Privacy notice
Information on the processing of personal data by Eclose, RNA-seq analysis, provided under Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”).
Last updated: 2026-10-03
1. Controller and contact
Aspis-Bio — operated by Marco Gualtieri runs this console and decides why and how your personal data is processed (the “controller”, Art. 4(7) GDPR).
Contact address for every request under this notice: main@aspis-bio.com.
2. Scope of this notice
This notice applies to Eclose, the RNA-seq analysis console (the “service”), which the controller offers by invitation only. It covers:
- the MCP server, through which your AI assistant (Claude, through claude.ai, Claude Desktop or Claude Code; or Codex) uses your account;
- the personal area at /results, where you see your jobs and download your results;
- the optional recovery email;
- the feedback tool (console_feedback), through which your assistant can send the controller a request, suggestion, problem report or opinion on your behalf and with your OK.
It also covers the requests you send by email to the contact address in section 1 — for example a request for access to the service. The data are your email address and what you write; the legal basis is Art. 6(1)(b) GDPR (steps taken at your request before an agreement) or, for other correspondence, Art. 6(1)(f); they are kept until the request is closed and for at most 12 months after that, unless an account is created for you, in which case the rules for the account apply (sections 3, 4 and 8).
3. Categories of data and their sources
Per processing activity: the data processed and where they come from. The data are provided by you, directly or through your AI assistant, or are generated by the console when you use it.
Account and access
Your account: the user id the controller gave you, your role, the date it was created, your weekly quota and a one-way hash (SHA-256) of your access token. Your token itself is never stored: it is shown once, when it is issued, and only its hash is kept in the controller's configuration file on the controller's own computer. The OAuth connection records also keep only hashes.
Source The controller, when it creates your account (user id, role, quota); the console, when it issues your token (shown to you once).
Sequencing files (FASTQ)
Your sequencing files (FASTQs) that you upload or ask the console to download.
Source You: uploaded from your computer, or fetched by the analysis server from the links you give (for example ENA, Dropbox, a sequencing provider).
Results, run files and job records
Results and run files: tables, reports, quality control, the record of what was run, progress messages, and the job record with the sample names, file names and conditions you chose, the cost of the job and any refund.
Source Generated by the analysis from your files and from the settings, sample names, file names and conditions you chose; the cost of each job is computed by the console and counted against your limits.
Security log
A security log: time, your user id, which action, whether it worked and a short note. For the steps of connecting an AI app to your account (OAuth), the log also holds your IP address.
Source Generated by the console when you or your AI assistant use it; the IP address, in the OAuth steps, is that of the connection as forwarded by Cloudflare.
Rate limiting
Your IP address and request counts in the console's memory.
Source Your connection (the IP address as forwarded by Cloudflare) and your requests.
Sign-in on the /results page
In the /results page, your token in the session storage of your own browser tab.
Source You: the token you type into the sign-in form of the /results page.
Feedback and requests
What you choose to send the controller through your AI assistant's feedback tool (a request, suggestion, problem report or opinion): your user id, the text, the job it is about if you name one, and the time. The text is free text and may contain personal data; your assistant sends it only with your OK and in your own words. No IP address and no token is stored with it.
Source You, through your AI assistant's feedback tool.
Recovery email (optional)
Your recovery email address, if you choose to add one (optional), an address you have entered but not yet confirmed, and the one-time links the console emails to it (stored only as hashes).
Source You, on the /results page; or the controller, if you asked it to set the address for you.
Access requests and correspondence by email
Your email address and whatever you write in the message, when you ask the controller by email for access to the service or write to it about anything covered by this notice, and the controller's reply.
Source You: the email you send to the contact address.
