Back to Home
Legal

Privacy Policy

Last updated: December 29, 2025

At Ekayana, we are committed to protecting your privacy and ensuring the security of your research data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Bio-AI DIDs sequencer platform and related services.

Our platform is designed with privacy as a core principle, leveraging decentralized technologies and GDPR-compliant practices to give you control over your data.

Information We Collect

We collect information you provide directly to us, including:

  • Account Information: Email address, name, organization, and authentication credentials when you create an account.
  • Research Data: Files, datasets, and metadata you upload to our platform.
  • Usage Data: Information about how you interact with our services, including API calls, storage usage, and feature utilization.
  • Technical Data: IP addresses, browser type, device information, and access logs for security and performance optimization.

We use content-addressed storage (IPFS), meaning your data is identified by its cryptographic hash rather than location, enhancing both security and integrity.

How We Use Your Information

Your information is used to:

  • Provide Services: Store, retrieve, and manage your research data using decentralized infrastructure.
  • Maintain Security: Protect against unauthorized access, fraud, and abuse through UCAN-based authorization.
  • Improve Platform: Analyze usage patterns to enhance performance and develop new features.
  • Communicate: Send service updates, security alerts, and respond to your inquiries.
  • Comply with Law: Meet legal obligations and respond to lawful requests from authorities.

We never sell your personal information or use your research data for purposes other than providing our services.

GDPR Compliance

As a GDPR-compliant platform, we ensure:

  • Data Minimization: We collect only the data necessary to provide our services.
  • Purpose Limitation: Your data is used only for the purposes stated in this policy.
  • Storage Limitation: Data is retained only as long as necessary for the stated purposes.
  • Integrity & Confidentiality: We implement robust security measures including encryption and access controls.
  • Accountability: We maintain records of processing activities and conduct regular audits.

Our decentralized architecture ensures that you maintain control over your data at all times through capability-based authorization (UCAN).

Your Rights

Under GDPR and applicable privacy laws, you have the right to:

  • Access: Request a copy of your personal data we hold.
  • Rectification: Correct inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Restriction: Limit how we process your personal data.
  • Portability: Receive your data in a structured, machine-readable format.
  • Object: Object to processing based on legitimate interests.
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise these rights, contact us at privacy@ekayana.com. We respond to all requests within 30 days.

Data Transfers

Your data may be processed in multiple locations due to our decentralized infrastructure:

  • IPFS Network: Content is distributed across nodes globally for redundancy and availability.
  • Filecoin Storage: Long-term archival may involve storage providers in various jurisdictions.
  • Processing Servers: API requests are processed in data centers with appropriate security certifications.

For transfers outside the EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Your explicit consent for specific transfers

All transfers maintain the same level of protection as required by GDPR.

Data Security

We implement comprehensive security measures:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Content Addressing: IPFS CIDs provide tamper-evident storage with cryptographic verification.
  • Access Control: UCAN-based capability authorization ensures fine-grained permissions.
  • Audit Logging: All access to your data is logged for compliance and security monitoring.
  • Post-Quantum Cryptography: ML-DSA-87 signatures (FIPS 204) authenticate identity and authorization, and ML-KEM-1024 (FIPS 203) protects stored content against "harvest now, decrypt later" attacks.
  • Regular Audits: We conduct security assessments and penetration testing.

In case of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR.

Questions About Privacy?

Contact our Data Protection Officer at privacy@ekayana.com

Contact Us