Last updated: July 2026 | Applicable to the Phonos web application
FyreFly Systems GbR
Maximilian Scheinast-Peter, Janek Franz Fabian
Bergstraße 16
06366 Köthen
Germany
Email: service@fyreflysystems.com
Website: fyreflysystems.com
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is FyreFly Systems GbR, represented by Maximilian Scheinast-Peter and Janek Franz Fabian.
The protection of your personal data is very important to us. This privacy policy informs you about the nature, scope, and purpose of the processing of personal data when using our Phonos web application ("Service"). We process your data exclusively on the basis of the legal provisions (GDPR, TKG).
When you access our website, the browser on your device automatically sends information to our web server. This information is temporarily stored in a log file:
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring system security and stability)
Retention period: The data is deleted as soon as it is no longer required for the purpose of its collection, and no later than after 90 days.
Registration is required to use our Service. We collect the following personal data:
| Data Type | Purpose of Processing | Legal Basis |
|---|---|---|
| Username | Identification and authentication | Art. 6(1)(b) GDPR (contract performance) |
| Email address | Communication, two-factor authentication, password reset | Art. 6(1)(b) GDPR (contract performance) |
| Password (hashed) | Authentication and access protection | Art. 6(1)(b) GDPR (contract performance) |
| Profile picture (optional) | Personalization of the user profile | Art. 6(1)(a) GDPR (consent) |
| Organization/team membership | Project management and access control | Art. 6(1)(b) GDPR (contract performance) |
When using the Service, we process the following data:
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in providing the services)
Retention period: Your research data is stored for as long as your account is active. You may delete individual files or projects at any time.
In order to improve our Service, we collect anonymized usage statistics:
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in optimizing our Service)
We use technically necessary cookies to provide the Service. These cookies are essential for the functioning of the website:
| Cookie Name | Purpose | Duration |
|---|---|---|
| session | Maintaining your login session | Session (until logout) |
| csrf_token | Protection against cross-site request forgery attacks | Session |
| user_preferences | Storing your user preferences (language, theme, etc.) | 1 year |
| disclaimer_accepted | Storing the disclaimer consent | Session |
| phonos-language | Storing your language preference | 1 year |
| analytics_consent | Storing analytics consent preference (server-side readable) | 1 year |
| phonos_remember | "Remember me" token for persistent login (rotating, theft-detecting); only set if you tick "Keep me signed in" at login | 30 days (sliding; 90-day hard cap) |
| phonos_2fa_trust | Device/IP trust token to skip the email 2FA step on a trusted device (optional, off by default) | 3 days |
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical functionality and security) for essential cookies; additionally Art. 6(1)(b) GDPR (performance of a contract) for the phonos_remember and phonos_2fa_trust cookies, as they implement a sign-in convenience you requested; Art. 6(1)(a) GDPR and § 25(1) TTDSG for the analytics_consent cookie (which stores your consent choice).
In addition to cookies, we use your browser's localStorage to store the following consent-related items:
| Key | Purpose | Duration |
|---|---|---|
| cookie-consent-v2 | Storing your cookie consent decision ("accepted" or "rejected") | Until cleared by user or browser |
| cookie-consent-date | Timestamp of your consent decision | Until cleared by user or browser |
| cookie-preferences | Granular cookie category preferences | Until cleared by user or browser |
| cookie-consent-version | Version of the cookie/privacy policy you agreed to (so we can re-ask if it changes) | Until cleared by user or browser |
These localStorage items themselves are not transmitted to our servers. When you make a choice, however, we store a server-side record as proof of consent (Art. 7(1) GDPR): the timestamp, the choice made, the policy version, technical access metadata (IP address, browser/user-agent) and — for signed-in users — your account ID. You can clear the localStorage items at any time via your browser settings or by withdrawing consent in the cookie settings panel.
We use Cloudflare as a Content Delivery Network (CDN) and for security services. Cloudflare sets cookies to protect the website and optimize delivery:
| Cookie Name | Purpose | Duration |
|---|---|---|
| __cflb | Load balancing - traffic distribution | Session |
| __cf_bm | Bot management for security | 30 minutes |
| cf_clearance | Security verification (after challenge) | 1 year |
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and fast website delivery)
Privacy policy: https://www.cloudflare.com/privacypolicy/
Our server infrastructure is hosted on Google Cloud Platform (GCP) in the European Union. Google may set technical cookies for:
Hosting location: Google Cloud Platform, European Union
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable hosting)
Privacy policy: https://policies.google.com/privacy
We use Google Analytics 4, a web analytics service provided by Google, to understand how visitors use the Service and to improve it. Google Analytics is loaded only after you give your consent via our cookie banner (Google Consent Mode is set to "denied" by default and is updated to "granted" only when you opt in). If you reject analytics cookies, Google Analytics is not activated and no analytics cookies are set.
