GDPR and Data Protection
Last updated: June 28, 2026 | Effective: June 6, 2026
Our commitment
BCINexus designs BCILattice around local computation and data minimization. This page summarizes rights and controls for users covered by the GDPR, UK GDPR, and similar data-protection laws. It should be read with the Privacy Policy and any signed data processing agreement.
Legal bases for processing
- ContractAccount access, subscriptions, team workspaces, support, and requested product features.
- Legitimate interestsSecurity, fraud prevention, reliability, abuse prevention, product analytics, and product improvement.
- ConsentMarketing communications and other optional processing where consent is required.
- Legal obligationBilling records, tax records, compliance requests, and legally required disclosures.
Your rights
Access
Request a copy of personal data we hold about you.
Rectification
Correct inaccurate or incomplete personal data.
Erasure
Request erasure where the law requires or permits it, subject to retention limits.
Portability
Request supported account data in a machine-readable format where available.
Objection
Object to certain processing based on legitimate interests.
Restriction
Ask us to limit processing while a request or dispute is reviewed.
Controller and processor roles
BCINexus is generally a controller for account, billing, website, support, analytics, security, and platform operations data. For uploaded datasets or project materials in an institution-managed workspace, the institution may act as controller and BCINexus may act as processor under a signed data processing agreement.
Retention and erasure limits
Privacy removal, anonymization, export, objection, restriction, or erasure requests are reviewed manually through [email protected]. Requests may be limited where data is needed for reviewer activity, research papers, publications, security records, billing records, legal records, backups, disputes, abuse prevention, platform integrity, or publication integrity.
International transfers
Where personal data is transferred internationally, BCINexus uses appropriate safeguards required by applicable law, such as contractual commitments, subprocessor agreements, and Standard Contractual Clauses where relevant. Region-specific deployment requires a separate enterprise agreement.
Responsible party
Responsible party: BCINexus. Formal legal entity name, registered address, DPO, EU representative, and UK representative details require business/legal approval before publication. Until those details are approved, privacy requests should be sent to [email protected] and legal notices to [email protected].
Exercising your rights
Email [email protected]. We may request identity verification before acting on a request. You may also contact your local supervisory authority.