Effective Date: 30 June 2026 · Last Updated: 30 June 2026
SmartAIm s.r.o. ("SmartAIm", "we", "us", or "our"), incorporated under Slovak law, operates the RE:Search Lab platform (the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over it.
We are the data controller within the meaning of Regulation (EU) 2016/679 (the "GDPR").
When you register, we collect: full name, email address, password (stored as a cryptographic hash — we do not store your plain-text password), user role within your Organization (Admin or Member), organization name and description, and account creation and update timestamps.
Data you enter while using the Service, including:
We automatically record activity events (e.g., created, updated, deleted) on research entities, including the action type, entity identifier, timestamp, and the user ID who performed the action. These logs are used for audit and security purposes.
When you share projects or experiments with other users, we store the recipient's email address and the permission level granted (View or Edit).
Required vs. optional data: Providing your name, email address, and password is required to create an Account and use the Service — without this data we cannot provide the Service to you. All other data you enter into the Service (experiments, notes, publications, etc.) is provided voluntarily.
| Processing Activity | Legal Basis |
|---|---|
| Account registration and authentication | Performance of a contract (Art. 6(1)(b)) |
| Storing and displaying your research data | Performance of a contract (Art. 6(1)(b)) |
| Activity/audit logs | Legitimate interests (Art. 6(1)(f)) — specifically, our interest in maintaining the security and integrity of the Service, detecting abuse, and enabling recovery from errors. We have assessed that these interests are not overridden by your data protection rights, given that the logs are limited in scope, retained for only 12 months, and are not used for profiling. |
| Service improvement and bug fixing | Legitimate interests (Art. 6(1)(f)) — improving reliability and functionality benefits both parties; we have assessed this does not override your data protection rights. |
| Collaboration and sharing features | Performance of a contract (Art. 6(1)(b)) |
We do not process your personal data based on consent, except where we are required to obtain it for specific purposes introduced in future Service updates.
We use the data we collect solely to:
We do not use your data for marketing, profiling, automated decision-making, or advertising.
We do not sell your personal data. We do not share your personal data with third-party advertisers, analytics providers, or data brokers.
The Service is fully self-hosted. As of the date of this Policy, we do not use third-party cloud services, payment processors, email marketing platforms, or external analytics tools that receive your personal data.
We may disclose your data if required by applicable law, regulation, or court order, or to protect the rights, safety, or property of SmartAIm, our users, or the public.
Processor role. Where users upload datasets containing personal data of third parties (e.g., research subjects, survey respondents), SmartAIm processes such data solely as a data processor acting on the user's instructions. The user bears full responsibility as data controller for that data, including ensuring a lawful basis for its processing under applicable law.
Authentication Cookie. We set a single HTTP-only cookie named auth_token to manage your authenticated session. This cookie:
As this cookie is strictly necessary to deliver the Service you have requested, it does not require your prior consent under applicable EU cookie rules (ePrivacy Directive / Art. 5(3)).
Browser Local Storage. The AI Assistant feature stores conversation history in your browser's local storage on your own device. This data never leaves your device and is not transmitted to our servers.
We use no tracking cookies, analytics cookies, advertising cookies, or third-party cookies of any kind.
| Data Category | Retention Period |
|---|---|
| Account data | For the duration of your account, plus up to 30 days after deletion for backup expiry |
| Research data (experiments, papers, grants, etc.) | Until you delete it or your account is closed |
| Uploaded files | Until you delete the attachment or your account is closed |
| Activity logs | Up to 12 months, then deleted |
| Collaboration/sharing records (recipient email, permissions) | Deleted when the share is revoked or the account is closed |
| Auth cookie | Expires after 7 days; deleted on logout |
After account closure, we will delete or anonymize your personal data within 30 days, except where we are required by law to retain it for a longer period.
We implement the following security measures:
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
In the event of a personal data breach, we will notify the Úrad na ochranu osobných údajov SR within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, in accordance with GDPR Art. 34.
As a data subject under the GDPR, you have the following rights:
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you. |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data. |
| Erasure (Art. 17) | Request deletion of your personal data ("right to be forgotten"). |
| Restriction (Art. 18) | Request that we restrict processing of your data in certain circumstances. |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format. |
| Objection (Art. 21) | Object to processing based on legitimate interests. |
| No automated decisions (Art. 22) | Not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We make no such decisions. |
To exercise any of these rights, contact us at info@smartaim.sk. We will respond without undue delay and in any event within one month of receiving a verified request. In cases of complexity or volume, we may extend this period by up to two additional months and will notify you of the extension and the reasons within the first month.
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at info@smartaim.sk and we will promptly delete such data.
SmartAIm is based in the Slovak Republic (EU). The Service is self-hosted. Your data is processed within the EU/EEA. We do not transfer your personal data to countries outside the EU/EEA.
You have the right to lodge a complaint with the Slovak supervisory authority for data protection at any time:
Úrad na ochranu osobných údajov Slovenskej republikyYou may also lodge a complaint with the supervisory authority in your EU member state of residence or place of work.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email at least 30 days before the changes take effect. The "Last Updated" date at the top of this page reflects the most recent revision.
SmartAIm s.r.o.
Karpatské námestie 7770/10A, 831 06 Bratislava, Slovak Republic
Company ID: 55679463 · VAT: SK2122061106
Email: info@smartaim.sk