Legal | Data Protection

GDPR and Data Protection

Last updated: June 28, 2026 | Effective: June 6, 2026

Our commitment

BCINexus designs BCILattice around local computation and data minimization. This page summarizes rights and controls for users covered by the GDPR, UK GDPR, and similar data-protection laws. It should be read with the Privacy Policy and any signed data processing agreement.

Legal bases for processing

  • ContractAccount access, subscriptions, team workspaces, support, and requested product features.
  • Legitimate interestsSecurity, fraud prevention, reliability, abuse prevention, product analytics, and product improvement.
  • ConsentMarketing communications and other optional processing where consent is required.
  • Legal obligationBilling records, tax records, compliance requests, and legally required disclosures.

Your rights

Access

Request a copy of personal data we hold about you.

Rectification

Correct inaccurate or incomplete personal data.

Erasure

Request erasure where the law requires or permits it, subject to retention limits.

Portability

Request supported account data in a machine-readable format where available.

Objection

Object to certain processing based on legitimate interests.

Restriction

Ask us to limit processing while a request or dispute is reviewed.

Controller and processor roles

BCINexus is generally a controller for account, billing, website, support, analytics, security, and platform operations data. For uploaded datasets or project materials in an institution-managed workspace, the institution may act as controller and BCINexus may act as processor under a signed data processing agreement.

Retention and erasure limits

Privacy removal, anonymization, export, objection, restriction, or erasure requests are reviewed manually through [email protected]. Requests may be limited where data is needed for reviewer activity, research papers, publications, security records, billing records, legal records, backups, disputes, abuse prevention, platform integrity, or publication integrity.

International transfers

Where personal data is transferred internationally, BCINexus uses appropriate safeguards required by applicable law, such as contractual commitments, subprocessor agreements, and Standard Contractual Clauses where relevant. Region-specific deployment requires a separate enterprise agreement.

Responsible party

Responsible party: BCINexus. Formal legal entity name, registered address, DPO, EU representative, and UK representative details require business/legal approval before publication. Until those details are approved, privacy requests should be sent to [email protected] and legal notices to [email protected].

Exercising your rights

Email [email protected]. We may request identity verification before acting on a request. You may also contact your local supervisory authority.