Legal
Privacy Notice
Last updated: 5 August 2026
This Privacy Notice explains how EFEVRE TECH LTD ("EFEVRE TECH," "we," "us," or "our") collects, processes, and protects personal data through the BioSkepsis biomedical literature platform — accessible via bioskepsis.ai, app.bioskepsis.ai, related APIs, SDKs, plug-ins, and applications (collectively, the "Service"). It is issued under the General Data Protection Regulation (EU) 2016/679 (GDPR), the ePrivacy Directive 2002/58/EC, and Cyprus Law 125(I)/2018.
1. Data Controller and Contact
For all personal data processed through the Service — including account data, queries, uploaded documents, model outputs returned to you, billing information, and support correspondence — EFEVRE TECH LTD acts as the data controller within the meaning of Article 4(7) GDPR.
EFEVRE TECH LTD only acts as a data processor on your behalf where we have entered into a separate written Data Processing Agreement (e.g., for enterprise or institutional customers who upload personal data of their own data subjects). Absent a signed DPA, our default role is controller.
EFEVRE TECH LTD
Limited liability company incorporated in the Republic of Cyprus
Cyprus company registration no.: HE 384880
Registered office: 104 Kykliki Leoforos Street, 6056 Larnaca, Cyprus
Email: [email protected]
We have not appointed a Data Protection Officer because our processing does not meet the thresholds in Article 37(1) GDPR. Privacy enquiries should be sent to the email above. As an EU-established controller, we are not required to designate an Article 27 representative.
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus): www.dataprotection.gov.cy · [email protected], or with the supervisory authority in your EU/EEA Member State of residence.
2. Categories of Data We Process
- Account information: name, email, organisation/affiliation, hashed credentials (managed by Clerk).
- Usage and device data: IP address, user-agent, browser type, device class, timestamps, page views, referrer, and basic technical logs.
- Search and query data: prompts, search terms, filters, uploaded documents, and the AI outputs returned to you. Stored under your account so you can revisit your history.
- Billing data: subscription tier, billing email, transaction identifiers, country, VAT details where applicable. Card and bank data are handled directly by Stripe; we do not store full card numbers.
- Research-interest indicators: topic, entity, methodology, assay, biomarker, target, and therapeutic-area signals derived from your queries and saved papers. These are used to operate and personalise the Service and, only as described in §4, in Commercial Data Products.
- Support correspondence: the content of any messages you send us.
- Cookie and consent data: your cookie-consent choice and the resulting analytics/ad-measurement signals — see the Cookie Policy.
We do not request and do not knowingly collect special categories of personal data under Article 9 GDPR (e.g., health, biometric, or genetic data identifying a living individual). Do not upload such data unless you have a clear legal basis and a compelling need. If you do, you are solely responsible for that processing.
3. Purposes and Legal Bases
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and operate the Service (account, search, AI outputs, billing) | Contract — Art. 6(1)(b) |
| Authentication, security, fraud and abuse prevention | Legitimate interest — Art. 6(1)(f) |
| Service improvement using anonymised, aggregated metrics | Legitimate interest — Art. 6(1)(f) |
| Analytics and ad-measurement cookies | Consent — Art. 6(1)(a) and ePrivacy Art. 5(3) |
| Customer support and product communications | Contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) |
| Compliance with legal, tax, and accounting obligations | Legal obligation — Art. 6(1)(c) |
| Establishment, exercise, or defence of legal claims | Legitimate interest — Art. 6(1)(f) |
| Inclusion of your professional profile in a directory or dataset licensed to life-science organisations (§4.4) | Consent, Art. 6(1)(a). Optional, unbundled, and withdrawable at any time. |
| Anonymising personal data to create aggregated insight products (§4.3) | Legitimate interest, Art. 6(1)(f). The resulting anonymous data falls outside the scope of the GDPR. |
4. Model Training, Data Disclosure, and Commercial Data Products
4.1 No model training. EFEVRE TECH LTD does not use your prompts, uploaded documents, AI outputs, or any other user-provided content to train, fine-tune, or evaluate our own or any third party's machine-learning models.
4.2 Baseline on disclosure. Except in the two cases described in §4.3 and §4.4, we do not sell, license, or otherwise disclose your identifiable content for marketing, profiling, or AI-development purposes. We never disclose your raw prompts, queries, or uploaded documents to any Recipient.
4.3 Anonymised, aggregated insight products. We may process, license, and sell anonymised, aggregated statistical data derived from use of the Service, such as thematic research-interest trends, topic- and entity-frequency indicators, methodology and assay interest, biomarker and target signals, and therapeutic-area demand signals. Recipients may include pharmaceutical, biotechnology, diagnostics, genomics, life-science technology, and research organisations and their agents.
Anonymised, aggregated metrics that cannot reasonably be re-identified (e.g., feature usage rates, latency distributions) are also used to improve the Service.
