Privacy Policy

Effective Date: 30 June 2026  ·  Last Updated: 30 June 2026

1. Introduction

SmartAIm s.r.o. ("SmartAIm", "we", "us", or "our"), incorporated under Slovak law, operates the RE:Search Lab platform (the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over it.

We are the data controller within the meaning of Regulation (EU) 2016/679 (the "GDPR").

2. Data We Collect

2.1 Account and Identity Data

When you register, we collect: full name, email address, password (stored as a cryptographic hash — we do not store your plain-text password), user role within your Organization (Admin or Member), organization name and description, and account creation and update timestamps.

2.2 Research and Operational Data

Data you enter while using the Service, including:

  • Experiments: name, description, hypothesis, methodology, results, conclusions, dataset metadata, Git repository URLs, environment configurations, tags
  • Parameters and Metrics: key-value pairs, units, step numbers, timestamps
  • Notes and Attachments: note text, uploaded files (filename, size, type, storage path) up to 50 MB each
  • Projects and Spaces: name, description, status
  • Publications: title, authors, abstract, DOI, venue, funding source, keywords, collaborator names and roles
  • Grants: title, funding agency, amounts, principal investigator names, grant documents
  • Events: title, speaker name/biography/affiliation, location, capacity, tags

2.3 Activity Logs

We automatically record activity events (e.g., created, updated, deleted) on research entities, including the action type, entity identifier, timestamp, and the user ID who performed the action. These logs are used for audit and security purposes.

2.4 Collaboration Data

When you share projects or experiments with other users, we store the recipient's email address and the permission level granted (View or Edit).

2.5 Data We Do NOT Collect

  • No analytics or tracking data — we use no third-party analytics, advertising pixels, or behavioral tracking.
  • No payment or billing data — the Service currently has no paid plans.
  • No AI conversation data on our servers — the AI Assistant's conversation history is stored only in your browser's local storage on your own device and is never transmitted to our servers.

3. How We Collect Data

  • Directly from you, when you register, enter information in the Service, or upload files.
  • Automatically, when the Service records activity log events as part of normal operation.

Required vs. optional data: Providing your name, email address, and password is required to create an Account and use the Service — without this data we cannot provide the Service to you. All other data you enter into the Service (experiments, notes, publications, etc.) is provided voluntarily.

4. Legal Basis for Processing (GDPR Art. 6)

Processing ActivityLegal Basis
Account registration and authenticationPerformance of a contract (Art. 6(1)(b))
Storing and displaying your research dataPerformance of a contract (Art. 6(1)(b))
Activity/audit logs Legitimate interests (Art. 6(1)(f)) — specifically, our interest in maintaining the security and integrity of the Service, detecting abuse, and enabling recovery from errors. We have assessed that these interests are not overridden by your data protection rights, given that the logs are limited in scope, retained for only 12 months, and are not used for profiling.
Service improvement and bug fixing Legitimate interests (Art. 6(1)(f)) — improving reliability and functionality benefits both parties; we have assessed this does not override your data protection rights.
Collaboration and sharing featuresPerformance of a contract (Art. 6(1)(b))

We do not process your personal data based on consent, except where we are required to obtain it for specific purposes introduced in future Service updates.

5. How We Use Your Data

We use the data we collect solely to:

  • Provide, maintain, and improve the Service.
  • Authenticate you and authorize access to your Organization's data.
  • Enable collaboration and sharing of research data within your Organization.
  • Maintain audit logs for security and operational integrity.
  • Respond to your support inquiries.

We do not use your data for marketing, profiling, automated decision-making, or advertising.

6. Data Sharing and Third Parties

We do not sell your personal data. We do not share your personal data with third-party advertisers, analytics providers, or data brokers.

The Service is fully self-hosted. As of the date of this Policy, we do not use third-party cloud services, payment processors, email marketing platforms, or external analytics tools that receive your personal data.

We may disclose your data if required by applicable law, regulation, or court order, or to protect the rights, safety, or property of SmartAIm, our users, or the public.

Processor role. Where users upload datasets containing personal data of third parties (e.g., research subjects, survey respondents), SmartAIm processes such data solely as a data processor acting on the user's instructions. The user bears full responsibility as data controller for that data, including ensuring a lawful basis for its processing under applicable law.