4. Purposes and legal bases
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Recognise you and enforce your limits. | Account and access | Art. 6(1)(b) — performance of the agreement (the service you asked for) | Until the controller deletes your account; an AI-app connection 30 days after its last use |
| Run the analysis you request. | Sequencing files (FASTQ) | Art. 6(1)(b) — performance of the agreement (the service you asked for) | 4 days (storage backstop: 30 days) |
| Deliver the analysis and let you check how it was produced. | Results, run files and job records | Art. 6(1)(b) — performance of the agreement (the service you asked for) | 30 days in storage; 90 days on the controller's computer, then a billing summary |
| Detect abuse and settle questions about who did what. | Security log | Art. 6(1)(f) — legitimate interest | 365 days (12 months); IP addresses 90 days |
| Rate limiting, so no one can flood the service. | Rate limiting | Art. 6(1)(f) — legitimate interest | Memory only: one minute (up to 24 hours for the recovery-email limits); gone at restart |
| Keep you signed in while the tab is open. | Sign-in on the /results page | Art. 6(1)(b) — performance of the agreement (the service you asked for); the browser storage is strictly necessary for the page you asked for | Until you sign out or close the tab |
| Improve the service and answer you. | Feedback and requests | Art. 6(1)(f) — legitimate interest (improving the service, answering you) | 6 months |
| Token recovery only: to send you a link to get a new token if you lose it, and — if the controller sends you one — an invite. Used for nothing else, and never shared except with the email provider that sends the message. | Recovery email (optional) | Art. 6(1)(a) — consent (an invite: Art. 6(1)(b)) | Until you remove it; unused links 30 minutes, 24 hours or 7 days (by kind) |
| Examine and answer your request, and, if you are invited, create your account. | Access requests and correspondence by email | Art. 6(1)(b) — steps taken at your request before an agreement; otherwise Art. 6(1)(f) — legitimate interest in answering correspondence | Until the request is closed, then at most 12 months — unless an account is created, when the account's own rules apply |
Notes on the legal bases
- Performance of the service you asked for (GDPR Art. 6(1)(b)): your account, files, results and job records.
- Legitimate interest in keeping the service secure (GDPR Art. 6(1)(f)): the security log and rate limiting.
- What you send through the feedback tool rests on the controller's legitimate interest in improving the service and answering you (GDPR Art. 6(1)(f)); whether to send anything, and what, is your own choice — nothing is sent without your OK. You may object (Art. 21) at any time by asking the controller, who deletes it.
- Your recovery email rests on your consent (GDPR Art. 6(1)(a)): the confirmation click is the proof of it and “Remove” withdraws it. An invite sent to your email address is a step taken at your request before an agreement (Art. 6(1)(b)). An address the controller entered for you, without a confirmation click, is used only when you asked for it.
- Your email to the contact address is processed to take steps at your request before an agreement (GDPR Art. 6(1)(b)) when you ask for access to the service, and otherwise on the controller's legitimate interest in answering the correspondence it receives (Art. 6(1)(f)).
Legitimate interest and your right to object
The controller relies on legitimate interest for four things: keeping the service secure and preventing abuse (the security log and rate limiting), protecting its own cloud spend and settling disputes over quotas and refunds (the security log), improving the service and answering you (feedback), and answering the correspondence it receives (emails). The controller has weighed these interests against yours and concluded that they do not override your rights, because the data are limited to what is needed (an IP address is written to disk only in the security log, for the OAuth steps, and is replaced after the period in section 8; feedback carries no IP address and no token and is sent only with your OK), because every item has a fixed, short retention period, and because the data are not used for profiling, advertising or any purpose other than the one stated, nor shared with anyone other than the recipients in section 6.
You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21(1) GDPR): write to the contact address. The controller then stops that processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. The controller does not use personal data for direct marketing.
5. Special categories of data
The service is meant for RNA-seq data of cell lines and other research material that does not identify a person. Do not upload data relating to an identified or identifiable natural person, and do not put such data in sample names, file names, job names or feedback.
Human samples are accepted only from cell lines, and you attest that when you submit them. Patient or clinical material is not accepted.
For human data the console enforces this: it refuses a human job unless the submission carries the attestation “cell-lines-only”. The controller does not intend to process special categories of personal data (Art. 9 GDPR), such as genetic or health data of a person, and the service is not set up for them. If you find that such data were submitted, tell the controller, who deletes them.
