LEGAL

Privacy policy

Last updated 2026-07-30 · Version 1.3

Onkydra does not ingest patient-identifiable data. Cohorts are Monte Carlo draws from public statistical distributions, never real patient records.

1. Data controller and how to contact us

The controller of personal data collected through the Onkydra workspace is Onkydra, operating from the Republic of Ireland. You can reach us at hello@onkydra.com. For data protection questions specifically, the same mailbox reaches the person responsible for privacy at Onkydra. Full entity details, registered business address, and any designated Article 27 representative will be added after incorporation and counsel review.

Onkydra is a research tool operated on a research-use-only basis. This policy covers the personal data we process about you as a workspace user. It does not cover the public molecular datasets and literature we draw on to generate reports, because those do not contain personal data of workspace users.

2. Scope: no patient-identifiable data

The Onkydra workspace does not accept patient-identifiable data, health records, or genotype data from users. Uploading such data is a breach of the Terms of service. If we detect such data in a submission we will delete it and notify you. This policy therefore focuses on the personal data of the workspace user (typically a professional researcher, biotech R&D staff member, or founder), not on any patient population.

3. What personal data we process

We process only what we need to run the Service.

  • Account data. Your email address, display name, and Firebase Authentication uid.
  • Billing data. Handled by Stripe on our behalf. We store a Stripe customer id, subscription state, and the invoice history required for accounting. We do not store payment card numbers.
  • Workspace usage. Queries you submit, cohorts you create, artefacts you generate, and the associated agent-loop trace (agent identity, tool invocation, token count, timing). This is logged for reproducibility, for the audit trail required by our internal quality-assurance process, and for the XPRIZE submission evidence pack.
  • Analytics. Standard product analytics (page views, referrer, user agent, coarse geographic location) collected without cookies, in aggregated, pseudonymised form.
  • Communications. If you email us, or contact us through a form, we retain the content of the exchange.

4. Purposes and lawful bases

We rely on the lawful bases listed in Article 6(1) of the GDPR.

  • Article 6(1)(b) contract. Operating your account, delivering the Service, providing customer support, and processing your subscription payments.
  • Article 6(1)(c) legal obligation. Retaining tax and accounting records under Irish and EU law, responding to lawful requests from public authorities, and handling data subject requests.
  • Article 6(1)(f) legitimate interests. Running security controls, preventing abuse and fraud, investigating incidents, generating the internal quality-assurance audit trail, and improving the methodology. Where we rely on this basis you can object at any time by emailing us; the balancing test is available on request.
  • Article 6(1)(a) consent. Any marketing communications you opt in to. You can withdraw consent at any time by emailing us, or by replying to any email we send and asking us to stop; withdrawal does not affect the lawfulness of processing before withdrawal.

5. Special-category data (Article 9)

We do not process special categories of personal data within the meaning of Article 9 of the GDPR (health data, genetic data, biometric data for identification purposes, and the other categories listed there). The molecular data the Service reasons about is drawn from already-public research datasets and is not linked to any identified or identifiable patient inside the workspace.

6. Who we share it with

We use a small set of processors, each engaged under the provider's standard Article 28 data-processing terms.

  • Google Cloud. Application hosting, Cloud SQL for Postgres, Firebase Authentication, Cloud Storage, and Vertex AI (the Gemini family).
  • Stripe Payments Europe, Limited. Subscription billing, invoicing, and the Customer Portal.
  • Resend. Transactional email such as receipts, waitlist notifications, and account notifications.
  • Loops. Waitlist and product-announcement CRM. Processes contact name, email address, organisation, stated role, and the user group that role maps to.
  • Cloudflare. Cookieless analytics on every page, including the signed-in workspace. Processes page view, referrer, user agent, and coarse country. No cookie is set and no cross-site identifier is created.

We do not sell your personal data. We do not use it to train foundation models. The current live list, the processing region for each entry, and the changelog of every addition or removal are published at onkydra.com/subprocessors. Material changes are notified to account admins at least 30 days before they take effect.

7. Storage location and international transfers

The primary database (Cloud SQL for Postgres) is hosted in the Google Cloud Platform region europe-west2 (London, United Kingdom), in a single zone with no failover replica. Its automated backups are stored in Google's EU multi-region, not in the primary region, so database contents leave the United Kingdom as part of the ordinary backup cycle. The United Kingdom is currently covered by the European Commission's adequacy decision for personal data transfers from the European Economic Area. The application serving the workspace runs in europe-west4 (Netherlands), inside the European Economic Area, as does the Cloud Storage bucket holding the reference data and model artefacts the Service reads. Our build and deployment infrastructure uses Google-managed storage that may sit outside the European Economic Area; it holds application source and build output only, never workspace or personal data.

