EpiNexus
Home Features Pipelines How to Use FAQ Blog About Contact Launch App
Launch App

Privacy Policy

Last updated: 6 October 2026

At a glance

  • Who we are: EpiNexus is provided by EpiNexus, Sweden. Write to info@epinexus.io about anything on this page.
  • This website (epinexus.io) sets no cookies, stores nothing on your device and has no analytics. Our web host logs each request (IP address, page, browser) to deliver and protect the site.
  • The application (app.epinexus.io) holds your account details (your email address; optionally your name, institution, role and research area), the files you upload, your results, and technical logs.
  • Where: your files and results are stored and analysed in Google Cloud in Belgium. Sign-in is handled by Google Firebase Authentication in the USA, under the EU–US Data Privacy Framework.
  • Research data: we process it on behalf of your institution. Sequencing data from people may be uploaded only in pseudonymised form, and only after your institution has signed a data processing agreement with us.
  • Your rights: to access, correct, delete, restrict and take your data with you, to object, and to complain to a data protection authority.

On this page

  1. Who is responsible (legal notice)
  2. Visiting this website
  3. Your account in the application
  4. Research data you upload
  5. Emails
  6. Who receives data
  7. Transfers outside the EU
  8. How long we keep data
  9. Storage on your device
  10. Your rights
  11. Security
  12. Automated decisions
  13. Children
  14. Changes to this page

1. Who is responsible (legal notice)

The controller of the personal data described on this page — the organisation that decides why and how it is used — is:

EpiNexus
Teknikringen 7, 583 30 Linköping
Sweden
Email: info@epinexus.io

These details are also the legal notice for this website and the EpiNexus application. We have not appointed a data protection officer; for any question about your data, write to the email address above.

For research data you upload to the application, your institution is the controller and we act on its behalf (section 4).

2. Visiting this website

This website is a set of static pages hosted by Hostinger International Ltd (Cyprus) on a server in France. When you open a page, your browser sends the server your IP address, the page requested and your browser type, and the server records them with the time in an access log.

  • Why: to deliver the pages, and to detect and stop attacks and misuse.
  • Legal basis: our legitimate interest in running a secure website (GDPR Art. 6(1)(f)).
  • How long: Hostinger keeps the logs on its own schedule; we can view only the last 7 days and don't copy them.

The website sets no cookies, stores nothing on your device, and has no analytics, advertising or social-media plugins. Its fonts and scripts are served from our own server, so your browser contacts no one else. You contact us by email (section 5).

3. Your account in the application

The EpiNexus application at app.epinexus.io is available by invitation during the pilot. We receive your email address — and sometimes your name and institution — from the person who invites you.

What we holdDetails
Your profileYour email address, which an account needs; optionally your name, institution, role and research area.
Sign-inGoogle Firebase Authentication stores your email address and your password in hashed form (we never see your password), sends the emails that let you set or reset it, and records the IP address and browser used to sign in, to protect accounts from abuse.
Your use of the serviceYour projects, sample descriptions, file names and sizes, analysis settings, runs and their computing time, the accession numbers you import, and the reports you create.
Technical logsEach request to the application: IP address, time, the address requested and your browser. The machines that run analyses log the steps of each run.
  • Why: to give you access, run the analyses you ask for, keep the service secure, account for computing costs, and answer your questions.
  • Legal basis: where you or your institution have an agreement with us, providing the service under it (Art. 6(1)(b)); otherwise our legitimate interest in running the pilot you asked to join (Art. 6(1)(f)). Technical logs: our legitimate interest in keeping the service secure and working (Art. 6(1)(f)).

4. Research data you upload

Most data analysed in EpiNexus — from mice, plants, cell lines and other organisms — is not personal data. Sequencing data from people is: it carries their genetic information, which the GDPR treats as a special category (Art. 9), and it remains personal data when it is pseudonymised.

