Privacy notice

Information on the processing of personal data by Eclose, RNA-seq analysis, provided under Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”).

Last updated: 2026-10-03

1. Controller and contact

Aspis-Bio — operated by Marco Gualtieri runs this console and decides why and how your personal data is processed (the “controller”, Art. 4(7) GDPR).

Contact address for every request under this notice: main@aspis-bio.com.

2. Scope of this notice

This notice applies to Eclose, the RNA-seq analysis console (the “service”), which the controller offers by invitation only. It covers:

It also covers the requests you send by email to the contact address in section 1 — for example a request for access to the service. The data are your email address and what you write; the legal basis is Art. 6(1)(b) GDPR (steps taken at your request before an agreement) or, for other correspondence, Art. 6(1)(f); they are kept until the request is closed and for at most 12 months after that, unless an account is created for you, in which case the rules for the account apply (sections 3, 4 and 8).

3. Categories of data and their sources

Per processing activity: the data processed and where they come from. The data are provided by you, directly or through your AI assistant, or are generated by the console when you use it.

Account and access

Your account: the user id the controller gave you, your role, the date it was created, your weekly quota and a one-way hash (SHA-256) of your access token. Your token itself is never stored: it is shown once, when it is issued, and only its hash is kept in the controller's configuration file on the controller's own computer. The OAuth connection records also keep only hashes.

Source The controller, when it creates your account (user id, role, quota); the console, when it issues your token (shown to you once).

Sequencing files (FASTQ)

Your sequencing files (FASTQs) that you upload or ask the console to download.

Source You: uploaded from your computer, or fetched by the analysis server from the links you give (for example ENA, Dropbox, a sequencing provider).

Results, run files and job records

Results and run files: tables, reports, quality control, the record of what was run, progress messages, and the job record with the sample names, file names and conditions you chose, the cost of the job and any refund.

Source Generated by the analysis from your files and from the settings, sample names, file names and conditions you chose; the cost of each job is computed by the console and counted against your limits.

Security log

A security log: time, your user id, which action, whether it worked and a short note. For the steps of connecting an AI app to your account (OAuth), the log also holds your IP address.

Source Generated by the console when you or your AI assistant use it; the IP address, in the OAuth steps, is that of the connection as forwarded by Cloudflare.

Rate limiting

Your IP address and request counts in the console's memory.

Source Your connection (the IP address as forwarded by Cloudflare) and your requests.

Sign-in on the /results page

In the /results page, your token in the session storage of your own browser tab.

Source You: the token you type into the sign-in form of the /results page.

Feedback and requests

What you choose to send the controller through your AI assistant's feedback tool (a request, suggestion, problem report or opinion): your user id, the text, the job it is about if you name one, and the time. The text is free text and may contain personal data; your assistant sends it only with your OK and in your own words. No IP address and no token is stored with it.

Source You, through your AI assistant's feedback tool.

Recovery email (optional)

Your recovery email address, if you choose to add one (optional), an address you have entered but not yet confirmed, and the one-time links the console emails to it (stored only as hashes).

Source You, on the /results page; or the controller, if you asked it to set the address for you.

Access requests and correspondence by email

Your email address and whatever you write in the message, when you ask the controller by email for access to the service or write to it about anything covered by this notice, and the controller's reply.

Source You: the email you send to the contact address.

4. Purposes and legal bases

Processing activities, purposes, legal bases and retention
PurposeDataLegal basisRetention
Recognise you and enforce your limits.Account and accessArt. 6(1)(b) — performance of the agreement (the service you asked for)Until the controller deletes your account; an AI-app connection 30 days after its last use
Run the analysis you request.Sequencing files (FASTQ)Art. 6(1)(b) — performance of the agreement (the service you asked for)4 days (storage backstop: 30 days)
Deliver the analysis and let you check how it was produced.Results, run files and job recordsArt. 6(1)(b) — performance of the agreement (the service you asked for)30 days in storage; 90 days on the controller's computer, then a billing summary
Detect abuse and settle questions about who did what.Security logArt. 6(1)(f) — legitimate interest365 days (12 months); IP addresses 90 days
Rate limiting, so no one can flood the service.Rate limitingArt. 6(1)(f) — legitimate interestMemory only: one minute (up to 24 hours for the recovery-email limits); gone at restart
Keep you signed in while the tab is open.Sign-in on the /results pageArt. 6(1)(b) — performance of the agreement (the service you asked for); the browser storage is strictly necessary for the page you asked forUntil you sign out or close the tab
Improve the service and answer you.Feedback and requestsArt. 6(1)(f) — legitimate interest (improving the service, answering you)6 months
Token recovery only: to send you a link to get a new token if you lose it, and — if the controller sends you one — an invite. Used for nothing else, and never shared except with the email provider that sends the message.Recovery email (optional)Art. 6(1)(a) — consent (an invite: Art. 6(1)(b))Until you remove it; unused links 30 minutes, 24 hours or 7 days (by kind)
Examine and answer your request, and, if you are invited, create your account.Access requests and correspondence by emailArt. 6(1)(b) — steps taken at your request before an agreement; otherwise Art. 6(1)(f) — legitimate interest in answering correspondenceUntil the request is closed, then at most 12 months — unless an account is created, when the account's own rules apply

