IPROCESS PRIVACY POLICY
Last updated: September 14, 2026
1. INTRODUCTION
This Privacy Policy explains how iProcess Global Research Inc. ("iProcess," "we," "our," or "us") collects, uses, discloses, retains, and protects personal data in connection with the research operations platform and laboratory-services marketplace that iProcess makes available at axisone.ai and its subdomains ("AxisOne").
This Policy applies to personal data we receive through AxisOne and its modules, our public websites, account registration, communications, events, surveys, waitlists, referral programs, beta testing, and information provided by a customer, employer, institution, marketplace participant, or other authorized third party.
This Policy does not govern a third-party website or service that merely links to or from AxisOne. Information about a corporation or other legal entity is generally not personal data, although information about its employees, representatives, investigators, experts, laboratory personnel, or other individuals may be.
Capitalized terms not defined in this Policy have the meanings given in the applicable terms or agreement governing your use of AxisOne.
2. WHO WE ARE AND OUR PRIVACY ROLES
iProcess Global Research Inc. is a Texas corporation located at 7301 N State Highway 161, Suite 136, Irving, Texas 75039, USA. Our privacy contact is privacy@axisone.ai.
iProcess as controller. We act as a controller or business when we determine the purposes and means of processing personal data, including for account administration, authentication, billing, AxisOne security, marketplace administration, compliance, marketing, and our own business operations.
iProcess as processor or service provider. When we process personal data contained in Customer Data solely on behalf of an institutional customer and subject to that customer's instructions, we act as that customer's processor or service provider. The applicable customer agreement or data processing agreement governs that processing and controls to the extent it conflicts with this Policy.
Customer-directed processing. An institutional customer determines which users may access its Workspace and which Customer Data is submitted, shared with collaborators, or disclosed to marketplace participants. If your personal data was submitted by or on behalf of an institutional customer, that customer may be the appropriate party to address your privacy request. We will assist the customer as required by applicable law and our agreement with the customer.
Independent marketplace participants. Laboratories, suppliers, researchers, experts, and other counterparties may act as independent controllers for personal data they receive to evaluate, enter into, or perform a transaction. Requester or provider identity may be masked before an applicable matching or contracting milestone, as described in AxisOne.
3. PERSONAL DATA WE COLLECT
The personal data we collect depends on the features you use, your relationship with us, your settings, and your location.
3.1. Information You Provide
- Account and profile information. Name, business email address, telephone number, job title, role, organization, organization type, country, professional biography, expertise, profile image, and account preferences. iProcess uses Clerk to provide authentication for AxisOne. Authentication credentials and authentication factors are handled by Clerk; iProcess receives provider identifiers, profile information, authorization attributes, and session-related claims needed to operate AxisOne.
- Laboratory and supplier information. Contact details, facility address, certifications, accreditations, capabilities, equipment, capacity, quality documents, compliance information, payout-onboarding status, and information about authorized representatives or beneficial owners where required.
- Customer Data and Research Content. Protocols, study designs, methods, prompts, project context, manuscripts, abstracts, figures, presentations, recordings or transcripts you choose to include, grant materials, requests for quote, scopes of work, expert-review materials, and generated outputs. These materials may contain personal data if you include names, contact details, or other information relating to an individual.
- Transaction information. Requests, proposals, quotes, orders, Statements of Work, milestones, shipping records, project records, invoices, purchase orders, disputes, and marketplace correspondence.
- Payment and payout information. Stripe and Stripe Connect process payment-card, bank, identity-verification, and payout information. iProcess does not intentionally store full payment-card or bank-account numbers. We may receive customer, account, transaction, billing, card-brand, last-four-digits, country, tax, payout-status, and fraud-prevention information from Stripe.
- Communications. Support requests, feedback, survey responses, interview or beta-program information, marketing preferences, email and SMS communications, and consent records.
- Calls and working sessions. Participant details, scheduling information, attendance, chat, and, where the feature clearly indicates that recording is enabled, audio, video, recordings, or transcripts.
- Shipping information. Sender and recipient names, laboratory and researcher contact information, origin and destination addresses, package dimensions and weight, carrier selections, tracking information, and limited project or specimen-shipment metadata needed to obtain labels and coordinate delivery.
3.2. Information Collected Automatically
- Device and network data. IP address, browser and device type, operating system, language, time zone, referring page, requested URLs, and diagnostic information.
