← Back to Home

Privacy Policy

Effective Date: March 2026 | Valid for Phonos Web Application

1. Data Controller

FyreFly Systems GbR

Maximilian Scheinast-Peter, Janek Franz Fabian
Bergstraße 16
06366 Köthen
Germany

Email: service@fyreflysystems.com
Website: fyreflysystems.com

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection laws is FyreFly Systems GbR, represented by Maximilian Scheinast-Peter and Janek Franz Fabian.

2. General Information on Data Processing

The protection of your personal data is very important to us. This privacy policy informs you about the type, scope, and purpose of the processing of personal data when using our Phonos Web Application ("Service"). We process your data exclusively on the basis of legal provisions (GDPR, German Telecommunications Act).

Important Principles:
  • We only process data for specified, explicit, and legitimate purposes
  • Data processing is limited to what is necessary
  • Your data is stored securely and protected against unauthorized access
  • You have the right to access, rectify, and delete your data at any time

3. Collection and Storage of Personal Data

3.1 When Visiting the Website

When accessing our website, the browser on your device automatically sends information to our website server. This information is temporarily stored in a log file:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the retrieved file
  • Website from which access was made (referrer URL)
  • Browser used and, if applicable, the operating system of your computer and the name of your access provider

Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in ensuring system security and stability)

Retention Period: Data is deleted as soon as it is no longer required for the purpose of its collection, at the latest after 90 days.

3.2 Registration and Service Use

Registration is required to use our service. We collect the following personal data:

Data Type Purpose of Processing Legal Basis
Username Identification and authentication Art. 6 para. 1 lit. b GDPR (contract performance)
Email Address Communication, two-factor authentication, password reset Art. 6 para. 1 lit. b GDPR (contract performance)
Password (hashed) Authentication and access protection Art. 6 para. 1 lit. b GDPR (contract performance)
Profile Picture (optional) Personalization of user profile Art. 6 para. 1 lit. a GDPR (consent)
Organization/Team Membership Project management and access control Art. 6 para. 1 lit. b GDPR (contract performance)

4. Processing of Usage and Research Data

4.1 Uploaded Files and Calculations

When using the service, we process the following data:

  • Protein Sequences and Structure Data: Scientific data uploaded or entered by you
  • Calculation Results: Results generated by our AI models (ESMFold, AlphaFold2, DiffDock, ProteinMPNN, Metal3D)
  • Job Metadata: Timestamps, parameters used, calculation duration
  • Project and File Management: Organization structure of your research data

Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance) and Art. 6 para. 1 lit. f GDPR (legitimate interest in providing services)

Retention Period: Your research data is stored as long as your account is active. You can delete individual files or projects at any time.

4.2 Usage Statistics and Analytics

To improve our service, we collect anonymized usage statistics:

  • Number of calculations performed per model type
  • Average calculation times
  • Frequency of use of certain features
  • Storage space usage (aggregated)

Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in optimizing our service)

5. Cookies and Tracking Technologies

5.1 Technically Necessary Cookies (Own Cookies)

We use technically necessary cookies to provide the service. These cookies are essential for the website to function:

Cookie Name Purpose Duration
session Maintaining your login session Session (until logout)
csrf_token Protection against cross-site request forgery attacks Session
user_preferences Storing your user preferences (language, theme, etc.) 1 year
disclaimer_accepted Storing disclaimer consent Session

Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in technical functionality and security)

5.2 Cloudflare Cookies (CDN and Security)

We use Cloudflare as a Content Delivery Network (CDN) and for security services. Cloudflare sets cookies to protect the website and optimize delivery:

Cookie Name Purpose Duration
__cflb Load balancing - traffic distribution Session
__cf_bm Bot management for security 30 minutes
cf_clearance Security verification (after challenge) 1 year

Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in secure and fast website delivery)
Privacy Policy: https://www.cloudflare.com/privacypolicy/

5.3 Google Cloud Platform Cookies

Our server infrastructure is hosted on Google Cloud Platform (GCP) in the European Union. Google may set technical cookies for:

  • Load balancing and traffic distribution
  • Session persistence
  • Security monitoring

Hosting Location: Google Cloud Platform, European Union
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in reliable hosting)
Privacy Policy: https://policies.google.com/privacy

5.4 Analytics and Tracking

We do NOT use external tracking services such as Google Analytics, Facebook Pixel, or similar third-party trackers. All usage statistics are collected internally and anonymized.

