DATAIZE Privacy Policy
For DATAIZE websites, Insight on Oncology (IO), and related servicesLast Updated: September 4, 2026Seoul Medical Informatics Intelligence Lab, Inc. ("DATAIZE," "we," "our," or "us") respects the privacy of visitors, account users, institutional users, researchers, and other individuals whose Personal Information is processed through the Services. This Privacy Policy explains what we collect, how we use and disclose it, how we protect and retain it, and the rights available to you.
This Policy applies to DATAIZE-operated websites and domains, including www.dataize.io and other DATAIZE domains where this Policy is linked, as well as IO, web applications, APIs, research-support services, and related online services (collectively, the "Services"). It does not override an applicable Order Form, DPA, BAA, institutional privacy notice, research consent, or other agreement that lawfully governs a specific dataset or deployment.
IMPORTANT FOR CLINICAL AND RESEARCH DATAIO is a Research Use Only (RUO) environment. Account users must be adults, but authorized Institutional Data may include data about minors or other patients where the Institution has a valid legal basis and required approvals. Do not upload directly identifiable clinical data unless your deployment and institutional procedures expressly permit it.
1. Our Role: Controller vs. Processor
DATAIZE may process different categories of information in different legal roles:
Account, website, billing, and support information. DATAIZE generally determines the purposes and means of processing this information and acts as a controller/business for its own operations.
Institutional and research data. When an Institution provides or controls Research Data, clinical data, PHI, or other Institutional Data for use in IO, the Institution generally determines the research purpose, lawful basis, access rules, and retention instructions. DATAIZE acts as a processor/service provider or Business Associate where applicable and processes the data under the Institution's instructions and contract.
BAA/DPA priority. If a duly executed BAA, DPA, research agreement, or procurement contract imposes more specific privacy or security requirements, that agreement controls for the relevant data and Services.
2. Information We Collect
| Category | Examples |
|---|---|
| Account and identifiers | Name, email address, phone number, organization, role, account ID, login information, and account status. |
| Institutional/professional information | Institution, department, professional role, procurement or contract contact information, and administrator assignments. |
| Commercial and transaction information | Order, invoice, payment status, subscription/license term, procurement and transaction records. In-app billing may not be enabled in all deployments. |
| Device and network information | IP address, browser, operating system, device identifiers, timestamps, authentication/security events, and technical usage data. |
| Usage and interaction data | Notes/projects accessed, workflow stages, selected model or tool, feature interactions, errors, support events, and other telemetry reasonably needed to operate and secure the Services. |
| Research prompts and project content | Research questions, prompts, messages, selected topics, study-design inputs, Note titles, instructions, source metadata, and user-entered research context. |
| Research Data and Submitted Data | Datasets, structured or unstructured files, codebooks, institutional data sources, cohort data, intermediate datasets, variables, schemas, and artifacts connected to or uploaded into authorized deployments. |
| Sensitive Medical Data / PHI | Clinical, medical, genomic, pathology, biomarker, imaging, treatment, laboratory, or other health-related data, including PHI where applicable. Processing is limited to authorized deployments and purposes. |
| Outputs and research artifacts | Literature summaries, PICO structures, designs, analysis specifications, generated/executed code, tables, figures, datasets, reports, manuscripts, workflow history, tool versions, and validation history. |
| Location and preferences | Approximate or precise location only when a feature is enabled and permitted; language, theme, model, and workflow preferences where available. |
| Support information | Problem descriptions, screenshots, Note name, error messages, environment and dataset version identifiers. Support requests should exclude patient identifiers, original patient data, passwords, and access tokens. |
3. Sources of Information
Directly from you. When you create an account, submit a research question, upload or connect data, select tools/models, contact support, or enter into a transaction.
From your Institution. When an authorized hospital, university, laboratory, company, public agency, or research organization provisions your account, configures your deployment, or provides Institutional Data.
