EpiSAP Platform — Privacy Policy
Version 1.3

Issuer (controller / data fiduciary / business): EPISAPIENT PTY LTD (ACN 664 593 542) of Queensland, Australia ("Episapient", "we", "us", "our")
Effective date: as recorded by the agreement gate at the time of your Acceptance
Hash: as recorded by the agreement gate at the time of your Acceptance
Companion document: EpiSAP Platform — Terms of Use. Where used in this Policy, capitalised terms not defined here have the meaning given in the Terms.

Plain-English summary (not the binding document — clause 3 onwards governs). EpiSAP is a vault you use to protect intellectual property using post-quantum cryptography and blockchain anchoring. We need a small amount of personal information to run your account, secure the Platform, and meet our legal obligations. Your vault content (the files, models, documents, code, designs you upload) is your property under the Terms — we host and protect it on your behalf, but we do not use it to train public AI models, sell it, or treat it as ours. Personal data you give us is handled in line with this Policy and the privacy law of your country. If you live in Australia, India, the United States, the EU, the UK, Canada, or anywhere else, the relevant Schedule at the end of this Policy explains what extra rights you have.

How to read this document

This document has the same structure as the Terms of Use:

  1. The Body (clauses 1–19) sets out global privacy provisions that apply to every user of the Platform.
  2. The Schedules (A–D) at the end contain region-specific provisions that modify the Body for users in those regions. Each Schedule states clearly when it applies. Order of precedence is in clause 2.

For shared concepts (User Content, Feedback, Platform IP, Episapient, Acceptance, Beta Tester, Material breach), the Terms definitions apply unless this Policy specifically defines a privacy-specific term.

BODY — Global Privacy Provisions

1. Definitions

Capitalised terms not defined in this Policy have the meanings given in the Terms of Use. Privacy-specific terms used in this Policy are:

"Controller" or "Data Fiduciary" or "Business" — the natural or legal person that, alone or jointly with others, determines the purposes and means of the Processing of Personal Information. For Personal Information processed in connection with the Platform, the Controller is Episapient (subject to clause 8 in respect of Personal Information embedded in User Content, where you may be the Controller and we may act as your Processor).

"Cross-border Transfer" — the transfer of Personal Information from a country in which a data subject is located to another country, including transfers within Episapient and to sub-processors.

"Data Subject", "Data Principal", or "Consumer" — the identified or identifiable natural person to whom Personal Information relates.

"DPDPA" — the Digital Personal Data Protection Act 2023 (India).

"GDPR" — Regulation (EU) 2016/679 (the EU General Data Protection Regulation), and where the context requires, the UK GDPR as adopted by the Data Protection Act 2018 (UK).

"Personal Information" or "Personal Data" — any information relating to an identified or identifiable natural person, as that term is defined under the Privacy Act 1988 (Cth) (Australia), the GDPR, the UK GDPR, the DPDPA, the CCPA/CPRA (California), and equivalent laws of any other jurisdiction in which a user is located. The term has its broadest reasonable meaning across these laws.

"Privacy Officer" — the individual at Episapient with day-to-day responsibility for privacy compliance and complaints handling, contactable at privacy@episapvault.com. The Privacy Officer is not a designated Data Protection Officer for the purposes of GDPR Art 37 or DPDPA s 10 unless that designation is separately stated in this Policy.

"Processing" — any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

"Processor" or "Data Processor" — a natural or legal person that Processes Personal Information on behalf of a Controller.

"Sensitive Personal Information" or "Special Category Data" — Personal Information that, under the law of the relevant jurisdiction, is treated as sensitive and subject to additional safeguards. Examples include: information about racial or ethnic origin; political opinions; religious or philosophical beliefs; trade-union membership; genetic data; biometric data processed for identification; health data; data about sex life or sexual orientation (GDPR Art 9); precise geolocation, government identifiers, financial-account information, contents of communications, and account credentials (CCPA/CPRA § 1798.140(ae)); and the categories listed in DPDPA where applicable.

"Vault Content" or "User Content" — has the meaning given in the Terms (clause 1 of the Terms): the data, documents, files, images, models, code, or other material you upload to the Platform other than Feedback. Vault Content may itself contain Personal Information about you or about third parties; clause 8 addresses how that Personal Information is treated.

2. Scope; Relationship to the Terms

2.1 This Privacy Policy applies to Personal Information that Episapient collects, uses, discloses, stores, transfers, or otherwise Processes in connection with your access to or use of the Platform (including the EpiSAP Quantum Vault, CollabHub, and any other services or features under the EpiSAP brand).

2.2 This Policy is incorporated into the Terms by reference (see Terms clause 9). On matters concerning Personal Information, this Policy prevails over the Body of the Terms in the event of conflict (Terms clause 23.2(d)). Non-derogable local law and the applicable regional Schedule prevail over both, in the order set out in Terms clause 23.2.

2.3 This Policy does not cover:

  1. third-party websites, services, or applications that you may access through links from the Platform (those are governed by the third party's own privacy notice);
  2. your collection and processing of Personal Information embedded in your Vault Content for your own purposes (you act as the Controller for that processing — see clause 8); or
  3. information that has been irreversibly anonymised so that no individual is reasonably identifiable.

3. Personal Information We Collect

We collect the following categories of Personal Information.

CategoryExamplesSource
Registration dataName, email address, password (stored hashed), country of residence, organisation (optional), role (optional), verification token responses.Direct from you at sign-up.
Account dataAccount ID, account-tier status (Beta Tester, paid, etc.), account preferences, two-factor-authentication enrolment, recovery contact (optional), API keys you generate.Direct from you and generated by the Platform.
Vault Content metadata (NOT the body of Vault Content — that remains User Content under the Terms, clauses 5.1–5.5)File name, file size, file type, upload timestamp, content hash (SHA-256 and other hashes), blockchain-anchoring transaction reference, vault-folder structure, version-history pointers, watermark identifiers (where used).Generated by the Platform when you interact with the vault.
Feedback (per Terms clause 7.1)Suggestions, bug reports, feature requests, beta-tester observations, and any Personal Information you choose to include in those communications.Direct from you through any communication channel.
Device and usage dataIP address, user-agent string, device identifiers (where applicable), operating system, browser, language, time zone, pages or features accessed, click events, error events, performance metrics, login timestamps.Automatically when you access the Platform.
Cookies and similar technologiesSession cookies, authentication tokens, preference cookies, analytics identifiers, security/anti-fraud cookies. See Annex 2 for the full list.Set by the Platform and (where you consent) by sub-processors.
Payment data (collected only if and when a paid tier is introduced)Billing name, billing address, payment-card last four digits / token (the full PAN is handled by the payment processor, not by us), invoice history, tax identifiers.Direct from you and from the payment processor.
Identity-verification data (collected only if and when know-your-customer verification becomes required for your account type)Government-ID type and number, ID document image, liveness-check artefacts, verification result.Direct from you and from the identity-verification provider.
Security-event dataAuthentication attempts (success and failure), suspicious-activity flags, abuse signals, IP-reputation lookups, audit-log entries connected to your account.Generated by the Platform and security sub-processors.
Support communicationsEmails, support tickets, chat transcripts, screenshots you provide, records of phone calls (where permitted by law and disclosed at the start of the call).Direct from you.
Agreement-gate evidenceTime of Acceptance, IP address at Acceptance, user-agent at Acceptance, hash of the rendered Terms and Privacy Policy shown to you, hash of any non-disclosure agreement accepted (per Terms clause 2.3).Generated by the agreement gate.
Regulatory attestations (added v1.2)Where you create an idea or download a patent draft that triggers a regulatory soft-gate, we record (a) for the Indian Patents Act 1970 s 39 attestation: the option you selected, the jurisdiction the draft was generated for, the version and SHA-256 hash of the modal text shown to you, your IP address, and your user-agent at the time of attestation; (b) for the ICMR / health-data attestation: a flag indicating whether the idea contains or derives from human-subject data, and (if so) the ethics-committee approval number and date you provided; (c) for any other compliance soft-gate added in future, the equivalent record. These records are written to evidence the User's own representation; they do not constitute Episapient's verification of the underlying claim.Generated when you submit the relevant attestation.
Publication-overlap scan inputs and outputs (added v1.2)When you (or an authorised institution administrator for an idea attributed to your institution) initiate a Publication Watch / Pub-Alerts scan, we extract topical keywords from the idea (subject to a PII scrub that strips email addresses, URLs, phone numbers, and IPs) and submit them to the external public-record APIs listed in our Data Sources & Attribution Policy (Crossref, NCBI E-utilities, OpenAlex, arXiv; bioRxiv and medRxiv are reached via Crossref). We then submit the keywords plus short excerpts of candidate abstracts (capped at 5,000 characters) to the LLM provider configured for your tenant (default: OpenAI; configurable per Annex 1) for an overlap analysis. The resulting alert records are stored in the publication_alerts table associated with your idea.Generated when you initiate or schedule a scan.

