Privacy Notice
How we collect, use, store, disclose, and otherwise process personal data in connection with OVAITY and our Services.
Last updated: 17 August 2026
This Privacy Notice explains how OVAITY ("OVAITY", "we", "us", or "our") collects, uses, stores, discloses, and otherwise processes personal data in connection with our websites, applications, platforms, products, and related services (collectively, the "Services").
This Privacy Notice applies when you:
- visit ovaity.com or another OVAITY website that links to this Privacy Notice;
- access or use an OVAITY beta, pilot, workspace, or other product environment;
- create or use an account;
- join our waitlist or apply for beta or early access;
- request a demonstration;
- communicate or interact with us;
- participate in an event, pilot, research collaboration, or commercial discussion with us; or
- otherwise interact with OVAITY in circumstances where we determine the purposes and means of processing your personal data.
OVAITY provides software and artificial-intelligence-enabled services primarily to organizations engaged in scientific research and development. In certain circumstances, our customers may use the Services to process personal data for which they determine the purposes and means of processing. In those circumstances, the customer generally acts as the controller and OVAITY generally acts as a processoror service provider on the customer's behalf. Such processing is governed primarily by the applicable customer agreement and, where required, a Data Processing Agreement ("DPA").
This Privacy Notice primarily describes processing for which OVAITY acts as a controller.
1. Who is responsible for your personal data?
The controller responsible for processing described in this Privacy Notice is:
OVAITY
Zurich, Switzerland
Email: connect@ovaity.com
For privacy-related requests, please contact connect@ovaity.com with the subject line Privacy Request.
Where an OVAITY customer controls personal data processed through the Services, requests relating to that data should generally be directed to the relevant customer. Where appropriate, we will assist customers in responding to such requests in accordance with applicable law and our contractual obligations.
2. Scope and our role
OVAITY may process personal data in different legal capacities depending on the circumstances.
2.1 OVAITY as controller
OVAITY generally acts as controller when processing personal data relating to:
- visitors to our website;
- people who join our waitlist;
- beta applicants;
- prospective customers;
- customer representatives and business contacts;
- users establishing or administering accounts;
- people contacting OVAITY;
- event participants;
- marketing recipients;
- job applicants, where applicable;
- suppliers, partners, advisors, and other business contacts; and
- security, fraud-prevention, compliance, and service-administration activities for which OVAITY determines the purposes and means of processing.
2.2 OVAITY as processor
Where an organization uses OVAITY to upload, connect, analyze, structure, retrieve, generate, or otherwise process information under that organization's control, the organization may act as controller and OVAITY may act as processor.
This may include personal data contained within:
- scientific documents;
- experimental records;
- research notes;
- datasets;
- reports;
- uploaded files;
- project information;
- connected third-party systems;
- prompts and instructions;
- AI-generated outputs;
- metadata;
- audit records; and
- other customer-controlled content.
Such processing is performed on the customer's documented instructions and is subject to the relevant customer agreement and DPA, where applicable.
OVAITY does not determine the scientific, clinical, employment, or other substantive purposes for which customers choose to process customer-controlled personal data through the Services.
3. Personal data we collect
The personal data we collect depends on how you interact with OVAITY.
3.1 Information you provide directly
We may collect:
- name;
- business email address;
- telephone number;
- organization or institution;
- job title or professional role;
- account credentials and account identifiers;
- communication preferences;
- waitlist and beta application information;
- information submitted when requesting a demonstration;
- messages and correspondence;
- support requests;
- survey and feedback responses;
- event registration information;
- information submitted in forms;
- information you provide during commercial discussions; and
- any other information you voluntarily provide to us.
Please do not provide personal data that is unnecessary for the relevant purpose.
3.2 Account and workspace information
When you use an OVAITY account or workspace, we may process:
- account identifiers;
- organization membership;
- permissions and access roles;
- authentication information;
- login events;
- feature usage;
- workspace activity;
- user actions;
- timestamps;
- audit events;
- security events; and
- configuration information.
