Privacy Notice
1. Who is responsible for your data
The controller for the personal data described here is The Smart Blend SRL, registered office at 2 Avenue Albert Mahiels, 4020 Liege, Belgium, company number 0672.626.308, VAT number BE 0672.626.308.
For anything in this notice, including a request to exercise your rights, write to privacy@iucliddossierflow.com. We are not required to appoint a Data Protection Officer and have not appointed one, so requests are handled by the company itself at that address.
Two different roles are worth separating. For account and billing data we are the controller. For the study reports and dossier content our customers upload, we act as a processor on the customer organisation's instructions, under the data processing terms in section 10.
2. What we collect, and why
| Category | What it covers | Why we hold it |
|---|---|---|
| Account | Name, work email address, hashed password, organisation name, role, invitation records | To create and secure your account, and to separate your organisation's data from every other one. Necessary to perform the contract. |
| Content | Substances, uploaded study reports, drafted dossier content, review decisions | To provide the service you asked for. This is your material, processed on your instructions. |
| Billing | Subscription status, wallet transactions, invoices, the country and VAT number used for tax | To charge for the service and to meet accounting and VAT obligations. |
| Operational | Session records, job status, token usage and cost records, error and audit records, security logs | To run the service, meter usage, investigate failures and detect abuse. Our legitimate interest in a service that works and is not attacked. |
| Correspondence | Emails you send us and our replies | To answer you and to keep a record of what was agreed. |
We do not ask for special categories of personal data and you must not upload any. We do not profile you, we do not sell data, we do not advertise, and we take no automated decision that produces a legal or similarly significant effect on you. The drafting the service performs is automated, but it decides nothing about a person: it produces a draft that one of your colleagues then reviews.
3. Artificial intelligence and your study reports
This is the part customers most need to understand, so it is described here rather than buried in a sub-processor list. Our language model provider is Anthropic PBC, and your documents are sent to it in two situations:
- Drafting a record. The extracted text of the study report, together with the IUCLID field schema for that endpoint, is sent to the model, which returns structured data.
- Reading a scanned report. If a large share of a report's pages carry no usable text layer, images of those pages are sent to a vision-capable model for transcription. Without this, an older scanned study simply cannot be read. Only the pages that lack a text layer are sent this way.
- Content sent for drafting or transcription is not used to train models, under Anthropic's commercial terms. Anthropic may retain inputs and outputs for a limited period for safety and abuse detection, as described in its own terms, and then deletes them.
- The model has no access to your IUCLID installation, no credentials and no ability to act. It returns text, which is validated and then reviewed by a person in your organisation before anything is written anywhere.
- Anthropic processes this content in the United States. See section 8 on transfers.
- Study reports are ordinarily technical documents rather than personal data. Where a report contains personal data, for example the name of an investigator or a study author, it is processed only as part of that document. It is not extracted, indexed, used to build a profile, or used for any other purpose.
If you want a specific study kept out of this entirely, do not upload it. Everything the service does with a document requires sending it for processing.
4. Where your documents are stored, and for how long
An uploaded study report is held as a single encrypted-in-transit record in our database in the EU, not scattered across a filesystem, and it is deleted automatically as soon as it has no remaining purpose. During a drafting run it is written to a private temporary file for the duration of that one call and removed the instant the call returns, whether it succeeded or failed. That temporary file is never backed up and never becomes part of our stored state.
- Uploaded study reports are deleted once every endpoint the file was tagged to has been resolved. Where a draft was approved, the source file is purged straight away: the pipeline never reads it again. Where a draft was rejected, the file is kept for a grace period of 48 hours so that a retry does not force a re-upload, and is then deleted automatically. A file you remove yourself is purged immediately.
- Drafted content and substance records are kept while your account is active, because that is your working material, and are deleted on request or when the account is closed.
- Account data is deleted within 30 days of account closure or of an erasure request, apart from what is covered by the next point.
- Invoices and financial records are kept for 7 years, the period required by Belgian accounting and VAT law. This is a deliberate exception to erasure, not an oversight: we are legally required to retain them.
- Security, audit and job records are kept for 12 months, then deleted. These record what happened, not what was in your documents.
- Backups roll on a 30 day cycle. A record deleted from the live system disappears from backups within that window.
5. Who we share it with
We use a small number of processors, each for one clearly defined job:
| Processor | Purpose | Where it processes |
|---|---|---|
| Anthropic PBC | Language models that draft dossier content and transcribe scanned pages | United States |
| Render Services, Inc. | Application hosting and the database | EU region, Frankfurt, Germany. Render is a US company and its support staff may access systems for maintenance. |
| Stripe | Payment processing and invoicing | EU and United States |
| Twilio SendGrid | Transactional email only: verification, password reset, team invitations | EU and United States |
Study reports and dossier content go only to Anthropic and to our hosting provider. They are never sent to Stripe or to our email provider.
