Effective date: September 9, 2026.
1. Controller
Biocompile, Inc. is the controller responsible for the personal data processed through this website.
Biocompile, Inc.
Frontier Tower
995 Market Street
San Francisco, CA 94103
United States
Email: contact@biocompile.com
We apply GDPR-level protections to all visitors as our baseline and provide additional, region-specific rights where local law requires. To exercise your data-protection rights, contact us at the address above. See the imprint for full company details.
2. Data we collect
2.1 Contact form and pilot form
Two forms on this site send us a message. The contact form collects your name, your email address, and your message. The pilot form collects your name, your email address, the company, institution or team you belong to, and your answers to four open questions: your research focus, the roadblocks you run into, what you would most want taken off your plate, and the area of science that excites you. The four answers are free text, so what they contain is what you choose to write in them; please leave out anything confidential that your enquiry does not need.
By checking the consent checkbox on either form, you consent to this processing solely to respond to your enquiry (Art. 6(1)(a) GDPR). Your submission is composed into one message, forwarded to our team inbox, and not stored in a database. We retain correspondence for the duration of the enquiry thread plus six months after the last exchange. You may withdraw consent at any time by contacting us, though this does not affect the lawfulness of processing carried out before withdrawal.
2.2 Analytics (PostHog EU)
We use PostHog, hosted exclusively in the EU (Frankfurt, Germany), for privacy-preserving aggregate usage measurement. Analytics requests are sent to a path on our own domain and relayed by our servers to PostHog rather than being sent from your browser directly. This changes only the network route: the request, and the IP address it originates from, pass through our infrastructure before PostHog receives it, while the data described below and your consent choice stay the same. PostHog operates in one of three modes depending on your consent choice:
- Before you make a choice (anonymous mode). We record aggregate measurement
of how our pages are used, each event carrying the address of the page you are on: a
page-view and a page-exit event (between them giving how long the page was open, how far
down it you scrolled, and the referring site's domain if there is one), which part of the
page was in front of you and for how long, clicks on page elements, page-speed
measurements, which of our calls to action came into view and which you selected,
whether the consent banner was shown and what you chose on it, and a redirect event when you
leave for our application. If you start a signup, the steps you take on the step described in
section 2.5 are recorded in the same way: that it opened, that you selected the field,
whether you submitted, closed or left it, how long it was open, and, on submit, the domain
part of the address you entered. The address itself is never sent to our analytics, in this
mode or any other, and neither is anything else you type: click measurement records which
element was selected and the text printed on it, which on this site is our own published
wording, and never the contents of a field.
No cookies or localStorage entries are set, no device identifier is created or persisted,
session recording and surveys are disabled, element attributes are masked, and we instruct
PostHog to discard your IP address.
Events carry the name and version of your browser and operating system, and nothing else
about your device. Your screen and window dimensions, your device type, your time zone and
your browser's full user agent string are all refused before anything is sent, as is the
high-entropy device-model identifier that browsers can expose. Those are the values a
browser fingerprint is ordinarily assembled from, and no measurement on this site is built
on any of them. Clicks that hit nothing, rapid repeated clicks in one spot, and the
coordinates of clicks and scrolling are switched off in this mode for the same reason: a
coordinate means nothing without the window it was measured in.
If the link you followed carried an advertising click identifier, it is replaced with the
word
<masked>before the page address is sent, in this mode and in every other. Because nothing is stored on or read from your device, and no identifier links one page you open to the next, this mode falls outside TDDDG Section 25 (formerly TTDSG Section 25) consent requirements. It is limited to first-party measurement of how our own pages perform and are used, which is the audience-measurement purpose recognised by the CNIL, and is based on our legitimate interest in measuring aggregate use of our public marketing site (Art. 6(1)(f) GDPR). The processing is strictly limited to what is necessary to produce aggregate statistics and cannot identify you. - After you accept (full mode). We record everything the anonymous mode
records, and consent changes two things about it. A visit identifier is stored in
localStorage and a cookie, so the pages you open can be read as one visit rather than as
unrelated arrivals. And the values listed above as refused are no longer refused: your
screen and window dimensions, your device type, your time zone and your browser's user
agent are sent, and clicks that hit nothing, rapid repeated clicks and the coordinates of
clicks and scrolling are recorded again. Your IP address is still discarded, and an
advertising click identifier in the page address is still masked.
Because you consented, links from this site to our application also carry that visit
identifier and the session identifier as web address parameters (
ph_didandph_sid), so that the pages you saw here and what you go on to do in the application are measured as one journey rather than two unrelated ones. Neither value contains your name or your email address. In anonymous mode no such identifier exists and nothing is carried across. This is based on your consent (Art. 6(1)(a) GDPR). PostHog analytics data is retained for up to 7 years, the retention period of our analytics platform's current plan. - After you decline (no analytics). No PostHog requests are made and any in-memory analytics from anonymous mode are opted out.