Notes on the legal bases

Legitimate interest and your right to object

The controller relies on legitimate interest for four things: keeping the service secure and preventing abuse (the security log and rate limiting), protecting its own cloud spend and settling disputes over quotas and refunds (the security log), improving the service and answering you (feedback), and answering the correspondence it receives (emails). The controller has weighed these interests against yours and concluded that they do not override your rights, because the data are limited to what is needed (an IP address is written to disk only in the security log, for the OAuth steps, and is replaced after the period in section 8; feedback carries no IP address and no token and is sent only with your OK), because every item has a fixed, short retention period, and because the data are not used for profiling, advertising or any purpose other than the one stated, nor shared with anyone other than the recipients in section 6.

You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21(1) GDPR): write to the contact address. The controller then stops that processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. The controller does not use personal data for direct marketing.

5. Special categories of data

The service is meant for RNA-seq data of cell lines and other research material that does not identify a person. Do not upload data relating to an identified or identifiable natural person, and do not put such data in sample names, file names, job names or feedback.

Human samples are accepted only from cell lines, and you attest that when you submit them. Patient or clinical material is not accepted.

For human data the console enforces this: it refuses a human job unless the submission carries the attestation “cell-lines-only”. The controller does not intend to process special categories of personal data (Art. 9 GDPR), such as genetic or health data of a person, and the service is not set up for them. If you find that such data were submitted, tell the controller, who deletes them.

6. Recipients and processors

Files and results are stored in the EU: Scaleway, region fr-par (Paris, France (EU)). The controller itself, which runs the console on its own computer, has access to all the data described in this notice. The processors and other recipients are:

Scaleway SAS (France)

EU hosting of compute and object storage (region fr-par): your FASTQs, results and job records live there, and the virtual machines that run your analysis.

Where Paris, France (EU)

Processor under its General Conditions of Services and Data Processing Agreement.

Scaleway contracts (General Conditions and DPA) · Scaleway privacy policy

Cloudflare, Inc.

Encrypted tunnel that carries requests to the console. Cloudflare terminates TLS at its edge for console.aspis-bio.com and forwards requests through the tunnel to the console, so it can technically see the content of the requests and responses that pass through it: access tokens in headers, OAuth tokens, MCP tool arguments and results, job metadata, presigned links, and the /results and consent pages.

Where Global network; EU transfer safeguards under its Customer DPA

FASTQ and result files do not pass through Cloudflare: uploads and downloads go directly between your computer and Scaleway object storage via presigned links. Cloudflare acts as a processor under its Customer DPA and keeps technical logs under its own terms.

Cloudflare keeps its own technical logs for the period stated in its terms and privacy policy (linked here); the controller cannot shorten that period, and an erasure on the console does not reach them.

Cloudflare Customer DPA · Cloudflare privacy policy

Resend, Inc.

Sends the console's emails (confirmation of your recovery email, a link to get a new token, an invite) — only if you set a recovery email or the controller sends you an invite — and a short alert the controller receives when you send feedback through your AI assistant. It receives the address and the content of the message: for your emails, your address and a one-time link, never a token; for a feedback alert, the controller's address, your user id, the kind, the length of the text and the job id if any — never the text itself.

Where The sending domain is configured in Resend's eu-west-1 (Ireland) region, which decides only where emails are sent from; Resend stores account data, email metadata and logs in the United States.

Processor under Resend's Data Processing Addendum (Art. 28), which applies automatically and includes the EU Standard Contractual Clauses (Module Two) for the transfer to the United States. Resend can read the messages it sends, so anyone with access to the mailbox or to Resend's copy could open the link inside; a link works once, for a limited time, and only shows a token after a button press.

Resend keeps its own technical logs for the period stated in its terms and privacy policy (linked here); the controller cannot shorten that period, and an erasure on the console does not reach them.

Resend Data Processing Addendum · Resend privacy policy

Emails you send to the contact address are stored by the provider that hosts that mailbox, which acts for the controller.

Your AI provider

Your AI provider is not the controller's processor: for what your assistant receives it is an independent controller, under the agreement you made with it.

