Terms of Use of DATAIZE

Insight on Oncology (IO) and related DATAIZE servicesLast Updated: September 4, 2026

IMPORTANT — RESEARCH USE ONLYInsight on Oncology ("IO") is an AI-enabled research environment for oncology and real-world data research. It is not a medical device and is not intended to diagnose, treat, or make patient-specific clinical decisions. AI-generated literature summaries, study designs, code, analyses, visualizations, and reports must be reviewed by qualified users before use.

These Terms of Use (the "Terms") are a legal agreement between you and Seoul Medical Informatics Intelligence Lab, Inc., doing business as DATAIZE ("DATAIZE," "we," "our," or "us"). They govern your access to and use of DATAIZE-operated websites, IO, APIs, data-processing services, research-support services, technical documentation, Tool Hub resources, and related services (collectively, the "Services").

If you use the Services on behalf of a hospital, university, research institute, company, government body, or other organization (an "Institution"), you represent that you are authorized to bind that Institution to these Terms. An Order Form, procurement contract, data processing agreement ("DPA"), business associate agreement ("BAA"), statement of work, or other signed agreement may supplement or override these Terms for the specific Services covered by that agreement.

1. Eligibility and Authorized Use

Age and capacity. You must be at least 18 years old and legally capable of entering into a binding agreement. The Services are not directed to children as account users.

Professional and institutional use. IO is intended for researchers, clinicians, statisticians, data analysts, institutional administrators, and other authorized users engaged in research, analytics, and related evidence-generation activities.

Institutional authorization. If your account or data access is provided by an Institution, your use is also subject to the Institution's policies, IRB/ethics approvals, data-use agreements, security procedures, and instructions.

Research-only scope. You may use IO for research, analytical, educational, and informational purposes within the authorized scope. You may not use IO Outputs as the sole basis for diagnosis, treatment, patient-specific clinical decisions, or other regulated clinical use unless DATAIZE expressly certifies a separate product for that use and applicable law permits it.

2. Definitions

TermMeaning
AccountA registered or institutionally provisioned DATAIZE user account.
Institutional DataData supplied, controlled, or made available by an Institution for use with the Services.
Research DataDatasets, files, notes, codebooks, source materials, and other research inputs, including structured and unstructured data.
Sensitive Medical DataMedical, clinical, genomic, laboratory, pathology, biomarker, treatment, imaging, or other health-related information, including PHI where applicable.
Submitted DataUser Content you upload, connect, enter, submit, or otherwise make available to the Services, including Research Data and Institutional Data.
User ContentPrompts, questions, instructions, notes, messages, uploaded files, selected settings, and other material you or your Institution provide.
OutputsResults produced by the Services, including literature summaries, PICO structures, study designs, cohort definitions, analysis specifications, code, tables, figures, datasets, model outputs, reports, manuscripts, and Research Result Packages.
Tool HubThe IO registry through which DATAIZE may make available validated research methods, pipelines, models, and other tools, including DATAIZE-developed and third-party/open-source tools.
De-identified DataData that has been de-identified, anonymized, or otherwise processed so that it does not identify an individual, subject to applicable law.

3. Accounts, Access, and Institutional Administration

Accurate information. You must provide accurate account information and keep it current.

Credential security. Credentials are personal to the authorized user. You must not share passwords, access tokens, or other credentials, and you are responsible for activity under your Account.

Incident reporting. Notify DATAIZE or your Institution promptly if you suspect unauthorized access, credential compromise, or a security incident.

Institutional controls. Institutions may provision, suspend, or revoke accounts and may impose additional access, export, retention, and data-handling requirements.

Feature status. Certain collaboration, sharing, notification, billing, export, audit, retention, or settings features may vary by deployment or may not be available in the current product version. A visible share or download control does not itself constitute institutional authorization to disclose or export data.

4. Description of IO and Service Availability

IO connects a research question to a staged workflow that may include literature review, study design, data profiling, cohort construction, statistical/AI/ML analysis, validation, research artifacts, manuscript support, and reporting. Depending on the deployment, IO may use a DAG-based workflow, Human-in-the-Loop (HITL) approval points, partial re-execution ("Delta" changes), and execution-history records.