6. Recipients and processors
Files and results are stored in the EU: Scaleway, region fr-par (Paris, France (EU)). The controller itself, which runs the console on its own computer, has access to all the data described in this notice. The processors and other recipients are:
Scaleway SAS (France)
EU hosting of compute and object storage (region fr-par): your FASTQs, results and job records live there, and the virtual machines that run your analysis.
Where Paris, France (EU)
Processor under its General Conditions of Services and Data Processing Agreement.
Scaleway contracts (General Conditions and DPA) · Scaleway privacy policy
Cloudflare, Inc.
Encrypted tunnel that carries requests to the console. Cloudflare terminates TLS at its edge for console.aspis-bio.com and forwards requests through the tunnel to the console, so it can technically see the content of the requests and responses that pass through it: access tokens in headers, OAuth tokens, MCP tool arguments and results, job metadata, presigned links, and the /results and consent pages.
Where Global network; EU transfer safeguards under its Customer DPA
FASTQ and result files do not pass through Cloudflare: uploads and downloads go directly between your computer and Scaleway object storage via presigned links. Cloudflare acts as a processor under its Customer DPA and keeps technical logs under its own terms.
Cloudflare keeps its own technical logs for the period stated in its terms and privacy policy (linked here); the controller cannot shorten that period, and an erasure on the console does not reach them.
Resend, Inc.
Sends the console's emails (confirmation of your recovery email, a link to get a new token, an invite) — only if you set a recovery email or the controller sends you an invite — and a short alert the controller receives when you send feedback through your AI assistant. It receives the address and the content of the message: for your emails, your address and a one-time link, never a token; for a feedback alert, the controller's address, your user id, the kind, the length of the text and the job id if any — never the text itself.
Where The sending domain is configured in Resend's eu-west-1 (Ireland) region, which decides only where emails are sent from; Resend stores account data, email metadata and logs in the United States.
Processor under Resend's Data Processing Addendum (Art. 28), which applies automatically and includes the EU Standard Contractual Clauses (Module Two) for the transfer to the United States. Resend can read the messages it sends, so anyone with access to the mailbox or to Resend's copy could open the link inside; a link works once, for a limited time, and only shows a token after a button press.
Resend keeps its own technical logs for the period stated in its terms and privacy policy (linked here); the controller cannot shorten that period, and an erasure on the console does not reach them.
Emails you send to the contact address are stored by the provider that hosts that mailbox, which acts for the controller.
Your AI provider
Your AI provider is not the controller's processor: for what your assistant receives it is an independent controller, under the agreement you made with it.
The provider of the AI assistant you connect (e.g. Anthropic for Claude, OpenAI for Codex) receives everything the console returns to your assistant — job status and metadata, sample names, warnings, result summaries (QC, top genes, tables your assistant requests), Methods text, download links, and pipeline code you ask for. When you connect through a connector in a web or desktop app (for example claude.ai or Claude Desktop), the requests to the console are made from the provider's servers, which also hold the access token for your session. If your assistant downloads and reads result files, their content also reaches the provider. That processing happens under your own agreement with your AI provider, not under this console's control; check your provider's data and training settings before working with sensitive data. Files you download yourself (from the links or the /results page) go only between your computer and Scaleway.
Links to download your result files are handed to your AI assistant only during the first 24 hours after a job finished, and each such link expires no later than the close of that window. Afterwards the assistant gets the list of files without links, and you download them from your personal area (the /results page, signed in with your console token), which keeps serving links for the whole retention period.
FASTQ files are not sent to your AI provider: uploads go directly from your computer to Scaleway through the upload link, and link inputs (ENA, Dropbox, sequencing-provider links) are fetched by the analysis server. Only if your assistant opens a file to inspect it (for example its first reads) does that excerpt reach your provider.