The provider of the AI assistant you connect (e.g. Anthropic for Claude, OpenAI for Codex) receives everything the console returns to your assistant — job status and metadata, sample names, warnings, result summaries (QC, top genes, tables your assistant requests), Methods text, download links, and pipeline code you ask for. When you connect through a connector in a web or desktop app (for example claude.ai or Claude Desktop), the requests to the console are made from the provider's servers, which also hold the access token for your session. If your assistant downloads and reads result files, their content also reaches the provider. That processing happens under your own agreement with your AI provider, not under this console's control; check your provider's data and training settings before working with sensitive data. Files you download yourself (from the links or the /results page) go only between your computer and Scaleway.

Links to download your result files are handed to your AI assistant only during the first 24 hours after a job finished, and each such link expires no later than the close of that window. Afterwards the assistant gets the list of files without links, and you download them from your personal area (the /results page, signed in with your console token), which keeps serving links for the whole retention period.

FASTQ files are not sent to your AI provider: uploads go directly from your computer to Scaleway through the upload link, and link inputs (ENA, Dropbox, sequencing-provider links) are fetched by the analysis server. Only if your assistant opens a file to inspect it (for example its first reads) does that excerpt reach your provider.

7. Transfers outside the EEA

Personal data are processed in the EU, except as shown below. The documents linked in section 6 contain the safeguards and are the means to obtain a copy of them; the controller also gives you a copy on request.

Transfers of personal data outside the European Economic Area
RecipientDestinationSafeguard
Scaleway SASNone: Paris, France (EU).Not applicable.
Cloudflare, Inc.Possible: its network is global, and it processes the requests that pass through it.The EU Standard Contractual Clauses in its Customer DPA (https://www.cloudflare.com/cloudflare-customer-dpa/).
Resend, Inc.The United States: Resend stores account data, email metadata and logs there.The EU Standard Contractual Clauses, Module Two, in its Data Processing Addendum (https://resend.com/legal/dpa).
Your AI providerDecided by your provider.None by the controller: the provider is an independent controller and acts under the agreement you made with it.

8. Retention

Retention periods
DataPeriodHow it is enforced
Account: user id, role, quota, hash of your tokenUntil the controller deletes your accountOn the controller's computer; no expiry.
AI-app (OAuth) connectionAccess 60 minutes; renewal 30 days after the last useEnds at once if you or the controller revoke it.
Sequencing files (FASTQ)4 daysDaily clean-up by the console; the storage's own 30-day rule is the backstop.
Results, run files and the storage copy of the job record30 daysStorage rule on every object; about 1 more day for the previous version.
Job record on the controller's computer (names, files, conditions, messages)90 days after the job finishesThen reduced to a billing summary (date, status, cost, refund figures). Exception: while a question about the job's analysis machine is open (it may still be billing, or is kept for reuse) the full record stays until that is resolved; the controller checks such open questions at least monthly.
Billing summaryUntil the controller deletes your accountKept under your user id; no sample name, file name or result.
Security log365 days (12 months)IP addresses in it are replaced by a placeholder after 90 days. A damaged line without a readable date is not removed automatically; the controller removes such lines by hand when found.
IP address and request counts for rate limitingOne minute (up to 24 hours for the recovery-email limits)Memory only; gone when the console restarts.
Feedback and requests6 monthsDeleted by a daily check; sooner if the controller deletes it or your account is erased.
Recovery email addressUntil you remove it or your account is erasedYou remove it on the /results page at any time.
Recovery links (one-time)30 minutes (token recovery), 24 hours (confirmation), 7 days (invite)A link works once; an expired one is deleted within 1 hour, by an hourly check.
Emails to the contact addressUntil the request is closed, then at most 12 monthsDeleted by the controller by hand; the account's rules apply if an account is created.
Technical logs of Cloudflare and ResendPer the provider's termsThe controller cannot shorten them; see the privacy policies in section 6.
Token in your browser tab (/results)Until you sign out or close the tabHeld by your browser, not by the console.

The storage is configured to delete everything this console writes about 30 days after it was stored, and to abort uploads that were never completed after 1 day. The storage keeps previous versions of files: a deleted or expired file leaves an old version that is itself removed about 1 day later, so every deletion described in this notice — expiry, the daily clean-up, an erasure — is complete about 1 day after it happens.

Details of the retention rules

9. Your rights

You have the following rights, which you can exercise free of charge as described at the end of this section.

Access (Art. 15)

See your own jobs, results and quota on the /results page (sign in with your token) or ask your AI assistant. For the feedback you sent, the security log or anything else, ask the controller.

Rectification (Art. 16)

Your recovery email, where the feature is on, you change yourself on the /results page. The other records are generated by the console: ask the controller to correct a wrong user id or quota; the content of a job is what you submitted, and you run it again if it was wrong.