3.3 Technical and usage information
When you access the Services, certain information may be collected automatically, including:
- IP address;
- browser type and version;
- operating system;
- device characteristics;
- language settings;
- referring URL;
- pages or features accessed;
- date and time of access;
- session information;
- diagnostic information;
- performance information;
- error information;
- security events;
- approximate location derived from IP address; and
- similar technical information.
We do not collect precise GPS location through the OVAITY marketing website unless explicitly stated and lawfully enabled for a particular feature.
3.4 Marketing attribution
Where permitted, we may process campaign parameters, referral information, and similar attribution data to understand how visitors discover OVAITY and evaluate our outreach.
4. Scientific and customer content
OVAITY is designed to enable scientific organizations to connect and work with research information.
Customer-controlled content may include scientific or technical information and, depending on how a customer uses the Services, could contain personal data or sensitive information.
OVAITY does not require customers to upload personal data, health data, genetic data, patient data, clinical data, or other special-category or sensitive personal data unless such processing has been expressly agreed and appropriate contractual, technical, organizational, and legal safeguards are in place.
Customers are responsible for determining whether they are legally permitted to provide personal data to OVAITY and for establishing an appropriate legal basis for their processing.
Where OVAITY processes such information as a processor, OVAITY processes it on behalf of the relevant customer and in accordance with the applicable agreement, DPA, documented instructions, and applicable law.
Customers should not upload directly identifying patient information, protected health information, genetic information linked to identifiable individuals, or other highly sensitive personal data unless the relevant OVAITY service has expressly been approved for that use and the necessary contractual and technical safeguards have been established.
5. How we use personal data
We may process personal data for the following purposes:
Providing the Services
To:
- operate our websites and applications;
- create and manage accounts;
- provide workspace functionality;
- provide requested AI functionality;
- process beta applications;
- maintain waitlists;
- provide demonstrations;
- provide customer support;
- authenticate users; and
- administer customer relationships.
Communicating with you
To:
- respond to inquiries;
- provide support;
- communicate about beta access;
- send service-related communications;
- provide security notifications;
- communicate changes to our Services, agreements, or policies; and
- otherwise administer our relationship with you or your organization.
Improving the Services
We may analyze service usage, feedback, performance, errors, and aggregated or de-identified information to:
- understand how the Services are used;
- improve functionality;
- improve usability;
- diagnose technical problems;
- develop new functionality; and
- improve reliability and security.
Where consent is legally required for analytics technologies, we will obtain consent before using them.
Security and abuse prevention
We may process information to:
- protect accounts;
- detect unauthorized access;
- investigate suspicious activity;
- prevent fraud and misuse;
- enforce applicable agreements;
- protect our systems;
- maintain audit records;
- investigate security incidents; and
- protect OVAITY, our customers, users, and third parties.
Marketing
Subject to applicable law and your preferences, we may send information about:
- OVAITY;
- product developments;
- events;
- early-access opportunities;
- research-related content; and
- other relevant commercial communications.
You may opt out of marketing communications at any time.
Legal and compliance purposes
We may process information where necessary to:
- comply with applicable laws;
- respond to lawful requests;
- establish, exercise, or defend legal claims;
- comply with regulatory requirements;
- investigate suspected violations;
- enforce contractual rights; and
- protect the rights, safety, security, or property of OVAITY or others.
6. Legal bases for processing
Where the GDPR, UK GDPR, Swiss Federal Act on Data Protection ("FADP"), or comparable laws apply, our legal basis depends on the relevant processing activity.
We may rely on:
Contract
Processing may be necessary to perform a contract with you or to take steps at your request before entering into a contract.
Legitimate interests
We may process personal data where necessary for legitimate interests pursued by OVAITY or another party, provided those interests are not overridden by applicable data-protection rights.
