Draft — not yet reviewed by counsel
The data inventory below is accurate. The controller identity, legal bases, retention periods and sub-processor list still need legal review before launch.
Privacy notice
Last updated 2026-09-01
This notice explains what personal data OrganMatch collects when you use the platform, why we hold it, how long we keep it, and what you can ask us to do with it. It is written to meet Articles 13 and 14 of the UK and EU General Data Protection Regulation.
Who is responsible for your data
NEEDS COUNSEL — the registered controller name, company number, registered address, and a contact address for data protection questions. If OrganMatch has no EU establishment, an Article 27 EU representative must also be appointed and named here.
What we collect, and why
Your account
Created when you register, and required to give you an account at all.
- Email address, full name, and the organisation you give
- Your role on the platform, and whether your email has been verified
- A hashed password — we never store the password itself
- Optional profile details: biography, website, and a separate contact email
- Your preferred display currency
Your research work
The substance of what you use the platform for. This can include experimental records that are commercially sensitive to you or your institution.
- Protocols you author or contribute
- Lab book experiments, their steps, reagents, batch records and yields
- Deviations you record against a protocol, including your stated reasons
- Protocols you save, and your progress through SOP steps
Commercial records
- Subscriptions and the plan you are on
- Commercial licences you hold, and quote requests you send
- Revenue share records, where you contribute protocols as a provider
NEEDS COUNSEL — payment card details are handled by our payment processor and never reach our servers. Confirm the processor and name it here.
Organisations and teams
- Your membership of an organisation and your role within it
- Invitations you send or receive
Where you join an organisation, administrators of that organisation can see your membership and activity within it.
Activity and security records
- An audit log of significant actions taken on your account
- Record-level audit entries for changes to protocols and curation decisions
- Which protocols have been viewed
- Notifications generated for you
Audit records exist so that changes to scientific records are attributable and reversible. They are deliberately harder to erase than other data — see Your data.
Developer access
- API keys you create, and webhook endpoints you register
- Delivery records for webhooks sent to those endpoints
If we emailed you about a published method
This section is for people who are not OrganMatch users. If you received an email from us about a protocol derived from your published work, we hold some information about you and did not get it from you. Under Article 14 GDPR we have to tell you what and why, so:
- What we hold: your name, your email address, and the institutional affiliation printed on the publication.
- Where we got it: the public publication record — PubMed and PubMed Central. We take the corresponding author's address as the journal printed it. We do not buy contact lists, and we do not guess: where a publication does not identify a corresponding author, we hold nothing.
- Why we hold it: to tell you that our catalogue contains a protocol derived from your published method, to let you see how it is presented, and to give you a way to correct it, have the attribution anonymised, or have the entry removed.
- Our lawful basis: legitimate interests (Article 6(1)(f)) — ours in describing published methods accurately, and yours in being told that your work is being described and being able to object. NEEDS COUNSEL — the balancing test behind this should be written down and kept, not merely asserted here.
- How long: until you ask us to stop, or until the protocol is removed from the catalogue. If you unsubscribe we keep your address on a suppression list, and only on that list, so that we do not contact you again by mistake — deleting it entirely is what would let that happen.
- Who else sees it: nobody. It is not published, not shown on any protocol page, and not shared with any other organisation. Our email provider processes the message in order to deliver it.
You can object at any time, and you do not have to give a reason. Every email we send carries a one-click unsubscribe link, or write to contact@organthis.com. You also have the rights listed under Your rights below, including access, correction and erasure.
Stopping the emails is not the same as changing how a protocol is attributed. Those are separate requests and we answer them separately — use attribution and takedown for the second.
We do not use tracking pixels, and we do not record whether you opened a message or clicked a link. These emails go out in small daily batches rather than as a single mailing.
Why we are allowed to hold it
NEEDS COUNSEL — each category above must be mapped to an Article 6 lawful basis. The likely shape is: contract for account, subscription and lab-book data; legitimate interests for audit, security and abuse prevention; consent for marketing email; legal obligation for financial records. This mapping is a legal decision and should not be guessed.
How long we keep it
NEEDS COUNSEL — retention periods per category. Financial records typically carry a statutory minimum. Audit records need a defined period rather than "indefinitely". Deleted accounts need a stated wind-down window.
Who else sees it
We do not sell personal data. We share it only with service providers who help us run the platform, and only as far as they need it.
NEEDS COUNSEL — a complete sub-processor list: hosting provider and the country its servers sit in, payment processor, transactional email provider, and any error-tracking or analytics service. Each needs a data processing agreement, and any transfer outside the EEA needs a stated safeguard.
Where your data is held
NEEDS COUNSEL — confirm the hosting region and state it plainly. Name any processor that stores or accesses data outside the EEA, and the transfer mechanism relied on.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some uses of it, and ask us to restrict how we use it while a question is resolved. You can also complain to your national data protection authority.
How to make any of these requests, and what happens to scientific records when you do, is set out on Your data.
Changes to this notice
If we change how we use your data in a way that affects you, we will tell you before the change takes effect rather than only updating this page.