Your choice is recorded only in your own browser: in localStorage (cookie-consent-v2 holds the decision, cookie-preferences the per-category selection, and cookie-consent-date / cookie-consent-version record when and against which policy version you decided) and in an HTTP cookie named analytics_consent (value 1 or 0, SameSite=Strict; Secure, 1 year expiry) so the server can also detect your preference. Our cookie banner presents equally prominent "Accept all" and "Reject all" buttons next to a granular toggle, and analytics is switched off by default. We ask for your choice again after 12 months, or sooner if this policy materially changes.
You can withdraw or change your consent at any time, as easily as you gave it — by reopening the cookie settings banner here, or via the Cookie Settings panel in your account settings. Withdrawing analytics consent also deletes Google's _ga / _gid cookies from your browser. To be able to demonstrate that consent was given (Art. 7(1) GDPR), we keep a server-side record of each consent action — the timestamp, the choice made, the policy version, the usual technical access metadata (IP address, browser/user-agent) and, for signed-in users, your account ID. It is stored as part of our audit logs (legal basis Art. 6(1)(c)/(f) GDPR — complying with and proving compliance with consent obligations), contains no analytics data, and is used solely as proof of consent.
We have enabled IP anonymization (anonymize_ip), so your IP address is truncated by Google before any storage or further processing. Analytics cookies are set with the SameSite=Strict; Secure flags.
| Cookie Name | Purpose | Duration |
|---|---|---|
| _ga | Distinguishes unique users (Google Analytics) | up to 2 years |
| _ga_<container-id> | Persists session state (Google Analytics 4) | up to 2 years |
| _gid | Distinguishes unique users | 24 hours |
Data collected: anonymized IP address, page views, referrer, approximate location (country/region level), device, browser and operating system information, and interaction events.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for users in the EU/EEA), with onward processing by Google LLC, USA.
Measurement ID: G-F47CK5SK8J
Legal basis: Art. 6(1)(a) GDPR (your consent) and § 25(1) TTDSG (storage of and access to information on your device). You may withdraw your consent at any time with effect for the future via the cookie settings.
Third-country transfer: Data may be transferred to the USA. Google LLC relies on the EU Standard Contractual Clauses and the EU–US Data Privacy Framework as the transfer mechanism.
Privacy policy: https://policies.google.com/privacy · Google Analytics data practices
We do not use Google Analytics data for advertising, ad personalization, or cross-site profiling (ad_storage, ad_user_data, and ad_personalization remain denied). We use no other third-party trackers such as Facebook Pixel.
We do not share your personal data with third parties unless:
We use the following data processors and third-party providers:
| Service Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (compute, storage, networking) for the Phonos platform | EU/Schengen Area (Frankfurt, Ireland, Stockholm, Paris) |
| Google Cloud Platform (GCP) | Hosting of server infrastructure and databases | EU/Schengen Area |
| Nebius AI | GPU compute infrastructure for AI/ML model execution (Boltz2, Evo2, and other computational models) | EU/Schengen Area |
| Cloudflare, Inc. | Content Delivery Network (CDN), DDoS protection, SSL/TLS encryption | EU/USA (Standard Contractual Clauses) |
| IONOS SE | Email delivery (transactional emails, 2FA codes, notifications) | Germany (GDPR compliant) |
| Stripe, Inc. | Payment processing for premium subscriptions | EU/USA (Standard Contractual Clauses, GDPR compliant) |
| NVIDIA DGX Cloud / NVIDIA NIM | GPU inference for models offered in Research Preview mode. Inputs you submit to a Research Preview model (sequences, structures, ligands, parameters) are sent to NVIDIA NIM APIs for processing. | USA (Standard Contractual Clauses + EU–US Data Privacy Framework) |
| Google LLC (Gemini AI) | Optional conversational AI assistance, file analysis, and AI-powered search (activated when using @gemini mentions or search functionality) | Worldwide / USA (Standard Contractual Clauses + EU–US Data Privacy Framework) |
| Google LLC / Google Ireland Ltd. (Google Analytics) | Consent-based, IP-anonymized website analytics (only loaded after you accept analytics cookies) | EU with onward transfer to USA (Standard Contractual Clauses + EU–US Data Privacy Framework) |
Data processing agreements have been concluded with all processors in accordance with Art. 28 GDPR. For transfers to third countries outside the EU, EU Standard Contractual Clauses are used.
Parts of the Phonos platform run on Amazon Web Services (AWS) cloud infrastructure within the European Union / Schengen Area (preferentially in the Frankfurt, Ireland, Stockholm, or Paris regions). AWS provides the underlying compute, storage, and networking resources required to operate the Service. Resources may be distributed across one or more EU/Schengen regions for resilience and performance; no data leaves the EU/Schengen Area.