Anonymisation methodology. Data released under §4.3 is irreversibly anonymised and aggregated so that no individual is reasonably identifiable by any means reasonably likely to be used, whether alone or in combination with other data available to the Recipient. Before any release we run a documented re-identification assessment covering small cohorts, rare or unique query combinations, and free-text that could reveal an individual, and we suppress, generalise, or aggregate further (for example by applying minimum-cohort thresholds) where residual risk exists. Outputs are screened so they do not reveal special-category or sensitive data about any individual, including a user researching their own health condition. Only derived, aggregated indicators are released. Because data meeting this standard is not personal data, this processing does not rely on your consent; the act of anonymising is carried out under our legitimate interests (Art. 6(1)(f)). Every release is made under a written agreement prohibiting re-identification and restricting onward use to the agreed purpose.
4.4 Professional directories (opt-in only). Only if you give prior, specific, freely given, informed and unambiguous opt-in consent, we may include your professional profile in directories or datasets that we license or sell to life-science organisations for professional-engagement purposes.
- Categories of data disclosed: your name, professional email, institutional affiliation, and research-interest indicators derived from your use of the Service. Never your raw prompts, queries, or uploaded documents.
- Categories of Recipients: pharmaceutical, biotechnology, diagnostics, genomics, life-science technology, and research organisations, and agents acting on their behalf.
- Purposes: identification of subject-matter experts, advisory engagement, research collaboration, and scientific exchange.
- Controller-to-controller status: each Recipient acts as an independent data controller for its own use of the data. It is responsible for giving you its own transparency information and for honouring your rights against it. We disclose only under a written agreement requiring compliance with applicable data-protection law, no re-identification, and no unauthorised onward sale.
- Consent is optional and unbundled: your access to the Service, its price, and its functionality do not depend on whether you grant it. It is requested separately from your acceptance of the Terms, with equal prominence given to "yes" and "no".
- Withdrawal: you may withdraw at any time and without detriment from your account settings or by emailing [email protected]. Withdrawal takes effect promptly and removes you from all future releases. It cannot recall data already disclosed to a Recipient, but we will notify Recipients of your withdrawal and require them to cease further processing where the law requires.
- Retention: we include your profile only while your consent remains active. On withdrawal, deletion of your account, or deletion of the underlying data, you are excluded from the next and all subsequent releases. Each Recipient sets its own retention period as an independent controller, and is contractually required to disclose that period to you.
- Sensitive data excluded: we do not knowingly include data revealing your own health condition or other special-category data (Art. 9 GDPR) or "sensitive personal information" under US law. Where such data is detected in free-text it is excluded before disclosure.
4.5 United States: notice of sale and share, and how to opt out. For the purposes of US state privacy laws, our disclosures under §4.4 may constitute a "sale" or "share" of personal information. You may opt out at any time using the "Do Not Sell or Share My Personal Information" link on the Website, and we honour recognised opt-out preference signals, including Global Privacy Control (GPC). We do not sell or share the personal information of a consumer we know to be under 16 without opt-in consent, and we provide the right to limit the use of sensitive personal information where applicable. Disclosures under §4.3 involve anonymous data only and are therefore not a sale or share of personal information.
4.6 These products are forward-looking. Content collected before the effective date of this Notice, under our previous commitment not to disclose it, is not included in any Commercial Data Product. Only data collected after you have been given notice and, where §4.4 applies, have given consent, is eligible for inclusion.
5. Sub-Processors and Recipients
We engage the following sub-processors under written agreements that include the safeguards required by Article 28 GDPR. Each may receive limited categories of personal data strictly necessary for the function described.
| Provider | Purpose | Location | Transfer Mechanism |
|---|---|---|---|
| Clerk, Inc. | Authentication, session management, social login (e.g., Google) | United States | EU SCCs + EU–US Data Privacy Framework (where certified) |
| Stripe, Inc. / Stripe Payments Europe Ltd | Subscription billing, payment processing, fraud prevention | United States; Ireland (EU) | EU SCCs + EU–US DPF |
| Google LLC / Google Ireland Ltd (Vertex AI & Gemini) | Large language model inference for AI outputs | EU regions where available; otherwise United States | EU SCCs + EU–US DPF |
| Google LLC (GA4, Google Tag Manager, Google Ads) | Analytics and ad-conversion measurement (only with your consent) | United States | EU SCCs + EU–US DPF; IP truncation enabled |
| Cloud hosting and CDN provider | Application hosting, storage, content delivery | EEA primary; global edge for static assets | EU SCCs where applicable |
| Allen Institute for AI (Semantic Scholar API) | Bibliographic metadata for biomedical literature search | United States | API queries; minimal personal data transmitted |
| NCBI / U.S. National Library of Medicine (E-utilities, PubMed) | Bibliographic metadata for PubMed records | United States | Public API; minimal personal data transmitted |
Recipients are not sub-processors. The life-science organisations that receive data under §4.4 are not sub-processors acting on our instructions. They are independent data controllers, and the Article 28 framework above does not apply to them. Their receipt of your data is governed by your consent under §4.4 and by a written controller-to-controller agreement. A current list of the categories of Recipients is maintained in §4.4, and we will update it as those categories change.
We may also disclose personal data where required by law, court order, or other lawful request from a competent authority.