7. Transfers outside the EEA
Personal data are processed in the EU, except as shown below. The documents linked in section 6 contain the safeguards and are the means to obtain a copy of them; the controller also gives you a copy on request.
| Recipient | Destination | Safeguard |
|---|---|---|
| Scaleway SAS | None: Paris, France (EU). | Not applicable. |
| Cloudflare, Inc. | Possible: its network is global, and it processes the requests that pass through it. | The EU Standard Contractual Clauses in its Customer DPA (https://www.cloudflare.com/cloudflare-customer-dpa/). |
| Resend, Inc. | The United States: Resend stores account data, email metadata and logs there. | The EU Standard Contractual Clauses, Module Two, in its Data Processing Addendum (https://resend.com/legal/dpa). |
| Your AI provider | Decided by your provider. | None by the controller: the provider is an independent controller and acts under the agreement you made with it. |
8. Retention
| Data | Period | How it is enforced |
|---|---|---|
| Account: user id, role, quota, hash of your token | Until the controller deletes your account | On the controller's computer; no expiry. |
| AI-app (OAuth) connection | Access 60 minutes; renewal 30 days after the last use | Ends at once if you or the controller revoke it. |
| Sequencing files (FASTQ) | 4 days | Daily clean-up by the console; the storage's own 30-day rule is the backstop. |
| Results, run files and the storage copy of the job record | 30 days | Storage rule on every object; about 1 more day for the previous version. |
| Job record on the controller's computer (names, files, conditions, messages) | 90 days after the job finishes | Then reduced to a billing summary (date, status, cost, refund figures). Exception: while a question about the job's analysis machine is open (it may still be billing, or is kept for reuse) the full record stays until that is resolved; the controller checks such open questions at least monthly. |
| Billing summary | Until the controller deletes your account | Kept under your user id; no sample name, file name or result. |
| Security log | 365 days (12 months) | IP addresses in it are replaced by a placeholder after 90 days. A damaged line without a readable date is not removed automatically; the controller removes such lines by hand when found. |
| IP address and request counts for rate limiting | One minute (up to 24 hours for the recovery-email limits) | Memory only; gone when the console restarts. |
| Feedback and requests | 6 months | Deleted by a daily check; sooner if the controller deletes it or your account is erased. |
| Recovery email address | Until you remove it or your account is erased | You remove it on the /results page at any time. |
| Recovery links (one-time) | 30 minutes (token recovery), 24 hours (confirmation), 7 days (invite) | A link works once; an expired one is deleted within 1 hour, by an hourly check. |
| Emails to the contact address | Until the request is closed, then at most 12 months | Deleted by the controller by hand; the account's rules apply if an account is created. |
| Technical logs of Cloudflare and Resend | Per the provider's terms | The controller cannot shorten them; see the privacy policies in section 6. |
| Token in your browser tab (/results) | Until you sign out or close the tab | Held by your browser, not by the console. |
The storage is configured to delete everything this console writes about 30 days after it was stored, and to abort uploads that were never completed after 1 day. The storage keeps previous versions of files: a deleted or expired file leaves an old version that is itself removed about 1 day later, so every deletion described in this notice — expiry, the daily clean-up, an erasure — is complete about 1 day after it happens.
Details of the retention rules
- Account and access. Until the controller deletes your account. An AI-app connection (OAuth) lasts until you or the controller revoke it, and expires 30 days after its last use.
- Sequencing files (FASTQ). Object storage in fr-par. Deleted after 4 days by a daily clean-up the console runs; a 30-day storage rule on the same area is the backstop (about 1 more day for the previous version). Copies on the analysis machine disappear when the machine is deleted at the end of the job (an idle machine may be kept for your next job for less than an hour).
- Results, run files and job records. Object storage in fr-par; each object is deleted about 30 days after it was stored (about 1 more day for the previous version; the job record the console mirrors there goes with the same rule). The controller's own computer keeps the job record (and any results the controller downloaded) for 90 days after the job finishes — or longer while a question about the job's analysis machine is still open (the machine may still be billing, or is kept for reuse): the full record then stays until that is resolved (no fixed limit is built into the console; the controller checks open questions at least monthly); then it is reduced to a billing summary — date, status, cost and refund figures — and the sample names, file names, logs, messages and downloaded results are deleted. The billing summary stays on the controller's computer, under your user id, until your account is erased.