Human control. Research direction, clinical definitions, analysis assumptions, and approval of major steps remain the responsibility of authorized users. IO may pause for user approval before proceeding.

Product versions. Menus, workflow stages, supported file formats, export formats, models, tools, and automation levels may differ by deployment, institution, and release. Documentation describes the referenced product version and does not guarantee that every documented feature is enabled in every environment.

Maintenance and changes. We may modify, patch, improve, replace, suspend, or discontinue features when reasonably necessary for security, reliability, legal compliance, product development, or contractual requirements. Material changes to paid institutional scope will be handled under the applicable Order Form or contract.

5. Research Responsibilities and Human Verification

IO is designed to support reproducible research, not to replace professional scientific judgment. You and your Institution remain responsible for the research protocol, data legality, methodological choices, interpretation, publication, and downstream use of Outputs.

Data authority and approvals. Use only data that you are legally and institutionally authorized to process. Obtain required IRB/ethics approvals or waivers, patient or participant authorizations where applicable, data-use permissions, and contractual rights.

Direct identifiers. Do not upload directly identifiable clinical data unless the applicable deployment, contract, approvals, and security procedures expressly permit it. Do not include patient identifiers, passwords, access tokens, or original patient data in ordinary support requests.

Methodological review. Verify population definitions, inclusion/exclusion criteria, time zero, exposure/comparator definitions, outcomes, censoring, confounders, missing-data handling, estimands, statistical assumptions, uncertainty, and robustness/sensitivity analyses.

Literature verification. Verify AI-generated citations, PMID references, PICO elements, quoted evidence, and literature summaries against the underlying source before relying on or publishing them.

Output consistency. Confirm that tables, figures, datasets, reports, and manuscripts use the intended data version, cohort, labels, and approved analysis conditions. Do not selectively omit failed nodes, non-estimable results, or material sensitivity analyses in a misleading manner.

Sharing and export. Comply with your Institution's policies for data export, publication, retention, deletion, disclosure, and external sharing. Generated Artifacts may contain intermediate or sensitive data even when the final report does not.

6. User Content, Submitted Data, and Data Rights

6.1 Ownership

As between you (or your Institution) and DATAIZE, you or your Institution retain ownership of User Content and Submitted Data, subject to the limited rights required for DATAIZE to provide the Services and any rights of third parties in source materials or datasets.

6.2 Service Operation License

You grant DATAIZE a limited, non-exclusive, worldwide, royalty-free license to host, store, process, transmit, display, transform, and otherwise use Submitted Data solely as reasonably necessary to provide, secure, support, maintain, and improve the functionality and performance of the Services for you, subject to these Terms, the Privacy Policy, and applicable contractual restrictions.

6.3 AI/ML Training Requires Separate Consent

NO DEFAULT MODEL TRAINING ON SUBMITTED DATADATAIZE will not use Submitted Data — whether identifiable, pseudonymized, or de-identified — to train or fine-tune general-purpose or DATAIZE AI/ML models, or for unrelated AI/ML research and development, unless you or your Institution provides a separate, specific, affirmative authorization or opt-in that clearly identifies the permitted purpose. Any such authorization may be withdrawn prospectively as provided in the applicable consent or agreement.

6.4 De-identified and Aggregated Data

Where permitted by law and contract, DATAIZE may use De-identified Data and aggregated usage data for service security, quality assurance, reliability, error detection, statistical analysis, benchmarking, and service optimization, provided DATAIZE does not attempt to re-identify individuals except as legally required or expressly authorized.

6.5 Submission Authority

You represent that you have the necessary rights, permissions, lawful bases, consents, waivers, and institutional approvals to submit or connect Submitted Data and to authorize the processing described in these Terms and the Privacy Policy.

