Effective date: 2 October 2026
Service: BioAudit-v1
BioAudit-v1 is operated by the service owner identified on the website and in the applicable Terms of Use. The operator determines why and how personal data is processed and is responsible for applicable privacy obligations.
Privacy questions and deletion requests should be sent to: privacy@example.com
BioAudit-v1 is designed to collect the minimum information required to operate the service:
BioAudit-v1 should not require a name, date of birth, address, identity document, phone number, medical record, or educational record unless a separate documented purpose and lawful basis exist.
Users must not submit:
Chat questions may be sent to a configured AI provider to generate an educational response. Users should remove unnecessary personal data before submitting a question.
AI output can be inaccurate. Scientific claims should be checked against the verified sources displayed with the response. AI output is not medical, clinical, legal, laboratory, financial, or examination advice.
The service may retrieve metadata and links from trusted scientific providers such as PubMed, NCBI, Crossref, RCSB PDB, UniProt, and official educational sources. Source availability and metadata may be verified by the server, but source verification does not guarantee that every generated statement is correct.
Payment details should be entered only into the payment provider's secure checkout. BioAudit-v1 should store payment order identifiers and payment status rather than card numbers or payment authentication secrets.
Subject to applicable law and operational requirements, users may request:
A deletion request can be submitted through the account controls or by contacting privacy@example.com.
NEET and JEE learners may include minors. The operator must determine the applicable age, consent, parental-consent, and child-data requirements before allowing minors to create accounts or purchase subscriptions.
The service should not knowingly collect unnecessary personal information from children.
The operator may use infrastructure and processors for hosting, email delivery, AI processing, database storage, payment processing, monitoring, and security. Providers should receive only the information necessary for their documented service purpose and should be governed by appropriate contracts and security controls.
Security measures include server-side authorization, HttpOnly session cookies, CSRF protection, restricted CORS, encrypted transport, hashed one-time tokens, server-only secrets, database access controls, and payment webhook verification.
No security measure can guarantee absolute security. Suspected incidents should be reported immediately to security@example.com.
Material changes will be published with a new policy version and, where required, presented for renewed consent.
Privacy complaints and grievances should be sent to: grievance@example.com
BioAudit-v1 · Policy version 2026-10-02