  • Our role. We process the data you upload or import on behalf of your institution, which decides what is analysed and is the controller; we are its processor (Art. 28). We use the data only to run the analyses you ask for and to help you when you ask us to. We don't share it, sell it, use it for our own research, or try to identify anyone in it.
  • Where. Files and results are stored in Google Cloud Storage in Belgium (region europe-west1). Each analysis runs on its own temporary virtual machine in the same region, deleted when the run ends.
  • Who can see it. Each project is visible only to the account that owns it. EpiNexus staff access it only when needed to operate the service, or to help you at your request.

Before you upload sequencing data from people

  • Your institution must first sign a data processing agreement with us (GDPR Art. 28). Write to info@epinexus.io.
  • Your institution needs its own legal basis and a condition under Art. 9 — usually scientific research with the safeguards of Art. 89(1), or the participants’ explicit consent — and the approvals its study requires.
  • Upload pseudonymised data only: no names, dates of birth, hospital or record numbers or other direct identifiers — also not in file names, sample names, project names or file headers.
  • Don’t use “Open in UCSC” (below) for data you may not share outside your institution.

If you took part in a study whose data was analysed in EpiNexus, please contact the institution that collected your samples. We pass any request we receive on to it.

Public data. When you import data from GEO, SRA or ENA, EpiNexus downloads the files from the public archives (ENA at EMBL-EBI, NCBI, and NCBI’s copies in the AWS Open Data programme), sending them only the accession numbers. Controlled-access data (dbGaP, EGA) can’t be imported.

Genome browser and UCSC. The application’s genome browser loads reference tracks (genome sequence and genes) from igv.org, so your browser sends igv.org (USA) your IP address and the genome region you view. “Open in UCSC” is used only when you click it: it gives the UCSC Genome Browser (University of California, Santa Cruz, USA) links, valid for 24 hours, from which UCSC fetches the tracks you chose.

5. Emails

When you write to info@epinexus.io, we receive your email address, your name if you give it, and what you write. Our email runs on Google Workspace.

  • Why: to answer you and keep a record of our exchanges.
  • Legal basis: providing the service, or steps you asked for before an agreement (Art. 6(1)(b)); otherwise our legitimate interest in answering enquiries (Art. 6(1)(f)).
  • How long: 2 years after our last exchange, unless an agreement with you or your institution requires longer.

We don’t send newsletters or marketing emails.

6. Who receives data

These service providers process data for us under data processing agreements, only on our instructions:

ProviderWhat forWhere
Hostinger International LtdHosting this websiteFrance (EU)
Google CloudHosting the application: servers, file storage, analysis machines, logs, backupsBelgium (EU)
Google Firebase AuthenticationSign-in and password emailsUSA
Google WorkspaceOur emailGoogle data centres, in and outside the EU

When you open the genome browser or click “Open in UCSC”, your browser also contacts igv.org or the UCSC Genome Browser in the USA directly (section 4); they are not our service providers. We share personal data with no one else and never sell it. We disclose it to authorities only when the law requires us to.

7. Transfers outside the EU

Firebase Authentication processes sign-in data in the USA, and Google Workspace may store email outside the EU. Google LLC is certified under the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision (Implementing Decision (EU) 2023/1795); Google’s data processing terms also include the EU standard contractual clauses (Implementing Decision (EU) 2021/914). You can check Google’s certification on the Data Privacy Framework list, and ask us for a copy of the safeguards.

The genome browser’s requests to igv.org, and “Open in UCSC”, go from your browser to those services in the USA, which no adequacy decision covers. They happen only when you open the genome browser or click “Open in UCSC”.

8. How long we keep data

DataHow long
Website access logsAs Hostinger keeps them; we can view only the last 7 days and don’t copy them.
Application access logsOldest entries are deleted once a log reaches its fixed size (250 MB).
Logs of analysis machines30 days.
Your accountUntil you ask us to delete it, or the agreement with you or your institution ends; we then delete it within 30 days. Firebase removes it from its own backups within 180 days.
Your files and resultsUntil you delete them or their project, or your account is deleted. A deleted run can be restored for 7 days; its files are then removed. Deleted files stay in Google’s recovery copy for a further 7 days.
Records of deleted runsA deleted run’s name, settings and computing time stay with its project, for accounting, until the project is deleted.
Unfinished uploadsCancelled and removed after 7 days.
Database backups (accounts, projects, runs — not your files)30 days.
Server disk snapshots (database and logs)14 days.
Emails2 years after our last exchange.

