Skip to content

Privacy Policy

MolTrace processes account data, project metadata, spectral files, analysis outputs, usage logs, support communications, billing metadata, and audit events to provide the platform, secure customer workspaces, improve reliability, and support regulatory review.

  • Account and organization information
  • Uploaded spectral files and raw FID archives
  • Analysis results, reports, approvals, and audit trail events
  • Usage, diagnostics, support, and security logs
  • Billing and subscription metadata handled by payment processors

Data is used to operate MolTrace, process analyses, generate reports, enforce security controls, provide support, maintain auditability, and improve product reliability. Customer data must not be used for model training unless the customer has explicitly opted in through an approved data-use agreement.

Retention depends on workspace settings, customer contracts, GxP obligations, and applicable law. Default questionnaire values for legal review are:

Record typeDraft retention position
Analytical files and generated reports7 years unless a customer contract requires a different validated retention period.
Audit logsIndefinite retention for regulated workspaces unless legal counsel approves a shorter period.
Account and support recordsRetain while the account is active, then delete or archive according to the contract.

Customers may request access, correction, export, deletion, portability, or restriction where applicable. Privacy requests should route to privacy@moltrace.com.

Use these structured answers when generating the production Privacy Policy, then send the output to counsel before publishing.

QuestionDraft answer
Product typeSaaS / cloud software for scientific analysis and regulated documentation support.
Personal dataEmail, name, organization, role, support communications, usage logs, billing metadata.
Customer dataSpectral files, raw FID archives, project metadata, reports, approvals, and audit events.
ProcessorsAWS for storage and compute, Stripe for payments, Postmark for email. Verify the live processor list before launch.
Hosting regionsAWS eu-west-1 and us-east-1 unless a customer agreement specifies otherwise.
Regulatory regimesGDPR, UK GDPR, and CCPA/CPRA where applicable. Add other regimes as operations expand.
User rightsAccess, rectification, erasure, portability, restriction, objection where applicable, and complaint routes.

This page is live as the customer-facing policy location, but final production language must be approved by legal counsel before paid onboarding.