6. Sharing Data with Third Parties

6.1 General Principle

We do not share your personal data with third parties unless:

  • You have expressly consented (Art. 6 para. 1 lit. a GDPR)
  • Sharing is necessary for contract performance (Art. 6 para. 1 lit. b GDPR)
  • There is a legal obligation (Art. 6 para. 1 lit. c GDPR)

6.2 Data Processors and Third-Party Providers

We use the following data processors and third-party providers:

Service Provider Purpose Location
Google Cloud Platform (GCP) Hosting of server infrastructure and databases European Union
Nebius AI GPU compute infrastructure for AI/ML model execution (Boltz2, Evo2, and other computational models) European Union
Cloudflare, Inc. Content Delivery Network (CDN), DDoS protection, SSL/TLS encryption EU/USA (Standard Contractual Clauses)
IONOS SE Email delivery (transactional emails, 2FA codes, notifications) Germany (GDPR compliant)
Stripe, Inc. Payment processing for premium subscriptions EU/USA (Standard Contractual Clauses, GDPR compliant)
NVIDIA DGX Cloud GPU compute infrastructure used exclusively for demonstration and testing purposes (demo environment only) USA (Standard Contractual Clauses)
Google LLC (Gemini AI) Optional conversational AI assistance, file analysis, and AI-powered search (activated when using @gemini mentions or search functionality) Worldwide / USA (Google's data protection framework)

Data processing agreements have been concluded with all processors in accordance with Art. 28 GDPR. For transfers to third countries outside the EU, EU Standard Contractual Clauses are used.

6.3 Special Notes on Third-Party Providers

Google Cloud Platform (GCP)

Our server infrastructure runs on Google Cloud Platform in the European Union. All your data is stored exclusively on servers within the EU.

Privacy Policy: https://policies.google.com/privacy
Legal Basis: Art. 6 para. 1 lit. f GDPR, Art. 28 GDPR

Cloudflare (CDN and Security)

Cloudflare improves the performance and security of our website through caching, DDoS protection, and SSL encryption. IP addresses and technical information are processed.

Privacy Policy: https://www.cloudflare.com/privacypolicy/
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in security and performance)

Stripe (Payment Processing)

When you subscribe to a paid plan, payment information is transmitted directly to Stripe. We do NOT store complete credit card data on our servers.

Processed Data: Name, email address, billing address, payment method (tokenized)
Privacy Policy: https://stripe.com/privacy
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance), Art. 6 para. 1 lit. c GDPR (legal obligations)

NVIDIA DGX Cloud (Demo Environment)

NVIDIA DGX Cloud GPU infrastructure is used exclusively for demonstration and testing purposes. No production user data is processed on this platform. Only synthetic or sample data is used during demo sessions.

Privacy Policy: https://www.nvidia.com/en-us/about-nvidia/privacy-policy/
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in platform testing and demonstration)
Note: This infrastructure is not used for processing actual user research data. All production workloads run on Nebius AI within the EU.

Google Gemini AI (Optional AI Assistance)

When you explicitly use Gemini features by @mentioning gemini in project chats or requesting file analysis, your queries and context are sent to Google's Gemini API.

Processed Data: User queries, project context, file content (optional, limited to 10,000 characters)
Privacy Policy: https://policies.google.com/privacy
Legal Basis: Art. 6 para. 1 lit. a GDPR (consent through active usage), Art. 6 para. 1 lit. b GDPR (contract performance)
Note: This is an optional feature. You can use all core features without activating Gemini integration.

6.4 Data Location and Transfer

All your core research data and scientific calculations (protein structure prediction, molecular docking, sequence design) are stored and processed exclusively on servers within the European Union (Google Cloud Platform). No transfer of your core research data to third countries outside the EU takes place.

Exception - Optional Gemini Feature: If you choose to use the optional Gemini AI features by @mentioning gemini, the data you send in those specific queries may be processed by Google on servers worldwide, including the USA. This is clearly communicated when you use the feature, and you have full control over what data you share with Gemini.

Cloudflare and Stripe may transfer technical data (IP addresses, metadata) to the USA as part of their services. This is done based on EU Standard Contractual Clauses and additional security measures in accordance with GDPR.

7. Use of AI Models and Scientific Data

7.1 Locally Hosted AI Models

All core AI calculations (ESMFold, AlphaFold2, DiffDock, ProteinMPNN, Metal3D, Boltz2, Evo2) are performed on our own server infrastructure or on Nebius AI GPU infrastructure within the European Union. Your research data for structure prediction, molecular docking, and DNA generation is NOT transmitted to external AI services outside the EU. NVIDIA DGX Cloud is used exclusively for demonstration and testing purposes and does not process any production user data.

7.2 Google Gemini AI Integration (Optional Feature)

The Service offers optional AI-powered features through Google Gemini AI, including conversational assistance, file analysis, and intelligent search. These features are only activated when you explicitly use them by mentioning @gemini in project chats, requesting file analysis, or using the search functionality.