Such interests may include:
- operating and improving our Services;
- responding to business inquiries;
- managing business relationships;
- securing our systems;
- preventing fraud and abuse;
- maintaining appropriate business records;
- understanding service usage;
- developing our products;
- protecting legal rights; and
- proportionate B2B marketing.
Consent
Where required, we may process personal data on the basis of consent, including for certain cookies, analytics, or marketing activities.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
Legal obligation
We may process personal data where necessary to comply with legal obligations.
Vital interests
In exceptional circumstances, we may process personal data where necessary to protect the vital interests of an individual.
7. Artificial intelligence and machine learning
OVAITY provides features that use artificial intelligence, machine learning, foundation models, large language models, and related technologies ("AI Features").
7.1 How AI Features may process information
Depending on the feature used, AI Features may process:
- user prompts;
- instructions;
- project context;
- documents;
- scientific information;
- retrieved information;
- connected data;
- metadata;
- previous interactions;
- generated outputs; and
- other information necessary to provide the requested functionality.
AI processing may involve retrieval, classification, summarization, extraction, reasoning, generation, transformation, recommendation, workflow execution, or similar computational operations.
7.2 Third-party AI providers
OVAITY may use third-party infrastructure or AI model providers to provide certain AI Features.
Where such providers process personal data on our behalf, we seek to subject them to appropriate contractual and data-protection obligations.
A current list of material subprocessors is available on request at connect@ovaity.com. The specific provider used may depend on the relevant OVAITY feature, customer configuration, model availability, technical requirements, geographic requirements, and contractual arrangements.
7.3 Model training
OVAITY does not use customer research content to train publicly available general-purpose AI models for unrelated purposes.
OVAITY does not authorize third-party AI service providers to use customer content to train their general-purpose models except where this has been expressly agreed with the relevant customer and is permitted by applicable law.
OVAITY may use aggregated, de-identified, anonymized, or otherwise non-personal information to analyze and improve its Services where permitted by law and applicable customer agreements.
7.4 AI outputs
AI-generated outputs may be incomplete, inaccurate, outdated, misleading, or otherwise incorrect.
AI Features are intended to assist users and are not a substitute for appropriate professional, scientific, clinical, regulatory, legal, or other expert judgment.
Users remain responsible for reviewing and validating AI-generated outputs before relying on them, particularly where outputs may influence research, clinical, regulatory, safety-critical, or other consequential decisions.
7.5 Automated decision-making
OVAITY does not currently intend its generally available Services to make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect an individual.
Customers must not use OVAITY AI Features for legally regulated automated decision-making, employment decisions, patient diagnosis or treatment decisions, or other high-impact decisions unless such use has been expressly agreed with OVAITY and all applicable legal, contractual, validation, human-oversight, and risk-management requirements have been satisfied.
If OVAITY introduces functionality involving legally significant automated decision-making, we will implement applicable safeguards and provide any notices required by law.
7.6 AI transparency
Where required by applicable law, OVAITY will provide appropriate information to enable users to understand when they are interacting directly with an AI system or receiving AI-generated or AI-manipulated content.
OVAITY may implement technical measures, notices, labels, provenance information, metadata, or other mechanisms to support applicable transparency requirements.
8. EU Artificial Intelligence Act
Certain AI Features may fall within the scope of Regulation (EU) 2024/1689 (the "EU AI Act").
OVAITY evaluates its obligations under the EU AI Act based on, among other factors:
- the relevant AI system;
- its intended purpose;
- OVAITY's role in the relevant supply chain;
- whether OVAITY acts as provider, deployer, importer, distributor, or another regulated actor;
- the functionality provided;
- the context in which the system is used; and
- applicable risk classification.
Where required, OVAITY will implement measures applicable to its role and the relevant AI system, which may include transparency, documentation, human-oversight, technical, record-keeping, information, risk-management, or other obligations.
Nothing in this Privacy Notice represents that every AI Feature is subject to the same classification or regulatory requirements under the EU AI Act.