7. Cookies and Local Storage

Authentication Cookie. We set a single HTTP-only cookie named auth_token to manage your authenticated session. This cookie:

  • Contains a JSON Web Token (JWT) identifying your session.
  • Expires after 7 days.
  • Is marked HttpOnly (inaccessible to JavaScript) and Secure (transmitted only over HTTPS in production).
  • Is strictly necessary for the Service to function. It does not track your browsing behavior.

As this cookie is strictly necessary to deliver the Service you have requested, it does not require your prior consent under applicable EU cookie rules (ePrivacy Directive / Art. 5(3)).

Browser Local Storage. The AI Assistant feature stores conversation history in your browser's local storage on your own device. This data never leaves your device and is not transmitted to our servers.

We use no tracking cookies, analytics cookies, advertising cookies, or third-party cookies of any kind.

8. Data Retention

Data CategoryRetention Period
Account dataFor the duration of your account, plus up to 30 days after deletion for backup expiry
Research data (experiments, papers, grants, etc.)Until you delete it or your account is closed
Uploaded filesUntil you delete the attachment or your account is closed
Activity logsUp to 12 months, then deleted
Collaboration/sharing records (recipient email, permissions)Deleted when the share is revoked or the account is closed
Auth cookieExpires after 7 days; deleted on logout

After account closure, we will delete or anonymize your personal data within 30 days, except where we are required by law to retain it for a longer period.

9. Data Security

We implement the following security measures:

  • Passwords are hashed using bcryptjs with 12 salt rounds; plain-text passwords are never stored.
  • Session tokens are signed JSON Web Tokens (HS256) stored in HTTP-only, SameSite cookies.
  • The application is served over HTTPS in production.
  • Data is isolated at the Organization level; users only access data within their own Organization.
  • File uploads are stored with randomly generated names (UUIDs) to prevent enumeration.

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

In the event of a personal data breach, we will notify the Úrad na ochranu osobných údajov SR within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, in accordance with GDPR Art. 34.

10. Your Rights (GDPR)

As a data subject under the GDPR, you have the following rights:

RightDescription
Access (Art. 15)Request a copy of the personal data we hold about you.
Rectification (Art. 16)Request correction of inaccurate or incomplete data.
Erasure (Art. 17)Request deletion of your personal data ("right to be forgotten").
Restriction (Art. 18)Request that we restrict processing of your data in certain circumstances.
Portability (Art. 20)Receive your data in a structured, machine-readable format.
Objection (Art. 21)Object to processing based on legitimate interests.
No automated decisions (Art. 22)Not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We make no such decisions.
Right to Object: Where we process your data based on legitimate interests (Art. 6(1)(f) — currently activity/audit logs), you have the right to object to that processing at any time under Art. 21 GDPR. On receipt of an objection, we will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

To exercise any of these rights, contact us at info@smartaim.sk. We will respond without undue delay and in any event within one month of receiving a verified request. In cases of complexity or volume, we may extend this period by up to two additional months and will notify you of the extension and the reasons within the first month.

Note on current implementation: Account self-deletion and bulk data export features are being developed and will be available in a future release. In the meantime, you may exercise your right to erasure or data portability by contacting us directly — we will fulfil your request manually within 30 days.

11. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at info@smartaim.sk and we will promptly delete such data.

12. International Data Transfers

SmartAIm is based in the Slovak Republic (EU). The Service is self-hosted. Your data is processed within the EU/EEA. We do not transfer your personal data to countries outside the EU/EEA.

13. Supervisory Authority

You have the right to lodge a complaint with the Slovak supervisory authority for data protection at any time:

Úrad na ochranu osobných údajov Slovenskej republiky
(Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27, Slovak Republic
Web: dataprotection.gov.sk

You may also lodge a complaint with the supervisory authority in your EU member state of residence or place of work.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email at least 30 days before the changes take effect. The "Last Updated" date at the top of this page reflects the most recent revision.

15. Contact Us

SmartAIm s.r.o.

Karpatské námestie 7770/10A, 831 06 Bratislava, Slovak Republic

Company ID: 55679463  ·  VAT: SK2122061106

Email: info@smartaim.sk