7. Privacy, Sensitive Medical Data, and HIPAA

Our handling of Personal Information is described in the DATAIZE Privacy Policy. Where DATAIZE acts as a processor/service provider for Institutional Data, the Institution remains responsible for determining the lawful basis, research authorization, and permitted purpose. Where DATAIZE is a Business Associate under HIPAA and receives PHI, the parties must enter into an applicable BAA; if these Terms conflict with a duly executed BAA regarding PHI, the BAA controls.

For data-profiling and study-design workflows, IO is designed to use schema information, variable definitions, data structure, and summary information rather than patient-level values for language-model reasoning where technically and contractually configured. Other workflows, models, or tools may require access to more detailed data to perform an authorized analysis. The actual data path depends on the deployment, enabled model/tool, and institutional configuration.

8. Oncology Tool Hub and Third-Party Tools

Tool Hub may include DATAIZE-developed tools and third-party or open-source research methods, pipelines, and models. DATAIZE may standardize tool inputs/outputs, validate execution on test data, and track tool versions and validation history; however, inclusion in Tool Hub does not guarantee scientific validity for your particular study.

License conditions. You must comply with any third-party or open-source license, citation, attribution, or use restriction applicable to a selected tool or component.

Research suitability. You are responsible for confirming that the tool's intended population, input variables, outcome, validation scope, assumptions, and outputs fit your study.

External integrations. If a tool, model, API, or integration requires processing by an external provider, the applicable data flow, provider terms, and institutional approval requirements apply. Do not enable an external integration for Sensitive Medical Data unless permitted by your Institution and contract.

No endorsement. Availability, popularity, recommendation, or technical validation of a tool is not a substitute for scientific, clinical, statistical, or regulatory validation for your intended use.

9. AI Outputs, Research Artifacts, and No Medical Advice

Outputs may be probabilistic, incomplete, inaccurate, non-reproducible outside the specified environment, or affected by the quality, version, structure, and completeness of inputs. IO may generate code, call tools, execute analyses, validate shapes/types, and produce Artifacts, but no automated check eliminates the need for qualified review.

No medical device or medical practice. Unless separately certified and expressly identified by DATAIZE, the Services do not constitute a medical device, the practice of medicine, or professional medical, legal, or regulatory advice.

No sole reliance. Do not use Outputs as the sole basis for diagnosis, treatment, clinical decisions, patient communications, or regulated healthcare decisions.

Independent verification. Users remain responsible for verifying Outputs and for all decisions, publications, submissions, and actions taken in reliance on them.

No warranty of accuracy. To the maximum extent permitted by law, DATAIZE does not warrant that any Output is complete, accurate, clinically suitable, statistically valid, or fit for a particular purpose.

10. Fees, Licenses, and Professional Services

10.1 Institutional and Procurement Licenses

The standard IO procurement configuration may be offered as a one-year software license, but the actual term, price, users, compute/storage allowance, deployment environment, maintenance, training, and support scope are governed by the applicable Order Form or public procurement contract. Billing may be handled by invoice, procurement, or other contractual channels; in-app billing is not required for a valid paid license.

10.2 Professional and Data Extraction Services

DATAIZE may separately provide project-based professional services, including Clinical Data Analysis (CDA) data extraction, normalization, structuring, or preparation of analysis-ready datasets. Scope, timing, deliverables, and fees are determined project by project.

Project statusDefault refund treatment for project-based data extraction services
No extraction or execution initiatedEligible for full cancellation/refund, subject to the applicable order or payment terms.
Partially initiatedRefund, if any, is limited to the unexecuted portion; already consumed test runs, parsing, transformation, extraction, compute, or infrastructure may be charged.
Extraction completedPayment is final and non-refundable, except for payment error or Company fault as required by law or contract.
Company-caused interruptionDATAIZE will assess the affected unexecuted scope and may provide correction, re-performance, or a corresponding refund.

Changes to a purchased project scope may require re-scoping, additional fees, and written confirmation. DATAIZE is not obligated to perform work beyond the agreed scope without such confirmation. For software licenses and all other Services, the applicable Order Form or contract controls renewal, cancellation, and refund terms.