Erasure (Art. 17)

Ask the controller. The erasure the console carries out deletes the data the console holds about you — your token and AI-app connections stop working, your recovery email if you set one, the feedback you sent, your job records and downloaded results on the controller's computer, your uploaded files and results in storage, and your user id in the security log (replaced by a random placeholder), and any open multi-part upload is cancelled. Links you were given before the erasure cannot be recalled: a single-file upload link stays usable for up to 1 hour and other links for up to 24 hours, and download links then point at deleted files — so a single-file upload that still lands through an unexpired link is removed by the daily clean-up within about 4 days (the 30-day storage rule is the backstop). The storage keeps a deleted file's previous version for about 1 more day, so the erasure is complete about 1 day after the controller carries it out. Your files and results also expire automatically, as stated above. While a job of yours is unfinished or a question about its analysis machine is open, the console refuses the erasure: it is delayed, not refused for good, and the controller carries it out once the question is resolved. The erasure covers what the console holds. Emails you sent to the contact address are deleted by hand by the controller; copies held by processors (the technical logs of Cloudflare and, where the email feature is on, of the email provider) follow their own retention; and your AI provider holds its own copy under your agreement with it.

Restriction of processing (Art. 18)

Ask the controller at the contact address, in the cases of Art. 18(1) (for example while you contest the accuracy of data, or while an objection is being examined). The console has no restriction switch, so the controller does it by hand: on request it revokes your access, so that no job runs and nothing new is processed, and keeps your stored data unused until the restriction is lifted or you ask for erasure. Apart from storage, the data are then processed only with your consent, for legal claims, or as the law allows. Restriction is not erasure: your stored data is kept but not used (short-lived technical records such as sign-in grants and links still expire on their own). The controller tells you before the restriction is lifted.

Data portability (Art. 20)

Your results and files are downloadable by you from the /results page (or through your AI assistant), in the formats the analysis produced (tables, reports, files). For any other data you provided, ask the controller for a copy in a structured, commonly used, machine-readable format.

Objection (Art. 21)

You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21(1) GDPR): write to the contact address. The controller then stops that processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. The controller does not use personal data for direct marketing.

Withdrawal of consent (Art. 7(3))

Where processing is based on your consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of the processing carried out before it (Art. 7(3) GDPR). The recovery email rests on your consent: “Remove” on the /results page withdraws it at once.

Recovery email

You can see, change or remove your recovery email yourself at the bottom of the /results page, at any time. Removing it, or an erasure, deletes the address and every outstanding link.

Complaint to a supervisory authority (Art. 77)

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

How to exercise your rights

Write to the contact address in section 1, from the address or the channel you were invited on, or make the request with your console token. You do not need to give a reason. The controller may ask for information needed to confirm who you are (Art. 12(6)), and acts only on a request that comes from you.

The controller answers within one month of receiving the request (Art. 12(3) GDPR). Where necessary, considering the complexity and number of requests, that period may be extended by two further months; you are then told of the extension and its reasons within the first month. The answer is free of charge, unless a request is manifestly unfounded or excessive (Art. 12(5)).

10. Whether providing data is required

To use the service you need an account: the user id, the access token and the files and settings of the jobs you run are necessary to conclude and perform the agreement under which the service is provided, and the security log and rate limiting are part of operating it. Without them the controller cannot give you access. No statute requires you to provide them.

The feedback you send through the feedback tool is optional (it is sent only with your OK), and declining has no consequence for the service. An email to the contact address is optional too; without it the controller cannot answer you. The recovery email is optional too: without it, a lost token is replaced by the controller instead of by you.

11. Automated decision-making

The controller takes no decision about you based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). The service does run automatic technical checks — whether a sequencing library looks like full-length or 3′-end RNA-seq, whether an input is valid, and the quota, spend and rate limits that the controller sets for each account — but these concern the libraries and requests you submit, not an evaluation of you as a person.

12. Browser storage and cookies

The /results page keeps your token in the session storage of your own browser tab, under the key aspis-console-token, so that you stay signed in while the tab is open. It is removed when you sign out or close the tab, and it is sent only to this console, in the requests the page makes.

While the optional recovery email is on, the page also stores one flag in the local storage of your browser, under the key aspis-console-nudge-off, with the value 1, when you choose “Not now” on the reminder to add a recovery email. It holds no personal data, nothing specific to you, and stays until you clear your browser data.

The console sets no cookie. It uses no analytics, advertising or tracking tool, and no font, script, image or other resource from a third party: every page loads only files from the console's own address. The storage described here is strictly necessary to provide the page you asked for, so no consent banner is shown.

13. Security measures

14. Changes to this notice

The controller may amend this notice, in particular when a processor, a retention period or a category of data changes. The version in force is the one published at this address, identified by the date above. If the controller intends to process your data for a purpose other than the one stated here, it informs you beforehand (Art. 13(3) GDPR).

Last updated: 2026-10-03.

Back to your jobs