- AxisOne activity and security data. Authentication events, pages and features used, timestamps, credit consumption, AI generation and simulation histories, document and Statement of Work revisions, milestone approvals, payment events, access history, error records, audit events, and security logs.
- Browser storage. Local storage and session storage used for functional purposes such as theme preferences, onboarding drafts, navigation state, workflow handoffs, temporary public-check tokens, and post-authentication redirects. Some locally stored drafts expire automatically; other preferences remain until cleared by you or your browser.
- Cookies and similar technologies. Authentication and hosting providers may use cookies or similar technologies necessary for authentication, session security, fraud prevention, and essential operation of AxisOne. We do not currently use our own advertising pixels or session-replay technology. If we introduce non-essential analytics or advertising technologies, we will provide any notice and choice required by applicable law.
3.3. Information From Other Sources
- Your employer, institution, customer, laboratory, supplier, expert, collaborator, or marketplace counterparty.
- Public professional profiles, institutional websites, publication and grant databases, clinical-trial registries, government records, sanctions lists, and other public sources.
- Professional-profile enrichment providers when you ask to import or enrich a profile.
- Compliance, sanctions-screening, fraud-prevention, payment, and identity-verification providers.
- Event, referral, co-marketing, and business partners that are authorized to provide the information.
4. RESTRICTED DATA
Do not submit Protected Health Information ("PHI") or identifiable patient, research-subject, donor, or specimen-linked clinical information to AxisOne unless iProcess has expressly agreed in a separate written agreement to process that information and the parties have implemented the required contractual, technical, and organizational safeguards.
Unless expressly approved in writing, do not submit personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; genetic data; biometric data used to uniquely identify an individual; health information relating to an identifiable individual; information concerning an individual's sex life or sexual orientation; precise geolocation; government identification numbers; or criminal-conviction or offense information (collectively, "Restricted Data").
Information that has been anonymized so that it no longer relates to an identifiable individual is not Restricted Data for purposes of this Policy. If Restricted Data is submitted without an applicable written arrangement, we may restrict access to or delete it. Contact privacy@axisone.ai before submitting information that may fall within these categories.
5. AI AND AUTOMATED PROCESSING
AxisOne includes AI-assisted features for functions such as protocol generation and refinement, protocol parsing and readiness analysis, research brainstorming, virtual simulations, laboratory matching, draft Statements of Work, expert-review workflows, publication and regulatory assistance, grant and venue matching, professional-profile assistance, and dissemination materials.
Third-party AI processing. Depending on the feature you affirmatively use, relevant prompts, protocol or project text, manuscript or dissemination content, conversation history, selected transcripts, references, public professional information, and requested output instructions may be transmitted to OpenAI, Anthropic, Gamma, or another AI provider identified in the applicable workflow or our subprocessor disclosures. We limit the information transmitted to what is reasonably necessary to provide the requested functionality.
AI training. Unless a customer expressly authorizes it in writing, iProcess does not use identifiable Customer Data or customer-specific Confidential Information to train publicly available or third-party artificial intelligence models. We use commercially reasonable service configurations and contractual protections intended to prohibit third-party AI providers from using Customer Data to train their models without authorization. A provider may retain limited information for security, abuse prevention, billing, or legal compliance as permitted by the applicable service configuration and contract.
Internal improvement. iProcess may use Usage Data, Aggregated Data, and anonymized Protocols that cannot reasonably identify a customer, User, or individual to operate, secure, analyze, develop, test, evaluate, and improve AxisOne and iProcess's proprietary AI Services and machine-learning technologies.
Human review and responsibility. AI Outputs may be incomplete, inaccurate, outdated, inconsistent, or biased. They are decision-support tools and do not constitute scientific, medical, regulatory, legal, or other professional advice. Users must independently review and validate AI Outputs before use.
Automated outputs. AxisOne may generate readiness scores, match scores, ranked laboratory shortlists, screening indicators, and other automated outputs. These outputs are generally advisory and are not intended to make a decision based solely on automated processing that produces legal or similarly significant effects on an individual. Potential sanctions or compliance matches are not treated as conclusive without human review. Where required by law, you may request information about, correction of information used in, or human review of an automated outcome by contacting privacy@axisone.ai.
