Effective and last updated: July 23, 2026

Privacy Policy

This policy explains what data we collect, how we use it, and your choices. It complements our Terms of Use.

Controller. Z Genome Lab™ is the controller for account, website, billing and support data processed through ZGL OS. An institution using ZGL OS for its own research may instead be the controller for research content it uploads, with Z Genome Lab acting under that institution’s instructions.

1. Information we collect

  • Account and entitlement data: name, email, password hash, organization, role, plan, license, pilot, module scope, API-key metadata and seat assignment.
  • Technical and usage data: module actions, timestamps, request status, browser/device information, security logs and IP address where available.
  • Billing data: selected product, invoice reference, payment status and billing contact. We do not collect card details on this site.
  • Support data: messages you send us and related metadata.
  • Research content: sequences, variants, parameters, reports and provenance data submitted to the platform. Genomic or health-linked information may be sensitive personal data; do not upload identifiable human data unless you have a lawful basis, required approvals and authority to do so.

2. How we use information

  • Provide, maintain, and improve the platform and modules.
  • Personalize features, troubleshoot, and ensure reliability.
  • Communicate about product updates, billing, and security.
  • Enforce subscription, license, pilot, API and module-access rules.
  • Generate requested reports, evidence artifacts and reproducibility records.
  • Comply with legal obligations and enforce terms.

Depending on the context, processing is based on performance of a contract, steps requested before a contract, legitimate interests in operating and securing ZGL OS, consent for optional activities, or legal obligations. Processing of identifiable genomic or health data requires an additional lawful condition and appropriate safeguards supplied by the responsible institution or user. Applicable frameworks may include Algerian Law 18-07, as amended, and the EU GDPR where its territorial rules apply.

4. Cookies & analytics

We use essential session and security storage for sign-in, entitlement enforcement and abuse prevention. Optional analytics or marketing storage is used only according to your selection and applicable law. Disabling essential storage may prevent authenticated features from working.

5. Sharing & processors

We may use vetted hosting, infrastructure, communications, security and invoicing providers strictly to deliver the service. Contracts and access controls must limit processors to documented purposes. We may disclose information when legally required or during a properly structured business transaction with appropriate safeguards. We do not sell personal data.

6. Data retention

Account and entitlement records are retained while the account or commercial agreement is active and for the period reasonably needed to resolve disputes and meet legal obligations. Security, audit and usage records are retained only for operational, evidence and fraud-prevention needs. Research content follows the workspace or institutional agreement and is deleted or returned when required, subject to backups, legal holds and requested evidence retention. Deletion requests are honored unless continued retention is required or lawfully justified.

7. Security

We apply measures appropriate to risk, including encryption in transit, hashed passwords, authenticated sessions, least-privilege entitlements, API-key controls, audit logging, backups and administrative access controls. No system is risk-free. Confirmed personal-data incidents are assessed and notified to authorities or affected people where legally required.

8. International transfers

Where data is transferred internationally, we use a lawful transfer mechanism and safeguards appropriate to the origin, destination and sensitivity of the data, including contractual protections and transfer assessments where required. Institutional customers should not submit controlled data until the required transfer terms are agreed.

9. Your rights

Subject to applicable law, you may request information, access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. We may verify identity before acting. You may also complain to the competent data-protection authority, including Algeria’s ANPDP where applicable.

10. Children’s privacy

ZGL OS is a professional research service and is not directed to children. Users must be at least 18 or the age of legal capacity in their jurisdiction. Do not submit a minor’s identifiable genomic data without valid legal authority, ethics approval and all required safeguards.

11. Changes

We will update this policy from time to time. Material changes will be communicated via email or in-app notice.

12. Contact

Questions, objections or data requests: contact@zgenomelab.com. Please write “Privacy Request” in the subject and do not send genomic or other sensitive data by ordinary email.