Customers are independently responsible for assessing legal requirements arising from their deployment and use of OVAITY in their particular context, including whether their intended use may constitute a high-risk or otherwise regulated use under applicable AI legislation.
10. How we disclose personal data
We do not sell personal data.
We may disclose personal data to the following categories of recipients where necessary:
Service providers and subprocessors
These may include providers supporting:
- cloud infrastructure;
- hosting;
- databases;
- storage;
- authentication;
- cybersecurity;
- communications;
- email delivery;
- analytics;
- customer support;
- form processing;
- AI functionality;
- monitoring;
- development infrastructure; and
- other technical operations.
Current providers may include, depending on the relevant Service:
- Vercel — website hosting and analytics;
- Resend — transactional and operational email;
- Typeform — forms and beta applications.
A current subprocessor list is available on request at connect@ovaity.com.
Professional advisors
We may disclose information where reasonably necessary to lawyers, accountants, auditors, insurers, consultants, and other professional advisors subject to appropriate confidentiality obligations.
Authorities and legal recipients
We may disclose information where reasonably necessary to:
- comply with law;
- comply with a court order;
- respond to a legally valid governmental request;
- investigate unlawful conduct;
- protect legal rights;
- enforce agreements; or
- protect the safety or security of OVAITY, our customers, users, or others.
Where legally permitted and reasonably practicable, we seek to assess governmental requests for legal validity and appropriate scope.
Corporate transactions
Personal data may be disclosed or transferred in connection with:
- financing;
- investment;
- due diligence;
- restructuring;
- merger;
- acquisition;
- asset sale;
- insolvency; or
- another corporate transaction.
Where appropriate, recipients will be subject to confidentiality or other protective obligations.
11. International transfers
OVAITY is based in Switzerland.
Certain service providers or subprocessors may process information from, or provide support from, countries outside Switzerland, the European Economic Area ("EEA"), or the country in which the relevant individual is located.
Where applicable law requires safeguards for an international transfer of personal data, OVAITY will use an appropriate transfer mechanism.
Depending on the circumstances, these mechanisms may include:
- an adequacy decision;
- the European Commission's Standard Contractual Clauses;
- the Standard Contractual Clauses as adapted or recognized under Swiss law;
- another approved contractual mechanism; or
- another lawful transfer mechanism permitted by applicable law.
Where appropriate, we may also implement supplementary technical, contractual, or organizational safeguards.
The fact that OVAITY hosts certain research infrastructure or customer data in Switzerland does not necessarily mean that no data is ever technically processed outside Switzerland. Any applicable international processing depends on the relevant Service, configuration, provider, and customer agreement.
Customers with specific data-residency requirements should ensure those requirements are expressly included in their contractual arrangement with OVAITY.
12. Data residency
OVAITY seeks to provide infrastructure appropriate for scientific research environments.
Primary customer research data stored within the OVAITY production workspace is hosted in Switzerland.
However, certain metadata, communications, support information, telemetry, AI requests, or other information may be processed through third-party providers in other jurisdictions depending on the relevant configuration.
Data-residency commitments made to individual customers are governed by the applicable customer agreement.
No statement in this Privacy Notice should be interpreted as a contractual guarantee of exclusive Swiss processing unless such a guarantee is expressly included in a written agreement with OVAITY.
13. Security
OVAITY uses technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Depending on the relevant Service and environment, these measures may include:
- access controls;
- role-based authorization;
- authentication controls;
- encryption in transit;
- encryption at rest;
- logging and monitoring;
- audit functionality;
- infrastructure security;
- backup procedures;
- software-development controls;
- vulnerability management;
- incident-response procedures;
- data minimization; and
- supplier-management measures.
No information system is completely secure. Accordingly, we cannot guarantee that unauthorized access, disclosure, loss, misuse, or alteration will never occur.
