatory, technical, or business changes. The current version is published with its effective date.
14. Contact and supervisory authority
To exercise privacy rights or submit inquiries, use the contact channel published on the platform. Where applicable, you may also contact your local data protection authority.