This Policy explains what personal data GeneData ("we") collects, why, how we use it, and the rights you have.
What we collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Account data | name, email, password hash | You, at signup | Authentication, support, billing |
| Workspace data | workspace name, member list, role | You | Multi-tenant isolation |
| Customer Data | datasets you upload, pipeline definitions, AI prompts you send | You | The Service itself |
| Usage telemetry | which pages you visit, request counts, feature usage | Auto-collected | Improve the product, capacity planning, billing |
| Diagnostic data | error stack traces, slow queries (PII-redacted before storage) | Auto-collected | Debug + improve reliability |
| Audit log | who did what action, when, from what IP | Auto-collected | Security + compliance |
| Billing data | payment method (stored by Stripe, not us), invoice history | You + Stripe | Process payments |
We do NOT collect: government ID numbers, financial account numbers beyond what Stripe stores, health information (unless your Customer Data contains it — see §HIPAA below), or location data beyond IP address.
How we use it
- Provide the Service
- Bill you accurately
- Send transactional emails (password reset, invoice, security alerts) — see email templates
- Improve the Service via aggregated, de-identified analytics
- Comply with legal obligations (subpoenas, audit requirements)
- Detect fraud + abuse
- We will NEVER sell or share personal data with advertisers
How long we keep it
| Category | Retention |
|---|---|
| Account data | Life of the account + 30 days after closure |
| Customer Data | Life of the account + 30 days after closure |
| Audit log | 7 years (cold-archived after 90 days to S3 Object Lock — see audit retention CronJob) |
| Email log | 90 days |
| Backups | 14 days daily + 8 weekly + 12 monthly + 7 yearly |
| Diagnostic data | 30 days (raw); 13 months (aggregated/de-identified) |
Your rights (GDPR / CCPA)
You can:
- Access all personal data we hold about you — request via
dsar@genedata.ioor in-app - Correct inaccurate data — edit in your dashboard or request
- Delete ("right to be forgotten") — purge runs within 30 days of request; audit-log entries are anonymized (your email replaced with
[REDACTED]) but retained for compliance - Export (data portability) — JSON archive of your workspace data, available on demand
- Restrict processing — pause us from using your data while a dispute resolves
- Object to processing — opt-out of non-essential telemetry
- Withdraw consent — disable optional AI features that send data to third-party LLMs
Implementation: apps/api/src/lib/dsar-deletion.ts walks every table that holds subject data and either deletes or anonymizes.
Subprocessors
See subprocessors.md (referenced from the DPA). We notify customers 30 days before adding a new subprocessor that processes Customer Data.
International transfers
If you're in the EU, EEA, or UK, your data may be transferred to the US under Standard Contractual Clauses or the EU-US Data Privacy Framework (where applicable). Enterprise customers can opt for EU-region hosting (architecture supports this; contact sales).
Cookies + tracking
We use functional cookies only (authentication, preferences). No third-party advertising cookies. No tracking pixels in transactional emails.
Children
The Service is not for users under 16. We do not knowingly collect data from minors.
Security
We protect your data using:
- TLS 1.2+ in transit
- AES-256-GCM at rest for secrets (secret-crypto.ts)
- Annual penetration tests
- SOC 2 Type II (in progress; evidence collected monthly via collect-evidence.sh)
- Per-tenant network isolation in our K8s cluster (NetworkPolicy)
- PII-redacted logs (pii-redactor.ts)
Breach notification: we will notify affected customers within 72 hours of confirming a security incident affecting their data, per GDPR Art. 33.
HIPAA / regulated data
GeneData is NOT a HIPAA-covered entity by default. Enterprise customers handling Protected Health Information must sign a HIPAA BAA before uploading PHI. Without a BAA, you agree not to upload PHI to the platform.
Contact
- Privacy questions: privacy@genedata.io
- Data Protection Officer (EU): dpo@genedata.io (designate person)
- DSAR requests: dsar@genedata.io
Changes
We'll notify you of material changes via in-app banner + email at least 30 days before they take effect.