Data Transmitted to Google: When you use Gemini-powered features, the following data may be sent to Google's Gemini API:

  • Your query text and conversation context
  • Search queries and result context (when using search)
  • Project names and descriptions (if mentioned in the query)
  • File content (if you request file analysis, limited to first 10,000 characters)

Data Processing by Google: Google processes this data to generate AI responses. Google's data processing practices are governed by their Privacy Policy. Google may use API data to improve their services in accordance with their terms. We recommend reviewing Google's privacy policy at https://policies.google.com/privacy and their AI data usage policies.

Data Location: Google Gemini API requests may be processed on Google's servers worldwide, including outside the European Union. Data transfers to the USA are based on Google's compliance with applicable data protection frameworks.

Legal Basis: Art. 6 para. 1 lit. a GDPR (consent through active usage of the feature) and Art. 6 para. 1 lit. b GDPR (contract performance)

Your Control: You have full control over this feature. Simply avoid using @gemini mentions or AI assistance features if you prefer to keep your data entirely within our infrastructure. You can use all core protein analysis features without ever triggering Gemini integration.

7.3 Confidentiality of Scientific Data

Important Note for Researchers:
  • Your protein sequences and structure data are treated confidentially
  • We do NOT use your data for training AI models
  • Your research results remain your intellectual property
  • We do not share data with competitors, other researchers, or commercial entities

8. Data Security

We implement technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons:

  • Encryption: HTTPS/TLS for all data transmissions
  • Password Protection: Secure hash algorithms (bcrypt) for passwords
  • Two-Factor Authentication (2FA): Additional protection for user accounts
  • Access Control: Role-based access control for projects and data
  • Regular Backups: Secure data backup to prevent data loss
  • Firewall and Monitoring: Protection against unauthorized access
  • Data Encryption: Encryption of sensitive data in the database

9. Your Rights as a Data Subject

Under the GDPR, you have the following rights regarding your personal data:

9.1 Right of Access (Art. 15 GDPR)

You have the right to obtain information about the personal data we process. You can request an overview of your data in your account settings at any time.

9.2 Right to Rectification and Erasure (Art. 16, 17 GDPR)

You have the right to rectify inaccurate or incomplete data and to erase your data ("right to be forgotten"). You can delete your account and all associated data in the settings at any time.

9.3 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request restriction of processing of your data if accuracy is disputed, processing is unlawful, or data is no longer needed.

9.4 Right to Data Portability (Art. 20 GDPR)

You have the right to receive the data concerning you in a structured, commonly used, and machine-readable format. You can export your research data in the dashboard at any time.

9.5 Right to Object (Art. 21 GDPR)

You have the right to object to the processing of your personal data if it is based on legitimate interests.

9.6 Right to Withdraw Consent (Art. 7 para. 3 GDPR)

If processing is based on your consent, you can withdraw it at any time. The lawfulness of processing carried out until withdrawal remains unaffected.

9.7 Right to Lodge a Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your data.

10. Retention Period

We store your personal data only as long as necessary for the fulfillment of purposes or legal retention requirements exist:

Data Type Retention Period
Account Data (username, email) Until account deletion
Research Data (sequences, structures, jobs) Until manual deletion or account deletion
Server Log Files Maximum 90 days
Billing Data (for paid features) 10 years (legal retention requirement)
Email Communication Until account deletion + 6 months

11. Automated Decision-Making and Profiling

We do not use automated decision-making in accordance with Art. 22 GDPR. AI models are used exclusively for scientific calculation of protein structures and properties, not for evaluation or profiling of individuals.

12. Data Protection for Minors

Our service is intended for persons who have reached the age of 16. Persons under 16 may only use the service with the consent of their legal guardians. We do not knowingly collect personal data from persons under 16 without appropriate consent.

13. Changes to this Privacy Policy

We reserve the right to amend this privacy policy to adapt it to changed legal situations or changes to the service. The current version can always be found on this page. We will notify you of significant changes by email.

14. Privacy Contact

If you have questions about data protection, to exercise your rights, or for complaints, you can contact us at any time:

Data Protection Officer:

FyreFly Systems GbR
Maximilian Scheinast-Peter, Janek Franz Fabian
Email: service@fyreflysystems.com
Subject: "Data Protection - Phonos"

We strive to respond to your inquiries within 30 days.

For technical platform issues, you can use the in-app Report Bug button after login. Submitted bug reports may include your issue description plus diagnostic metadata such as current URL/view, browser user agent, platform, language, viewport/screen size, timezone, and IP address to enable troubleshooting.

Terms of Service | Licenses | Home