Certain foundation-model inference calls (for example, Gemini models on Google's global endpoint) may be routed to Google data centres outside the United Kingdom or the European Economic Area. Any such transfer is covered by the European Commission's Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, together with the safeguards set out in the Google Cloud Data Processing Addendum. Stripe, Resend, Loops, and Cloudflare transfers to non-EEA jurisdictions rely on the same Standard Contractual Clauses.

8. Retention

  • Account data is retained for the life of your account and deleted within 30 days of account termination, except where a longer retention is required by law.
  • Workspace usage and agent-loop traces are retained for 36 months, then deleted or aggregated beyond identifiability.
  • Billing records are retained for the period required by Irish tax law (currently six years from the end of the accounting period), under Article 6(1)(c).
  • Communications are retained for as long as needed to resolve the matter, then deleted or archived.
  • Backups are taken daily, the seven most recent are kept on a rolling basis, and the point-in-time recovery window is seven days. A backup taken before deletion may therefore still hold data until it rotates out and is overwritten in the ordinary course. Residual backup copies are not restored into the live service.

9. Your rights under the GDPR

You have the right to:

  • Access your personal data (Article 15).
  • Rectify inaccurate or incomplete personal data (Article 16).
  • Erase your personal data (Article 17), subject to the exceptions in Article 17(3), notably retention required by law.
  • Restrict processing in the circumstances of Article 18.
  • Port your personal data to another controller in a structured, commonly used, machine-readable format (Article 20).
  • Object to processing based on our legitimate interests (Article 21).
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (Article 22).
  • Withdraw consent at any time where processing is based on Article 6(1)(a).

10. How to exercise your rights, and lodge a complaint

To exercise any of the rights above, use the workspace Settings page (Export data, Erase account) or email hello@onkydra.com. We respond within one month of receipt of a valid request, in line with Article 12(3). The period may be extended by up to a further two months for complex or numerous requests; if so, we will tell you within one month.

If you believe our processing of your personal data infringes the GDPR, you have the right under Article 77 to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. Our lead supervisory authority is the Irish Data Protection Commission (dataprotection.ie; complaints webform at forms.dataprotection.ie/contact). We would appreciate the chance to address your concern directly before you escalate.

11. Cookies

We use one cookie: a Firebase Authentication session cookie so you stay signed in, which is strictly necessary to deliver the Service you have requested. Site analytics run through Cloudflare Web Analytics, which is cookieless and sets no identifier, so there is no analytics cookie to accept or withdraw. We do not set advertising cookies, do not run cross-site tracking, and do not sell any identifiers.

12. Security

We implement the technical and organisational measures required by Article 32 of the GDPR. Data in transit is encrypted with TLS 1.2 or higher. Data at rest is encrypted by Google Cloud. Firebase Authentication ID tokens are verified server-side on every workspace request. Row-level access controls in Cloud SQL Postgres ensure that a workspace session can only read data owned by the authenticated user. Access to production systems is limited to the smallest necessary set of people, over multi-factor authentication and per-secret IAM. We test our controls on an ongoing basis.

13. Personal data breaches

If a personal data breach occurs and is likely to result in a risk to the rights and freedoms of natural persons, we will notify the Irish Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of it, in line with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay under Article 34.

14. Automated decision-making

The Service uses automated processing to generate research reports. This processing does not make decisions that produce legal or similarly significant effects on you as a natural person within the meaning of Article 22, because the outputs are research use only and any downstream scientific or clinical decision is made by a qualified human.

15. Children

The Service is directed at professional researchers and is not intended for anyone under 16, which is the digital age of consent set for Ireland under Article 8 of the GDPR by section 31 of the Data Protection Act 2018. We do not knowingly collect personal data from anyone under 16.

16. Changes to this policy

We may update this policy from time to time. Material changes are notified to the email address on your account at least 14 days before they take effect, and are recorded in the version stamp at the top of this page.

This policy is a plain-language template and will be reviewed by qualified Irish counsel and updated as our subprocessor list and processing activities expand. Registered entity details, business address, and (if triggered by scale) a Data Protection Officer under Article 37 will be added at that point. Questions: hello@onkydra.com.