Privacy Policy

Data protection for demonstration platform visitors

πŸ“‹ Privacy Policy Overview

VariantBase.com is a demonstration platform showcasing generic industry concepts for genetic variant knowledge platforms. We are committed to protecting your privacy and handling any personal information with transparency and security.

⚠️ IMPORTANT: No Clinical Data Accepted

This is a demonstration platform only. Do NOT submit any Protected Health Information (PHI), patient data, genetic test results, or confidential clinical information. We are not a healthcare provider, not HIPAA compliant, and this platform is not intended for medical or clinical use.

πŸ“Š Information We Collect

Information You Voluntarily Provide

Contact & Acquisition Inquiries

  • Contact Form Data: Name, email address, company name, job title, and inquiry message when you contact us about domain acquisition
  • Communication Records: Any additional information you provide in follow-up emails or communications
  • Business Information: Company details, intended use case, and acquisition timeline when provided voluntarily

Demonstration Platform Interactions

  • API Demo Usage: Non-personal usage data from interacting with our variant lookup demonstration (search queries are not stored)
  • Platform Navigation: Pages visited and features accessed during your demonstration experience

Important: We do NOT collect, store, or process any actual genetic data, patient information, or clinical results. All demonstration queries are processed temporarily and not retained.

Automatically Collected Information

Data Type
Collection Purpose
Retention Period
IP Address
Security, abuse prevention, analytics
90 days
Browser Information
Technical compatibility, user experience
30 days
Device Type
Responsive design optimization
30 days
Page Views & Navigation
Platform improvement, user experience
Aggregated only
Referrer URLs
Traffic analysis, marketing insights
30 days
Session Duration
Platform usage analytics
Aggregated only

🎯 How We Use Your Information

Primary Use Cases

πŸ“ž

Domain Acquisition Communications

Responding to inquiries about VariantBase.com acquisition, providing domain information, and facilitating transfer discussions with qualified parties.

🎨

Platform Demonstration

Showcasing genetic variant platform concepts to potential acquirers, including API functionality and user interface capabilities.

πŸ“ˆ

User Experience Optimization

Improving demonstration content, navigation, and technical performance based on aggregated usage patterns and feedback.

πŸ”’

Security & Abuse Prevention

Monitoring for security threats, preventing automated abuse, and ensuring platform integrity for legitimate users.

βš–οΈ

Legal Compliance

Meeting legal obligations, maintaining records as required by law, and responding to valid legal requests when necessary.

πŸ“Š

Anonymous Analytics

Creating aggregated, non-identifiable statistics about platform usage to improve demonstration effectiveness and content.

What We Do NOT Do With Your Data

  • ❌ No Data Sales: We never sell, rent, or lease your personal information to third parties
  • ❌ No Marketing Lists: We do not add you to marketing lists or share data with marketers
  • ❌ No Unsolicited Communications: We only contact you in response to your inquiries
  • ❌ No Clinical Data Processing: We do not collect, store, or analyze any health or clinical information
  • ❌ No Behavioral Profiling: We do not create detailed user profiles or track behavior across other sites
  • ❌ No Automated Decision Making: We do not use personal data for automated profiling or decision-making

πŸ›‘οΈ Data Protection & Security

Technical Security Measures

πŸ” Encryption & Transport Security

  • TLS/SSL encryption for all data transmission
  • HTTPS enforcement across entire platform
  • Secure form submission protocols
  • Encrypted storage of contact form data

🏰 Access Controls & Authentication

  • Restricted access to personal data on need-to-know basis
  • Multi-factor authentication for administrative access
  • Regular access review and permission auditing
  • Secure credential management practices

πŸ”„ Data Backup & Recovery

  • Regular encrypted backups of essential data
  • Secure off-site backup storage
  • Tested data recovery procedures
  • Business continuity planning

πŸ“± Infrastructure Security

  • Regular security updates and patches
  • Firewall and intrusion detection systems
  • Monitoring for security threats and anomalies
  • Secure hosting with reputable providers

Data Retention Policies

Contact Form Submissions
2 years from last communication
Domain acquisition discussions and follow-up
Email Communications
2 years from last exchange
Business relationship management
Server Logs (IP addresses)
90 days
Security monitoring and abuse prevention
Analytics Data
Permanently (anonymized)
Platform improvement and optimization
Technical Logs
30 days
Technical troubleshooting and optimization

🀝 Third-Party Services & Data Sharing

Limited Third-Party Integrations

We use minimal third-party services, selected specifically for their strong privacy practices and compliance with data protection regulations.

