Back to home

Legal

Privacy Policy

Effective August 6, 2026.

LynQX, Inc. (“LynQX,” “we,” “us”) takes data protection seriously because life sciences demands it. This policy explains what we collect, why, where it’s stored, who can see it, and what rights you have. It describes the system as it runs today, not as we intend it to run later. This is a plain-English overview; specific obligations are defined in our Terms of Service and our Data Processing Addendum (DPA), available on request to [email protected].

1. What we collect

  • Account data — name, email, role/persona, organization affiliation, and a Supabase Auth identifier. Supabase Auth is our identity provider; if you sign in with Google, LinkedIn, or ORCID we receive the profile and email fields those providers release. Provided when you sign up.
  • Profile data for experts and candidates — resumes you upload or paste, credentials (e.g. NPI, ORCID), publications, patents, trial roles, capability statements. Supplied by you, or fetched from the specific public links contained in your resume.
  • Engagement data — needs you express, projects you create or apply to, messages, scheduled meetings, contracts, invoices, milestones.
  • Usage and audit data — page views, feature usage, and an append-only audit record of regulated actions (actor, action, target, timestamp).
  • PHI — only in HIPAA-mode workspaces, only when explicitly flagged, and only with a signed BAA. PHI is never included in a prompt sent to a language model.

2. How we use it

  • Operate the marketplace: matching, verification, scheduling, billing, audit.
  • Improve the agents — but never train third-party models on customer data.
  • Comply with regulatory obligations (debarment screening, audit retention, etc.).
  • Send transactional notifications and (with consent) product updates.

3. Where data lives

Primary application data sits in Postgres (with the pgvector extension) hosted by Supabase. A Neo4j graph and a Redis queue run on infrastructure we operate. Uploaded files and generated documents go to S3-compatible object storage (AWS S3 or Cloudflare R2) when it is configured for the deployment. LynQX runs in a single region today; see §5.

4. Sub-processors and sharing

We share your data only with the sub-processors below, with regulators on legal request after legal review, and with other LynQX users via the matching and engagement flows you initiate. We never sell your data.

  • Supabase — authentication and the primary Postgres database. Holds account and application data.
  • Groq — our primary language-model provider. Agent prompts are sent to Groq, which means resume text, profile content, and conversation text you give an agent are processed there. AI-assisted resume processing runs only when you consent to it.
  • OpenAI — text embeddings for semantic matching, when embeddings are enabled for the deployment. Profile text is sent; no embeddings vendor receives PHI.
  • Anthropic — an optional secondary model path for candidate profile drafting, active only when the deployment configures an Anthropic key.
  • Resend — transactional email (verification, password reset, notifications).
  • Stripe — subscription and invoice payments, when live payments are enabled for your account. We never store card numbers.
  • Sentry — error and performance telemetry, when configured. Events pass through a scrubber that strips credentials, request bodies, and PHI-classified fields before they leave our systems.
  • AWS S3 / Cloudflare R2 — object storage for uploads and generated documents.

We ask each sub-processor for a Data Processing Addendum. Where a vendor would be exposed to PHI, a BAA is required before that vendor is used in a HIPAA-mode workspace. Current DPA/BAA status for any specific vendor is available on request.

5. International transfers (GDPR)

LynQX currently runs in a single region. For workspaces configured with an EU residency mode, the Compliance Sentinel blocks transfers of EU personal data to a US destination at the application layer; we do not yet operate a separate EU database cluster, so EU-only physical residency is not something we can offer today. Standard Contractual Clauses are available where transfers are necessary. If you require physical EU residency, contact [email protected] before onboarding.

6. Your rights

  • Access — request a full export of what we hold about you. Requests can be made in-product or by emailing [email protected], and we respond within 30 days.
  • Rectification — edit most fields in-product; admin path for the rest.
  • Erasure— candidates can delete their profile from the profile editor, and account erasure can be requested through the same channels as access. One exception: the audit log is append-only and hash-chained, so erasure severs the link to you rather than rewriting those rows — rewriting them would destroy the integrity guarantee for every other person’s records too. Retention there is limited to what a legal basis supports (typically 7 years).
  • Portability — machine-readable JSON export.
  • Objection — opt out of agent-driven matching at any time. Candidate profiles are private until you explicitly publish them, and a published profile can be set to stealth or private, or unpublished.

7. Retention

Account data: for the life of the account + 90 days. Audit logs: 7 years. Engagement records: 7 years for tax / dispute purposes. Detailed retention schedule in the DPA.

8. Security

TLS in transit (TLS 1.3 where the client supports it). Encryption at rest is provided by our database and object-storage providers. Tenant isolation is enforced redundantly — every query is scoped to your organization in the application layer, Postgres row-level security policies enforce the same boundary in the database, and graph queries carry a tenant property. The audit log is append-only and hash-chained, so tampering is detectable. Application-level field encryption is not yet implemented; sensitive fields are protected by provider-level encryption at rest plus the isolation and access controls above. See our Security page for the current control set and what is still on the roadmap.

9. Cookies

See our Cookie Policy for the specific cookies we set. Functional cookies only by default; analytics with consent.

10. Children

LynQX is not for users under 18. Our Terms require it, and we close any account we learn belongs to a minor.

11. Changes

We’ll notify all account holders by email at least 30 days before material changes take effect. Historical versions are kept and available on request.

12. Contact

Privacy questions, DSR requests, or DPA: [email protected]. For security issues: [email protected].