3.1 Sensitive Personal Information. The Platform does not require you to provide Sensitive Personal Information. We will not knowingly collect Sensitive Personal Information unless (a) you choose to include it in Vault Content (in which case we Process it only as necessary to host and secure the vault — we do not look at the substantive content of your vault); (b) you provide it as part of identity verification (where this is required to comply with law and is processed under additional safeguards); or (c) you choose to include it in Feedback or support communications (in which case we ask you not to do so).

3.2 Children. The Platform is not directed at children under 18. See clause 14 and (for users in the United States) Schedule C.5 in respect of children under 13 (COPPA).

4. How We Collect Personal Information

We collect Personal Information in three ways:

  1. Directly from you — when you register an account, log in, configure preferences, upload Vault Content, give Feedback, contact support, complete identity verification, or pay for a paid tier.
  2. Automatically — through cookies, software development kits (SDKs), server logs, audit logs, and analytics tools when you access the Platform. See Annex 2 for cookies and similar technologies.
  3. From third parties — including (where you choose to use them) authentication providers (single sign-on / OAuth), identity-verification providers, payment processors, fraud and abuse prevention services, and publicly available sources where we need to verify identity or comply with sanctions / anti-money-laundering law (Terms clause 2.1(c)). The current list of sub-processors is at https://vault.episapvault.com/legal/sub-processors (see Annex 1).

5. Why We Use Personal Information (Purposes)

We Process Personal Information for the following purposes. Where the law applicable to you requires us to identify a lawful basis (clause 6), we map each purpose to that basis below.

PurposeWhat we doLawful basis (where required)
Provide the PlatformCreate and maintain your account, host your Vault Content, run the post-quantum cryptography and blockchain-anchoring features, deliver CollabHub functionality, deliver any feature you have enabled.Contract performance (GDPR Art 6(1)(b)); analogous bases under DPDPA, UK GDPR, and other laws.
Secure the PlatformAuthenticate you, detect fraud and abuse, prevent unauthorised access, run security monitoring and audit logs, investigate security incidents, terminate access in case of abuse (Terms clause 17.2).Legitimate interests (GDPR Art 6(1)(f)) — Episapient's interest in protecting the Platform, other users, and the integrity of evidentiary records, balanced against your interests; legal obligation where applicable.
Comply with lawRespond to lawful regulatory or law-enforcement requests; comply with sanctions and export-control law (Terms clause 2.1(c)); comply with tax, accounting, and record-keeping obligations; comply with privacy and security laws including breach-notification obligations (clause 12); comply with the Bharatiya Sakshya Adhiniyam s 65B for evidentiary records (Terms Schedule B.12; Privacy Policy Schedule B.11).Legal obligation (GDPR Art 6(1)(c)) and analogous bases.
Communicate with youService announcements (changes to the Platform, security notices, billing), responses to your enquiries, account recovery, and (with your opt-in) product updates and marketing.Contract performance (service messages); consent (marketing — clause 16); legitimate interests (security notices).
Improve the PlatformAnalyse usage to fix bugs, improve performance, and design new features; act on Feedback (Terms clauses 7.3 and 7.13); train internal operational AI models on irreversibly anonymised data (within the meaning of clause 7.2(b)); aggregate analytics that do not identify any individual are out of scope of this restriction. Where Feedback contains personal data and we propose to use it for training internal AI models, we will conduct and publish a DPIA in accordance with Terms clause 7.13(e) and clause 7.5 of this Policy.Legitimate interests; consent where required for analytics cookies (clause 15).
Vault evidentiary integrityMaintain the agreement-gate evidence; preserve hashes of Vault Content; maintain blockchain-anchoring records (Terms clause 11); produce certificates on reasonable request (Terms Annex 3).Contract performance; legitimate interests; legal obligation where applicable. Retention is governed by clause 10 and is longer than the general retention period (Terms clause 11.2 — 10 years).
Resolve disputes; enforce the TermsInvestigate alleged breaches, defend or pursue claims, comply with court orders, support arbitration proceedings (Terms clause C.11 for US Users).Legitimate interests; legal obligation; establishment, exercise, or defence of legal claims (GDPR Art 9(2)(f) for any special-category data).
M&A and corporate transactionsIf we are involved in a merger, acquisition, financing, restructure, insolvency, or sale of assets, we may disclose Personal Information to the counterparty under appropriate confidentiality arrangements (clause 8 and Terms clause 25.1).Legitimate interests, subject to user notice obligations.

6. Lawful Bases (Where Required by Law)

For users in jurisdictions whose privacy law requires a lawful basis for Processing (including the EU, UK, and analogous regimes), we rely on one or more of the following bases:

  1. Consent (GDPR Art 6(1)(a); UK GDPR; DPDPA s 6 for India; analogous bases under other laws) — where you have given freely-given, specific, informed, unambiguous, and (for special-category data) explicit consent. Consent can be withdrawn at any time without affecting the lawfulness of Processing already carried out.
  2. Contract performance (GDPR Art 6(1)(b)) — where Processing is necessary to perform our contract with you (the Terms) or to take pre-contractual steps at your request.
  3. Legal obligation (GDPR Art 6(1)(c)) — where Processing is necessary to comply with a legal obligation to which Episapient is subject.
  4. Vital interests (GDPR Art 6(1)(d)) — where Processing is necessary to protect your or another natural person's vital interests (rare for the Platform; relevant only in narrow security or emergency scenarios).
  5. Public interest task (GDPR Art 6(1)(e)) — we do not generally rely on this basis.
  6. Legitimate interests (GDPR Art 6(1)(f)) — where Processing is necessary for our legitimate interests or those of a third party, except where overridden by your interests or fundamental rights. We carry out a legitimate-interests assessment before relying on this basis. You may object to Processing on this basis (clause 13).

Under the CCPA/CPRA and other US state privacy laws (Schedule C), the framework is different: we provide notice at collection and respect opt-out rights for sale, sharing, and use of Sensitive Personal Information. Under the DPDPA (Schedule B), Processing is permitted on the basis of consent or for certain "legitimate uses" listed in the Act.

7. AI Training Carve-Out

This clause cross-references and reinforces Terms clause 5.5.

7.1 We will not use your User Content (Vault Content) to train any artificial-intelligence model that is publicly distributed or made available to other users.

7.2 The only exceptions are:

  1. You have given express, separate, opt-in consent to use specified User Content for a specified training purpose.
  2. The User Content has been irreversibly anonymised within the meaning of Article 4(1) and Recital 26 of the GDPR (and not merely pseudonymised or aggregated) such that you cannot reasonably be re-identified by any means likely to be used by us or by any other person, and the resulting model and outputs do not allow re-identification.
  3. Use is required for security, abuse-prevention, or compliance purposes (for example, training a malware-detection classifier on hashes or signatures, or anti-fraud signal detection on aggregated metadata).

7.3 Internal operational metrics about the Platform (latency, error rates, feature adoption, infrastructure load) are not subject to this restriction. Aggregate analytics that do not identify you are not subject to this restriction.

7.4 Feedback (Terms clause 7.1) is treated separately and is governed by Terms clause 7. We may use Feedback to improve the Platform — including by training internal models — subject to Terms clause 7.13 (good-faith use; not sold or licensed as a product on its own; treated under this Privacy Policy where it contains personal data). Where Feedback contains personal data and we propose to use it for training internal AI models, we will conduct and publish a DPIA in accordance with Terms clause 7.13(e) and clause 7.5 of this Policy.