Feature-flag decision endpoints and third-party data sharing are disabled in every mode.
Session recording is disabled in every mode on this website. We honour the Do-Not-Track (DNT) browser signal and the
Global Privacy Control (GPC) signal. When either is detected, no analytics run in
any mode. A browser sending Global Privacy Control is not shown the consent banner either,
because the signal is already an answer, and the "Cookie settings" link has nothing to change
for as long as that signal is sent. Otherwise you can withdraw or re-grant consent at any time
via that link in the footer (Art. 7(3) GDPR).
2.3 Bot protection (Cloudflare Turnstile)
Our contact form and our pilot form use Cloudflare Turnstile to protect against automated abuse. Turnstile processes limited technical data (browser type, interaction patterns) to verify you are human. This is based on our legitimate interest in preventing spam (Art. 6(1)(f) GDPR).
2.4 Server logs
This website runs on our own infrastructure in the Amazon Web Services Frankfurt region (eu-central-1), within the European Union. Standard server access logs record truncated IP addresses, request paths, timestamps, and HTTP status codes. These are retained for up to 14 days and used exclusively for security monitoring and debugging.
2.4a Scans of a printed QR code
Some of our printed material — conference posters, flyers, business cards —
carries a QR code that resolves through an address we operate at
app.biocompile.com/qr/ before sending you on to the page it points at. That
redirect is served by our application rather than by this website, and it is recorded so we
can tell which printed material people actually use. It is also what lets us change where a
printed code sends people without reprinting it.
We keep the code that was scanned, the campaign and material it belongs to, whether the request looked like a person or like an automated link checker, a country code, and a coarse device kind. We do not store your IP address and we do not store your full browser identification string. To tell a repeat scan from a new one within a single day we keep a one-way hash of your address and browser string under a key generated fresh every day and never written down, so scans on different days cannot be linked to each other. Nothing is written to or read from your device during the redirect.
The hash is deleted after 90 days and the scan records after 25 months, leaving only counts. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR in knowing whether our printed material works; the balancing test is available on request. You can object under Art. 21 GDPR, and you can avoid it entirely by typing the address printed beside the code instead of scanning it.
2.5 Signup step
When you select a button that starts a signup, we show a short step that asks for your work email address before sending you to our application at app.biocompile.com. We store that address, its domain and a coarse classification of that domain (a work address, a free mailbox, a shared role address, or a disposable one), the time you entered it, the page and the button you came from, the domain of the site that referred you if there was one, your language preference, the wording of the notice you were shown on the step at that moment, and a keyed hash of your IP address used to limit abuse of the form. We cannot reverse that hash to your address. We do this so that we can prefill the signup form for you. This is based on our legitimate interest in completing a signup you started yourself (Art. 6(1)(f) GDPR). We do not add this address to a mailing list, we do not enrich it with data from other sources, and we do not share it with advertisers or data brokers.
The step also tells you, at the moment you enter the address, that a founder may write to you once to help you get started. That single message is the only thing we send as a result of this step. It is about the signup you began yourself, it is announced to you before you hand the address over, and it is not sent at all once an account exists, because there is then nothing to help you start. It is based on the same legitimate interest (Art. 6(1)(f) GDPR), and it is not a newsletter: there is no sequence behind it and no second message if you do not reply. Anything beyond that one message would need your consent, and the place we would ask for it is inside the product, not on this step.
If we cannot store the address at that moment, for example because the service that holds it is unavailable, we send it instead to our own support inbox so that your signup is not lost. That message goes through Twilio SendGrid, our email provider, and is held in our inbox at Google Workspace. We delete it there within 30 days. This is the only case in which the address reaches a mailbox rather than our database, and it carries nothing beyond the address, the page you came from and the button you selected.
You may object to this processing at any time under Art. 21(1) GDPR. Write to contact@biocompile.com and we will delete your address. If you do not complete signup, we delete the record 90 days after you entered it. If you do complete signup, we delete the record within 30 days of your account being created, after which your address is held only as part of your account.
Your address is passed to app.biocompile.com through a single-use token that expires after ten minutes, so that the address itself does not appear in a web address, in server logs, or in your browser history.
Closing the step, with the Escape key or by selecting outside it, returns you to the page you were on and stores nothing. The step is asked once per visit: after you have given an address, later signup buttons go straight through. The buttons themselves carry the ordinary signup link, so opening one in a new tab or going to app.biocompile.com/signup directly reaches signup without passing through the step.
