Effective 31 August 2026
Privacy Policy
This Privacy Policy explains how ResearchKit (“we”, “us”) collects, uses, and shares personal data when you visit researchkit.run, use the Service, or subscribe through Microsoft Marketplace. It should be read with our Terms and Conditions.
1. Who this applies to
This policy covers visitors to our website, people who contact us, and users of a ResearchKit workspace (including administrators who activate a marketplace subscription). Customer’s own use of the Service to process its files and datasets is governed by the Customer’s instructions and the Terms. We process that Customer Data as a provider of the Service.
2. Data we collect
- Account and contact data: name, email address, organisation or workspace name, and messages you send to us.
- Marketplace subscription data: offer, plan, quantity, subscription identifiers, status, and purchaser or beneficiary details Microsoft sends us so we can resolve, activate, and manage the subscription.
- Usage and technical data: log data such as IP address, browser type, timestamps, and error events needed to operate and secure the Service.
- Customer Data: content users upload or generate in a workspace (files, prompts, experiment outputs). We process this to provide the features Customer requested.
3. How we use data
We use personal data to:
- provide, secure, and support the Service;
- create and administer workspaces and user accounts;
- fulfil Microsoft Marketplace landing-page and webhook requirements;
- communicate about the Service, security, and product changes;
- comply with law and enforce our Terms.
We do not sell personal data. We do not use Customer Data to train foundation models for other customers.
4. Sharing
We share personal data only with:
- infrastructure and subprocessors that host or operate the Service on our behalf;
- Microsoft, to the extent required to bill and administer a marketplace subscription;
- professional advisers or authorities when required by law or to protect rights and safety.
5. Retention
We keep account and subscription records for as long as the workspace is active and for a reasonable period afterwards as needed for billing, security, and legal obligations. Customer Data is retained according to workspace settings and our operational backups, and is deleted or de-identified when no longer required.
6. Security
We use administrative, technical, and organisational measures appropriate to the nature of the Service, including access controls and isolated execution where offered. No method of transmission or storage is completely secure.
7. International transfers
The Service may be hosted or accessed in countries other than the one where Customer or a user is located. Where required, we use appropriate safeguards for cross-border transfers.
8. Your rights
Depending on applicable law, you may have rights to access, correct, delete, or restrict processing of your personal data, or to object or request portability. To exercise these rights, contact hello@researchkit.run. If you are a user of a Customer workspace, we may redirect you to that Customer as the controller of workspace content.
9. Cookies
We use cookies and similar technologies that are necessary to keep you signed in and to protect the Service. We do not use advertising cookies on the marketing site.
10. Changes
We may update this policy by posting a new version on this page with a revised effective date.
11. Contact
Privacy questions: hello@researchkit.run.
