Privacy
Last updated 27 August 2026. This policy applies to every VSQRD deployment. Where your organization's written agreement with VSQRD says something more specific, the agreement governs.
The short version
VSQRD is laboratory software that runs as a separate installation for each customer. Your data lives in your organization's own deployment, with its own database. We do not sell it, we do not use it for advertising, we do not run analytics or trackers, and we do not record your IP address or device. We collect the minimum needed to run the system and to keep the audit record that regulated work requires, and we keep that record for as long as the regulations ask us to.
Who we are and who this covers
VSQRD builds and hosts laboratory information management software for research labs. This policy covers the people who use it: staff of the organization that runs the deployment.
Your organization decides what data goes into its deployment and why. VSQRD processes that data on the organization's behalf, under a written agreement. If you are in the EU or UK, that makes your organization the controller and VSQRD the processor.
What we collect
We hold only what the work needs:
- Account details from your organization's identity provider: your name, email address, the organization you belong to, and your role.
- What you do in the system: the studies, samples, results, and documents you create or upload, and the approvals and signatures you give. Every change is attributed to the person who made it. That attribution is the point of a regulated record, and it is kept.
- Contact details your organization records for the clients it works for — a name, a work email, a phone number — as part of the record of who ordered a piece of work.
- If you use the built-in assistant: the conversation you have with it, and the records it reads on your behalf.
- A few small cookies that keep you signed in. They are listed below.
Where a deployment handles human biological samples, the sample record carries a code, the consent it arrived under, and how identifiable it is. The lab that holds the sample is responsible for the consent. The system enforces, row by row, that a sample is never used beyond what its consent allows.
What we do not collect
Just as important is what is not there:
- No IP addresses, device fingerprints, or user agents are stored.
- No location data.
- No analytics, advertising, or tracking scripts of any kind, and no third-party cookies. Fonts and scripts are served from the deployment itself, not from outside networks.
- No passwords. Sign-in is handled by your organization's identity provider; VSQRD never sees or stores a password of its own.
We never sell personal data and never share it for marketing.
Why we hold it
To run the service for you: to sign you in, show you the work that belongs to you, and let you do your job.
To keep the audit record. Regulated work has to be able to show who did what, and when. That record is written once and cannot be edited or deleted afterwards, by anyone, including us. It is what makes your studies defensible.
To send you the notifications you have asked for, and to keep the system secure.
Who else can see it
Access is narrow by design:
- People in your own organization, according to the teams and roles your organization sets up, and no wider than the permission rules allow — a deployment's own rules can only tighten those, never widen them.
- VSQRD staff, only when needed to operate or support the deployment, and only under the agreement with your organization.
To run a deployment we rely on a small number of service providers, each for one job, each bound by its own data-protection terms. Your organization's agreement names exactly which ones apply to your deployment. They are: the identity provider that signs you in (WorkOS, unless your organization uses its own); the email provider that delivers notifications (the email carries your address and a short subject line, never the contents of a study); the cloud provider that hosts the deployment and its encrypted backups; and, if the assistant is enabled, the AI provider described below. None of them is permitted to use your data for anything other than providing that service to you.
The assistant
Some deployments include an assistant you can talk to inside the workbench. When you use it, your conversation and the records it reads for you are sent to an AI model provider to produce its reply. That happens only when you use the assistant, and only with the records you are allowed to see anyway. The provider processes the conversation to answer it and is not permitted to use it to train its models.
The assistant cannot change anything on its own. Every write it proposes waits for a person to approve it, and the record shows that person, not the assistant, as the one who acted. It can never sign a document or issue a credential. Your organization can turn the assistant off entirely.
How we keep it safe
Security is built into how the system is made, not bolted on:
- Everything moves over encrypted connections, and the database and its backups are encrypted at rest.
- Each customer has its own deployment and its own database. There is no shared database between customers.
- Sign-in cookies are encrypted so their contents cannot be read or forged. Access keys for automated tools are stored only as one-way hashes; the key itself is shown once and never kept.
- The audit record is append-only at the database and hash-chained, so any attempt to alter history is detectable.
- Signing a record requires proving who you are again at that moment, not just having a browser open.
- The software we run is built from pinned, verified sources, and each running deployment reports the exact version and digest it is serving.
No system is perfectly secure. If we ever learn of a breach that affects your data, we will tell your organization promptly so it can tell you.
How long we keep it
Study records and the audit record are kept for the life of the work plus the retention period the regulations require, which is often many years. That is the law for this kind of work, and it is what your organization is relying on us for.
When your account is closed, it is deactivated: you can no longer sign in, and you disappear from the lists of people who can be assigned work. Your name stays on the records you signed and the changes you made, because a signature that vanishes is no longer a signature. We do not delete the audit record, and we cannot.
Uploaded documents are archived rather than deleted for the same reason. Conversations with the assistant are kept with the record of what the assistant was asked to do.
Your choices and rights
You can:
- See the personal data held about you, and have it corrected, through your organization's administrator or by writing to us.
- Get a copy of your data in a usable format. The audit record exports with its chain, so it can be verified rather than merely read.
- Choose which notifications reach you by email, in your settings.
- Have your account deactivated at any time.
- Ask us to stop using your data in a way you did not expect. Tell us, and we will look into it.
Because of the retention rules above, we cannot erase the audit record or remove your name from records you signed, even on request. Where the law gives you a right to erasure, that right is limited by these legal obligations, and we will explain exactly what we can and cannot do.
If you are in the EU or UK, your first point of contact is usually your own organization, because it decides how your data is used. You can also write to us directly, and you have the right to complain to your data protection authority.
Cookies
We set only the cookies needed to keep you signed in, and none from anyone else:
- A session cookie that keeps you signed in. Its contents are encrypted. It ends when you sign out or your session expires.
- A short-lived cookie, ten minutes at most, used only during sign-in to protect the login handshake.
There are no analytics, advertising, or preference-tracking cookies.
Children
VSQRD is a professional tool for laboratory staff. It is not directed at, and not to be used by, anyone under 18.
Changes to this policy
If we change this policy in a way that matters, we will tell your organization before the change takes effect, and the date at the top of this page will change. We will not quietly widen what we collect or who sees it.
Getting in touch
Questions, requests, or concerns about any of the above go to vivien@vsqrd.com. We read every message and will answer within a reasonable time.