7.5 DPIA summaries. Where we conduct an AI-training campaign in reliance on clause 7.2(a) (express opt-in consent) or where Feedback containing personal data is to be used for AI-model training in reliance on Terms clause 7.13(e), we will publish a Data Protection Impact Assessment summary in this Policy (or at a URL referenced from this Policy) before the campaign begins, identifying: (a) the purpose of the training; (b) the categories of Personal Information processed; (c) the lawful basis (in addition to consent where applicable) and the legitimate-interests assessment where relevant; (d) the technical and organisational measures applied (including any anonymisation, pseudonymisation, or differential-privacy techniques); (e) the retention period for training data; (f) data-subject rights and how to withdraw consent; and (g) the residual risk assessment and mitigations. Current DPIA summaries are listed at https://vault.episapvault.com/legal/dpia (the page returns "no active DPIAs" until the first AI-training campaign is announced). This clause implements Terms clause 5.5(a) and Terms clause 7.13(e).

8. Sharing and Disclosure

We disclose Personal Information only in the limited circumstances described below.

8.1 Service providers / sub-processors. We use sub-processors to deliver the Platform (cloud hosting, email delivery, identity verification, payment processing when launched, analytics, security monitoring, customer support tooling, and similar). Sub-processors act on our documented instructions, are bound by written contracts that meet the standards required by the applicable privacy law (including GDPR Art 28 standard contractual clauses where relevant), and are listed at https://vault.episapvault.com/legal/sub-processors (Annex 1). We give reasonable advance notice of changes to the sub-processor list before adding a new sub-processor that materially affects Personal Information.

8.2 Successors and corporate transactions. If Episapient is involved in a merger, acquisition, financing, restructure, insolvency, or sale of substantially all our assets (Terms clause 25.1), Personal Information may be disclosed to the prospective or actual counterparty under appropriate confidentiality and use restrictions. Per Terms clause 25.1, we will use reasonable endeavours to ensure the assignee is bound by terms substantially equivalent to these in respect of your User Content, Feedback, and Personal Information, and we will give you written notice.

8.3 Legal-process disclosures. We may disclose Personal Information if we reasonably believe in good faith that disclosure is required by law, court order, subpoena, search warrant, or other lawful process; necessary to comply with sanctions, export-control, or anti-money-laundering law; or necessary to protect Episapient's rights or the rights, safety, or property of any user or the public. Where lawfully permitted, we will give you advance notice of compelled disclosure so you can seek a protective order.

8.4 Research collaborators (CollabHub). If you use CollabHub, you may share Personal Information and Vault-related metadata with other CollabHub users you choose to collaborate with. We are not responsible for what those collaborators do with information you share with them through that feature; you act as the Controller for that sharing.

8.5 Vault Content embedding third-party Personal Information. If your Vault Content contains Personal Information about other people, you are responsible (as Controller / Data Fiduciary / Business) for having a lawful basis to upload that information and for honouring any rights those people may exercise against you. We act as your Processor / Data Processor for that information and process it only to host, secure, and provide the Platform to you.

8.6 No sale or rent. We do not, and will not, sell or rent your Personal Information for monetary consideration. Schedule C describes the position under the broader CCPA/CPRA definition of "sale" and "sharing" (which can include certain cross-context behavioural advertising); we currently do not engage in any sale or sharing as defined by CCPA/CPRA, and if that ever changes we will provide a "Do Not Sell or Share My Personal Information" mechanism (Schedule C.4).

9. Cross-Border Transfers

9.1 Where data is hosted. Personal Information and Vault Content are primarily stored and processed in AWS region ap-southeast-2 (Sydney, Australia), including AWS RDS PostgreSQL (primary database), AWS ECS Fargate (application runtime), AWS Secrets Manager, AWS CloudWatch Logs, and AWS ECR. Edge / DNS / TLS termination is performed by Cloudflare on its global Anycast edge network. Other sub-processor locations are listed at https://vault.episapvault.com/legal/sub-processors (Annex 1). Episapient is established in Queensland, Australia, and our staff and contractors who access Personal Information do so primarily from Australia, with the possibility of access from other locations where they are travelling or otherwise lawfully permitted to process Personal Information consistent with this Policy.

9.2 Transfer mechanisms. Where we transfer Personal Information from a jurisdiction whose law restricts cross-border transfer (including the EU/EEA, the UK, India, and others), we rely on one or more of the following mechanisms (depending on the jurisdiction):

  1. an adequacy decision (or equivalent recognition) by the originating jurisdiction's data-protection authority;
  2. Standard Contractual Clauses approved by the European Commission (or the UK International Data Transfer Agreement / Addendum), supplemented where necessary by additional technical and organisational measures consistent with the Schrems II jurisprudence;
  3. Binding Corporate Rules (where adopted in future);
  4. your explicit consent to the transfer, given after being informed of the possible risks (Art 49(1)(a) GDPR);
  5. necessity for the performance of a contract between you and us (Art 49(1)(b) GDPR);
  6. a derogation that is established for the establishment, exercise, or defence of legal claims (Art 49(1)(e) GDPR); or
  7. the equivalent mechanism available under the originating jurisdiction's law.

9.3 India. Cross-border transfers from India are governed by section 16 of the DPDPA and any restriction the Central Government notifies. Schedule B.4 elaborates.

9.4 China. The Platform is not currently offered in mainland China. Before any China launch, a separate schedule will be drafted to address the Personal Information Protection Law 2021 (PIPL) and related data-localisation and outbound-transfer requirements (see Terms Schedule D.5).

10. Retention

10.1 General principle. We retain Personal Information for as long as necessary to fulfil the purposes set out in clause 5, comply with our legal obligations, resolve disputes, and enforce our agreements.

10.2 Account data. We retain account data for the duration of your account and for at least 30 days after termination (consistent with the export window in Terms clause 17.4), and up to a maximum of 7 years after termination unless a longer period is required by law.

10.3 Vault Content. Vault Content is retained for the duration of your account, plus the 30-day export window in Terms clause 17.4, after which we may delete it in accordance with Terms clause 17.4 and clause 10.5 of this Policy.

10.4 Evidentiary / blockchain anchoring records. Hashes, anchoring transaction references, and agreement-gate evidence are retained for not less than 10 years from the date of anchoring (Terms clause 11.2) and may persist on public blockchains for the chain's lifetime, outside our control.

10.5 Category-specific retention table. The following retention periods apply by default. Where a longer or shorter period is required by law, the legal period overrides.

CategoryDefault retentionNotes
Registration and account dataAccount lifetime + 30 days; up to 7 years post-terminationReduced if you exercise a valid erasure right (clause 13).
Vault Content (body)Account lifetime + 30 days export windowTerms clause 17.4.
Vault Content metadata (hashes, anchoring records)10 years from anchoringTerms clause 11.2.
FeedbackIndefinite (we may retain Feedback for the lifetime of the resulting Platform IP)Personal Information embedded in Feedback is treated under this Policy and may be erased on request where lawful.
Device and usage logs12–24 months (rolling)Aggregated analytics retained longer.
CookiesPer Annex 2Session cookies expire on logout.
Payment and tax records7 yearsAustralian Taxation Office and equivalent foreign requirements.
Identity-verification artefactsAs required by AML/CTF and KYC law in the relevant jurisdictionTo be set when KYC is launched.
Security-event logs12–24 monthsLonger for incidents under active investigation.
Support communications3 yearsLonger if connected to a dispute or legal hold.
Agreement-gate evidence10 years from AcceptanceSupports evidentiary use under Bharatiya Sakshya Adhiniyam s 65B and equivalents.
Application audit logs (idea capture, evolution, locking, sharing, admin actions)Indefinite while the underlying account exists; deleted within 30 days of permanent account deletion except where retention is required to defend a legal claim or to maintain the integrity of the lock-hash chain that the idea evidencesAudit logs form part of the evidentiary record for IP provenance disputes (Terms clause 11) and ICMR / Patents Act s 39 attestations. Pruning the audit log mid-account-life would invalidate later-asserted priority dates. Aggregated, irreversibly de-identified audit telemetry may be retained longer for security analysis (clause 10.6).

10.6 Anonymisation. We may retain irreversibly anonymised data indefinitely for analytics and Platform improvement; such data is no longer Personal Information.