Automatically from your device and use of the Services. Through logs, cookies, authentication systems, and similar technical mechanisms used for operation, security, and analytics.
From service providers and integrations. Cloud infrastructure, identity providers, communications vendors, payment or billing providers, AI/model providers enabled for the deployment, and other contracted service providers.
From public or licensed research sources. For example, bibliographic metadata and abstracts returned through authorized literature-search integrations such as PubMed, and metadata about research tools or models.
4. How We Use Information
Provide and operate the Services. Authenticate users; create and manage Notes; connect authorized sources; profile data; build and execute workflows; call permitted tools/models; generate, validate, store, display, and export Artifacts; and provide institutional administration.
Support reproducible research. Record approved research conditions, workflow state, changes, tool/model versions, and generated results where the deployment supports those functions.
Security and reliability. Detect unauthorized access, investigate errors, monitor performance, prevent abuse, patch vulnerabilities, respond to incidents, and maintain continuity.
Customer support and maintenance. Respond to questions, troubleshoot errors, provide updates, patches, training, and maintenance under the applicable contract.
Billing and contract administration. Process orders, invoices, procurement, license terms, and payment records where applicable.
Analytics and product improvement. Understand feature performance and usage, improve usability and reliability, and evaluate research workflows using aggregated or appropriately de-identified information where permitted.
Communications and marketing. Send service notices, security alerts, support communications, and — where permitted — marketing communications. You may opt out of non-essential marketing.
Legal compliance. Comply with law, enforce agreements, protect rights and safety, respond to lawful requests, and maintain records required by regulation or contract.
5. AI, Language Models, and Model Training
5.1 Patient-level Data Minimization in Language-Model Workflows
IO is designed so that, for data-profiling and study-design workflows, language-model reasoning ordinarily uses variable definitions, schema/data-structure information, code systems, units, missingness, measurement timing, and other summary information rather than patient-level values, where technically and contractually configured. Other authorized analysis steps may require more detailed data to execute statistical or computational tasks. The actual data path depends on the workflow, selected model/tool, and deployment.
5.2 Third-Party AI/Model Providers
Some deployments may allow selection or use of third-party AI/model providers. If enabled, prompts, metadata, permitted content, or other information necessary for inference may be transmitted to that provider under DATAIZE's contract and the Institution's deployment settings. The specific provider and data path may vary by environment. Sensitive Medical Data should not be sent to an external model provider unless the applicable Institution, contract, and law authorize that processing.
5.3 No Default Training on Submitted Data
Submitted Data is not used for model training by defaultDATAIZE will not use Submitted Data — including identifiable, pseudonymized, or de-identified Institutional or clinical data — to train or fine-tune general-purpose or DATAIZE AI/ML models, or for unrelated AI/ML research and development, unless you or your Institution gives a separate, specific, affirmative authorization or opt-in for that purpose.
6. Tool Hub, Third-Party Tools, and External Integrations
IO may provide a Tool Hub containing DATAIZE-developed and third-party/open-source methods, pipelines, and models. DATAIZE may validate tool execution and standardize inputs/outputs, but the tool's license and technical architecture may affect how data is processed.
Where a Tool Hub tool executes inside the authorized IO environment, data may remain within that environment subject to its configuration.
Where an external API, model, cloud service, or tool is enabled, information necessary for that integration may be disclosed to the external provider as authorized by contract and institutional settings.
We encourage Institutions to review tool/model licenses, validation scope, data-flow requirements, and subprocessors before enabling use with Sensitive Medical Data.
7. How We Disclose Information
Service providers and subprocessors. We may disclose information to vendors that provide cloud hosting, security, communications, support, analytics, payment/billing, AI/model inference, or other services on our behalf, subject to contractual confidentiality and data-protection obligations. The exact providers vary by deployment; AWS is among the cloud providers used by DATAIZE in certain environments.
