BioAudit-v1 Privacy Policy

Effective date: 2 October 2026

Service: BioAudit-v1

This policy is an implementation draft and must be reviewed and adapted by the Data Fiduciary or business operator with qualified legal advice before production use.

1. Who controls the data

BioAudit-v1 is operated by the service owner identified on the website and in the applicable Terms of Use. The operator determines why and how personal data is processed and is responsible for applicable privacy obligations.

Privacy questions and deletion requests should be sent to: privacy@example.com

2. Information collected

BioAudit-v1 is designed to collect the minimum information required to operate the service:

BioAudit-v1 should not require a name, date of birth, address, identity document, phone number, medical record, or educational record unless a separate documented purpose and lawful basis exist.

3. Information that should not be submitted

Users must not submit:

4. Purposes of processing

5. AI processing

Chat questions may be sent to a configured AI provider to generate an educational response. Users should remove unnecessary personal data before submitting a question.

AI output can be inaccurate. Scientific claims should be checked against the verified sources displayed with the response. AI output is not medical, clinical, legal, laboratory, financial, or examination advice.

6. Citations and external sources

The service may retrieve metadata and links from trusted scientific providers such as PubMed, NCBI, Crossref, RCSB PDB, UniProt, and official educational sources. Source availability and metadata may be verified by the server, but source verification does not guarantee that every generated statement is correct.

7. Payments

Payment details should be entered only into the payment provider's secure checkout. BioAudit-v1 should store payment order identifiers and payment status rather than card numbers or payment authentication secrets.

8. Data retention

9. User controls

Subject to applicable law and operational requirements, users may request:

A deletion request can be submitted through the account controls or by contacting privacy@example.com.

10. Children and minors

NEET and JEE learners may include minors. The operator must determine the applicable age, consent, parental-consent, and child-data requirements before allowing minors to create accounts or purchase subscriptions.

The service should not knowingly collect unnecessary personal information from children.

11. Service providers

The operator may use infrastructure and processors for hosting, email delivery, AI processing, database storage, payment processing, monitoring, and security. Providers should receive only the information necessary for their documented service purpose and should be governed by appropriate contracts and security controls.

12. Security

Security measures include server-side authorization, HttpOnly session cookies, CSRF protection, restricted CORS, encrypted transport, hashed one-time tokens, server-only secrets, database access controls, and payment webhook verification.

No security measure can guarantee absolute security. Suspected incidents should be reported immediately to security@example.com.

13. Changes to this policy

Material changes will be published with a new policy version and, where required, presented for renewed consent.

14. Grievance contact

Privacy complaints and grievances should be sent to: grievance@example.com

BioAudit-v1 · Policy version 2026-10-02

BioAudit-v1 Privacy Policy

BioAudit-v1 Privacy Policy

Effective date: 2 October 2026

Service: BioAudit-v1

This policy is an implementation draft and must be reviewed and adapted by the Data Fiduciary or business operator with qualified legal advice before production use.

1. Who controls the data

BioAudit-v1 is operated by the service owner identified on the website and in the applicable Terms of Use. The operator determines why and how personal data is processed and is responsible for applicable privacy obligations.

Privacy questions and deletion requests should be sent to: privacy@example.com

2. Information collected

BioAudit-v1 is designed to collect the minimum information required to operate the service:

BioAudit-v1 should not require a name, date of birth, address, identity document, phone number, medical record, or educational record unless a separate documented purpose and lawful basis exist.

3. Information that should not be submitted

Users must not submit:

4. Purposes of processing

5. AI processing

Chat questions may be sent to a configured AI provider to generate an educational response. Users should remove unnecessary personal data before submitting a question.

AI output can be inaccurate. Scientific claims should be checked against the verified sources displayed with the response. AI output is not medical, clinical, legal, laboratory, financial, or examination advice.

6. Citations and external sources

The service may retrieve metadata and links from trusted scientific providers such as PubMed, NCBI, Crossref, RCSB PDB, UniProt, and official educational sources. Source availability and metadata may be verified by the server, but source verification does not guarantee that every generated statement is correct.

7. Payments

Payment details should be entered only into the payment provider's secure checkout. BioAudit-v1 should store payment order identifiers and payment status rather than card numbers or payment authentication secrets.

8. Data retention

9. User controls

Subject to applicable law and operational requirements, users may request:

A deletion request can be submitted through the account controls or by contacting privacy@example.com.

10. Children and minors

NEET and JEE learners may include minors. The operator must determine the applicable age, consent, parental-consent, and child-data requirements before allowing minors to create accounts or purchase subscriptions.

The service should not knowingly collect unnecessary personal information from children.

11. Service providers

The operator may use infrastructure and processors for hosting, email delivery, AI processing, database storage, payment processing, monitoring, and security. Providers should receive only the information necessary for their documented service purpose and should be governed by appropriate contracts and security controls.

12. Security

Security measures include server-side authorization, HttpOnly session cookies, CSRF protection, restricted CORS, encrypted transport, hashed one-time tokens, server-only secrets, database access controls, and payment webhook verification.

No security measure can guarantee absolute security. Suspected incidents should be reported immediately to security@example.com.

13. Changes to this policy

Material changes will be published with a new policy version and, where required, presented for renewed consent.

14. Grievance contact

Privacy complaints and grievances should be sent to: grievance@example.com

BioAudit-v1 · Policy version 2026-10-02

CTYPE html>