11. Security

11.1 We implement reasonable technical and organisational measures intended to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are intended to comply with GDPR Art 32, the Australian Privacy Principles (APP 11), DPDPA s 8(5) (reasonable security safeguards), the security requirements of the CCPA/CPRA, and equivalent obligations under other laws.

11.2 Without limiting the generality of clause 11.1, our measures include:

  1. encryption in transit (TLS) and encryption at rest. Vault Content is encrypted using one or more cryptographic primitives selected from those described in our published security documentation (which may include post-quantum primitives where so described). References here and in our marketing to "quantum", "post-quantum", or "quantum-resistant" describe design objectives and the primitives in use at the relevant time, not warranties of any particular cryptographic property (Terms clause 14.4);
  2. role-based access controls and the principle of least privilege for staff and contractors;
  3. multi-factor authentication for administrative access;
  4. logging and monitoring of access to Personal Information;
  5. secure software-development practices, including code review and vulnerability management;
  6. network segmentation and intrusion detection;
  7. regular backups and tested recovery procedures;
  8. vendor risk assessment for sub-processors;
  9. staff privacy and security training; and
  10. an incident-response plan covering detection, containment, eradication, recovery, notification, and post-incident review.

11.3 No security measure is infallible. Consistent with Terms clause 14.1, we do not warrant that the Platform is free of vulnerabilities or that Personal Information will never be subject to unauthorised access. You should keep independent backups of materially important records during the beta period (Terms clause 14.2).

12. Breach Notification

12.1 Notification to you. If we become aware of an actual or reasonably-suspected unauthorised access to or disclosure of your Personal Information or Vault Content, we will notify you within 72 hours of becoming aware (Terms clause 10), except where a shorter or longer period is required by law in your jurisdiction.

12.2 Notification to regulators. Where required by law, we will notify the relevant regulator within the applicable statutory period:

  1. Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth) Part IIIC) — "as soon as practicable" after we are reasonably satisfied that the breach is an "eligible data breach";
  2. EU/EEA supervisory authorities under GDPR Art 33 — within 72 hours of becoming aware of a personal-data breach, where feasible, except where the breach is unlikely to result in a risk to data subjects' rights and freedoms;
  3. UK Information Commissioner's Office under the UK GDPR — same 72-hour standard as GDPR;
  4. India CERT-In under the CERT-In Directions, 2022 — within 6 hours of becoming aware of an applicable cyber-incident (Terms Schedule B.11);
  5. India Data Protection Board under the DPDPA — as required by the Act and any rules made under it;
  6. California Attorney General and affected residents under Cal. Civ. Code § 1798.82 — "in the most expedient time possible and without unreasonable delay";
  7. other US-state Attorneys General as required by the relevant state law (Schedule C.4(e)); and
  8. any other regulator with jurisdiction.

12.3 Notification content. Notifications will include (to the extent then known) the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point for further information.

13. Your Privacy Rights (Generic Statement)

Subject to the regional Schedule applicable to you, and to the conditions and exceptions provided in your local privacy law, you have the following rights in respect of Personal Information about you that we hold:

  1. Right of access — to confirm whether we are processing your Personal Information and to obtain a copy.
  2. Right of correction / rectification — to have inaccurate or incomplete Personal Information corrected.
  3. Right of erasure / deletion ("right to be forgotten") — to have Personal Information erased in defined circumstances, subject to exceptions for legal claims, freedom of expression, and our retention obligations.
  4. Right of portability — to receive Personal Information you have provided in a structured, commonly-used, machine-readable format and (where technically feasible) have it transmitted to another controller.
  5. Right of objection — to object to Processing based on legitimate interests, and to object to direct marketing at any time.
  6. Right of restriction — to have Processing restricted in defined circumstances (for example, while a correction request is being assessed).
  7. Right not to be subject to solely automated decision-making — including profiling, that produces legal or similarly significant effects, except where permitted by law and subject to safeguards. We do not currently make solely automated decisions of that kind.
  8. Right to withdraw consent — where Processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of Processing already carried out.
  9. Right to lodge a complaint — with us first (clause 18) and with the relevant regulator (Schedule A–D as applicable).
  10. Right of nomination — for users in India, the right under the DPDPA to nominate a person to exercise rights in the event of death or incapacity (Schedule B.7).
  11. Right of grievance redressal — for users in India, the right under DPDPA s 13 to a readily-available grievance-redressal mechanism (Schedule B.8).

13.1 How to exercise. Send a request to privacy@episapvault.com identifying the right you wish to exercise and providing enough information for us to verify your identity and the relevant Personal Information. We respond within statutory time limits and at no charge for reasonable requests; abusive, manifestly unfounded, or excessive requests may attract a fee or be refused, with reasons.

13.2 Authorised agent. Where the law allows, you may use an authorised agent (such as the agent mechanism under CCPA § 1798.135) to exercise rights on your behalf. We may verify the agent's authorisation.

13.3 Vault Content holding third-party data. Where Personal Information is embedded in Vault Content you have uploaded and the request is from a third party (clause 8.5), we will refer the request to you, the Controller, and assist you to respond as your Processor.

14. Children

14.1 The Platform is not directed to or designed for use by individuals under 18, and we do not knowingly collect Personal Information from individuals under 18 in connection with their direct use of the Platform. By accepting the Terms, you confirm that you are at least 18 (Terms clause 2.1(a)).

14.2 For users in the United States, we do not knowingly collect Personal Information from children under 13 in violation of the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501–6506). If we learn that we have collected such Personal Information, we will delete it promptly. See Schedule C.5.

14.3 If you become aware that a child has provided Personal Information to us, contact privacy@episapvault.com and we will take reasonable steps to investigate and delete that information.

15. Cookies and Similar Tracking Technologies

15.1 We use cookies, local storage, session storage, and similar technologies (collectively, "cookies") for the categories below. The full list is in Annex 2.

  1. Strictly necessary cookies — required to provide the Platform (authentication, session management, security). These cannot be turned off without disabling the Platform.
  2. Functional cookies — remember your preferences (language, theme, view settings).
  3. Analytics cookies — help us understand how the Platform is used and improve it. Set with your consent in jurisdictions where consent is required.
  4. Advertising cookies — we do not currently set advertising cookies. If that ever changes, we will update this Policy and seek consent where required.

15.2 EU/UK consent banner. For users in the EU/EEA and UK, we present a consent banner consistent with the ePrivacy Directive (Directive 2002/58/EC) and the relevant implementing law. The banner displays the categories of cookies we use, identifies which categories require your consent, and allows you to make a choice before any non-essential cookie is set. The Platform sets only essential, security, and consent-recording cookies by default; non-essential cookies (analytics, preferences) are not set unless and until you opt in. You can withdraw consent at any time via the cookie-preferences link in the footer, and we treat withdrawal as having the same effect as initial refusal. (Pilot phase note: where granular per-category UI is not yet available, we present consent on an essential-only basis — that is, we collect no consent for non-essential cookies because we do not set any — rather than ship a non-functional ‘Reject all’ button.)

15.3 Do Not Track / Global Privacy Control. We honour the Global Privacy Control (GPC) browser signal as an opt-out of "sale" or "sharing" for Users to whom the CCPA/CPRA applies (Schedule C.4(b)). We treat a valid GPC signal as a deemed opt-out without requiring further action by the User.

16. Marketing Communications

16.1 Service messages (account, security, billing, material changes to the Terms or Policy) are sent on the basis of contract performance and legal obligation; you cannot opt out of these while you maintain an active account.

16.2 Marketing messages are sent only on an opt-in basis. Each marketing email contains a one-click unsubscribe mechanism. Compliance specifics:

  1. Australia — Spam Act 2003 (Cth): consent (express or inferred), accurate sender information, functional unsubscribe (Schedule A.5).
  2. United States — CAN-SPAM Act (15 U.S.C. §§ 7701–7713): accurate header information, clear identification as advertising where applicable, valid postal address, opt-out honoured within 10 business days.
  3. Canada — CASL (Canada's Anti-Spam Legislation, S.C. 2010, c. 23): express or implied consent, sender identification, unsubscribe.
  4. EU/EEA — ePrivacy Directive and national implementations: prior consent (with limited soft-opt-in for similar products to existing customers).
  5. India — Telecom Commercial Communications Customer Preference Regulations and DPDPA consent rules (Schedule B).

17. Changes to this Policy

17.1 We may amend this Policy from time to time. For material changes that adversely affect your rights or that change the categories of Personal Information collected, the purposes of Processing, the categories of recipients, or the retention periods, we will give you not less than 30 days' written notice (consistent with Terms clause 18 and clause 21).

17.2 Notice will be by email to your account address and by an in-Platform notification (Terms clause 21.2). The current version, effective date, and version history are recorded in Annex 3.

17.3 Continued use of the Platform after the change takes effect constitutes acceptance of the amended Policy. If you do not accept a material amendment, you may terminate your account before the amendment takes effect (Terms clause 18) and exercise your data-export and deletion rights (Terms clause 17.4 and clause 13 of this Policy).

18. Contact and Complaints

18.1 Privacy Officer. Privacy questions, rights requests, and complaints should be sent to:

EPISAPIENT PTY LTD — Privacy Officer
Email: privacy@episapvault.com
Postal: 48 Castle Hill Drive, Murrumba Downs QLD 4503, Australia

18.2 How we handle complaints. We will acknowledge your complaint within 7 business days, investigate it, and respond substantively within 30 days (or such shorter period as required by law in your jurisdiction). If we cannot respond within 30 days, we will tell you why and give an expected response date.

18.3 Regulators. If you are not satisfied with our response, you may complain to the regulator in your jurisdiction. The relevant Schedule lists the contact points:

18.4 EU/UK Article 27 representative. As of the date at the head of this Policy, EpiSAP is in private beta and does not actively market to or accept users from the EEA or the UK. Where and from the date we designate territories within the EEA or the UK as supported, we will designate (a) an EU representative under GDPR Art 27 and (b) a UK representative under UK GDPR Art 27, and publish their contact details in Schedule D and at https://vault.episapvault.com/legal/eu-rep and /legal/uk-rep respectively, before the first User from that territory is on-boarded.

19. Governing Law

19.1 Default. Subject to non-derogable local privacy law and to the applicable Schedule, this Policy is governed by the laws of Queensland, Australia (consistent with Terms clause 19).

19.2 Non-derogable local privacy law prevails. Nothing in this clause limits the application of any non-derogable local privacy law to your Personal Information, and the order of precedence in Terms clause 23.2 applies.


SCHEDULES — Region-Specific Privacy Provisions

Schedule A — Australia

A.1 Application

This Schedule applies to and modifies the Body of this Policy in respect of any user who is (a) ordinarily resident in Australia, (b) accessing the Platform from within Australia, or (c) otherwise subject to Australian privacy law in connection with their use of the Platform (each, an "Australian User"). Capitalised terms not defined in this Schedule have the meanings given in the Body or in the Terms.

A.2 Privacy Act 1988 (Cth) and Australian Privacy Principles

We handle Personal Information about Australian Users in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in Schedule 1 to that Act, where applicable to us. Without limitation:

  1. APP 1 — this Policy is our open and transparent management notice;
  2. APP 3 — we collect Personal Information by lawful and fair means and for the purposes set out in clause 5 of the Body;
  3. APP 5 — this Policy provides the notice required at or as soon as practicable after collection;
  4. APP 6 — we use and disclose Personal Information only for the primary purpose of collection or a related secondary purpose within the Australian User's reasonable expectations, or as otherwise permitted by the Privacy Act;
  5. APP 8 — before disclosing Personal Information to overseas recipients, we take reasonable steps to ensure the recipient does not breach the APPs (clause 9 of the Body);
  6. APP 11 — we take reasonable steps to protect Personal Information from misuse, interference, loss, and unauthorised access, modification, or disclosure (clause 11);
  7. APP 12 — we provide access to Personal Information on request (clause 13);
  8. APP 13 — we correct Personal Information on request (clause 13).

A.3 Notifiable Data Breaches Scheme

If a breach is an "eligible data breach" under Part IIIC of the Privacy Act 1988 (Cth), we will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, in line with clause 12 of the Body and the OAIC's published guidance.

A.4 Sensitive Information

"Sensitive information" under section 6 of the Privacy Act 1988 (Cth) is collected only with the Australian User's consent or as otherwise permitted by the Act.

A.5 Spam Act 2003 (Cth)

Commercial electronic messages we send to Australian Users comply with the Spam Act 2003 (Cth), including consent, accurate sender information, and a functional unsubscribe facility (Body clause 16; Terms Schedule A.8).

A.6 Health information

If, in future, the Platform Processes "health information" within the meaning of section 6FA of the Privacy Act 1988 (Cth), we will comply with the additional obligations applicable to that information, and amend this Policy accordingly.

A.7 Complaints — OAIC

An Australian User who is not satisfied with our response to a privacy complaint may complain to the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner
GPO Box 5288, Sydney NSW 2001
Phone: 1300 363 992
Web: oaic.gov.au

A.8 Direct marketing — APP 7

We use Personal Information for direct marketing only with consent and provide a simple opt-out in every marketing message (APP 7 + Body clause 16.2(a)).

A.9 Governing Law and Jurisdiction

The default governing law and jurisdiction in clause 19 of the Body apply to Australian Users without modification.

Schedule B — India

B.1 Application

This Schedule applies to and modifies the Body of this Policy in respect of any user who is (a) ordinarily resident in India, (b) accessing the Platform from within India, or (c) otherwise subject to Indian privacy law in connection with their use of the Platform (each, an "Indian User" or "Data Principal"). Capitalised terms not defined in this Schedule have the meanings given in the Body or in the Terms.

B.2 Order of Precedence

If there is a conflict between this Schedule and the Body in its application to an Indian User, this Schedule prevails. The Body and this Schedule are otherwise to be read together. Non-derogable Indian law prevails over both.

B.3 Status under DPDPA

Episapient is the "Data Fiduciary" for Personal Information about Indian Users that we determine the purposes and means of Processing. Sub-processors that Process Personal Information on our behalf are "Data Processors". For Personal Information embedded in Vault Content uploaded by an Indian User about other people, the Indian User is generally the Data Fiduciary and Episapient acts as Data Processor (Body clause 8.5). Where the Central Government designates Episapient (or any class of Data Fiduciary that includes Episapient) as a Significant Data Fiduciary under DPDPA s 10, Episapient will comply with the additional obligations imposed by that designation, including (where applicable) appointment of a Data Protection Officer based in India, engagement of an independent data auditor, and periodic Data Protection Impact Assessments.

B.4 Cross-border Transfer (DPDPA s 16)

Cross-border transfers of Personal Information from India are made consistently with section 16 of the DPDPA. Where the Central Government restricts transfer to a particular country or territory by notification, we will not transfer Personal Information of Indian Users to that country or territory in contravention of that notification. The current list of recipient countries is in clause 9 of the Body and at https://vault.episapvault.com/legal/sub-processors.

B.5 Consent and Notice (DPDPA s 5 and s 6)

For Processing of Personal Information about an Indian User on the basis of consent, we will give a clear and plain-language notice (DPDPA s 5) describing the Personal Information, the purpose of Processing, the manner of exercising rights, and the manner of making a complaint to the Data Protection Board. Consent is free, specific, informed, unconditional, and unambiguous, and may be withdrawn at any time without affecting the lawfulness of prior Processing.

B.6 Legitimate Uses (DPDPA s 7)

For certain Processing, we may rely on the "legitimate uses" listed in section 7 of the DPDPA, including (where applicable) Processing for the purpose for which the Indian User has voluntarily provided Personal Information without indicating an objection, performance of a function under law, compliance with a court order, response to medical emergencies, employment-related purposes, and similar.

B.7 Data Principal Rights (DPDPA s 11–14)

An Indian User has the following rights under the DPDPA, exercisable by sending a request to privacy@episapvault.com:

  1. Right to information about Personal Information being Processed by us (s 11);
  2. Right to correction and erasure of Personal Information (s 12);
  3. Right to grievance redressal (s 13) — we provide a readily-available grievance-redressal mechanism, with the Privacy Officer as the point of contact;
  4. Right of nomination (s 14) — the Indian User may nominate another individual to exercise rights in the event of death or incapacity.

B.8 Grievance Redressal

Grievance contact: privacy@episapvault.com. We will acknowledge within 7 business days and substantively respond within the timeline prescribed by the DPDPA and rules made under it. If unresolved, the Indian User may approach the Data Protection Board of India.

