LEGAL

Privacy Policy

Effective Date: [Insert Date]|Version 4.1

This Privacy Policy governs the processing of personal and scientific data across the Skygenic Platform. It is incorporated by reference into the Skygenic Terms of Use and the SRL Governance Framework. In the event of conflict, the Terms of Use shall control. The SRL Governance Framework, incorporated herein by reference, provides the authoritative technical definitions of how user data is processed within the Scientific Reasoning Layer, including the Common Knowledge Threshold (CKT), Collective Discovery Signals (CDS), and the 70-scan inference architecture.

1. Definitions and Scope

"Platform": Skygenic systems, including SRL, AI models, scan engines, and analytical outputs, as further described in the SRL Governance Framework.

"SRL": The Scientific Reasoning Layer, Skygenic's network inference system. See SRL Governance Framework for full technical definitions.

"Scientific Signals": All derived outputs, including convergence, contradiction, confidence, and gap metrics.

"User Data": All account, scientific, and usage inputs submitted to the Platform.

"Report Outputs": Aggregated, non-reconstructable SRL outputs.

"Data Controller": Skygenic Inc. is the data controller under GDPR where applicable.

The Platform integrates public scientific data, private research inputs, system-generated network signals, and multi-scan analytical outputs (including up to 70 extensible scans). The SRL is a network inference system, not a deterministic truth engine or database.

2. Legal Basis for Processing

Where applicable, we process personal data under the following legal bases:

  • Performance of contract (Platform provision and account management).
  • Legitimate interests (scientific research, system operation, security, and improvement).
  • User consent (where expressly required by applicable law).
  • Legal obligation compliance.

Where multiple regulatory regimes apply (GDPR, LGPD, CPRA, PIPEDA, POPIA, APAC frameworks), we apply the highest reasonable privacy standard required for the user's jurisdiction.

3. Information We Collect

3.1 Account and Identity Data

  • Name
  • Email address
  • Institutional affiliation (if provided)
  • Authentication credentials
  • Billing and subscription data (if applicable)
  • Employer and professional information

3.2 Scientific and Research Inputs

Users may submit hypotheses, datasets, experimental results, structured biological or computational inputs, analytical queries, and SRL interaction history. Such inputs are treated as scientific signals and not as verified truth. They are not attributed to individuals in outputs and are processed within the SRL network inference system as described in the SRL Governance Framework.

3.3 System and Usage Data

We collect platform usage logs, system telemetry, feature interaction data, device and browser metadata, and strictly necessary session cookies (see Cookie Policy).

3.4 Derived SRL Network Signals

The Platform generates convergence signals, contradiction signals, confidence scores, gap classifications, and structural network metrics. These are derived from aggregated inputs, are non-attributable, and are non-reconstructable to individual users or datasets. See the SRL Governance Framework for a full description of signal generation, the CKT mechanism, and the CDS framework.

3.5 Genomic and Submitted Data

Users may submit genomic data and associated metadata ("Submitted Data"). Submitted Data shall only be provided in compliance with applicable laws and any applicable third-party agreements. Upon submission, users grant Skygenic the right to aggregate Submitted Data into non-identifying Aggregated Data and to use such Aggregated Data to improve the Platform. Where Submitted Data constitutes Protected Health Information, a Business Associate Agreement must be in place (see Section 11).

3.6 Payment Information

We may collect billing information including payment card details or bank transfer information. Skygenic does not store payment card information directly. Such information is processed by authorized third-party payment processors (which may include processors such as Stripe, Inc. or similar services) subject to their respective privacy and security policies. Payments may also be made via invoice and bank direct deposit, in which case only the information necessary to process the transaction is collected. By submitting payment information, you consent to its processing by our designated payment processor(s).

3.7 Automated Processing Disclosure

The Platform performs automated processing including statistical inference, graph-based scientific modeling, multi-scan evaluation, and semantic analysis. These may constitute automated profiling for scientific research purposes. However, no decision producing legal or similarly significant effects is made solely by automated processing without human interpretation.

4. How We Use Your Information

4.1 Platform Operation

  • Account management, authentication, and access control.
  • System execution and report generation.
  • Billing and payment processing.
  • Legal compliance.

4.2 Scientific Network Inference (SRL)

We process data to generate network-level scientific signals, mechanistic inference scores, convergence and contradiction detection, and gap identification. SRL outputs are scientific signals, not scientific truth. For the full technical description of how user data moves through the SRL, see the SRL Governance Framework.

4.3 Collaboration and Connectivity

Where explicitly enabled, blind collaboration signals, overlap detection, and optional connectivity pathways may be generated. No identity, dataset content, or attribution is disclosed without explicit user authorization.

