PioneerBio — Privacy Policy

Version 2.0 · Effective 4 August 2026

1. Introduction

PioneerBio ("we", "us", or "our") operates the PioneerBio platform ("the Service"). This Privacy Policy explains how we collect, use, disclose and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Swedish data protection law.

2. Data controller

PioneerBio
Pierre Hakizimana, PhD, Docent
pierre.hakizimana@liu.se

We are the data controller responsible for your personal data.

3. Personal data we collect

3.1 Information you provide

  • Account information: username, email address, password (stored hashed)
  • Profile information: name, organisation, profile picture (optional)
  • Your content: images, annotations, project data and analysis results
  • Communication: messages you send us

3.2 Collected automatically

  • Server logs: the pages you request, the date and time, your IP address, and your browser and operating system
  • Sign-in records: successful and failed sign-in attempts, with the IP address and browser they came from, kept to protect accounts against unauthorised access
  • Cookies: essential cookies for authentication and preferences (§11)

We do not use analytics or tracking tools, and we do not build usage profiles.

4. Legal basis for processing

  • Contract performance — to provide the Service (Art. 6(1)(b) GDPR)
  • Legitimate interests — to improve the Service, prevent fraud and maintain security (Art. 6(1)(f) GDPR)
  • Consent — where we ask for it (Art. 6(1)(a) GDPR)
  • Legal obligation — to comply with applicable law (Art. 6(1)(c) GDPR)

5. How we use your data

  • Provide and maintain the Service
  • Process your images and annotations
  • Manage your account and authentication
  • Enable collaboration within projects
  • Send service-related notifications
  • Respond to your support requests
  • Improve the Service and our teaching materials
  • Maintain security and prevent misuse
  • Comply with legal obligations

6. Data sharing and disclosure

6.1 We do not sell your data. We never sell personal data to third parties and do not use it for advertising.

6.2 Service providers. We share data with providers who help us operate the Service — cloud hosting, database, email delivery — under data processing agreements.

6.3 Legal requirements. We may disclose data where required by law or court order, or to protect our rights and the safety of others.

6.4 Project collaboration. Content you place in a project is accessible to the other members of that project, according to their role.

6.5 Course instructors. Where you use the Service as part of a course, your instructors and the course's teaching staff may access your work for teaching, supervision, feedback and assessment. This access does not depend on you sharing your work, and it is described in the Terms of Service, §4.3.

7. Where your data is held

7.1 The Service is hosted in the European Union — Microsoft Azure, Sweden Central. Your account data, your content and our database are stored there.

7.2 Some providers acting on our behalf may process limited data outside the EU/EEA — for example email delivery and platform support. Where that happens we rely on the safeguards GDPR permits, including the European Commission's Standard Contractual Clauses.

8. Data retention

8.1 We retain your personal data while your account is active, for as long as needed to provide the Service, and for as long as the law requires.

8.2 After you delete your account we delete or anonymise your data within 90 days, except where retention is legally required.

8.3 Accounts and content created for a course may be removed after the course ends. We will give notice and an opportunity to export your work first, as set out in the Terms of Service, §4.6.

9. Your rights

You have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct data that is inaccurate or incomplete
  • Erasure — request deletion of your data
  • Restriction — limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent
  • Complain — to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se) or your local supervisory authority

To exercise any of these, contact us at pierre.hakizimana@liu.se. We will respond within one month.

10. Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS/TLS) and at rest, access controls and authentication, regular updates, and backup and recovery procedures.

11. Cookies

11.1 We use cookies that are necessary for authentication, security and basic functionality.

11.2 You can manage cookies through your browser settings. Blocking essential cookies will prevent you from signing in.

12. Children

The Service is not intended for people under 16, and we do not knowingly collect personal data from children. If we become aware that we have, we will delete it.

13. Changes to this policy

We may update this Privacy Policy. The version and date at the top will change, and we will notify registered users of significant changes by email or through the Service.

14. Contact

PioneerBio
Pierre Hakizimana, PhD, Docent
Linköping University
pierre.hakizimana@liu.se

Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten): https://www.imy.se