B.9 Children's Personal Information (DPDPA s 9)

We do not knowingly Process Personal Information about a "child" within the meaning of the DPDPA (a person under 18 in India) or about a person with disability who has a lawful guardian, except with verifiable parental or guardian consent and otherwise in compliance with section 9 of the DPDPA. Tracking, behavioural monitoring, and targeted advertising directed at children are not undertaken on the Platform.

B.10 CERT-In Reporting

For Indian Users, the security incident notification commitment in clause 12 of the Body and Terms clause 10 is, where Episapient meets the definition of a "service provider" under the CERT-In Directions, 2022 in respect of the relevant incident, made in accordance with the timelines and procedures required by those Directions, including reporting to CERT-In within 6 hours of becoming aware of the incident (Terms Schedule B.11).

B.11 Bharatiya Sakshya Adhiniyam 2023 — Electronic Records

Electronic records produced by the agreement gate (clause 3 of the Body, "Agreement-gate evidence" row) are admissible in evidence under section 65B of the Bharatiya Sakshya Adhiniyam 2023 (which superseded section 65B of the Indian Evidence Act 1872 on and from 1 July 2024), subject to the production of the certificate required by that section, which we will provide on reasonable request (Terms Schedule B.12).

B.12 Information Technology Act 2000

To the extent the IT Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 continue to apply (during transition or in respect of "sensitive personal data or information"), we comply with the reasonable-security-practices standard set by those Rules in relation to such data.

B.13 Consumer Protection Act 2019

Nothing in this Policy limits any right or remedy an Indian User has as a consumer under the Consumer Protection Act 2019, the Consumer Protection (E-Commerce) Rules 2020, or any other law of India that cannot be lawfully limited or excluded (Terms Schedule B.9).

B.14 Data Protection Board of India — Complaints

An Indian User may complain to the Data Protection Board of India in accordance with the DPDPA and the rules made under it. Contact details for the Board will be those notified by the Central Government from time to time.

B.15 Severability

If any provision of this Schedule is held invalid or unenforceable by any Indian court, tribunal, or authority, that provision will be severed in respect of India only and the remaining provisions of this Schedule and the Body (which act as a body-level fallback for any severed Schedule provision) will continue in full force and effect (Terms clause 22.2).

Schedule C — United States

C.1 Application

This Schedule applies to any user who is (a) ordinarily resident in the United States, (b) accessing the Platform from within the United States, or (c) otherwise subject to US privacy law in connection with their use of the Platform (each, a "US User"). California-resident-specific provisions are in clause C.4. Other-state provisions are in clause C.4(e). Capitalised terms not defined in this Schedule have the meanings given in the Body or in the Terms.

C.2 Order of Precedence

If there is a conflict between this Schedule and the Body in its application to a US User, this Schedule prevails. The Body and this Schedule are otherwise to be read together. Non-derogable US-state and federal privacy law prevails over both.

C.3 Federal-Level Provisions

C.3.1 No "sale" of Personal Information for monetary consideration

We do not sell Personal Information for monetary consideration in any US state. Whether any of our Processing constitutes "sharing" or "sale" under the broader CCPA/CPRA or analogous state-law definitions is addressed in clause C.4.

C.3.2 GLBA / HIPAA / FCRA

The Platform is not a financial institution within the meaning of the Gramm-Leach-Bliley Act, a covered entity or business associate within the meaning of HIPAA, or a consumer-reporting agency within the meaning of the Fair Credit Reporting Act. If a US User chooses to upload Vault Content that contains data regulated by those statutes, the US User remains the responsible party for that data and we act as a Processor (Body clause 8.5).

C.3.3 CAN-SPAM Act

Our marketing emails comply with the CAN-SPAM Act (15 U.S.C. §§ 7701–7713) (Body clause 16.2(b)).

C.4 California — CCPA/CPRA Disclosures

C.4.1 Categories of Personal Information collected (last 12 months)

For California-resident US Users, the categories of "personal information" we collect, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to which we disclose personal information are set out in clauses 3, 4, 5, and 8 of the Body. Mapped to the categories listed in Cal. Civ. Code § 1798.140(v):

  1. Identifiers (name, email, IP, account ID) — collected; disclosed to service providers; not sold or shared;
  2. Customer-records information — collected if you provide it; disclosed to service providers; not sold or shared;
  3. Protected-classification characteristics — not collected;
  4. Commercial information — collected when you use a paid tier; disclosed to payment processors; not sold or shared;
  5. Biometric information — collected only if identity verification requires it, and only with consent;
  6. Internet/network activity — collected; disclosed to analytics and security service providers;
  7. Geolocation — we collect IP-derived approximate location; precise geolocation is not collected;
  8. Sensory data — not collected;
  9. Professional/employment information — collected only if you provide it (organisation, role);
  10. Education information — not collected;
  11. Inferences — we draw limited inferences for security and abuse-prevention purposes;
  12. Sensitive personal information (Cal. Civ. Code § 1798.140(ae)) — account credentials are collected; otherwise generally not collected unless you choose to include such information in Vault Content or identity-verification flows.

C.4.2 "Sale" and "Sharing"

We do not "sell" or "share" personal information as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah). If we ever do, we will provide a "Do Not Sell or Share My Personal Information" link and honour Global Privacy Control signals (Body clause 15.3).

C.4.3 Limit Use of Sensitive Personal Information

To the extent we Process Sensitive Personal Information (as defined in Cal. Civ. Code § 1798.140(ae)) for purposes other than those permitted by Cal. Civ. Code § 1798.121(a) without the right to limit, a California-resident US User may exercise the right to limit by sending a request to privacy@episapvault.com.

C.4.4 California rights

A California-resident US User may exercise the rights of access, deletion, correction, portability, opt-out of sale/sharing, limit use of sensitive personal information, and non-discrimination, as provided by the CCPA/CPRA. Authorised-agent requests under Cal. Civ. Code § 1798.135 are accepted with appropriate verification (Body clause 13.2).

C.4.5 California Shine the Light Act

California-resident US Users may request information about our disclosures of personal information to third parties for those third parties' direct-marketing purposes. We do not currently make such disclosures, and so the response to a request will reflect that fact.

C.4.6 California Notice at Collection

This Policy serves as the Notice at Collection for California-resident US Users, identifying the categories of personal information collected, the purposes of use, and whether the personal information is sold or shared.

C.4.7 California Privacy Protection Agency

A California-resident US User who is not satisfied with our response may complain to the California Privacy Protection Agency or the California Attorney General.

C.4.8 Other US-state comprehensive privacy laws

If the US User resides in another US state with a comprehensive privacy law, the rights granted to the US User under that state's law are not limited by this Policy. The states currently in scope (without limitation) are: Texas (TDPSA), Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA), Oregon (OCPA), Delaware (DPDPA), New Hampshire (NHPA), New Jersey (NJDPA), Maryland (MOPDA), and Minnesota (MCDPA), consistent with Terms Schedule C.10(e). We will comply with the applicable law's notice, consent, and rights-request requirements; in particular, we honour universal opt-out mechanisms (such as Global Privacy Control) where the relevant state law requires this.

C.5 Children — COPPA

Consistent with Body clause 14.2 and Terms Schedule C.9, the Platform is not directed to children under 13 and we do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501–6506). If we learn that we have collected such information, we will delete it promptly and, where applicable, notify the parent or guardian.

C.6 Breach notification — state laws

We will notify affected California residents and, where required by their threshold criteria, the California Attorney General under Cal. Civ. Code § 1798.82, and equivalent regulators in other US states under applicable state breach-notification statutes (Body clause 12.2).

C.7 DMCA — copyright

Privacy-relevant aspects of the DMCA notice-and-takedown procedure are at Terms Schedule C.14. Personal Information you provide in a DMCA notice is Processed for the purposes of responding to the notice, defending against fraudulent notices, and complying with 17 U.S.C. § 512.

C.8 Federal Trade Commission Act

We Process Personal Information consistently with our representations in this Policy. The FTC may enforce against deceptive or unfair privacy practices under Section 5 of the FTC Act.

C.9 Governing Law — carve-out

For US Users, this Policy is interpreted consistently with Terms Schedule C.12 (Delaware contract construction), except that non-derogable state privacy law of the US User's state of residence prevails on privacy matters.

