Sauriq
Back to home
Join private preview Log in

Privacy

How Sauriq processes personal data on this public site and in the invite-only product, and how to ask for access or deletion.

Version 2026-09-20.

On this page
  1. About this notice
  2. Who this notice applies to
  3. Demo requests
  4. Product accounts
  5. Workspace content
  6. Security and technical data
  7. Cookies
  8. Why we process this information
  9. Where information is stored
  10. Who else can see it
  11. How long we keep it
  12. Your requests
  13. International transfers
  14. Children
  15. Changes

1. About this notice

1.1 This notice describes how Sauriq processes personal data when you visit the public website, submit a Join private preview request, or use the invite-only product. It covers both the marketing site and the signed-in product as they are operated today.

1.2 Sauriq is the name of the service. The legal identity of the person or organization responsible for this processing has not yet been published. It must be added for this notice to be complete. Send privacy requests to [email protected].

1.3 Our Terms explain invite-only preview use.

2. Who this notice applies to

2.1 This notice applies to visitors of the public site, people who submit a demo request, invited product users, and teammates who can see membership or content in a shared workspace.

2.2 Product access is currently by invitation. A demo request does not create an account.

3. Demo requests

3.1 When you use Join private preview, we use the details you provide to respond to your request and arrange a walkthrough. We collect your name and work email, and any organization, team size, or message you choose to provide. We also record your agreement to be contacted, the form’s source page, and when the request was submitted. Your name, work email, and agreement to be contacted are needed to handle the request; the other fields are optional.

3.2 We use your request for that conversation, not for an advertising list. We do not sell your information. If you do not submit the form, we do not create a demo-request record from an ordinary page view.

4. Product accounts

4.1 For invited users, we process an email address, sign-in credentials, name and profile details to provide and administer an account. We store a password hash, not a recoverable password.

4.2 We also remember the preferences you set, such as language, timezone, working hours, availability, and interface settings.

4.3 We store the versions of the Terms and this notice accepted during registration when that flow is available. If your institution enables single sign-on, we store the identity-provider subject and related sign-in fields needed to link that login to your account.

4.4 Authorized people operating the service can access account information where needed. Teammates can see membership and content made available to them through their workspace access.

5. Workspace content

5.1 Members of a workspace can add research plans, canvases, files, messages, time entries, and related content. This may include personal data if users put it there. We process this content to provide the shared workspace.

5.2 Your organization decides why personal data is added to its workspace, what its members add, and who is invited. For that content, your organization acts as controller and we process it on the organization's behalf to provide the service. Access follows workspace membership and permissions. Please do not add information you are not authorized to share. For requests about workspace content, contact your organization; we will coordinate with it.

6. Security and technical data

6.1 We process technical information such as IP addresses, requested pages, access times, and sign-in or error events to deliver the site, keep the service available, prevent misuse, and diagnose problems.

6.2 We do not use this information for advertising or make decisions about people solely by automated means that have legal or similarly significant effects.

7. Cookies

7.1 We use necessary cookies to protect forms and keep signed-in users authenticated. We do not use analytics or advertising cookies.

7.2 The following cookies may be set, depending on which host you use:

Necessary cookies used by the public website and signed-in product
Name Host Duration Purpose
csrftoken Public website, when the demo form is shown Up to 1 year Protects the form from cross-site request forgery.
sessionid Signed-in product Up to 12 hours in production Keeps you signed in.
csrftoken Signed-in product Up to 1 year Protects product requests from cross-site request forgery.

7.3 The signed-in product also uses browser storage on your device for interface preferences, your recently selected workspace, and local draft information such as scratch notes. Visiting this notice does not itself set the cookies listed above. You can clear cookies and browser storage in your browser; doing so may affect forms, sign-in, and locally stored preferences or drafts.

8. Why we process this information

8.1 We rely on your consent to contact you about a demo request. You may withdraw it at any time using the route in section 12, without affecting processing that took place before withdrawal.

8.2 We process account and preference information as needed to provide the invite-only service to users and their organizations. For personal data an organization places in its workspace, that organization determines its legal basis and we process the content on its behalf to provide the service.

8.3 We rely on legitimate interests in operating and protecting the service for technical logs, rate limits, and security measures. Our interest is in keeping the service reliable and preventing misuse.

9. Where information is stored

9.1 Primary application data, uploaded files, and our own database backups are stored in the EU. We use access controls and encrypted connections to protect the service. Deleted information may remain in backup copies until those copies expire under section 11.

10. Who else can see it

10.1 Authorized people operating Sauriq may access information where needed to administer the service and respond to requests. Members of your workspace may see information according to their access.

10.2 Service providers process data as needed for application hosting and backups, network delivery and protection, and email. We do not sell personal data or share it for advertising.

11. How long we keep it

11.1 We delete demo requests 12 months after the last substantive contact about the request. You can withdraw consent to follow-up or request deletion sooner using the contact route in section 12.

11.2 Pending self-service registrations, if enabled and never activated, are deleted after 7 days. Authentication email tokens are kept for up to 30 days or until used.

11.3 We keep account and workspace information while the relevant account or workspace is active. We delete it from the live service within 30 days of closure, unless a legal obligation or documented legal hold requires longer retention.

11.4 Routine access and error logs are kept for 30 days. Records needed to investigate a specific security incident or defend a claim may be kept for up to 12 months.

11.5 Server backups rotate through seven daily copies. Separate database backups are kept for no more than 30 days. Information deleted from the live service may remain in these backups until the relevant copy expires.

12. Your requests

12.1 Depending on the circumstances, you can ask to access, correct, erase, or restrict processing of your personal data; object to processing based on legitimate interests; and receive or transfer data you provided where portability applies. You can withdraw consent to demo follow-up at any time without affecting prior processing.

12.2 Send privacy requests to [email protected]. If you have an account, you can also contact the person who invited you. We may need to verify your identity before disclosing account or workspace information, and may need to coordinate with your organization about its workspace content.

12.3 You can lodge a complaint with a data protection supervisory authority, including the authority in the EU country where you live or work.

13. International transfers

13.1 Primary application hosting is in the EU. Providers that deliver and protect the service or handle email may process connection and correspondence data outside the European Economic Area, including in the United States. For transfers covered by an adequacy decision, we rely on that decision; otherwise we rely on the European Commission's Standard Contractual Clauses in our provider agreements. You can request information about the applicable safeguards or a copy of them at [email protected].

14. Children

14.1 This preview is intended for professional laboratory and research teams. It is not directed at children, and we do not knowingly collect personal data from children through these pages.

15. Changes

15.1 We may update this notice when our practices change. The version date above identifies the current text. We will communicate material changes as appropriate before they take effect.

© 2026 Sauriq
Privacy Terms Log in