3. Hosting and processors
This website is hosted by:
- Amazon Web Services (Frankfurt, Germany, eu-central-1): server infrastructure
- Cloudflare (EU data centers): CDN, DDoS protection, Turnstile
- PostHog (Frankfurt, Germany): analytics (consent-gated)
- Twilio SendGrid: delivery of the messages this site sends, which are the contact and pilot enquiries in section 2.1 and the fallback described in section 2.5
- Google Workspace: the inbox those messages arrive in
Every processor is covered by a data processing agreement, and the processing itself takes place within the European Union. Five of these processors are established in the United States, so their flows are named individually rather than covered by one general statement. For Amazon Web Services, the data is stored in the EU region and the remaining exposure is potential access by the US parent; we rely on Amazon Web Services, Inc.'s certification under the EU-US Data Privacy Framework together with the EU Standard Contractual Clauses carried by the AWS Data Processing Addendum. For Cloudflare, Inc., any transfer or access outside the EEA is safeguarded by the EU Standard Contractual Clauses in Cloudflare's data processing agreement. PostHog, Inc. is likewise a United States company, and the position is the same as for Amazon Web Services: the analytics data is processed and stored exclusively in PostHog's European Union region, and the remaining exposure is potential access by the US parent, for which we rely on the EU Standard Contractual Clauses carried by the PostHog data processing agreement. For Twilio Inc. and Google LLC, any transfer or access outside the EEA is safeguarded by the EU Standard Contractual Clauses carried by their respective data processing agreements.
4. Your rights
Under GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent at any time (Art. 7(3))
- Lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, contact us at contact@biocompile.com. We will respond within one month.
4.1 California residents
If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the California Online Privacy Protection Act (CalOPPA):
- Categories of personal information collected: Internet or other electronic network activity information (anonymized measurement events in anonymous mode; pageviews, clicks, and Web Vitals in full mode); identifiers (name and email address via the contact form, the pilot form, and the signup step); professional or employment-related information (the company, institution or team and the research answers you give on the pilot form). We collect no sensitive personal information as California defines it, so the right to limit its use does not arise.
- Sale or sharing: We do not sell or share your personal information as defined under CCPA. PostHog operates as a service provider under contract and does not receive data for its own commercial purposes.
- Your rights: You have the right to know what personal information we collect, to request deletion, and to request correction. You have the right not to be treated differently for exercising any of them, and we do not: nothing on this site is withheld, delayed, degraded or priced differently according to what you chose. To exercise these rights, email contact@biocompile.com. We will respond within 45 days. Someone may make a request on your behalf if you give them written permission, and we may ask you to confirm it directly.
- Do Not Track / Global Privacy Control: This site honours both the DNT browser signal and the GPC signal, for every visitor and without regard to where they are. When either is detected, all analytics are disabled. No consent banner is shown either, because the signal is already an answer, and the footer says so on the page. The signal reaches us from one browser, so it is that browser we act on; we do not carry it across to your other devices, and a browser that does not send it is not read as having agreed to anything, it is simply asked.
5. Cookies and storage
This website sets no cookies and writes nothing to your browser's storage for measurement or
advertising before you make a choice on the consent banner. The one thing that can be written
before you choose is the short-lived Cloudflare Turnstile token described in the
Cookie Notice, and only if you submit the contact or pilot form
first; it is strictly necessary for that form and carries nothing about you.
Once you decide, a record of that decision
(__biocompile_consent) is stored in localStorage: your answer for each purpose
separately, the version of the wording you were shown, and the date. It contains no identifier.
It persists until you clear it or use the "Cookie settings" link in the footer, and it expires
after six months, after which you are asked again. A purpose you were never shown is recorded
as undecided rather than as agreement, so adding one asks you rather than assumes you.
No third-party tracking cookies are used at any time.
One further entry is written only if you start a signup: once you have answered the signup
step described in section 2.5, we note that answer (__biocompile_handoff) so that
the step is not shown to you again on the way to the same page. It is stored in sessionStorage,
which your browser discards when you close the tab, and it holds no personal data beyond the
single-use token described above.
For details on what each consent mode does, see Cookie Notice.
6. Retention summary
- Contact-form and pilot-form correspondence: duration of the enquiry thread + 6 months
- Signup step, signup not completed: 90 days from the day you entered your address
- Signup step, signup completed: deleted within 30 days of your account being created
- PostHog analytics (full mode): up to 7 years (analytics platform plan retention)
- Server logs: up to 14 days
- Consent choice: persisted in your browser's localStorage until you clear it, and asked again after six months
7. Changes
We may update this privacy policy to reflect changes in our practices or legal requirements. The current version is always available at this URL.