C.10 Severability

If any provision of this Schedule is held invalid or unenforceable by a US court, tribunal, or arbitrator, that provision will be severed in respect of US Users only and the remaining provisions of this Schedule and the Body (which act as a body-level fallback for any severed Schedule provision) will continue in full force and effect (Terms clause 22.2).

Schedule D — Worldwide / Other Jurisdictions

D.1 Application

This Schedule applies to any user who is not in scope of Schedule A, B, or C (each, an "Other-Jurisdiction User"). Capitalised terms not defined in this Schedule have the meanings given in the Body or in the Terms.

D.2 European Economic Area (EEA) — GDPR

D.2.1 Controller; contact details

For Personal Information about Other-Jurisdiction Users in the EEA, Episapient is the Controller within the meaning of GDPR Art 4(7). Contact: privacy@episapvault.com; postal address as in Body clause 18.1.

D.2.2 EU Article 27 Representative

EU Art 27 representative — Not yet designated. EpiSAP is in private beta and does not actively market to or accept users from the EEA as of the date at the head of this Policy. A representative will be designated and named here, and at https://vault.episapvault.com/legal/eu-rep, before the first EEA User is on-boarded.

D.2.3 Data Protection Officer

DPO designation — Not designated. Episapient has assessed its current Processing activities (private beta, limited-volume B2C / B2B research IP vault) against GDPR Art 37 and concluded that none of the three triggers (public authority; large-scale systematic monitoring; large-scale special-category) is met. The Privacy Officer at privacy@episapvault.com handles privacy questions, requests, and complaints. Episapient will re-assess on each material change to Processing activity, including (a) commercial launch in any EEA country; (b) introduction of biometric authentication or health-data Processing; (c) introduction of automated decision-making affecting Users; or (d) crossing 100,000 EEA Users.

D.2.4 Article 13 / Article 14 disclosures

The information required by GDPR Art 13 and Art 14 is set out in this Policy as follows:

D.2.5 GDPR data-subject rights

An EEA Other-Jurisdiction User may exercise the rights of access (Art 15), rectification (Art 16), erasure (Art 17), restriction (Art 18), portability (Art 20), objection (Art 21), and not to be subject to solely automated decisions (Art 22), and may withdraw consent and lodge complaints (Art 77).

D.2.6 Supervisory authority

An EEA Other-Jurisdiction User may complain to their local supervisory authority or to the supervisory authority of the EU Member State in which the alleged infringement occurred. A list of authorities is published by the European Data Protection Board.

D.2.7 ePrivacy Directive

Cookies and similar technologies set on terminal equipment of EEA Other-Jurisdiction Users are subject to the ePrivacy Directive (Directive 2002/58/EC) and national implementing law (Body clause 15).

D.2.8 Digital Services Act — notice-and-action

For Other-Jurisdiction Users in the EU, we operate a notice-and-action procedure consistent with the Digital Services Act (Regulation (EU) 2022/2065), which is described in the Terms. Personal Information provided in a notice is Processed for the purpose of evaluating and acting on the notice, including to communicate with notice-givers and content uploaders. Statements of reasons are provided where required by Art 17 DSA.

D.3 United Kingdom — UK GDPR + DPA 2018

D.3.1 Controller and UK Article 27 Representative

For UK Other-Jurisdiction Users, Episapient is the Controller. UK Art 27 representative — not yet designated; will be named here and at https://vault.episapvault.com/legal/uk-rep before the first UK User is on-boarded.

D.3.2 Rights and complaints

UK Other-Jurisdiction Users have the same rights as in clause D.2.5, exercisable under the UK GDPR and the Data Protection Act 2018. Complaints may be made to the Information Commissioner's Office (ICO) at ico.org.uk.

D.3.3 PECR

Cookies and electronic-marketing rules are governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003.

D.4 Canada

D.4.1 PIPEDA

For Other-Jurisdiction Users in Canada, Personal Information is Processed in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable, including the principles in Schedule 1 to PIPEDA.

D.4.2 Quebec — Law 25

For Other-Jurisdiction Users in Quebec, we comply with the Act respecting the protection of personal information in the private sector as amended by Law 25, including transparency, consent, retention, breach-notification, and rights to access, correction, and portability obligations. Privacy Officer: as designated in Body clause 18.1.

D.4.3 BC PIPA / Alberta PIPA

For Other-Jurisdiction Users in British Columbia or Alberta, we comply with BC PIPA or Alberta PIPA respectively where applicable.

D.4.4 CASL

Commercial electronic messages comply with Canada's Anti-Spam Legislation (CASL) (Body clause 16.2(c)).

D.4.5 Complaints

Canadian Other-Jurisdiction Users may complain to the Office of the Privacy Commissioner of Canada or to the relevant provincial commissioner (Quebec CAI, BC OIPC, Alberta OIPC).

D.5 Brazil — LGPD

For Other-Jurisdiction Users in Brazil, Personal Information is Processed in accordance with the Lei Geral de Proteção de Dados (LGPD, Lei n.° 13.709/2018) where applicable. Rights of confirmation, access, correction, anonymisation, blocking or deletion, portability, information about sharing, withdrawal of consent, and complaint to the ANPD (Autoridade Nacional de Proteção de Dados) are recognised.

D.6 South Africa — POPIA

For Other-Jurisdiction Users in South Africa, Personal Information is Processed in accordance with the Protection of Personal Information Act 2013 (POPIA) where applicable. Rights of access, correction, deletion, objection, and complaint to the Information Regulator are recognised.

D.7 Switzerland — FADP

For Other-Jurisdiction Users in Switzerland, Personal Information is Processed in accordance with the revised Federal Act on Data Protection (FADP, in force from 1 September 2023) where applicable.

D.8 China — PIPL (flag for separate schedule)

The Platform is not currently offered in mainland China. Before any China launch, a separate schedule will be drafted to address the Personal Information Protection Law 2021 (PIPL), the Data Security Law, the Cybersecurity Law, and any related cross-border-transfer assessment, standard contractual clauses, security assessment, or certification requirements (consistent with Terms Schedule D.5).

D.9 Other Local Law — General Catch-All

Where the privacy law of the country in which the Other-Jurisdiction User is ordinarily resident or accessing the Platform mandates a different treatment of any matter dealt with in the Body, that local law applies to the Other-Jurisdiction User to the extent of the inconsistency, and we will comply with that local law in respect of that Other-Jurisdiction User (consistent with Terms Schedule D.5).

D.10 Language

This Policy is issued in English. Where a translation is provided, the English version controls in the event of any inconsistency, except where the local law of the Other-Jurisdiction User's jurisdiction (including, without limitation, the Charter of the French Language (Quebec) and the Loi Toubon (France)) requires a translated version to control for consumer or privacy notices in that jurisdiction, in which case the translated version controls only to the extent required by that local law and only for the matters governed by it (consistent with Terms Schedule D.6).

D.11 Governing Law

For Other-Jurisdiction Users, the default governing law in clause 19 of the Body applies, subject to any non-derogable local law and to Terms clause 7.12 (which fixes Queensland law for the Platform IP assignment).

D.12 Severability

If any provision of this Schedule is held invalid or unenforceable in any jurisdiction, that provision will be severed in respect of that jurisdiction only and the remaining provisions of this Schedule and the Body (which act as a body-level fallback for any severed Schedule provision) will continue in full force and effect (Terms clause 22.2).


ANNEXES

Annex 1 — Sub-Processors

The list below identifies the sub-processors that Process Personal Information on our behalf as of the date at the head of this Policy. The list is updated at https://vault.episapvault.com/legal/sub-processors when sub-processors are added or removed. We will provide reasonable advance notice (no less than 30 days where practicable) of changes that materially affect Personal Information.

