Privacy Policy
How Interlit collects, uses, discloses, and protects personal data across its Enterprise Engagement and Self-Serve tiers, including legal bases, sub-processors, international transfers, retention, and your rights.
Effective date: July 13, 2026.
This Privacy Policy explains how Interlit GmbH ("Company," "we," "us") collects, uses, discloses, and protects personal data in connection with the Platform, made available under two engagement modes: the Enterprise Engagement and the Self-Serve Tier (together, the "Platform," each a "Service" as context requires). This is a single policy for a single controller; Sections 4 and 5 describe data practices separately for each Service where they differ.
1. WHO WE ARE AND SCOPE OF THIS POLICY
1.1 Interlit GmbH is a limited liability company under Swiss law, Strehlgasse 2, 8001 Zürich, registered under UID CHE-272.432.629, acting as the data controller for the personal data described in this Policy.
1.2 This Policy applies to visitors to our websites, registered Users of either engagement mode, and individuals whose data reaches us through a business Customer's use of the Platform. It does not apply to the practices of third-party sites we may link to.
2. HOW THIS POLICY APPLIES TO EACH ENGAGEMENT MODE
2.1 The Enterprise Engagement is a B2B and B2R (business and research-institution) service. It generally involves minimal personal data about individuals: primarily the business or institutional contact details of a Customer's personnel. Biological sequence and assay data submitted as Inputs is treated as the Customer's confidential business data, not personal data, unless it is linked to an identifiable human research participant, in which case Section 4.3 applies.
2.2 The Self-Serve Tier serves both individual consumers and business Customers. It involves account data, uploaded User Data (which may or may not contain personal data depending on what you choose to upload), Template metadata, payment data, and usage analytics, described in Section 5.
3. THE PROCESSING TABLE AT A GLANCE
3.1 The table below is a consolidated overview of every category of personal data we process, drawn from the more detailed Sections 4 and 5. Where GDPR applies, this table reflects the Article 30 record-of-processing information required to be made available in an accessible form; the authoritative internal record of processing activities is maintained separately by the Company and can be requested by a supervisory authority.
| Category | Examples | Engagement mode | Purpose | Legal basis (GDPR Art. 6) | Retention | Recipients / processors | International transfer safeguard |
|---|---|---|---|---|---|---|---|
| Account and contact data | Name, work email, employer or institution, role | Both | Account creation, authentication, contract administration | Performance of a contract (Art. 6(1)(b)) | Duration of account, plus statutory retention under Section 10 | Cloud hosting providers, published at interlit.ai/legal/subprocessors | SCCs or adequacy decision, detail at interlit.ai/legal/subprocessors |
| Enterprise project data (Inputs/Outputs) | Sequences, structures, assay data, predictions | Enterprise Engagement | Delivering the commissioned design or ranking project | Performance of a contract (Art. 6(1)(b)) | Duration of the Order Form, plus retention agreed in the Data Processing Addendum | Not disclosed to other customers; sub-processors under Section 8 where the Customer selects the training-license tier | SCCs where sub-processors are located outside Switzerland/EEA, detail at interlit.ai/legal/subprocessors |
| Human-subject-derived data | Clinical trial, biobank, or genetic sequencing data linked to an identifiable individual | Enterprise Engagement (where applicable) | Processing under a Data Processing Addendum on the Customer's instructions | Performance of a contract with the Customer, who is the controller (Art. 6(1)(b), processed by us as processor) | As specified in the applicable Data Processing Addendum | Cloud hosting providers under the Data Processing Addendum, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
| University/research project data | Contact, affiliation, and authorship details of designated researchers | Enterprise Engagement, university tier | Patent filing, co-ownership administration, academic publication | Performance of a contract (Art. 6(1)(b)); legitimate interests for patent administration (Art. 6(1)(f)) | Duration of joint ownership, plus statutory retention under Section 10 | Patent counsel and patent offices as necessary | Not typically transferred outside Switzerland/EEA; SCCs apply if it is |
| Licensed Dataset recipient data | Business contact and billing data of a licensee | Enterprise Engagement, co-offerings | Administering a Licensed Dataset license | Performance of a contract (Art. 6(1)(b)) | Duration of the license, plus statutory retention under Section 10 | Payment processors, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
| Self-Serve account data | Name, email, password hash, tier | Self-Serve Tier | Account creation and authentication | Performance of a contract (Art. 6(1)(b)) | Duration of account, plus statutory retention under Section 10 | Cloud hosting providers, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
| User Data you upload | Data files, tables, uploaded for visualization | Self-Serve Tier | Generating your Generated Visualizations | Performance of a contract (Art. 6(1)(b)) | Duration of account, or until you delete the underlying file | Cloud hosting providers and, where used for natural-language processing, third-party model providers, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