- Security log. On the controller's computer. An entry is deleted 365 days (12 months) after it was written; IP addresses in it are replaced by a placeholder after 90 days. These rules, and the replacement of your user id at an erasure, apply to readable entries: a damaged log line without a readable date is not removed automatically; the controller removes such lines by hand when found.
- Rate limiting. Memory only, counted over a window of one minute (up to 24 hours for the limits on the recovery-email features, where an email address is kept only as a one-way digest and an hourly clean-up drops what has passed its window) and never written to disk; gone when the console restarts.
- Sign-in on the /results page. Until you sign out or close the tab. The console sets no cookie and uses no analytics or third-party script.
- Feedback and requests. On the controller's computer, deleted 6 months after it was written (the console checks when it starts and then daily), sooner if the controller deletes it or your account is erased. At most 10 messages per day per user. The controller reads it on their own computer. While the email feature is on, the controller also gets a short alert email through the email provider named in section 6; the alert holds your user id, the kind, the length of the text and the job id if any — never the text itself, and no token and no link. The controller reads the text only in their own dashboard.
- Recovery email (optional). On the controller's computer, until you remove it (on the /results page, at any time) or your account is erased. An address you have not confirmed, and every unused link, is deleted within 1 hour after its link expires (the console checks every hour and when it starts, while it is running): 24 hours for the confirmation, 30 minutes for a token-recovery link, 7 days for an invite. A link works once. The console rate-limits requests per address and per IP address (in memory only: at most 3 token-recovery requests per address per hour).
- Access requests and correspondence by email. In the mailbox of the contact address, on the provider that hosts it, until your request is closed and for at most 12 months after that, when the controller deletes it by hand; if an account is created for you, what you wrote that is needed to run the account is not kept beyond the rules for the account.
9. Your rights
You have the following rights, which you can exercise free of charge as described at the end of this section.
Access (Art. 15)
See your own jobs, results and quota on the /results page (sign in with your token) or ask your AI assistant. For the feedback you sent, the security log or anything else, ask the controller.
Rectification (Art. 16)
Your recovery email, where the feature is on, you change yourself on the /results page. The other records are generated by the console: ask the controller to correct a wrong user id or quota; the content of a job is what you submitted, and you run it again if it was wrong.
Erasure (Art. 17)
Ask the controller. The erasure the console carries out deletes the data the console holds about you — your token and AI-app connections stop working, your recovery email if you set one, the feedback you sent, your job records and downloaded results on the controller's computer, your uploaded files and results in storage, and your user id in the security log (replaced by a random placeholder), and any open multi-part upload is cancelled. Links you were given before the erasure cannot be recalled: a single-file upload link stays usable for up to 1 hour and other links for up to 24 hours, and download links then point at deleted files — so a single-file upload that still lands through an unexpired link is removed by the daily clean-up within about 4 days (the 30-day storage rule is the backstop). The storage keeps a deleted file's previous version for about 1 more day, so the erasure is complete about 1 day after the controller carries it out. Your files and results also expire automatically, as stated above. While a job of yours is unfinished or a question about its analysis machine is open, the console refuses the erasure: it is delayed, not refused for good, and the controller carries it out once the question is resolved. The erasure covers what the console holds. Emails you sent to the contact address are deleted by hand by the controller; copies held by processors (the technical logs of Cloudflare and, where the email feature is on, of the email provider) follow their own retention; and your AI provider holds its own copy under your agreement with it.
Restriction of processing (Art. 18)
Ask the controller at the contact address, in the cases of Art. 18(1) (for example while you contest the accuracy of data, or while an objection is being examined). The console has no restriction switch, so the controller does it by hand: on request it revokes your access, so that no job runs and nothing new is processed, and keeps your stored data unused until the restriction is lifted or you ask for erasure. Apart from storage, the data are then processed only with your consent, for legal claims, or as the law allows. Restriction is not erasure: your stored data is kept but not used (short-lived technical records such as sign-in grants and links still expire on their own). The controller tells you before the restriction is lifted.