4.4 System Improvement

We may use aggregated or de-identified data to improve SRL scan architecture, refine weighting and inference systems, enhance semantic agent performance, and improve system reliability.

4.5 Communications

We may send system notifications, research insights, and platform updates. Users may opt out of non-essential communications at any time by emailing opt-out@skygenic.com.

5. Data Classification and the SRL Governance Framework

Skygenic operates a structured data classification model. The full technical definitions of each classification tier, the Common Knowledge Threshold (CKT), and the Collective Discovery Signal (CDS) mechanism are set forth in the SRL Governance Framework, which is incorporated into this Privacy Policy by reference. A summary is provided below.

  • Public Data: Published literature, public datasets, preprints, and open repositories. May be cited, attributed, and directly integrated into SRL structure.
  • Private Data: User hypotheses, institutional datasets, and unpublished research. Remains non-attributable, is not exposed in raw form, and contributes only to aggregated network signals.
  • Common Knowledge Threshold (CKT): Private data may only transition into aggregated SRL structure when independently validated across multiple organizations or supported by public scientific data. Single-source repetition is insufficient.
  • Non-Verification Standard: User scientific inputs are not validated at ingestion, not verified for correctness, and not assumed to be true. They are processed solely as structured scientific signals.

6. Data Sharing and Disclosure

We do not sell personal data.

We may share data only in the following circumstances:

  • Service Providers: Cloud infrastructure providers (including Google Cloud Platform), payment processors, analytics providers, and security vendors, under appropriate data processing agreements.
  • Institutional Deployments: Governed by separate contractual agreements.
  • Legal Compliance: In response to valid legal requests, court orders, or regulatory obligations.
  • Corporate Transactions: In the event of a merger, acquisition, or asset transfer, personal data may be transferred as part of that transaction, subject to equivalent privacy protections.
  • With Your Consent: For any other purpose with your prior written consent.

Where data is shared with other users for collaborative research, such sharing is governed by user-controlled permission settings. Users are responsible for ensuring that any sharing of Protected Health Information complies with applicable law.

7. International Data Transfers

Data may be processed in the United States, European Union/EEA, United Kingdom, Canada, Brazil, Singapore, Australia, South Africa, and other jurisdictions. Safeguards for cross-border transfers include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission where applicable.
  • Participation in the EU-U.S. Data Privacy Framework (DPF), where certified.
  • Adequacy decisions recognized under applicable law.
  • Encryption in transit and at rest.
  • Least-privilege access controls.

EU, UK, and Swiss individuals may direct privacy inquiries to dpo@skygenic.com. Unresolved complaints may be referred to JAMS Dispute Resolution (www.jamsadr.com), provided at no charge to the individual, as our designated independent recourse mechanism.

8. Data Security

Skygenic and its infrastructure partner, Google Cloud Platform, implement industry-standard security measures including:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Role-based access control and least-privilege principles.
  • Audit logging retained for a minimum of six (6) years in compliance with HIPAA requirements.
  • Monitoring, intrusion detection, and incident response procedures.
  • OWASP Top 10 security risk prevention controls.
  • Physically secured data center infrastructure managed by Google Cloud Platform.

No system guarantees absolute security. Transmission of information via the internet is at your own risk. You are responsible for maintaining the confidentiality of your login credentials.

9. Data Retention

9.1 Account Data

Retained while your account is active. Upon verified written request, account information (name, email, phone number, employer) will be removed, subject to legal and technical constraints.

9.2 Research Contributions and Audit Logs

Scientific inputs may be retained for as long as necessary for SRL scientific and system integrity purposes. HIPAA-mandated audit logs are retained for a minimum of six (6) years and cannot be altered once created. Deletion requests apply to raw account data only and do not retroactively alter derived SRL network states already generated.

9.3 Submitted Data

It is your responsibility to remove data files from the Platform prior to account termination. Upon termination, data files not removed by the user will be deleted, subject to any applicable legal hold requirements.

10. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

  • Access: Request confirmation of whether we hold personal data about you and obtain a copy.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to legal and technical constraints (see Section 9).
  • Data Portability: Request your data in a structured, machine-readable format where applicable.
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Opt-Out of Communications: Opt out of non-essential marketing communications.
  • California Residents — Do Not Sell/Share: California residents may request that we do not sell or share their personal information. We do not sell personal data. To exercise any opt-out right, contact opt-out@skygenic.com.

To exercise any of the above rights, please contact dpo@skygenic.com or opt-out@skygenic.com for opt-out requests. We will respond within thirty (30) days of receiving a verifiable request, or within such other period as required by applicable law. We may require identity verification before processing requests.