9. Storage on your device

This website stores nothing on your device. The application stores only what its features need, in your browser’s storage:

WhatWhyHow long
Sign-in session (Firebase Authentication)Keeps you signed inUntil you sign out, also after you close the browser
Display themeRemembers light or dark display, only if you choose oneUntil you change it or clear your browser’s data
Upload progressLets an interrupted upload continue; holds the project, the file’s name and size, and a reference to the uploadUntil the upload finishes or is cancelled
Sign-out noticeTells you once why you were signed outUntil you close the tab

No analytics, advertising or tracking technologies are used.

10. Your rights

You have the right to:

  • access the personal data we hold about you and receive a copy (Art. 15);
  • have it corrected (Art. 16) — you can also edit your profile in the application;
  • have it deleted (Art. 17) — you can delete your files, runs and projects yourself; write to us to delete your account;
  • restrict how we use it (Art. 18);
  • receive the data you gave us in a common, machine-readable format, or have it sent to another provider (portability, Art. 20);
  • object to its use (Art. 21; see the box below).

None of the processing on this page relies on your consent; if we ever ask for consent, you can withdraw it at any time.

Write to info@epinexus.io. We answer within one month; for complex requests we may extend this by two months, and will tell you why. It is free of charge. We may ask you to confirm your identity, for example by writing from your account’s email address.

Requests about research data from the people it describes go to the institution responsible for the study; we help it to answer them.

Your right to object

Where we use your data on the basis of our legitimate interests (Art. 6(1)(f)), you can object at any time, for reasons arising from your particular situation. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or need the data to establish, exercise or defend legal claims (Art. 21(1)). Write to info@epinexus.io.

Complaints

You can complain to a data protection authority, in particular in the EU country where you live, work, or where you think the problem arose (Art. 77). Sweden's authority is Integritetsskyddsmyndigheten (IMY), imy.se. The European Data Protection Board lists every authority. We would welcome the chance to resolve your concern first.

11. Security

We protect data with measures suited to what we hold:

  • all connections use HTTPS, and browsers are told to use nothing else (HSTS);
  • stored data is encrypted in Google Cloud (AES-256);
  • accounts are by invitation only; passwords are handled by Firebase and never reach our servers; every request is checked against the signed-in account on our server;
  • each project is visible only to its owner, and automated tests check that one account can’t reach another’s data;
  • each analysis runs on its own temporary machine, deleted when the run ends;
  • our database and job queue are not reachable from the internet;
  • the database is backed up, and backups are kept for 30 days;
  • every code change is scanned for known vulnerabilities in the software it uses and for leaked secrets, and the application’s server image for vulnerable packages;
  • access to the servers is limited to the people who run the service.

No system is completely secure. Use a strong password that you don’t use elsewhere; two-step sign-in is not available yet.

If a breach of personal data occurs, we notify the competent data protection authority within 72 hours where the law requires it (Art. 33), and the people affected without undue delay when the breach puts them at high risk (Art. 34). For research data, we inform your institution without undue delay so that it can do the same.

12. Automated decisions

We make no decisions about you based solely on automated processing, including profiling (Art. 22). EpiNexus grades the quality of sequencing data automatically; that concerns the data, not you.

13. Children

EpiNexus is a research tool and is not intended for anyone under 16.

14. Changes to this page

We update this page when what we do changes, and change the date at the top. We tell account holders by email about significant changes.

  • 6 October 2026: rewritten — who is responsible and our legal notice, legal bases, recipients, transfers outside the EU, retention periods, storage on your device, our role for research data, and your rights, including the right to object and to complain.
  • 3 October 2026: application accounts, storage location and sign-in described.

Questions about this page or your data? Write to info@epinexus.io.

EpiNexus

Epigenomics analysis platform. Upload your data, click run, and explore results — no coding required.

Platform

Features Pipelines Documentation

Help

How to Use FAQ Blog About

Connect

Contact Us Email Launch App Pilot Access
© 2026 EpiNexus. All rights reserved.
Privacy Legal notice