6. HOW WE USE PERSONAL DATA
We use personal data to:
- create, authenticate, administer, and secure accounts and Workspaces;
- provide, personalize, maintain, support, and troubleshoot AxisOne;
- process Customer Data and generate the AI Outputs and other results requested by Users;
- operate matching, contracting, marketplace, expert-review, payment, payout, shipping, and fulfillment workflows;
- schedule and provide calls, working sessions, notifications, email, and SMS where enabled;
- conduct sanctions, export-control, fraud, identity, and compliance screening;
- provide support, collect feedback, and communicate service, security, billing, and policy notices;
- operate referral, event, waitlist, and beta programs;
- measure use of AxisOne and improve its performance, reliability, accessibility, and security;
- develop and evaluate AxisOne using Aggregated Data and anonymized information as described in Section 5;
- market our services where permitted and honor communication choices;
- comply with legal, tax, accounting, audit, regulatory, and contractual obligations; and
- establish, exercise, or defend legal claims and enforce our agreements.
We do not sell personal data or share personal data for cross-context behavioral advertising, as those terms are defined by applicable U.S. state privacy laws. We also do not use or disclose sensitive personal information for purposes that require a right to limit under California law.
7. LEGAL BASES FOR EEA UK AND SWISS DATA
Where applicable, we rely on one or more of the following legal bases:
Purpose | Legal basis |
|---|---|
Accounts, AxisOne services, requested AI features, transactions, support, calls, and shipping | Performance of a contract; steps requested before a contract; legitimate interests in serving organizational customers |
Security, fraud prevention, auditing, service improvement, and essential analytics | Legitimate interests; legal obligation where applicable |
Sanctions, identity, and compliance screening | Legal obligation; legitimate interests in preventing unlawful or fraudulent transactions |
Payment, tax, accounting, and recordkeeping | Performance of a contract; legal obligation |
Business-to-business marketing | Legitimate interests, or consent where required |
Non-essential cookies or analytics | Consent where required |
Testimonials or identifiable promotional materials | Consent |
Disputes and legal claims | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we consider the nature of the data, the reasonable expectations of affected individuals, and available safeguards. You may object to processing based on legitimate interests as described in Section 13. You may withdraw consent at any time where consent is the legal basis, without affecting processing that occurred before withdrawal.
8. HOW WE DISCLOSE PERSONAL DATA
8.1. Within iProcess
We disclose personal data to personnel, contractors, advisors, and affiliated entities that need it to operate AxisOne, serve customers, meet legal obligations, or support business operations, subject to appropriate confidentiality and access restrictions.
8.2. Customer Organizations and Marketplace Participants
We disclose personal data to the institution that manages your account and to laboratories, research customers, experts, collaborators, suppliers, and other counterparties as directed by the applicable customer or as reasonably necessary to evaluate, enter into, administer, or perform a transaction. This may include identity and business-contact information, the relevant request or scope, Statements of Work and other contractual records, communications, project information, payment status, and shipping details. Pre-contract identity masking may apply to particular workflows. Once personal data is provided to an independent marketplace participant for its own evaluation or performance, that participant is responsible for its own privacy obligations.
8.3. Service Providers
We disclose personal data to service providers that process information on our behalf to provide hosting, storage, authentication, AI functionality, payments, communications, video calls, shipping, professional-profile enrichment, public-web research, security, screening, and related operational services. A provider receives information only when its service is configured and the relevant feature is used.
8.4. Legal Safety and Business Disclosures
We may disclose personal data to comply with law or lawful process; protect the rights, safety, or property of Users, iProcess, or others; investigate fraud, abuse, or security events; enforce agreements; or establish, exercise, or defend legal claims. Personal data may also transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and continued protection.
9. KEY SERVICE PROVIDERS
The following providers support AxisOne functions. Some providers are engaged directly by iProcess and others may act as subprocessors of another provider. Additional subprocessors may be identified in an applicable customer agreement, data processing agreement, or subprocessor list.