6. International Transfers
Several of our sub-processors are located in the United States or process data globally. Transfers outside the EEA are made under the European Commission's 2021 Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, or another transfer mechanism recognised under Articles 45–49 GDPR. Where appropriate, we apply supplementary measures (e.g., encryption in transit and at rest, data-minimisation, and access controls) following our transfer impact assessments.
7. Cookies and Analytics
For users in the EEA, UK, and Switzerland, all non-essential cookies (analytics and ad measurement) are denied by default via Google Consent Mode v2 until you grant consent in the cookie banner or on the Cookie Policy page. We do not use behavioural advertising cookies, and ad personalization is forced to "denied" regardless of consent.
8. Data Retention
- Account data: retained for the lifetime of your account, plus up to 90 days in backups after deletion.
- Search history, prompts, uploaded documents, and AI outputs: retained while your account is active so you can revisit them, and for up to 90 days after account deletion (or earlier deletion request) to allow for backup rotation. You may delete individual items at any time from in-app controls.
- Operational and security logs: retained up to 12 months for security auditing and abuse prevention.
- Billing and tax records: retained for the period required by Cyprus tax and accounting law (currently 7 years).
- Cookie-consent record: retained on your device for up to 12 months so we can respect your choice between visits.
- Anonymised, aggregated data: may be retained and licensed indefinitely as it no longer identifies you (see §4.3).
- Professional-directory inclusion (§4.4): your profile is included only while your opt-in consent remains active. Withdrawal, account deletion, or deletion of the underlying data excludes you from the next and all subsequent releases. Data already released to a Recipient is retained by that Recipient under its own retention policy as an independent controller.
- Consent records: the record of your §4.4 consent or withdrawal, including its timestamp and the version of the Terms in force, is retained for the duration of your account plus 6 years, so that we can demonstrate the lawfulness of processing under Article 7(1) GDPR.
9. Your Rights
Under Articles 15–22 GDPR you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten") subject to legal-retention exceptions;
- restrict processing in certain circumstances;
- receive your data in a portable, machine-readable format;
- object to processing based on our legitimate interests;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with a supervisory authority (see §1).
To exercise any of these rights, email [email protected]. We will respond within one (1) month of verifying your identity, extendable by up to two months for complex or numerous requests as permitted by Article 12(3) GDPR.
Commercial Data Products. In addition to the rights above, you may at any time withdraw your §4.4 consent, or object to that processing, from your account settings or by emailing us. We treat a request to be removed from our data products as covering all future releases, and we notify Recipients of your withdrawal so they can cease further processing where the law requires.
If you are a US resident. Depending on your state, you may also have the right to opt out of the sale or sharing of your personal information and of targeted advertising, to limit the use of sensitive personal information, to access, correct, and delete your personal information, to appeal a refused request, and not to be discriminated against for exercising any of these rights. Use the "Do Not Sell or Share My Personal Information" link on the Website, or email us. We honour recognised opt-out preference signals including Global Privacy Control (GPC).
10. Automated Decision-Making (Article 22 GDPR)
BioSkepsis uses generative-AI models to produce literature summaries, citations, and answers in response to your queries. These outputs are informational and decision-support tools intended to be reviewed by you. We do not make any decision that produces legal effects or similarly significant effects concerning you (such as credit, employment, healthcare, insurance, or access to essential services) based solely on automated processing within the meaning of Article 22(1) GDPR.
11. Personal Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Cyprus supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, we will notify affected data subjects without undue delay, in accordance with Article 34 GDPR.
12. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, role-based access controls, audit logging, secret rotation, dependency monitoring, and routine vulnerability assessments. No system is perfectly secure, and you remain responsible for the confidentiality of your credentials.
13. Social Logins (Clerk / Google)
Authentication is provided by Clerk, which supports email/password and social login (e.g., Google). If you sign in with a social provider, we receive basic profile data (such as email, name, and avatar URL) from that provider. We never receive your social-account password. Your use of the social provider remains subject to that provider's own terms and privacy policy.
14. Account Management and Deletion
You can view and update your account details from in-app account settings (managed by Clerk). To delete your account, use the in-app delete control where available or email [email protected]. Following a verified deletion request, we will erase your account from active systems within 30 days and from backups within 90 days, except where retention is legally required (see §8).
15. Children's Privacy
The Service is intended for professional and academic use by persons aged 18 or older. We do not knowingly collect personal data from children. If you are a parent or guardian and believe a child has provided personal data, contact [email protected] and we will delete the account and associated data without undue delay.
16. Third-Party Websites
The Service may contain links to third-party websites and resources (for example, publisher pages, PubMed records, or Semantic Scholar). Their privacy practices are not covered by this Notice. Please review the applicable third-party privacy policies before sharing personal data with them.
17. Updates to This Notice
We may update this Privacy Notice to reflect legal, technical, or operational changes. The "Last Updated" date above will always reflect the most recent revision. Material changes will be communicated through the Service or by email where appropriate. Continued use of the Service after the effective date of an update constitutes acceptance of the revised Notice.
18. Contact
Questions or requests should be directed to: [email protected].