11. Protected Health Information and HIPAA

You agree not to input or submit Protected Health Information (PHI) to the Platform unless a Business Associate Agreement (BAA) is in place with Skygenic. The BAA is available on our website. By creating a Skygenic user account, you are deemed to accept Skygenic's standard BAA unless a custom BAA has been separately executed. Custom BAA inquiries should be directed to legal@skygenic.com.

Skygenic acts as a Business Associate under HIPAA and maintains audit logs and security controls as required. Users, as Covered Entities or Business Associates, are responsible for ensuring that PHI is shared only with authorized personnel and that all applicable HIPAA obligations are fulfilled.

12. Children's Privacy

The Services are not intended for individuals under the age of 13 (or the applicable age of majority in the user's jurisdiction). We do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal data from a minor, we will delete it promptly. Contact dpo@skygenic.com if you believe we have collected data from a minor.

13. AI Systems and Network Signal Disclaimer

The Platform is a scientific infrastructure system. You acknowledge that outputs are probabilistic and non-deterministic; outputs are network-derived signals, not factual determinations; system behavior may change over time; all outputs are intended to generate scientific insight, not conclusions; and users are solely responsible for interpretation and validation. SRL outputs are aggregate network signals that are not individually attributable and may reflect incomplete or biased datasets. See the SRL Governance Framework for full technical disclosure.

14. No Clinical or High-Risk Use

The Platform must not be used for clinical diagnosis or treatment, patient care, regulatory submissions, medical decision-making, or safety-critical applications.

15. Third-Party Links and Services

The Services may contain links to third-party websites and resources. These links are provided for convenience only. Skygenic has no control over the contents of those sites and accepts no responsibility for them or for any loss or damage arising from their use. Accessing third-party websites is at your own risk and subject to the terms of those sites.

16. Copyright Infringement (DMCA)

If you believe that any content on the Platform infringes your copyright, please send a notice of copyright infringement to legal@skygenic.com including: (i) a description of the copyrighted work claimed to be infringed; (ii) identification of the infringing material; (iii) your contact information; (iv) a statement of good faith belief; and (v) a statement, made under penalty of perjury, that the information in the notice is accurate and that you are the copyright owner or authorized to act on their behalf. It is our policy to terminate the accounts of repeat infringers.

17. Accessibility

Skygenic is committed to making the Services accessible to users with disabilities. We strive to comply with applicable accessibility standards, including WCAG 2.1 guidelines where feasible. If you experience accessibility barriers, please contact info@skygenic.com.

18. Geographic Restrictions

Skygenic is based in the United States. We make no representation that the Services are appropriate or available outside the United States. Users who access the Services from outside the United States do so on their own initiative and are responsible for compliance with local laws. If your Submitted Data must be restricted to a specific geographic region, it is your responsibility to enable such restriction within the Platform.

19. Changes to This Policy

We may update this Privacy Policy at any time. The updated version will be posted with a revised effective date. For material changes, we will provide notice by: (i) posting a prominent notice on the website; and (ii) where you are a registered Platform user, displaying a notification banner at your next Platform login. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

20. Governing Framework Integration

This Privacy Policy is integrated with and subject to the Skygenic Terms of Use (controlling) and the SRL Governance Framework (technical specification). In the event of conflict between this Policy and the Terms of Use, the Terms of Use shall prevail.

21. Contact and Data Protection Officer

Appendix A — EU AI Act Transparency & System Disclosure

This Appendix is provided to align with EU AI Act transparency obligations (including Articles 12, 13, 14, and 50 where applicable) and supports the broader global AI compliance framework described in the SRL Governance Framework.

  • A.1 System Classification: The Platform is a scientific research AI-based inference system. It is not a clinical, legal, or safety-critical system and is not designated as a high-risk AI system under Annex III of the EU AI Act as of the effective date.
  • A.2 Nature of AI Processing: The SRL includes deterministic computational scans, statistical inference models, graph/network-based reasoning, and semantic agent-based analysis. Outputs represent probabilistic scientific inference.
  • A.3 Output Transparency: Outputs are generated via automated processing, may be incomplete or biased, and require expert interpretation.
  • A.4 Human Oversight: No output is intended for direct consequential use without human expert review and independent validation.
  • A.5 Data Usage for AI: Inputs may be processed for model inference, system improvement, and network signal generation. No personal data is used to produce individualized legal or significant effects.
  • A.6 Non-Substitution: The Platform does not replace scientific judgment, clinical expertise, or regulatory decision-making.
  • A.7 Classification Evolution: Risk classification may evolve depending on deployment context and jurisdiction.