Arbeitsbereich
ONCO/RADAR
AnmeldenKonto erstellenArbeitsbereichDevelopers
← Zurück zum Rechtscenter

Gültig ab: 2026-09-20 · Version: v1.1

Privacy Policy

Welche Daten OncoRadar verarbeitet, warum, mit wem und wie Export oder Löschung beantragt werden.

Convenience summary only. This localized summary is non-binding and is not a professional legal translation. The complete English controlling draft follows.

Betreiber: Celiums Solutions, LLC

1. Scope and operator

This Policy describes how Celiums Solutions, LLC, the sole operator of OncoRadar, handles personal data for the website, accounts, workspaces, API and MCP interfaces. Contact privacy@oncoradar.org for privacy matters. A business mailing address and jurisdiction-specific representative details remain pending review.

2. Data we handle

We handle the minimum data reasonably needed to operate accounts, research workspaces and developer access.

  • Account and identity: Cognito subject, email, display name. Purpose: Authentication and account administration.
  • Workspace and organization: memberships, projects, roles. Purpose: Tenant isolation and collaboration.
  • Research activity: saved searches, collections, alerts, research queries, generated outputs. Purpose: Provide research discovery and synthesis.
  • Developer access: API key prefix, scopes, last-used time, one-way secret hash. Purpose: API and MCP access control.
  • Security and operations: session hash, request ID, IP prefix, user-agent hash, audit events, quota usage. Purpose: Security, abuse prevention, reliability and enforceable quotas.
  • Legal records: document version, content hash, acceptance timestamp, request ID. Purpose: Prove the notice and terms presented.
  • Privacy requests: export or deletion request, status, completion timestamps. Purpose: Process and evidence privacy requests.

3. Sources and purposes

Data comes from you, organization administrators, your browser or API client, security logs, and configured research sources. We use it to authenticate users, provide search and synthesis, maintain workspaces, enforce quotas, secure and troubleshoot the service, answer requests, and maintain legal records. We do not use OncoRadar to sell personal data, deliver targeted advertising, or perform cross-site tracking.

  • Do not provide PHI, patient data, direct patient identifiers or clinical records.
  • Published literature and research metadata are service datasets and are not treated as your personal account data merely because you searched them.

4. Sharing and subprocessors

We disclose data to service providers only as needed for their configured functions, to an organization that controls a workspace, when you direct us, to protect rights and security, or when legally required. We do not attribute operation of OncoRadar to an infrastructure or open-source provider.

  • Amazon Web Services (AWS): Cloud hosting, Amazon RDS, Cognito identity, Bedrock Mantle model access, logging and backup services.

5. AI and research processing

The current implementation can send research queries, retrieved passages and synthesis instructions to Gemma through Amazon Bedrock Mantle. Qwen is configured for embeddings, and Hyphae is open-source data-plane technology used for indexing, retrieval and synthesis artifacts. Never submit patient data, third-party confidential information or secrets to prompts.

6. Retention, deletion and backups

A deletion request is recorded as pending, revokes active OncoRadar sessions and personal-workspace API credentials, and flags organization-workspace access for administrator and operator review; it does not erase active records or provider backups. No deletion is represented as complete until the operator has run and verified the required removal or de-identification process. Backup handling, organization records, legal holds and the completion timeline require documented operational and legal decisions.

  • Session: Until expiry, logout, security revocation, or deletion request; expired rows may be pruned operationally.
  • API credential: Until revoked/expired; only metadata and one-way hashes are stored.
  • Workspace content: Until deleted by an authorized user or processed through account deletion, subject to organization rights.
  • Licensed literature index: According to source licenses and service needs; it is not treated as a user's personal export.
  • Backups: Hyphae and RDS backups rotate under operational schedules; deletion propagates on backup rotation rather than instantly.
  • Audit, security and legal evidence: Limited to legitimate security/legal needs; final numeric periods remain pending review.

7. Your choices and requests

The localized privacy center provides an authenticated JSON export and a deletion-request workflow. Depending on applicable law, you may also request access, correction, restriction or objection by contacting the privacy address. We may verify identity and authority, protect other users' data, and retain a minimal request or legal record where permitted.

8. International processing and security

Providers may process data in configured locations. Exact production-region and transfer-mechanism disclosures remain pending operational and legal confirmation. We use safeguards described in the Security Notice, but no system is risk-free and we do not claim certifications not expressly listed.

9. Children and changes

OncoRadar is intended for professional and adult research use, not for children or collection of children's data. Contact us if such data may have been submitted. Policy updates will change the version or effective date, and material changes may be shown in-product.

Operational draft for review; not legal advice.

Legal: legal@oncoradar.org · Privacy: privacy@oncoradar.org

ONCO/RADAR

Werkzeug zur Forschungsexploration. Keine medizinische Beratung.

Methode
BedingungenDatenschutzZulässige NutzungHaftungsausschlussCookies und Speicher

Betreiber: Celiums Solutions, LLC