If we become aware of a personal-data breach, we will assess and respond to the incident and provide notifications where required by applicable law or contract.
14. Confidentiality and scientific information
Scientific and research information may have substantial commercial, intellectual-property, regulatory, or competitive value even where it does not constitute personal data.
The protection of confidential customer information is additionally governed by the applicable customer agreement, confidentiality agreement, DPA, or other contractual terms.
This Privacy Notice does not grant OVAITY any ownership rights in customer research content.
Ownership, licensing, confidentiality, intellectual-property rights, and permitted uses of customer content are governed by the applicable contractual agreement.
15. Data retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, security, contractual, and dispute-resolution requirements.
Retention periods depend on factors including:
- the type of information;
- the purpose of processing;
- the duration of our relationship;
- contractual requirements;
- applicable limitation periods;
- security requirements;
- legal obligations; and
- whether information is contained in backups or archives.
Marketing and prospect information will generally not be retained indefinitely and will be periodically reviewed.
Customer-controlled data is retained and deleted in accordance with the applicable customer agreement, DPA, product configuration, and documented customer instructions.
Following termination of a customer relationship, customer data may remain temporarily in backups or disaster-recovery systems until those systems are overwritten or deleted in accordance with our applicable retention procedures.
Where data no longer needs to be retained, we will delete, anonymize, or otherwise securely dispose of it where reasonably practicable and required by applicable law.
16. Data minimization and purpose limitation
We seek to process personal data that is adequate, relevant, and reasonably necessary for the relevant purpose.
We do not intentionally collect personal data merely because the technical capability to collect it exists.
Where reasonably practicable, OVAITY designs its Services to support customers in limiting processing to information necessary for their scientific and operational purposes.
17. Your privacy rights
Depending on applicable law, you may have rights including the right to:
- obtain information about processing;
- request access to personal data;
- receive a copy of certain personal data;
- correct inaccurate personal data;
- request deletion;
- request restriction of processing;
- object to certain processing;
- withdraw consent;
- receive certain data in a portable format;
- object to certain direct marketing;
- lodge a complaint with a competent supervisory authority; and
- obtain safeguards relating to certain automated decisions.
These rights are subject to applicable statutory requirements, exceptions, and limitations.
To exercise a privacy right, contact connect@ovaity.com with the subject line Privacy Request.
We may need to verify your identity before fulfilling a request.
If your request concerns information controlled by an OVAITY customer, we may refer the request to that customer or ask you to contact the customer directly.
18. Marketing communications
You may unsubscribe from OVAITY marketing emails at any time using the unsubscribe mechanism provided in the relevant communication or by contacting us.
Opting out of marketing does not prevent us from sending necessary transactional, security, account, support, contractual, or other non-marketing communications.
19. Children and minors
OVAITY's Services are intended for professional and organizational use and are not directed to children.
We do not knowingly solicit personal data directly from children under 16 through our general Services.
Where applicable law establishes a higher age requirement for a particular activity, we will apply that requirement.
If you believe a child has provided personal data directly to OVAITY without appropriate authorization, contact connect@ovaity.com.
This provision does not prevent an appropriately authorized research organization from processing information relating to minors through an OVAITY service where such processing is lawful, contractually authorized, and supported by appropriate safeguards.
20. Third-party services and integrations
OVAITY may allow users to connect or interact with third-party services, data sources, scientific tools, software platforms, websites, or integrations.
Where you direct OVAITY to connect to a third-party service, information may be exchanged with that service as necessary to provide the requested integration.
Third-party services operate under their own terms and privacy practices. OVAITY is not responsible for independent processing performed by third parties acting outside OVAITY's instructions or control.
You and your organization are responsible for ensuring that you have the necessary rights and authorization to connect third-party systems and transfer information through integrations.
21. Links to third-party websites
Our Services may contain links to websites or services operated by third parties.
This Privacy Notice does not govern independent third-party websites or services. We encourage you to review their privacy notices before providing personal data.
