1. Introduction
ChromaParse (“we”, “the service”) understands that pharmaceutical users hold data privacy as paramount. This Privacy Policy explains how we collect, use, store, and protect your personal information and uploaded data. By using ChromaParse, you agree to the terms of this policy.
We commit: your chromatography data is used only for the processing you request and is permanently deleted within 24 hours of completion. Max and Team subscribers’ data is never used for model training or shared with any third party. Free and Super tier data may be used for AI model training and quality improvement; registration is taken as consent.
2. Information we collect
2.1 Information you provide
- Account info: email, password (encrypted), phone number (optional)
- Contact info: name, email, company, and message you submit via the contact form
- Payment info: payment records processed by third-party providers (we do not directly store card details)
2.2 Automatically collected
- Usage data: login frequency, feature usage, count and type of files processed
- Device info: browser, OS, screen resolution
- Logs: IP address, access time, page paths (for security monitoring only)
2.3 Uploaded PDFs
The category we treat with the most care. Your chromatography PDFs contain sensitive analytical data, and our principles are:
- Process only: used solely for the data extraction you requested
- Don’t read: processing is automated, no human inspection
- Don’t retain: permanently deleted within 24 hours of completion
- Don’t share: Max/Team data is never shared, sold, or used for any other purpose (including model training). Free and Super tier data may be used for AI model training; see Section 1.
3. Use of information and legal basis
We use collected information for:
- Providing and maintaining ChromaParse
- Processing your file upload requests
- Managing your account and credits
- Sending service notifications (e.g. credit expiration reminders)
- Improving user experience and product
- Fraud prevention and security
We do not:
- Sell to advertisers or data brokers
- Send marketing without your consent
- Build user profiles for ad targeting
GDPR legal bases
For users in the European Economic Area (EEA), our legal bases for processing include:
- Contract performance (GDPR Art.6(1)(b)) — processing your data to provide ChromaParse
- Legitimate interests (GDPR Art.6(1)(f)) — service improvement and security
- Consent (GDPR Art.6(1)(a)) — where consent is required (non-essential cookies, AI training data use)
- Legal obligation (GDPR Art.6(1)(c)) — to satisfy applicable law
Per GDPR Art.27, our EU representative can be reached at [email protected] (subject line “EU Representative”).
4. Data storage and security
We implement the following technical measures:
- Transit encryption: site-wide HTTPS / TLS 1.3
- At-rest encryption: AES-256 database encryption, encrypted file system
- Access control: strict role-based access (RBAC)
- Auto-deletion: uploaded PDFs are permanently deleted within 24 hours of processing
- Audit logs: all data access actions logged
Data is stored within the People’s Republic of China (or in a region of your choosing), in accordance with the Personal Information Protection Law (PIPL) and Data Security Law.
5. Data retention
| Data type | Retention |
|---|---|
| Uploaded PDFs | Auto-deleted 24 hours after processing |
| Extracted result files | 30 days (manually deletable) |
| Account info | Lifetime of the account |
| Operation logs | 180 days |
| Payment records | Minimum legal retention (typically 3 years) |
6. International data transfer
Your data is stored primarily within mainland China. If you are in the EEA, UK, or other regions, cross-border transfer is governed by:
- Standard Contractual Clauses (SCCs) — adopted from the European Commission as our cross-border legal mechanism
- Adequacy decisions — where the recipient country has been recognized as providing adequate protection
- Data Processing Agreements (DPA) — enterprise customers may request a DPA covering SCCs
For more information or to request a DPA, contact [email protected].
7. Your rights
Under applicable data protection laws (China PIPL, EU/UK GDPR, California CCPA/CPRA), you have the right to:
- Access — view personal information we hold about you
- Rectification — correct inaccurate personal information
- Erasure (right to be forgotten) — request deletion of your account and personal data
- Restriction — limit our processing under specific conditions
- Data portability — export account data in a structured, common format
- Object — to processing based on legitimate interests (including AI training)
- Withdraw consent — for non-essential processing
- Refuse automated decisions — based solely on automated processing
California residents (CCPA): you have the right to know the categories and sources of personal information collected, business purposes, and third-party categories with whom shared. We do not sell personal information. You have the right to request deletion and to exercise these rights without discrimination.
To exercise the above rights, email [email protected]. We respond within statutory timelines (PIPL: 15 business days; GDPR: 30 days; CCPA: 45 days).
8. Cookie policy
We use essential cookies to maintain login state and site functionality. We do not use third-party tracking or advertising cookies. You can disable cookies in your browser at any time, though this may affect some functionality. See our standalone Cookie Policy for details.
9. Children’s privacy
ChromaParse is for enterprise users and not directed at minors. We do not knowingly collect information from individuals under 18. If we discover such collection occurred inadvertently, we will delete it.
10. Third-party services and subprocessors
We rely on the following third parties (each acting as a subprocessor):
- Cloud infrastructure: Aliyun — server hosting and data storage
- Payment: WeChat Pay, Alipay — paid subscription transactions (we do not directly store card data)
- Email: SendGrid — service notifications and account email
- Monitoring & logs: Sentry — error tracking and performance monitoring (does not include uploaded file content)
These providers have independent privacy policies; we select providers that meet our data protection standards. A complete subprocessor list is available on request.
11. Updates
We may update this Privacy Policy from time to time. Material changes will be communicated via email or site notice. We recommend periodic review of this page.
12. Contact us & DPO
For privacy or data protection questions:
- Privacy: [email protected]
- DPA requests: [email protected]
- Data Protection Officer (DPO): [email protected]
We respond within reasonable timeframes. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.