Processed data: Technical data (IP addresses, access logs), application data (temporary compute data, cached assets)
Privacy policy: https://aws.amazon.com/privacy/
Data processing agreement: AWS GDPR Data Processing Addendum (https://aws.amazon.com/compliance/gdpr-center/)
Legal basis: Art. 6(1)(f) GDPR, Art. 28 GDPR
Our server infrastructure runs on Google Cloud Platform within the European Union / Schengen Area. All your data is stored exclusively on servers within the EU/Schengen Area. Resources may be distributed across one or more regions for resilience and performance; no data leaves the EU/Schengen Area.
Processed data: Technical data (IP addresses, access logs), all application data (user accounts, project data, research data, database contents)
Privacy policy: https://policies.google.com/privacy
Legal basis: Art. 6(1)(f) GDPR, Art. 28 GDPR
Part of the Phonos platform runs on our own (on-premise) servers operated by FyreFly Systems GbR in Germany. These servers host application and database workloads and form part of our EU-based infrastructure together with AWS, Google Cloud Platform, and Nebius AI. On-premise infrastructure is operated under our own technical and organizational measures (see Section 8).
Nebius AI provides GPU compute infrastructure within the European Union / Schengen Area that we use to run our self-hosted AI/ML worker models (e.g. Boltz2, Evo2, and other computational models that are not in Research Preview mode). Inputs and results processed on this infrastructure remain within the EU/Schengen Area.
Processed data: Protein sequences, structural data, job parameters, temporary compute data
Privacy policy: https://nebius.com/legal/privacy
Data processing agreement: Concluded in accordance with Art. 28 GDPR
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 28 GDPR
Cloudflare improves the performance and security of our website through caching, DDoS protection, and SSL encryption. IP addresses and technical information are processed.
Privacy policy: https://www.cloudflare.com/privacypolicy/
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and performance)
When you subscribe to a paid plan, payment information is transmitted directly to Stripe. We do NOT store complete credit card data on our servers.
Processed data: name, email address, billing address, payment method (tokenized)
Privacy policy: https://stripe.com/privacy
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligations)
Some AI/ML models are offered in Research Preview mode. When you run such a model, the inference is performed through NVIDIA NIM APIs hosted on NVIDIA DGX Cloud. The input you submit for that model — including protein sequences, structural data, ligands, and job parameters — is transmitted to NVIDIA for processing and may be processed on servers located in the United States. Models that are not labeled "Research Preview" run on our EU/Schengen infrastructure (on-premise, AWS, Google Cloud Platform, or Nebius AI) and their inputs are not sent to NVIDIA DGX Cloud.
Because Research Preview inference involves a transfer to a third country, you should not submit confidential, proprietary, or personal data to Research Preview models that you are not comfortable sharing with NVIDIA under its terms.
Processed data: protein sequences, structural/molecular data, job parameters, and the resulting predictions
Privacy policy: https://www.nvidia.com/en-us/about-nvidia/privacy-policy/
Third-country transfer: EU Standard Contractual Clauses and the EU–US Data Privacy Framework
Legal basis: Art. 6(1)(b) GDPR (performance of the requested computation) and Art. 6(1)(f) GDPR (legitimate interest in operating the Research Preview)
Consent-based, IP-anonymized website analytics. Google Analytics is loaded only after you accept analytics cookies via the cookie banner and is described in detail in Section 5.4 above.
Processed data: anonymized IP address, page views, device/browser information, interaction events
Provider: Google Ireland Limited (EU), with onward processing by Google LLC, USA
Privacy policy: https://policies.google.com/privacy
Third-country transfer: EU Standard Contractual Clauses and the EU–US Data Privacy Framework
Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TTDSG
When you explicitly use Gemini features by @mentioning gemini in project chats or requesting file analysis, your queries and context are sent to Google's Gemini API.
Processed data: user queries, project context, file content (optional, limited to 10,000 characters)
Privacy policy: https://policies.google.com/privacy
Legal basis: Art. 6(1)(a) GDPR (consent through active usage), Art. 6(1)(b) GDPR (contract performance)
Note: This is an optional feature. You can use all core features without activating Gemini integration.
Your account data, project data, stored files, and the results of your scientific calculations are stored on infrastructure within the European Union / Schengen Area — namely our own on-premise servers in Germany together with AWS, Google Cloud Platform, and Nebius AI. Models that are not labeled "Research Preview" are also executed on this EU/Schengen infrastructure.
Exception 1 — Research Preview models (NVIDIA DGX Cloud / NVIDIA NIM): When you run a model that is offered in Research Preview mode, the input you submit for that computation is transmitted to NVIDIA NIM APIs on NVIDIA DGX Cloud and may be processed in the United States. The Research Preview status is indicated in the interface, and you control which models you run.