Sub-processorServiceData categoryRegion / residencyPurpose
Amazon Web Services, Inc.RDS PostgreSQL (primary database)Account data, User Content, audit logsap-southeast-2 (Sydney, Australia)Primary persistent storage
Amazon Web Services, Inc.ECS Fargate (application runtime)Request metadata, transient request bodiesap-southeast-2 (Sydney, Australia)Serverless application execution
Amazon Web Services, Inc.Secrets ManagerAPI keys, DB credentials, encryption keysap-southeast-2 (Sydney, Australia)Secure credential storage
Amazon Web Services, Inc.CloudWatch Logs & ECRApplication logs, container imagesap-southeast-2 (Sydney, Australia)Operational logging, image registry
Cloudflare, Inc.Authoritative DNS, edge proxy / CDNIP addresses, request metadata, TLSGlobal edge (Anycast)DNS resolution, DDoS protection, edge caching
Polygon Labs (Polygon PoS network)Public blockchainSHA-256 hash anchors only (no Personal Information)Public on-chain (decentralised)Optional immutable timestamping of idea-locks (feature-flagged)
Bitcoin / OpenTimestamps Calendar ServersPublic blockchainMerkle root of batched hashes (no Personal Information)Public on-chain (decentralised)Optional secondary anchor (feature-flagged; disabled by default)
OpenAI, Inc. (or compatible API per AI_BASE_URL config)Generative AI inferenceIdea content if and only if the User invokes the AI assistant; not used for model training (per provider terms)Provider-dependent (default: United States)Optional AI features (disabled by default; require OPENAI_API_KEY)
ORCID, Inc.OAuth identity providerEmail, name, ORCID iDUnited States / SwitzerlandOptional researcher SSO (disabled by default; only triggered by explicit User election)
Resend, Inc. (resend.com) — SMTP relayTransactional email deliveryRecipient email address, sender display name, body of platform-generated emails (verification, invitation, breach notification, transactional)United States (provider primary region)Account verification, invitation, breach notification, transactional messaging. Migration to Amazon SES (ap-southeast-2) is planned post-pilot; users will be notified under clause 18 before the change.
Redis (self-hosted on AWS, optional)Server-side session storeSession identifiersap-southeast-2 (Sydney, Australia)Multi-instance session continuity (enabled only when SESSION_REDIS_URL is set; default deployment uses signed cookies)
Crossref (Publishers International Linking Association, Inc.)DOI metadata API (added v1.2)Topical keywords extracted from idea content (PII-scrubbed); no Personal Information transmittedUnited States (Lynnfield, MA) — public REST APIRead-only DOI metadata lookup for journal articles and bioRxiv / medRxiv preprints when a Publication Watch scan is initiated. See Data Sources & Attribution Policy
National Center for Biotechnology Information (US National Library of Medicine, NIH)PubMed E-utilities API (added v1.2)Topical keywords extracted from idea content (PII-scrubbed); no Personal Information transmittedUnited States — public REST APIRead-only PubMed lookup when a Publication Watch scan is initiated. See Data Sources & Attribution Policy
OurResearch (OpenAlex)OpenAlex public scholarly API (added v1.2)Topical keywords extracted from idea content (PII-scrubbed); no Personal Information transmittedUnited States — public REST API (CC0 metadata)Read-only scholarly-record lookup when a Publication Watch scan is initiated
Cornell University (arXiv)arXiv API (added v1.2)Topical keywords extracted from idea content (PII-scrubbed); no Personal Information transmittedUnited States — public REST APIRead-only preprint lookup when a Publication Watch scan is initiated

Excluded categories. The Platform does not currently use third-party analytics, third-party identity-verification (KYC), payment processing, third-party customer-support tooling, or third-party advertising / behavioural-tracking sub-processors. If any of those is introduced, this Annex will be updated and Users notified per the change-notification mechanism above.

Annex 1.A — Episapient personnel with production access (added v1.3)

For transparency, the natural persons who hold administrative or infrastructure-level access to the production environment (AWS account 925091290713, ap-southeast-2; the production database; deploy tooling; and incident-response credentials) as of the date at the head of this Policy are:

NameRoleAccess scopeBackground-check status
Dr Ryan LivingstonDirector and founder, Episapient Pty LtdFull administrative access to the application, database, AWS console, deploy pipeline, and Episapient corporate accounts. Holds the master decryption keys for any server-side configuration secrets.Director of the Issuer.
Chandan JadhavInfrastructure / DevOps contractor to EpisapientAdministrative access to the AWS console (account 925091290713) for deploy, infrastructure configuration, and incident response. Does NOT hold passphrases for any User-encrypted (Quantum Private Mode) content; that ciphertext remains undecryptable by any Episapient personnel without the User's passphrase.Engaged under written contract with confidentiality obligations.

Both individuals are bound by the confidentiality obligations in the EpiSAP Platform Terms of Use and the agreements between them and Episapient. Access is logged at the AWS CloudTrail level and at the application audit-log level. Where technically feasible, role-based access controls and least-privilege scoping are applied; full administrative access is reserved for the named individuals above and is not granted to any other person without an updated disclosure in this Annex.

The list above is updated when the personnel set changes. Users may request the current list at any time via the Privacy contact in section 2.

Annex 2 — Cookies and Similar Technologies

The Platform uses the minimum-necessary set of cookies and browser-side storage. We do not use third-party advertising, analytics, or behavioural-tracking cookies as of the date at the head of this Policy.

Cookie / tokenCategoryPurposeProviderRetentionAttributes
sessionStrictly necessaryAuthenticated session and CSRF token state (Flask signed cookie)EpisapientSession (sliding 2-hour inactivity timeout via PERMANENT_SESSION_LIFETIME)HttpOnly; Secure; SameSite=Lax
episap_cookie_consentFunctional / consentRecords User election on the cookie consent banner so it does not re-displayEpisapientPersistent — 1 year (31,536,000 seconds)SameSite=Lax
episap-theme (browser localStorage, not an HTTP cookie)FunctionalStores light / dark mode preferenceEpisapient (client-side only)Persistent until cleared by Usern/a (client-side storage; never transmitted to the server)

Not in use. The Platform does not currently set Flask-Login remember_me cookies, third-party analytics cookies (e.g. Google Analytics), advertising-network cookies, or social-network embed cookies. The CSRF token is held inside the session cookie rather than a separate cookie. Strictly-necessary cookies are exempt from prior consent under GDPR Recital 32 / ePrivacy Directive Art 5(3) and the equivalent rule under DPDPA / IT Act 2000 / Privacy Act 1988 (Cth). Consent is recorded for the episap_cookie_consent banner action only.

Annex 3 — Version History

The current version of this Policy is recorded at the head of this document. Prior versions are retained by Episapient and made available on request. The hash of the version of the Policy accepted by each User is recorded in that User's UserConsent record at the time of Acceptance.

v1.2 changes (April 2026 — institution pilot): added two new categories to the table at section 3 (Regulatory attestations covering the Indian Patents Act s 39 soft-gate and the ICMR / health-data soft-gate; and Publication-overlap scan inputs and outputs covering the Publication Watch / Pub-Alerts feature). Added four new sub-processor entries to Annex 1 (Crossref, NCBI E-utilities, OpenAlex, and arXiv) covering the public-record APIs queried by Pub-Alerts. The full attribution and licensing basis for each of those sources is set out in the published Data Sources & Attribution Policy v1.0. No deletion or weakening of prior commitments; v1.2 is purely additive disclosure.

v1.3 changes (April 2026 — personnel access transparency): added Annex 1.A disclosing the named natural persons at Episapient who hold administrative or infrastructure-level access to the production environment. This is in response to procurement-counsel requests typical for institutional pilots and to align with DPDPA s 5 / s 6 transparency expectations. Also added a security-fix bundle (v19_57.3 deploy) that closed five data-egress paths surfaced in our internal audit. v1.3 is purely additive disclosure; no deletion or weakening of prior commitments.

Annex 4 — Hash Registry

Auto-populated by the agreement gate at deployment. The rendered HTML of this Policy is hashed (SHA-256) and recorded in each UserConsent row at the time of Acceptance, intended to support evidentiary use under section 65B of the Bharatiya Sakshya Adhiniyam 2023, section 10A of the Information Technology Act 2000, the Electronic Transactions Act 1999 (Cth), the Electronic Signatures in Global and National Commerce Act (15 U.S.C. §§ 7001 et seq.), the Uniform Electronic Transactions Act (US state-by-state), and equivalent electronic-records evidence regimes in other jurisdictions. Specific evidentiary use depends on the certificate provided by us at the time of any proceeding, which we will produce on reasonable request (Terms Annex 3).

— End of Privacy Policy v1.3 —