Your Institution and its administrators. Institutional administrators may access account information, usage information, project metadata, and data necessary to administer the authorized deployment, subject to the Institution's policies and contract.
Integrations selected or authorized by you or your Institution. Information may be disclosed to a third-party tool, model, API, identity provider, storage environment, or institutional system when you or your Institution enables that integration.
Corporate transactions. Information may be transferred in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable privacy obligations.
Legal and safety reasons. We may disclose information when required by law or when reasonably necessary to protect rights, safety, security, investigate fraud, or enforce our agreements.
With consent or instruction. We may disclose information for additional purposes when you or your Institution provides valid consent or instructions.
DATAIZE does not sell Submitted Data or Sensitive Medical Data. DATAIZE does not use Sensitive Medical Data for advertising or cross-context behavioral advertising unless a separate legally valid authorization expressly permits that use.
8. De-identified and Aggregated Information
Where permitted by law and contract, we may de-identify or aggregate information and use it for security, statistical analysis, quality assurance, reliability, error detection, benchmarking of analytical workflows, and service optimization. We do not attempt to re-identify De-identified Data except where legally required or expressly authorized. De-identification does not reduce protections where applicable law continues to treat the data as regulated.
9. Data Retention, Deletion, and Backups
Retention depends on the data category, deployment, contract, institutional policy, research requirements, legal obligations, and the purpose for which the information was collected. Institutional instructions and an applicable DPA/BAA may set different periods.
| Data category | General retention approach |
|---|---|
| Submitted Data / User Content | Retained while needed to provide the authorized Services or as directed by the Institution. After confirmed account/contract termination or closure, the current general policy is to process primary User Content for deletion or anonymization within 7 days, unless a longer/different period is required by law, contract, DPA/BAA, institutional policy, dispute protection, or legal hold. |
| System/security logs and minimal account metadata | May be retained for up to 30 days after termination/closure where needed for security, troubleshooting, legal, or compliance purposes, unless another period applies. |
| Backups | Encrypted backup copies may persist for continuity/disaster recovery and are expected to expire or be securely overwritten within up to 90 days after primary data deletion, unless a longer period is legally required. |
| Billing/contract records | Retained as required for contractual, accounting, tax, procurement, and legal obligations. |
| De-identified/aggregated information | May be retained for permitted security, quality, statistical, or service-optimization purposes, subject to applicable law and contract. |
Deletion from a user-facing interface may not immediately delete backup copies or legally required records. Where product UI deletion/retention controls are limited, DATAIZE and the Institution may process requests through administrative procedures or institutional SOPs.
10. Security and Breach Response
We use reasonable administrative, technical, and physical safeguards appropriate to the data and deployment. Measures may include encryption in transit and at rest, access control and role-based permissions, infrastructure/application monitoring and security logging, vulnerability management, patching, incident response, and vendor/subprocessor assessments.
No security measure is absolute. If a security breach involving Personal Information or Sensitive Medical Data triggers a legal or contractual notification duty, DATAIZE will notify affected Institutions, individuals, or authorities as required by applicable law and agreement.
Users should not send patient identifiers, raw patient data, passwords, access tokens, or other secrets through ordinary support channels. Product screenshots or support records should be minimized to the information necessary to diagnose the issue.
11. International and Cross-Border Transfers
DATAIZE is headquartered in the Republic of Korea and may use infrastructure, vendors, or service providers in other jurisdictions, including the United States, depending on the deployment and enabled services. Cross-border transfer of Personal Information is performed only where permitted by applicable law and contract. Where required, DATAIZE uses appropriate safeguards such as contractual protections, Standard Contractual Clauses, access controls, and encryption.
For Korean Personal Information subject to PIPA, where a cross-border transfer requires a separate notice or consent, DATAIZE or the applicable Institution will provide the legally required information about the recipient, country, purpose, transfer method/timing, retention period, and available rights or refusal consequences through the applicable notice, consent, DPA, or procurement documentation.