Exception 2 — Optional Gemini feature: If you choose to use the optional Gemini AI features by @mentioning gemini, the data you send in those specific queries may be processed by Google on servers worldwide, including the USA. This is clearly communicated when you use the feature, and you have full control over what data you share with Gemini.
Exception 3 — Consent-based Google Analytics: If you accept analytics cookies, anonymized analytics data may be transferred to Google in the USA (see Section 5.4).
In addition, Cloudflare and Stripe may transfer technical data (IP addresses, metadata) to the USA as part of their services. All transfers to the USA described above are based on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with additional safeguards in accordance with the GDPR.
AI/ML models are executed in one of two ways depending on the model:
Whether a given model runs in Research Preview mode is indicated in the interface, so you can decide which data to submit to which model.
The Service offers optional AI-powered features through Google Gemini AI, including conversational assistance, file analysis, and intelligent search. These features are only activated when you explicitly use them by mentioning @gemini in project chats, requesting file analysis, or using the search functionality.
Data transmitted to Google: When you use Gemini-powered features, the following data may be sent to Google's Gemini API:
Data processing by Google: Google processes this data to generate AI responses. Google's data processing practices are governed by their privacy policy. Google may use API data to improve their services in accordance with their terms. We recommend reviewing Google's privacy policy at https://policies.google.com/privacy and their AI data usage policies.
Data location: Google Gemini API requests may be processed on Google's servers worldwide, including outside the European Union. Data transfers to the USA are based on Google's compliance with applicable data protection frameworks.
Legal basis: Art. 6(1)(a) GDPR (consent through active usage of the feature) and Art. 6(1)(b) GDPR (contract performance)
Your control: You have full control over this feature. Simply avoid using @gemini mentions or AI assistance features if you prefer to keep your data entirely within our infrastructure. You can use all core protein analysis features without ever triggering Gemini integration.
We implement technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons:
Under the GDPR, you have the following rights regarding your personal data:
You have the right to obtain information about the personal data we process. You can request an overview of your data in your account settings at any time.
You have the right to rectify inaccurate or incomplete data and to erase your data ("right to be forgotten"). You can delete your account and all associated data in the settings at any time.
You have the right to request restriction of processing of your data if accuracy is disputed, processing is unlawful, or data is no longer needed.
You have the right to receive the data concerning you in a structured, commonly used, and machine-readable format. You can export your research data in the dashboard at any time.
You have the right to object to the processing of your personal data if it is based on legitimate interests.
If processing is based on your consent, you can withdraw it at any time. The lawfulness of processing carried out until withdrawal remains unaffected.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority competent for us is the State Commissioner for Data Protection of Saxony-Anhalt (Landesbeauftragter für den Datenschutz Sachsen-Anhalt), as FyreFly Systems GbR is based in Köthen, Saxony-Anhalt. Alternatively, you may also contact the data protection supervisory authority of your habitual residence or place of work.
We store your personal data only as long as necessary for the fulfillment of purposes or legal retention requirements exist:
| Data Type | Retention Period |
|---|---|
| Account data (username, email) | Until account deletion |
| Research data (sequences, structures, jobs) | Until manual deletion or account deletion |
| Server log files | Maximum 90 days |
| Consent records (proof of consent) | For as long as necessary to prove that consent was obtained, in line with applicable limitation periods |
| Billing data (for paid features) | 10 years (legal retention requirement) |
| Email communication | Until account deletion + 6 months |
We do not use automated decision-making in accordance with Art. 22 GDPR. AI models are used exclusively for scientific calculation of protein structures and properties, not for evaluation or profiling of individuals.
Our service is intended for persons who have reached the age of 16. Persons under 16 may only use the service with the consent of their legal guardians. We do not knowingly collect personal data from persons under 16 without appropriate consent.
We reserve the right to amend this privacy policy to adapt it to changed legal situations or changes to the service. The current version can always be found on this page. We will notify you of significant changes by email.
If you have questions about data protection, to exercise your rights, or for complaints, you can contact us at any time:
Data Protection Contact Point:
FyreFly Systems GbR
Maximilian Scheinast-Peter, Janek Franz Fabian
Email: service@fyreflysystems.com
Subject: "Data Protection - Phonos"
Due to our size and structure as a GbR, we are not legally required to appoint a Data Protection Officer (Art. 37 GDPR, § 38 BDSG). The controller within the meaning of the GDPR is the provider named in Section 1 above; please direct all data protection matters to the email address above.
We strive to respond to your inquiries within 30 days.
For technical platform issues, you can use the in-app Report Bug button after login. Submitted bug reports may include your issue description plus diagnostic metadata such as current URL/view, browser user agent, platform, language, viewport/screen size, timezone, and IP address to enable troubleshooting.