11. Intellectual Property and Output Use

11.1 DATAIZE Technology

The Services, including DATAIZE software, platform architecture, AI orchestration, user interfaces, tool wrappers, proprietary models, algorithms, documentation, trademarks, and other DATAIZE materials ("DATAIZE Content"), are owned by or licensed to DATAIZE and protected by intellectual-property laws.

11.2 Limited License

Subject to payment of applicable fees and compliance with these Terms, DATAIZE grants authorized users a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to use the Services and DATAIZE Content for the permitted internal research or institutional purposes during the applicable term.

11.3 Outputs and Exported Code

Unless an Order Form states otherwise, you may use Outputs generated for your authorized research and institutional purposes. If IO permits export of source code, settings, notebooks, or other execution materials, that export does not transfer ownership of the underlying IO platform, proprietary orchestration logic, or other DATAIZE Content. Exported materials may include or depend on third-party/open-source components that remain subject to their respective licenses.

11.4 Restrictions

  • Do not reverse engineer, decompile, or attempt to extract non-exported source code except to the extent such restriction is prohibited by law.
  • Do not resell, sublicense, publicly distribute, or commercially exploit the Services except under a written agreement with DATAIZE.
  • Do not remove copyright, attribution, trademark, license, or proprietary notices.
  • Do not use the Services or confidential DATAIZE materials to build or train a competing product or service in breach of applicable law or contract.

12. Prohibited Conduct

  • Use the Services for an unlawful, fraudulent, deceptive, or rights-infringing purpose.
  • Use IO for patient-facing diagnosis, treatment, or clinical decision-making outside an expressly authorized and legally permitted product scope.
  • Upload, connect, or disclose data without the required legal authority, consent, IRB/ethics approval, DUA, or institutional permission.
  • Upload directly identifiable clinical data into an environment not approved for such data.
  • Upload malware, malicious code, or content intended to disrupt, overload, or compromise the Services.
  • Attempt unauthorized access to accounts, systems, infrastructure, models, or data.
  • Probe or circumvent security controls, rate limits, access controls, pseudonymization, anonymization, or other safeguards.
  • Attempt to re-identify De-identified Data except where expressly authorized and lawful.
  • Misrepresent your identity, institutional affiliation, authority, research status, or approvals.
  • Use third-party tools or content in violation of their licenses, terms, or attribution requirements.

13. Security, Data Location, and Incident Response

DATAIZE uses reasonable administrative, technical, and physical safeguards appropriate to the applicable deployment and data, which may include encryption in transit and at rest, role-based access controls, infrastructure/application monitoring, vulnerability management, patching, incident-response procedures, and vendor/subprocessor risk management.

No method of transmission, storage, or software operation is completely secure. DATAIZE cannot guarantee that unauthorized access, disclosure, loss, or security incidents will never occur.

The Services may be deployed in DATAIZE-managed cloud infrastructure, a Private Cloud/VPC, or an Institution-specific environment. Data location and cross-border transfers depend on the deployment, enabled tools/models, and contract. DATAIZE will use appropriate legal safeguards for international transfers where required.

If a breach involving Personal Information or Sensitive Medical Data triggers a legal notification duty, DATAIZE will notify affected Institutions, users, or authorities as required by applicable law and the relevant contract.

14. Suspension, Termination, and Effect on Data

You may stop using the Services at any time and may request account closure subject to institutional administration and contractual obligations. DATAIZE may suspend or terminate access for breach of these Terms or the Privacy Policy, unpaid fees, security or legal risk, suspected misuse, or legal/regulatory requirements.

Unless a longer or different period is required by law, an Order Form, DPA, BAA, institutional policy, litigation hold, or legitimate dispute-protection need, DATAIZE will delete or anonymize User Content after termination or closure consistent with the applicable Privacy Policy and contract. The current general policy is to process primary User Content for deletion or anonymization within seven (7) days after confirmed termination/closure, retain limited system logs or minimal account metadata for up to thirty (30) days where needed for security or legal purposes, and allow encrypted backups to expire or be overwritten within up to ninety (90) days after primary deletion.