We do not sell personal data, we do not share it with advertisers, and no organisation using the service can see another organisation's data. We may also disclose data to professional advisers bound by confidentiality, to an authority where the law requires it, and to an acquirer if the business is sold, in which case you will be told.
We will tell customer organisations by email before adding or replacing a processor that handles their content, so that they can object.
6. Security
Passwords are hashed with bcrypt. Session, invitation and pairing tokens are stored only as hashes, never in the clear. Traffic runs over HTTPS with strict transport security. Every authenticated form carries CSRF protection, session cookies are HttpOnly and SameSite, and the application sends a content security policy that denies framing. Every stored record carries the organisation it belongs to, and every query is scoped to it. Access to production systems is limited to those who need it.
Note what we deliberately never receive: your IUCLID address, your IUCLID account, your IUCLID session, and any route into your network. The browser extension works inside the session you opened yourself, on your own machine.
No system is perfect. If a breach affecting your data occurs, we will notify the customer organisation without undue delay and, where the law requires it, the Belgian Data Protection Authority within 72 hours.
7. Your rights
Under the GDPR you may request access to your personal data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Write to privacy@iucliddossierflow.com and we will respond within one month. There is no charge unless a request is manifestly excessive.
If you are an employee of a customer organisation, requests about dossier content are normally handled by that organisation, since the data is theirs and we process it on their instructions. We will help them respond.
You may also lodge a complaint with your supervisory authority. In Belgium this is the Data Protection Authority, Rue de la Presse 35, 1000 Brussels.
8. International transfers
Our application and database run in the EU. Transfers outside the EEA happen in two places: to Anthropic in the United States for the model processing described in section 3, and to Stripe and our email provider for billing and account email. Each of these transfers relies on the Standard Contractual Clauses approved by the European Commission, together with the supplementary measures in the relevant provider's data processing agreement.
9. Cookies and what this site stores
These marketing pages set no cookies at all and load no third party content: no analytics, no advertising, no tracking pixels, no embedded video, and not even a webfont from an external service. Nothing about your visit is sent anywhere.
Two values are kept in your own browser's local storage, and never transmitted:
| Name | Purpose | Category | Kept until |
|---|---|---|---|
iuclid-cloud-theme |
Remembers whether you chose the light or the dark appearance | Strictly necessary for a preference you asked for | You clear it, or your browser storage |
df-cookie-consent |
Records the choice you made in the banner, so you are not asked again | Strictly necessary | You clear it, or your browser storage |
You can change or withdraw your choice at any time with the link in the footer of any page, as easily as you gave it. If measurement is ever added to this site, it will be listed in this table first and will only run after you accept.
The application itself, at your Dossier Flow address, is a separate matter. It sets a session cookie that keeps you logged in and a CSRF protection cookie, both strictly necessary to operate it, and neither used for tracking. The browser extension stores its pairing token locally in your own browser and sends it only to us.
10. Data processing terms for customers
Where we process dossier content on behalf of a customer organisation, this section is our data processing agreement under Article 28 GDPR, and it applies automatically from the moment you create an account. No separate signature is needed, though we will sign a customer's own form on request at privacy@iucliddossierflow.com.
- Subject matter and duration. Processing of the customer's study reports and dossier content for the purpose of drafting IUCLID records, for as long as the account exists.
- Nature and purpose. Storage, text extraction, transcription of scanned pages, automated drafting, validation, and display for review.
- Types of data and categories of person. Technical study content, which may incidentally contain the names and professional details of investigators, study authors and the customer's own staff.
- Instructions. We process only on the customer's documented instructions, which the use of the service constitutes, and as required by EU or Belgian law, in which case we will tell the customer unless the law forbids it.
- Confidentiality. Everyone we authorise to process the data is bound to confidentiality.
- Security. The measures in section 6.
- Sub-processors. The customer gives general authorisation to those listed in section 5. We will give notice before changes, and the customer may object and terminate if it objects on reasonable data protection grounds.
- Assistance. We will help the customer respond to data subject requests and meet its obligations under Articles 32 to 36, taking account of what we actually hold.
- Deletion. On the end of the service we delete the content according to section 4, except where the law requires retention.
- Audit. We will make available the information needed to demonstrate compliance, and allow an audit on reasonable notice, at most once a year, at the customer's cost, subject to confidentiality.
11. Changes
If this notice changes materially we will tell account holders by email at least 30 days before the change takes effect, and update the version and date at the top of this page.