22. Business customers' responsibilities
Organizations using OVAITY are responsible for their own compliance with applicable laws concerning their use of the Services.
Depending on the circumstances, this may include responsibility for:
- establishing a lawful basis for processing;
- providing required notices to data subjects;
- obtaining consent where required;
- complying with research ethics requirements;
- complying with clinical or health-data requirements;
- ensuring appropriate authorization for datasets;
- determining appropriate retention periods;
- configuring access permissions;
- responding to data-subject requests;
- assessing their intended use of AI systems;
- conducting data-protection impact assessments where required;
- conducting AI-related risk or impact assessments where required; and
- ensuring appropriate human oversight.
OVAITY's provision of technical functionality does not constitute legal, medical, clinical, regulatory, scientific, or compliance advice.
23. Research, health, genetic, and clinical information
OVAITY is intended to support scientific research, but not every OVAITY environment is necessarily approved or configured for every category of regulated data.
Unless expressly agreed in writing, customers must not assume that an OVAITY environment is certified, validated, or legally suitable for:
- identifiable patient records;
- protected health information;
- regulated clinical-trial records;
- genetic data relating to identifiable individuals;
- medical-device decision-making;
- clinical diagnosis;
- treatment recommendations;
- GxP-regulated records;
- electronic signatures subject to specialized regulatory requirements; or
- other specially regulated data or workflows.
Any such use must be expressly evaluated and agreed with OVAITY in advance.
25. Do Not Track and Global Privacy Control
Browser-based "Do Not Track" signals are not subject to a universally adopted technical or legal standard.
Where applicable law requires recognition of a legally valid browser-based opt-out preference signal, such as Global Privacy Control, we will process such signals as required by applicable law.
Our cookie preference mechanism remains available for managing cookie choices.
26. United States privacy rights
Residents of certain US states may have additional privacy rights under applicable state law.
Depending on the applicable jurisdiction and subject to statutory exceptions, these may include rights to:
- confirm whether personal data is processed;
- access personal data;
- correct personal data;
- delete personal data;
- obtain a portable copy;
- opt out of the sale of personal data;
- opt out of targeted advertising;
- opt out of certain profiling; and
- appeal certain decisions concerning privacy requests.
OVAITY does not sell personal data for monetary consideration.
OVAITY does not knowingly sell personal data belonging to children.
Where legally required, we will provide additional jurisdiction-specific disclosures or mechanisms.
Requests may be submitted to connect@ovaity.com with the subject line Privacy Request.
We may take reasonable steps to verify your identity and authority to submit a request.
27. Changes in ownership
If OVAITY undergoes a merger, acquisition, financing, restructuring, insolvency, sale of assets, or similar transaction, information may be transferred to relevant counterparties, professional advisors, financing parties, or successors where legally permitted.
Any successor that receives personal data will remain subject to applicable data-protection obligations.
28. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect:
- changes to our Services;
- new technologies;
- changes to our processing;
- changes to service providers;
- regulatory developments;
- changes in law; or
- improvements to our privacy practices.
The current version will display its latest revision date.
Where required by applicable law, we will provide additional notice of material changes.
29. Contact us
Questions regarding this Privacy Notice or OVAITY's privacy practices may be sent to:
OVAITY
Zurich, Switzerland
Email: connect@ovaity.com
Privacy requests: connect@ovaity.com
Subject: Privacy Request
30. Additional customer documentation
For organizational customers, additional privacy, security, and compliance terms may be contained in:
- the applicable customer agreement;
- a Data Processing Agreement;
- confidentiality agreements;
- security documentation;
- technical and organizational measures;
- service-specific documentation;
- a subprocessor list;
- data-residency commitments; and
- other applicable contractual documents.
If there is a conflict between this Privacy Notice and a written customer agreement concerning OVAITY's processing of customer-controlled data as a processor, the applicable contractual agreement will govern to the extent provided in that agreement.