← Back to home

Privacy Policy

Information pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

Last updated: 2026-04-22

Note: BioProGuide is currently in pre-launch. This policy describes the data-protection framework that will apply when V1.0.0 goes live.

1. Controller

The controller responsible for the processing of personal data on this website is:

Alexander Pekarsky

Austria (postal address available on request to legal@bioproguide.com)

Email: privacy@bioproguide.com

2. Scope and summary

This Privacy Policy applies to the website bioproguide.com and to all related sub-pages and services provided thereunder (collectively, the "Service"). It explains what personal data we collect, why we collect it, with whom we share it, and what rights you have.

Important: the BioProGuide application itself runs entirely in your web browser. Protein sequences, structural data, FASTA files, bioprocess parameters, and any computational outputs generated by the tool are processed locally on your device and are never transmitted to our servers, never stored by us, and never accessible to us.

3. Data we collect

3.1 Account data (collected when you register)

3.2 Usage data

3.3 Server-side logs

Our hosting provider (Vercel) automatically logs standard HTTP request metadata for security and abuse prevention:

These logs are retained for up to 30 days and are accessed only for security investigations.

3.4 Analytics

We use a privacy-friendly analytics tool (Plausible Analytics, EU-hosted) that collects aggregated, cookie-less pageview counts and referrer data. No personal data is transmitted, IP addresses are anonymised, and no cross-site tracking occurs.

3.5 Bot protection

During signup, we use hCaptcha to verify that you are a human. hCaptcha processes technical data (IP address, browser signals, cookies set by Intuition Machines, Inc.) for this purpose. See the hCaptcha Privacy Policy at https://www.hcaptcha.com/privacy.

3.6 What we do NOT collect

4. Purposes and legal bases

We process your personal data for the following purposes and on the following legal bases:

PurposeData processedLegal basis (GDPR)
Account managementEmail, OAuth identifier, hashed passwordArt. 6(1)(b) — performance of contract
Email verificationEmail, verification tokenArt. 6(1)(b) — performance of contract
Rate-limit enforcementUser ID, daily usage counterArt. 6(1)(f) — legitimate interest (fair use)
Bot preventionIP address, browser signals (hCaptcha)Art. 6(1)(f) — legitimate interest (security)
Server-side security logsIP address, user agent, timestampArt. 6(1)(f) — legitimate interest (security)
Aggregated analyticsPageview counts, referrer, country (anonymised)Art. 6(1)(f) — legitimate interest (service improvement)
Service communicationsEmail, message contentArt. 6(1)(b) / (f) — contract / legitimate interest

5. Retention

6. Recipients and sub-processors

We do not sell or rent personal data. We share personal data only with the sub-processors listed below, each of which is bound by a data-processing agreement (DPA) and processes data only on our instructions.

ProcessorLocationPurposeSafeguards
Vercel Inc.USAWebsite hosting, CDN, server-side request logsEU Standard Contractual Clauses; EU-US Data Privacy Framework
Supabase Inc.Germany (Frankfurt region)Authentication, user account database, session managementEU hosting; Data Processing Agreement in place
Resend Inc.USATransactional email delivery (verification, password reset)EU Standard Contractual Clauses
Intuition Machines, Inc. (hCaptcha)USABot and abuse prevention on signup formsEU Standard Contractual Clauses
Plausible AnalyticsGermany / EUPrivacy-friendly, cookie-less aggregated analyticsEU hosting; no personal data or cross-site tracking
Proton AGSwitzerlandInbound email hosting for info@/privacy@/legal@bioproguide.comSwiss DPA (adequate under Art. 45 GDPR); end-to-end encrypted where supported
Formspree Inc.USAPre-launch waitlist signup-form handlingEU Standard Contractual Clauses

7. International transfers

Where a processor is located outside the European Economic Area (EEA), transfers are safeguarded by EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR and, where applicable, by certification under the EU-US Data Privacy Framework or an adequacy decision under Art. 45 GDPR.

8. Your rights

Under the GDPR you have the following rights:

You can exercise these rights by emailing privacy@bioproguide.com. You may also delete your account at any time from your account settings page; account deletion triggers the erasure of associated personal data within the retention limits described in Section 5.

9. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Austria is:

Österreichische Datenschutzbehörde

Barichgasse 40-42, 1030 Wien, Austria

Email: dsb@dsb.gv.at · Web: https://www.dsb.gv.at

10. Security

We implement reasonable technical and organisational measures to protect your personal data, including:

11. Cookies

We use only strictly necessary cookies required for the authentication session (so that you remain logged in across page loads). We do not use advertising, profiling, or cross-site tracking cookies. Because no non-essential cookies are used, no cookie consent banner is required under the EU ePrivacy Directive. Our analytics tool is cookie-less.

12. Children

The Service is not directed at individuals under the age of 16. If you are under 16, please do not register for or use the Service. If we become aware that a child under 16 has provided us with personal data, we will delete the account.

13. Automated decision-making

The tool performs automated scientific computations at your request, but does not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version is always published at bioproguide.com/privacy with the revision date. Material changes will additionally be communicated by email to registered users at least 14 days before they take effect.

15. Contact

Questions about this Privacy Policy or data-protection matters: privacy@bioproguide.com