πŸ“§ Formspree (Contact Form Processing)

Secure contact form processing and email delivery
Data Shared: Form submissions (name, email, message content)
Privacy Policy: Formspree Privacy Policy
Compliance: GDPR compliant, SOC 2 Type II certified

🌐 Cloudflare (CDN & Security)

Content delivery, DDoS protection, and web security
Data Processed: IP addresses, request headers, technical metrics
Compliance: GDPR compliant, Privacy Shield certified

πŸ—οΈ Web Hosting Infrastructure

Secure website hosting and infrastructure services
Data Processed: Standard web server logs and technical data
Selection Criteria: Hosting providers chosen for strong privacy practices
Compliance: GDPR and SOC 2 compliant infrastructure

Data Sharing Limitations

🎯 Your Privacy Rights

GDPR & International Privacy Rights

Under the General Data Protection Regulation (GDPR) and other privacy laws, you have specific rights regarding your personal data:

πŸ‘οΈ

Right to Access

Request a copy of all personal data we hold about you, including how it's used and who it's shared with.

Contact us with verification to exercise this right
✏️

Right to Rectification

Correct any inaccurate or incomplete personal information in our records.

Email us or use the contact form with corrections
πŸ—‘οΈ

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data when it's no longer necessary for our legitimate purposes.

Submit deletion request with specific data to remove
πŸ“¦

Right to Data Portability

Receive your personal data in a structured, commonly-used format for transfer to another service.

Request JSON export of your data
πŸ›‘

Right to Object

Object to processing of your personal data for specific purposes, including direct marketing.

Email us with specific objection and reasoning
⏸️

Right to Restrict Processing

Limit how we use your personal data while we address concerns about accuracy or processing.

Contact us with specific restriction request

How to Exercise Your Rights

πŸ“§ Privacy Request Process

  1. Contact Us: Use our secure contact form or email with your privacy request
  2. Verify Identity: We may ask for verification to protect your privacy and prevent unauthorized access
  3. Specify Request: Clearly describe which right you're exercising and what specific action you want
  4. Receive Response: We'll respond within 30 days (may extend to 60 days for complex requests)

⏱️ Response Timeframes

Standard Privacy Rights Requests
30 days
Complex Requests (multiple rights)
60 days (with notification)
Data Deletion Requests
30 days to complete
Data Access/Portability Requests
30 days to provide data

Additional Privacy Protections

πŸ‡ΊπŸ‡Έ California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected and how it's used
  • Right to know if personal information is sold or disclosed to third parties
  • Right to opt-out of the sale of personal information (Note: We do not sell personal information)
  • Right to non-discrimination for exercising privacy rights

🌍 International Privacy Laws

We respect privacy rights under various international frameworks:

  • PIPEDA (Canada): Personal Information Protection and Electronic Documents Act compliance
  • LGPD (Brazil): Lei Geral de ProteΓ§Γ£o de Dados personal data protection
  • Privacy Act (Australia): Australian privacy principles and individual rights
  • Local Laws: Compliance with applicable local privacy regulations

πŸ“ž Privacy Contact Information

Data Protection Contact

πŸ“§

Primary Contact

For all privacy-related questions, data requests, or to exercise your rights:

Method: Use our secure contact form

Subject Line: Mark inquiries as "Privacy Request" or "Data Protection"

⏱️

Response Times

Privacy Inquiries: 1-2 business days for initial response

Data Requests: 30 days maximum for completion

Urgent Privacy Issues: Same-day response when possible

🎯

Purpose Limitation

Privacy Contact Only: This channel is exclusively for privacy-related matters

Domain Inquiries: Use regular contact form for acquisition discussions

Technical Issues: Not a technical support channel

Data Protection Authority Rights

πŸ›οΈ Right to Lodge Complaints

If you have concerns about our privacy practices that we cannot resolve directly, you have the right to lodge a complaint with your local data protection authority:

European Union: Your local Data Protection Authority (DPA) under GDPR
United Kingdom: Information Commissioner's Office (ICO)
California (US): California Privacy Protection Agency
Canada: Office of the Privacy Commissioner of Canada

We encourage you to contact us first to resolve any privacy concerns directly, but you have the right to lodge complaints with appropriate authorities if needed.

πŸ”„ Policy Updates & Changes

How We Handle Privacy Policy Updates

1

Regular Reviews

We review this privacy policy annually and whenever we make significant changes to our data practices or platform functionality.

2

Change Documentation

All material changes are documented with updated effective dates and version numbers clearly displayed at the top of this policy.

3

User Notification

For significant changes that affect your rights, we will notify users who have contacted us via email before the changes take effect.

4

Continued Use Consent

Your continued use of the platform after policy updates indicates acceptance. If you disagree with changes, please contact us or discontinue use.

Version History

Version 2.1
January 15, 2025
Enhanced third-party service documentation, expanded international privacy rights coverage
Version 2.0
January 1, 2025
Major update for GDPR compliance, added comprehensive rights section, restructured data protection measures
Version 1.0
December 1, 2024
Initial privacy policy for demonstration platform launch