Data portability (Art. 20)
Your results and files are downloadable by you from the /results page (or through your AI assistant), in the formats the analysis produced (tables, reports, files). For any other data you provided, ask the controller for a copy in a structured, commonly used, machine-readable format.
Objection (Art. 21)
You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21(1) GDPR): write to the contact address. The controller then stops that processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. The controller does not use personal data for direct marketing.
Withdrawal of consent (Art. 7(3))
Where processing is based on your consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of the processing carried out before it (Art. 7(3) GDPR). The recovery email rests on your consent: “Remove” on the /results page withdraws it at once.
Recovery email
You can see, change or remove your recovery email yourself at the bottom of the /results page, at any time. Removing it, or an erasure, deletes the address and every outstanding link.
Complaint to a supervisory authority (Art. 77)
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
How to exercise your rights
Write to the contact address in section 1, from the address or the channel you were invited on, or make the request with your console token. You do not need to give a reason. The controller may ask for information needed to confirm who you are (Art. 12(6)), and acts only on a request that comes from you.
The controller answers within one month of receiving the request (Art. 12(3) GDPR). Where necessary, considering the complexity and number of requests, that period may be extended by two further months; you are then told of the extension and its reasons within the first month. The answer is free of charge, unless a request is manifestly unfounded or excessive (Art. 12(5)).
10. Whether providing data is required
To use the service you need an account: the user id, the access token and the files and settings of the jobs you run are necessary to conclude and perform the agreement under which the service is provided, and the security log and rate limiting are part of operating it. Without them the controller cannot give you access. No statute requires you to provide them.
The feedback you send through the feedback tool is optional (it is sent only with your OK), and declining has no consequence for the service. An email to the contact address is optional too; without it the controller cannot answer you. The recovery email is optional too: without it, a lost token is replaced by the controller instead of by you.
11. Automated decision-making
The controller takes no decision about you based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). The service does run automatic technical checks — whether a sequencing library looks like full-length or 3′-end RNA-seq, whether an input is valid, and the quota, spend and rate limits that the controller sets for each account — but these concern the libraries and requests you submit, not an evaluation of you as a person.
12. Browser storage and cookies
The /results page keeps your token in the session storage of your own browser tab, under the key aspis-console-token, so that you stay signed in while the tab is open. It is removed when you sign out or close the tab, and it is sent only to this console, in the requests the page makes.
While the optional recovery email is on, the page also stores one flag in the local storage of your browser, under the key aspis-console-nudge-off, with the value 1, when you choose “Not now” on the reminder to add a recovery email. It holds no personal data, nothing specific to you, and stays until you clear your browser data.
The console sets no cookie. It uses no analytics, advertising or tracking tool, and no font, script, image or other resource from a third party: every page loads only files from the console's own address. The storage described here is strictly necessary to provide the page you asked for, so no consent banner is shown.
13. Security measures
- Encrypted connections (TLS) to the public address.
- Access tokens are stored only as one-way SHA-256 hashes and compared in constant time; a token is shown once, when it is issued.
- AI-app connections use OAuth 2.1 with PKCE and refresh-token rotation, and are tied to the hash of your token.
- Files and results are stored in the EU (Scaleway, Paris), in a separate area for each user, and download and upload links are short-lived.
- The analysis machine of a job is deleted when the job ends (an idle one may wait for your next job for less than an hour); the machine holds a storage key limited to that job.
- Fixed retention periods, enforced by daily clean-ups and by storage rules (section 8).
- The administration of the console is reachable only from the controller's own machine, or from the controller's private network; the security log records who did what, and never holds an email address, a token, a link secret or the text of a feedback message.
- Rate limits on requests, including per IP address, and per email address for the recovery email (the address held only as a digest, in memory).
- No analytics and no third-party script on any page.
14. Changes to this notice
The controller may amend this notice, in particular when a processor, a retention period or a category of data changes. The version in force is the one published at this address, identified by the date above. If the controller intends to process your data for a purpose other than the one stated here, it informs you beforehand (Art. 13(3) GDPR).
Last updated: 2026-10-03.