This English version is provided for convenience. The original document is written in Spanish and is available at bio-forging.com/privacy-policy.html.
This policy describes how BioForging ("we") collects, uses and protects the information of the users of the BioForging ELN electronic lab notebook, both in the web panel at bio-forging.com and in the mobile application ("the app") and the desktop program. By using the service you accept the practices described in this document.
The data controller is BioForging, domiciled in the Province of Buenos Aires, Argentina. Processing is governed by the Personal Data Protection Act No. 25,326 and its supplementary regulations.
1. Information we collect
Account and profile data
- Email address and password (required to sign in).
- Profile data: first name, last name, position, institution, area of interest, ORCID and preferred language.
- Laboratory memberships and the user's role within each laboratory.
Content you create in the app
- Projects, experiments, protocols, tasks, inventory, logbook entries and reports.
- Images and files you attach to experiments (uploaded to our storage server).
Technical and security data
- Audit log: actions performed (create, edit, delete, and so on), author, date and IP address, in order to maintain the traceability and integrity of the laboratory records.
- Internet connection status (to enable offline mode); it is not transmitted to third parties.
- Push notification identifier (Expo token) and the device platform (iOS/Android), used solely to send you notices related to your activity in the app.
Sales enquiries
- If you write to us through the site's contact form or subscribe to the newsletter, we store your name, email address, the message, the contact source, your IP address and the date, so that we can reply to you and to prevent automated spam.
We do not collect location data, we do not run advertising, and we do not track your activity in other apps or websites.
What the App Store privacy label declares
Apple requires every app to declare on its product page the categories of data it collects. This is the declaration for BioForging ELN on iOS, and it matches what is described above. In every case the data is linked to your account, is used solely for app functionality and is not used to track you.
- Contact Info — Name: the first and last name on your profile.
- Contact Info — Email Address: the address you sign in with.
- User Content — Photos or Videos: images you attach to experiments and to protocol steps.
- User Content — Other User Content: projects, experiments, protocols, inventory, samples, equipment, tasks, reports and comments.
- Identifiers — User ID: your account identifier within the platform.
- Identifiers — Device ID: the push notification token, the device platform and the IP address recorded in the audit log.
Location, health data, contacts, browsing or search history, advertising data and diagnostic data are not declared, because the app does not collect them.
2. Device permissions
- Camera: only when you choose to take a photo to attach it to an experiment.
- Photos / gallery: only when you choose to attach an existing image.
- Notifications: to warn you about task and reagent expiry dates (local notifications scheduled on your device) and about relevant events in your activity —such as task assignments, deletion requests or experiments ready to be signed— through push notifications sent from our server via the Expo service.
You can revoke these permissions at any time from your operating system settings.
3. How we use the information
- To authenticate you and keep your session signed in.
- To store and sync your lab notebook content across your devices.
- To show you your data offline through a local cache on the device.
- To send you local reminders about expiry dates.
- To maintain audit logs for the integrity and traceability of scientific information.
4. Where your data is stored
- The database and the application are hosted with our hosting provider, associated with
bio-forging.com, and are accessed over encrypted connections (HTTPS). - Attachments: step photos, PDFs and experiment annexes
are stored in a private Amazon Web Services (S3) bucket located in the
us-east-2region (Ohio, United States). The files are not public: they are served through signed links of limited duration. - International transfer: the above means that part of your information is stored outside Argentina. By using the service you consent to that transfer, under section 12 of Act No. 25,326.
- On your device, the password is stored encrypted in the system's secure storage (Keychain on iOS, Keystore on Android) and only if you enable the "Remember me" option.
- The rest of the data is kept in a local cache on the device to allow offline use.
- We apply reasonable measures to protect the information, although no system is completely infallible.
5. Cookies
We only use technical cookies, necessary for the service to work. We do not use advertising cookies, third-party analytics cookies or social network cookies, and we do not share cookies with anyone.
PHPSESSID— session cookie. It keeps you signed in and backs the CSRF protection. It is deleted when you close the browser.remember_token— created only if you tick "Remember me" when signing in, so that you are not asked for your password on every visit.- The chosen language (ES/EN) and the light/dark theme are stored in your own browser.
You can delete or block them in your browser; in that case you will not be able to sign in.
6. Who we share information with
We do not sell or rent your personal data. We share it only with the infrastructure providers strictly necessary to operate the service (hosting, file storage and the Expo push notification delivery service), which act on our instructions, or where required by law. Inside a shared laboratory, the content and the recorded actions may be visible to other members of that laboratory according to their role.
7. Data retention
We keep your information while your account is active. Audit logs may be retained for an additional period in order to meet integrity and traceability requirements. When you delete your account, we delete or anonymize your personal data except for what we must retain by legal obligation.
8. Your rights
You may access, rectify, update and delete your personal data, and request its portability, by writing to info@bioforging.com from your registered email address.
How to export your information
- From the application, right now: experiments and reports are exported as PDF, and inventory, activity and consumption lists as CSV.
- Full laboratory export: requested by email to info@bioforging.com and delivered as a compressed archive. There is no "download everything" button inside the application yet; we process it by hand within a reasonable time.
Under section 14(3) of Act No. 25,326, the data subject may exercise the right of access free of charge at intervals of no less than six months, unless a legitimate interest is demonstrated. The AGENCY FOR ACCESS TO PUBLIC INFORMATION, as the supervisory authority for Act No. 25,326, is empowered to handle the complaints and claims brought by those whose rights are affected by non-compliance with the rules in force on personal data protection.
Account deletion
To request the deletion of your account and the associated data, write to info@bioforging.com from your registered email address, or use the deletion option inside the app. We will process the request within a reasonable time.
9. Minors
The app is intended for laboratory professionals and students. It is not directed at children under 13 and we do not knowingly collect data from children of that age.
10. Changes to this policy
We may update this policy from time to time. We will publish the current version on this page with its last updated date.
11. Contact
For any privacy enquiry: info@bioforging.com
BioForging — Buenos Aires, Argentina