Privacy

Collect less. Explain why. Protect what remains.

This page states the intended privacy posture for the public U.S. site. Contractual notices and live-service details require approval before production publication.

Public site

The public experience is designed without advertising trackers or behavioral profiling. Standard server security logs may record request metadata for reliability and abuse prevention.

Member identity

The login page may pass an approved organization email as an optional login hint to the configured identity provider. Authentication, organization membership and access policy are enforced server-side.

Customer records

  • Access is tenant-, organization-, site-, role- and grant-aware.
  • Evidence is retained according to configured contractual and legal requirements.
  • Original documents remain distinct from OCR, redaction and other derivatives.
  • Cross-customer model training is disabled by default.

Counterparty sharing

Producer, lab, processor and supplier profiles are internal. Inventory, contacts, capabilities and laboratory evidence are disclosed only through explicit sharing grants and can be narrower than the organization's own view.

This draft is product copy, not a substitute for an approved privacy notice.