You are responsible for exporting any data or Outputs you are authorized and technically able to retain before closure. Institutional retention and export rules may limit what can be exported.

15. Disclaimers and Limitation of Liability

15.1 General Disclaimers

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES, DATAIZE CONTENT, AND OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, RELIABILITY, AVAILABILITY, OR CLINICAL SUITABILITY. DATAIZE DOES NOT WARRANT THAT THE SERVICES WILL BE ERROR-FREE, UNINTERRUPTED, SECURE, OR THAT ANY PARTICULAR RESEARCH RESULT WILL BE ACHIEVED.

15.2 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, DATAIZE AND ITS AFFILIATES, OFFICERS, EMPLOYEES, AND AGENTS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITIES, ARISING OUT OF OR RELATING TO THE SERVICES OR OUTPUTS, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, DATAIZE'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES WILL NOT EXCEED THE AMOUNT PAID TO DATAIZE FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY. Some jurisdictions do not permit certain exclusions or limitations, in which case the limitations apply only to the extent permitted by law.

16. Indemnification

To the extent permitted by law, you agree to indemnify, defend, and hold harmless DATAIZE and its affiliates, officers, employees, and agents from third-party claims, liabilities, losses, damages, costs, and reasonable fees arising from: (a) your violation of these Terms or the Privacy Policy; (b) your unlawful or unauthorized Submitted Data; (c) your violation of privacy, data-protection, intellectual-property, or other third-party rights; (d) your use of Sensitive Medical Data or Institutional Data without required authority; or (e) an attempt by you to re-identify De-identified Data. This obligation may be modified by an applicable institutional contract.

17. Governing Law and Dispute Resolution

These Terms and disputes arising from them or the Services are governed by the laws of the Republic of Korea, without regard to conflict-of-law principles. Unless mandatory law or a signed agreement requires otherwise, disputes that cannot be resolved amicably will be submitted to the exclusive jurisdiction of the competent courts of Seoul, Republic of Korea.

18. Miscellaneous

Entire agreement. These Terms, the Privacy Policy, and any applicable Order Form, DPA, BAA, procurement contract, consent form, statement of work, or supplemental terms constitute the agreement for the applicable Services.

Priority. A signed agreement controls over conflicting provisions of these Terms for the specific subject matter it addresses.

Amendments. We may update these Terms. Material changes will be communicated as required by law or contract. Continued use after the effective date may constitute acceptance where permitted.

Assignment. You may not assign these Terms without DATAIZE's written consent. DATAIZE may assign them in connection with a merger, acquisition, corporate reorganization, or sale of assets, subject to applicable law.

Severability and waiver. Invalid provisions will be enforced to the maximum extent permitted, and the remainder stays in effect. Failure to enforce a provision is not a waiver.

Force majeure. Neither party is liable for delay or failure caused by events beyond reasonable control, including disasters, war, government action, major cloud/internet outages, or labor disruptions, except payment obligations for Services already provided.

Independent parties. Nothing creates a partnership, joint venture, employment, fiduciary, or agency relationship between you and DATAIZE.

Third-party services. Third-party platforms, cloud providers, APIs, institutional systems, models, and tools are governed by their own terms where applicable. DATAIZE is not responsible for third-party availability or legality except as expressly assumed in a signed agreement.

Survival. Provisions that by nature should survive termination — including data rights, intellectual property, restrictions, disclaimers, liability limits, indemnification, governing law, and dispute resolution — survive termination.

Contact Information

Terms, contracts, and general inquiries: admin@dataize.io

Seoul Medical Informatics Intelligence Lab, Inc. (DATAIZE)

U.S. correspondence address: 2450 Holcombe Blvd, X+250, Houston, TX 77021, USA

Website: www.dataize.io (and other DATAIZE-operated domains where this document is linked)

Privacy and data-protection inquiries: privacy@dataize.io