1. Controller and scope
Clever Consult LLP, BIN 170140025804, is the controller for the public website, individual SciCollab accounts and product inquiries. For institution-managed projects, roles may be allocated differently by the written agreement and data processing addendum.
2. Data we process
- Account and identity data: name, email, language, organization, role and authentication records.
- Research workspace data: projects, sources, notes, protocols, datasets, findings, manuscripts, comments, files, versions and permissions.
- Inquiry data: the fields submitted through Demo, Contact, privacy or security requests.
- Technical data: security events, device and request metadata, diagnostic logs and consent choices.
- Optional analytics: product events and masked replay on permitted overview screens after explicit consent.
3. Purposes and legal bases
We process data to provide accounts and requested features, secure and operate the service, respond to inquiries, fulfil contracts, comply with law and improve the product where consent or legitimate interests permit. We request separate consent for optional analytics and do not use form data for unrelated marketing without an additional opt-in.
4. AI features and research content
Provider-backed AI features are disabled unless configured. When a user deliberately invokes one, the selected context needed for that task may be sent to the disclosed provider. SciCollab does not use customer research content to train its own models. Provider, region, retention and contractual controls must be disclosed before institutional activation.
5. Service providers and transfers
Where processing crosses borders, we use contractual and technical safeguards appropriate to the destination and service. An institutional data processing addendum and current subprocessor information are available through the Contact page.
- Self-managed application, PostgreSQL and object-storage infrastructure in Kazakhstan: hosting, storage, backup and service delivery.
- Transactional email provider: account security messages, invitations and inquiry confirmations; research files are not included.
- PostHog EU: optional product analytics only after consent; research text, files and form values are excluded, and replay is masked and limited.
- Configured AI provider: selected context only when a provider-backed feature is enabled and invoked.
6. Retention
- Demo, Contact, privacy and security inquiries: up to 24 months after the last substantive interaction.
- Individual account and project data: while the account is active, then deletion or anonymisation after closure, subject to export, disputes and legal duties.
- Security and diagnostic logs: normally up to 90 days, longer only for an active investigation or legal duty.
- Encrypted backups: overwritten on the operational backup cycle, with a target maximum of 35 days after primary deletion unless a legal hold applies.
- Consent records and contractual records: for the period needed to demonstrate compliance and establish or defend legal claims.
7. Your choices and rights
Depending on applicable law, you may request access, correction, export, restriction, objection or deletion and may withdraw consent without affecting earlier lawful processing. Submit a Privacy request through Contact. We verify identity before disclosing or deleting protected data and normally respond within 30 calendar days.
8. Security and incidents
We use access controls, encryption in transit, protected secrets, isolated storage, backups, malware scanning, logging and least-privilege operational access. No system is risk-free. Report a suspected vulnerability through Contact using the Security topic; do not include exploit data in a public message.
9. Children and changes
SciCollab is intended for higher education and professional research and is not directed to children under 16. Material policy changes will be dated here and, where required, notified in the application or by email.