Provider | Purpose and information involved |
|---|---|
Replit and Google Cloud | Application hosting, deployment, runtime infrastructure, databases or storage, operational logging, usage analytics, and AI-integration transport. |
Clerk | Authentication, account security, sessions, social sign-in where enabled, and identity attributes. |
OpenAI | Approved AI generation, parsing, transcription where enabled, and embeddings. Inputs may include prompts, opted-in protocol or project text, structured content, or audio needed for a requested feature. |
Anthropic | AI-assisted protocol, brainstorming, review, dissemination, and professional-profile workflows. Inputs may include prompts, research text, conversation context, references, selected transcripts, or public professional information. |
Gamma | Optional presentation generation. When selected by a User, dissemination-package content needed for the presentation is transmitted to Gamma, which may host the resulting presentation. |
Stripe and Stripe Connect | Payment processing, subscriptions, invoices, marketplace or milestone payments, identity and payout onboarding, transfers, refunds, disputes, tax-related information, and fraud prevention. |
Resend | Transactional and service email, including recipient address, subject line, message content, and delivery metadata. |
Twilio | SMS notifications and inbound SMS replies where a User provides a telephone number and the feature is enabled. |
Daily.co | Video-call rooms, participant identity, and attendance and, only where recording is enabled and disclosed, audio, video, recordings, or transcripts. |
EasyPost | Shipping rates, labels, tracking, and delivery coordination, including sender and recipient details, addresses, package information, carrier selections, and limited shipment context. |
OpenSanctions | Sanctions, politically exposed person, watchlist, and compliance screening using normalized person or entity identifiers. Potential matches are subject to human review. |
ContactOut and Parallel Web Systems | Optional professional-profile enrichment and public-web research. Information may include a public profile URL, search objective, query, public URL, or professional contact and employment information. |
Public databases and registries, such as PubMed, Europe PMC, ClinicalTrials.gov, government grant systems, and government screening lists, may receive search terms or record identifiers when AxisOne retrieves public information. A query may reveal a research interest even though these sources generally provide public information rather than process customer accounts maintained through AxisOne.
10. INTERNATIONAL DATA TRANSFERS
iProcess serves customers and works with service providers and marketplace participants in multiple countries. Personal data may be processed in the United States and other countries where iProcess, our customers, marketplace participants, or service providers operate. Those countries may have privacy laws that differ from the laws where you live.
Where required for transfers from the EEA, United Kingdom, or Switzerland, we use a lawful transfer mechanism, which may include an adequacy decision, the European Commission Standard Contractual Clauses, the United Kingdom Addendum or International Data Transfer Agreement, a Swiss adaptation, or another mechanism permitted by applicable law. We also implement supplementary measures where appropriate. You may request information about applicable safeguards by contacting privacy@axisone.ai.
11. DATA RETENTION
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide AxisOne, honor customer instructions, meet contractual commitments, maintain security and audit records, comply with law, resolve disputes, and enforce agreements. We determine the applicable period based on the nature and sensitivity of the information, the purposes for processing it, customer instructions, legal and contractual requirements, security needs, and applicable limitation periods.
Category | Retention period or criteria |
|---|---|
Account and profile information | For the duration of the account or customer relationship and for a reasonable period afterward for wind-down, security, support, legal, and backup purposes. |
Customer Data and AI Outputs | According to account controls, customer instructions, deletion requests, and the applicable customer agreement or data processing agreement. Third-party provider copies may be subject to shorter operational, security, or abuse-monitoring periods. |
Marketplace, payment, payout, invoice, tax, and shipping records | For the period required by tax, accounting, anti-fraud, sanctions, financial-services, and commercial-recordkeeping laws, which is commonly seven years for core transaction records. |
Compliance and sanctions records | For the period needed to document the screening decision and satisfy applicable sanctions, export-control, audit, fraud-prevention, or legal obligations. |
Communications, support, and call records | For the period reasonably necessary to provide support, administer the applicable workflow, document consent, resolve disputes, and satisfy legal obligations. Recordings and transcripts are retained according to the applicable workflow and customer agreement. |
Security, access, application, and audit logs | For limited periods determined by security need, hosting configuration, contractual commitments, and legal requirements. |
Backups | Until overwritten or isolated from ordinary use under the applicable backup cycle, subject to legal holds and security requirements. |
We may retain information longer when required by law, subject to a legal hold, or needed to establish, exercise, or defend legal claims. We may retain Aggregated Data or anonymized information that can no longer reasonably identify a customer, User, or individual.
12. SECURITY
We use administrative, technical, organizational, and physical safeguards designed to protect personal data, including encryption in transit, encryption at rest through our infrastructure providers, role-based and owner-scoped access controls, environment and credential separation, audit and security logging, vendor review, incident-response procedures, and confidentiality obligations.
Private files are subject to authorization and ownership checks. iProcess also applies feature-specific controls intended to limit disclosure of private Customer Data to external AI providers. No system is completely secure. You are responsible for protecting your credentials and devices and for promptly reporting suspected unauthorized access to security@axisone.ai.
13. YOUR PRIVACY RIGHTS
Depending on your location and subject to legal exceptions, you may have rights to access or obtain a copy of personal data; correct inaccurate personal data; delete personal data; restrict or object to processing; obtain portable data; withdraw consent; opt out of marketing, sale, targeted advertising, or certain profiling; limit specified uses of sensitive personal information; appeal a denied request; and obtain information about automated decision-making. We will not discriminate against you for exercising an applicable privacy right.
Submitting a request. Email privacy@axisone.ai or write to the address in Section 18. Describe the right you wish to exercise and the personal data or account involved. We may request information reasonably necessary to verify your identity, authority, and account ownership. An authorized agent may submit a request where permitted by law, subject to verification of the agent's authority and, where allowed, verification directly with you.
Customer-controlled data. If we process the relevant personal data as a processor or service provider for an institutional customer, we may refer your request to that customer and assist it in responding.
Response and appeal. We will respond within the period required by applicable law, generally one month under EEA and UK law and 45 days under many U.S. state laws, subject to permitted extensions. If we deny a request and applicable law provides an appeal right, you may appeal by emailing privacy@axisone.ai with the subject line "Privacy Appeal". We will respond to the appeal within the period required by applicable law and, if the appeal is denied, provide information about how to contact the appropriate state attorney general or other regulator where required.
Complaints. Residents of the EEA, United Kingdom, or Switzerland may complain to the supervisory authority where they live or work or where they believe a violation occurred. United Kingdom residents may contact the Information Commissioner's Office at ico.org.uk.
14. CALIFORNIA PRIVACY NOTICE
If the California Consumer Privacy Act applies to iProcess's processing of your personal information, this section supplements the other disclosures in this Policy. During the preceding 12 months, we may have collected the following statutory categories of personal information, depending on the features used: identifiers; customer-record information; commercial information; internet or other electronic-network activity; professional or employment-related information; audio, electronic, visual, or similar information; inferences drawn from other personal information; and sensitive personal information such as account log-in credentials and payment or identity-verification information handled primarily by our authentication and payment providers.
We collect those categories from the sources described in Section 3, use them for the purposes described in Sections 5 and 6, disclose them to the categories of recipients described in Sections 8 and 9, and retain them according to Section 11. We may disclose each applicable category to service providers and contractors for the business purposes described in this Policy and, when directed or necessary for a transaction, to customer organizations and marketplace participants.
We have not sold personal information or shared personal information for cross-context behavioral advertising during the preceding 12 months. We do not knowingly sell or share the personal information of individuals under 16. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law. California residents may exercise applicable rights using the methods described in Section 13.
15. MARKETING COOKIES AND BROWSER CHOICES
You may unsubscribe from marketing email using the link in the message or by contacting us. Marketing choices do not prevent service, security, transaction, billing, or legal notices. SMS marketing, if offered, will be subject to separate consent and opt-out controls.
Because we do not currently sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising, a browser-based opt-out preference signal does not presently change how we process personal data. If our practices change, we will update this Policy and recognize legally required opt-out preference signals. Some browsers also offer a "Do Not Track" setting. There is no uniform industry standard for those signals, and AxisOne does not currently respond to them separately from the choices described in this Policy.
16. CHILDREN
AxisOne is intended for professional and institutional users and is not directed to individuals under 18. We do not knowingly collect personal data from children. Contact privacy@axisone.ai if you believe a child has submitted personal data.
17. THIRD PARTY SERVICES
AxisOne may link to or open services operated by laboratories, journals, funders, payment providers, presentation providers, shipping carriers, and other third parties. Personal data you provide directly to an independent third party is governed by that party's privacy policy. We encourage you to review it.
18. CHANGES QUESTIONS AND COMPLAINTS
We may update this Policy to reflect changes in law, AxisOne, service providers, or business practices. We will post the revised Policy and update the "Last updated" date. Where required, we will provide additional notice or obtain consent before a material change takes effect.
Questions, requests, or complaints may be sent to privacy@axisone.ai or FAO Privacy, iProcess Global Research Inc., 7301 N State Highway 161, Suite 136, Irving, Texas 75039, USA. We will investigate privacy questions and complaints and respond within the period required by applicable law.