| Template metadata | Template name, license type, sharing scope | Self-Serve Tier | Operating the template-sharing feature | Performance of a contract (Art. 6(1)(b)) | Duration of the Template's availability, plus a reasonable period after removal for dispute handling | Cloud hosting providers, published at interlit.ai/legal/subprocessors; other Users, to the extent you choose to share a Template | SCCs, detail at interlit.ai/legal/subprocessors |
| Payment data | Billing address, payment-method token (not full card numbers, which are handled by our payment processor) | Both | Billing and fraud prevention | Performance of a contract (Art. 6(1)(b)) | Duration required by tax and accounting law under Section 10 | Payment processors, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
| Device and usage data | IP address, browser type, feature usage, crash logs, API usage metrics, log-in timestamps, error logs | Both | Security, product improvement, support | Legitimate interests (Art. 6(1)(f)) | Typically 12 months, detail at interlit.ai/legal/retention | Cloud hosting providers, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
| Cookies | Session cookies, preference cookies, analytics cookies (with consent where required) | Both | Session management, analytics | Legitimate interests for essential cookies; consent for non-essential cookies (Art. 6(1)(a)/(f)) | Session or up to 24 months for persistent cookies, detail at interlit.ai/legal/retention | Analytics sub-processors, where used, published at interlit.ai/legal/subprocessors | SCCs, detail at interlit.ai/legal/subprocessors |
3.2 The "Recipients / processors" and "International transfer safeguard" columns intentionally point to interlit.ai/legal/subprocessors rather than naming specific vendors in this document. We may change a cloud host, payment processor, or model sub-processor over time; keeping that detail on a dynamically maintained page lets us keep it current without every change requiring a new version of this Policy and a fresh notice to every Customer. Material changes to the categories of data, purposes, or legal bases in the table above are still notified as changes to this Policy under Section 16.
4. DATA WE COLLECT: ENTERPRISE ENGAGEMENT
4.1 Account and contact data: name, work email, employer or institution, and role of the individuals your organization designates as users of the Platform.
4.2 Project data: Inputs and Outputs associated with a project, treated as Customer's confidential business data under Section 6 of the Terms of Service.
4.3 Human-subject-derived data: if a Customer's Inputs are derived from human clinical trial participants, biobank samples, or genetic sequencing of identifiable individuals, the Customer remains the data controller for that underlying personal data, and the Company acts as a data processor under a Data Processing Addendum executed with that Customer before such data is submitted; see Section 14.
4.4 Platform usage data: log-in timestamps, API usage metrics, and error logs necessary for security and service operation.
4.5 Internal research data: the Company's internal demonstration-research and development activities process comparative-species protein, genomic, and sequence data sourced from public and licensed scientific databases; this data does not generally identify a natural person.
4.6 University and research-institution project data: where a university or research-institution Customer engages the Platform under the university tier described in Section 8 of the Terms of Service, project data and resulting Outputs may become jointly held by the Company and that Customer, and may include the contact, affiliation, and authorship details of the Customer's researchers, processed for purposes of patent filing, co-ownership administration, and academic publication.
4.7 Licensed Dataset recipients: where a pharmaceutical or biotechnology company Customer licenses a Licensed Dataset under Section 18 of the Terms of Service, the Company collects the licensee's business contact and billing data to administer that license; the Licensed Dataset itself is treated as the Company's confidential business data, not personal data, unless it embeds identifiable human-subject-derived data, in which case Section 4.3 applies.
5. DATA WE COLLECT: SELF-SERVE TIER
5.1 Account data, User Data, Template metadata, payment data, device and usage data, and cookies, described in the table at Section 3.1.
5.2 Whether User Data you upload contains personal data of other individuals (for example, a spreadsheet of customer records) is determined by your own choices; you are responsible for having a lawful basis to upload such data.
6. LEGAL BASIS FOR PROCESSING
6.1 Where the EU or UK GDPR applies, we rely on the legal bases set out per category in the table at Section 3.1: performance of a contract with you (account operation, generating Outputs and Generated Visualizations); our legitimate interests (security, fraud prevention, product improvement on de-identified data, subject to a documented balancing assessment); your consent (non-essential cookies, model-training opt-ins); and, though not currently relied on for any category above, compliance with a legal obligation would cover tax, accounting, and law-enforcement requests where they arise.
6.2 Where the Swiss Federal Act on Data Protection applies, processing is generally permitted absent a predetermined legal basis, except that high-risk profiling requires your consent, consistent with Section 13 of the Terms of Service.
6.3 Where the California Consumer Privacy Act applies, we do not sell personal data and do not share it for cross-context behavioral advertising; you may exercise the rights described in Section 11.