12. Your Privacy Rights
Depending on where you live and the role in which DATAIZE processes your information, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, or receive a portable copy of certain Personal Information. Institutional users may need to submit requests through their Institution when the Institution controls the data.
Access and confirmation. Request information about whether and how we process your Personal Information.
Correction. Request correction of inaccurate or incomplete Personal Information.
Deletion. Request deletion where applicable, subject to legal, contractual, research, backup, and institutional retention requirements.
Restriction or suspension. Request restriction or suspension of certain processing where applicable.
Objection and marketing opt-out. Object to certain processing based on legitimate interests and opt out of non-essential direct marketing.
Portability. Where applicable, request Personal Information in a structured, commonly used, machine-readable format.
Withdraw consent. Where processing is based on consent, withdraw it prospectively. Withdrawal does not affect processing lawfully completed before withdrawal.
To exercise applicable rights, contact privacy@dataize.io. We may need to verify your identity and authority. If the data is controlled by an Institution, we may direct the request to that Institution.
13. Additional Information for Specific Jurisdictions
13.1 Republic of Korea
For Personal Information subject to the Personal Information Protection Act (PIPA), DATAIZE processes Personal Information on a lawful basis, provides required notices/consents, applies safeguards, and supports applicable rights to access, correction, deletion, and suspension. Where processing is entrusted to service providers or transferred overseas, legally required disclosures or contractual measures will be provided through the relevant notice, consent, DPA, procurement documentation, or subprocessor information.
13.2 European Economic Area / United Kingdom
Where GDPR or UK GDPR applies, DATAIZE processes Personal Information on one or more lawful bases, including performance of a contract, legitimate interests, consent, and compliance with legal obligations. Where DATAIZE acts as a processor, the applicable Institution or customer is generally responsible for the lawful basis for Institutional Data. International transfers are protected through recognized safeguards where required. Individuals may also have the right to complain to a competent supervisory authority.
13.3 California
Where the California Consumer Privacy Act/California Privacy Rights Act applies, California residents may have rights to know/access, delete, correct, and opt out of certain sale or sharing, and to limit certain uses of sensitive personal information. DATAIZE does not sell Submitted Data or Sensitive Medical Data. To submit a request, contact privacy@dataize.io. We do not discriminate against individuals for exercising applicable privacy rights.
13.4 Washington, Nevada, and Other Consumer Health Laws
Where a U.S. state consumer-health privacy law applies to data that is not otherwise exempt or governed by HIPAA or institutional research exceptions, DATAIZE or the applicable Institution may provide a supplemental Consumer Health Privacy Notice describing the required categories, purposes, disclosures, and rights.
14. Children's Privacy
The Services are not intended for individuals under 18 to create or operate Accounts. We do not knowingly solicit account registration from children. Institutional Research Data may lawfully include information about minors where the Institution has the required legal basis, consent/authorization, IRB/ethics approval or waiver, and other protections. Such data is treated according to the applicable contract and law.
15. Cookies and Similar Technologies
DATAIZE websites and online Services may use cookies, local storage, and similar technologies for authentication, security, preferences, performance, and analytics. Where required by law, we provide consent choices for non-essential cookies. You can also control cookies through your browser, although disabling essential cookies may prevent certain Services from functioning.
16. Changes to This Policy
We may update this Policy as the Services, deployment models, vendors, or legal requirements change. We will post the updated date and provide additional notice of material changes where required by law or contract. We encourage you to review this Policy periodically.
Contact Information
Privacy and Data Protection inquiries: privacy@dataize.io
Seoul Medical Informatics Intelligence Lab, Inc. (DATAIZE)
U.S. correspondence address: 2450 Holcombe Blvd, X+250, Houston, TX 77021, USA
Website: www.dataize.io (and other DATAIZE-operated domains where this document is linked)
General support and administrative inquiries: admin@dataize.io