7. HOW WE USE PERSONAL DATA
7.1 To provide, maintain, and secure the Platform; to process payment; to provide customer support; to send service and security notices; to comply with legal obligations; and, only with your opt-in where required, to improve our models using de-identified or aggregated data.
7.2 We do not use Enterprise Engagement project data or Self-Serve Tier User Data to train models shared with other customers except as described in Section 10.6 and Section 8.2 of the Terms of Service.
8. SHARING AND SUB-PROCESSORS
8.1 We share personal data with service providers who process it on our instructions, including cloud hosting providers, payment processors, and, where used for natural-language query processing on the Self-Serve Tier, third-party model providers. The current list of these sub-processors, including their identity, location, and role, is published and kept up to date at interlit.ai/legal/subprocessors.
8.2 We will not add a new sub-processor with access to your personal data without updating interlit.ai/legal/subprocessors at least thirty days in advance, giving you an opportunity to object on reasonable data-protection grounds through info@interlit.ch before that sub-processor begins processing.
8.3 We may disclose personal data where required by law, to enforce this Policy or our Terms of Service, or to protect the rights, property, or safety of the Company, our Users, or the public, including reports made under Section 12.5 of the Terms of Service (biosecurity).
8.4 We do not sell personal data to third parties.
9. INTERNATIONAL DATA TRANSFERS
9.1 Where personal data is transferred outside Switzerland or the European Economic Area, we rely on an applicable adequacy decision, the EU-U.S. or Swiss-U.S. Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses supplemented, for Swiss personal data, by the Swiss Addendum recognizing the jurisdiction of the Swiss Federal Data Protection and Information Commissioner (FDPIC).
9.2 The specific countries to which personal data is transferred under this Section, and the safeguard relied on for each, form part of the sub-processor information published and kept up to date at interlit.ai/legal/subprocessors.
9.3 If we are required to appoint a representative in the European Union under Article 27 GDPR, that representative's contact details are published at interlit.ai/legal/eu-representative.
10. DATA RETENTION
10.1 We retain personal data for as long as necessary to provide the Platform, comply with legal, tax, and accounting obligations, and resolve disputes, after which it is deleted or irreversibly de-identified. In no event do we retain personal data for longer than ten years after your account becomes inactive or our relationship with you ends, except where a longer period is required by law, including the ten-year business-records retention duty under Article 958f of the Swiss Code of Obligations; we reserve the right to delete personal data sooner. Indicative retention periods for the specific data categories in Section 3.1 are published and kept up to date at interlit.ai/legal/retention.
11. YOUR RIGHTS
11.1 Subject to applicable law, you may request access to, rectification of, deletion of, or a portable copy of your personal data, and may object to or restrict certain processing. To exercise these rights, contact info@interlit.ch.
11.2 If you are in the European Economic Area, the United Kingdom, or Switzerland, you may lodge a complaint with your local supervisory authority or with the Swiss FDPIC. If you are a California resident, you have the rights described in the California Consumer Privacy Act, including the right to opt out of any future sale or sharing of personal data, which we do not currently engage in.
12. SECURITY
12.1 We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and logging, to protect personal data against unauthorized access, loss, or alteration.
13. CHILDREN
13.1 The Platform is not directed to individuals under eighteen years of age, and we do not knowingly collect personal data from children. If we learn that we have collected personal data from a child without appropriate consent, we will delete it.
14. DATA PROCESSING ADDENDUM FOR BUSINESS CUSTOMERS
14.1 A business Customer that requires the Company to process personal data on its behalf as a data processor, including an Enterprise Engagement Customer submitting human-subject-derived data, or a Self-Serve Tier Ultra tier Customer processing personal data of its own end users, may request a Data Processing Addendum, incorporating the current EU Standard Contractual Clauses and the Swiss Addendum where relevant, at interlit.ai/legal/dpa.
15. BREACH NOTIFICATION
15.1 We will notify the competent supervisory authority within seventy-two hours of becoming aware of a personal data breach where required under the GDPR, and as soon as possible where required under the Swiss Federal Act on Data Protection, and will notify affected individuals and business Customers without undue delay where the breach is likely to result in a high risk to their rights.
16. CHANGES TO THIS POLICY
16.1 We may update this Policy from time to time. Material changes, including a change to the categories of data, purposes, or legal bases in the table at Section 3.1, will be notified consistent with Section 20 of the Terms of Service. Adding, removing, or replacing an individual sub-processor is notified through interlit.ai/legal/subprocessors under Section 8.2 and does not by itself require a new version of this Policy. The effective date at the top of this Policy reflects the date of the latest version.
17. CONTACT AND SUPERVISORY AUTHORITIES
17.1 Questions about this Policy or requests concerning your personal data may be directed to info@interlit.ch or Strehlgasse 2, 8001 Zürich. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch.