Skip to main content
WEBSITE DATA · PRIVACY POLICY

Privacy Policy &
Website Data Handling

This notice explains how the current BioMacLab website handles information submitted through public forms and user accounts, what security metadata the application records, and how to contact BioMacLab about a privacy request. It does not claim a legal headquarters, designated privacy officer, clinical-data platform, or dedicated genomic-data transfer system that has not been formally established.

Effective: 10 Sep 2026
Reviewed: 10 Sep 2026
Revision: 1.0
SCOPE · RESPONSIBLE CONTACT

1. About This Privacy Notice

This Privacy Policy covers the public BioMacLab website, its contact and training-enquiry forms, and account-related features implemented in the current Laravel application.

BioMacLab’s final legal entity, formal controller identity, legal headquarters, and jurisdiction-specific privacy obligations have not been established in the current website project. This page therefore avoids presenting team-member locations or university affiliations as legal offices or data-controller locations.

Questions about personal information submitted through this website can be sent to the public contact channels shown on this page.

Legal identity review still required

This version is an evidence-based website privacy notice. Jurisdiction-specific controller wording, statutory notices, representative details, or formal privacy-officer designations should be added only after the corresponding legal facts are confirmed.

  • Website scope: Public pages, contact enquiries, training enquiries, authentication/account features, and administration of those records.
  • Project-specific data: Any separate research-data transfer, confidentiality arrangement, or project-processing role must be agreed for that engagement rather than inferred from this website policy.
WEBSITE DATA INTAKE

2. Information the Website Collects

The information recorded by the website depends on the feature you choose to use. The current public forms are designed for high-level enquiries rather than confidential dataset transfer.

Do not send sensitive files in the general forms

The public Contact and Training enquiry forms do not provide a genomic-data upload field. Do not paste patient-identifiable information, credentials, confidential datasets, or regulated biomedical data into these forms.

  • General Contact form: First name, last name, email address, optional phone number, enquiry type, message, and a privacy-consent timestamp. Legacy-compatible fields may also include organization and subject.
  • Training enquiries: Name, email, optional phone number, current degree or academic track, and a message describing training interest or background. These enquiries are stored through the same contact-message system.
  • Security and abuse metadata: For contact submissions, the application can store a one-way keyed hash derived from the requesting IP address and a bounded browser user-agent string to support abuse prevention and operational review.
  • User accounts: Where account features are used, the application stores the account identity and email, password hash, verification/authentication state, roles and permissions, and optional two-factor-authentication data for privileged administration.
RESEARCH DATA BOUNDARY

3. Research, Genomic & Biological Data

The current public website does not provide a general-purpose upload endpoint for FASTQ, FASTA, BAM, VCF, clinical records, or other research datasets. Public enquiry forms are intended to describe a project at a safe, high level.

If BioMacLab later agrees to receive research data for a specific project, the transfer method, permitted data types, responsibilities, confidentiality requirements, retention expectations, and any de-identification requirements should be documented for that engagement before files are exchanged.

No public genomic upload workflow

A project enquiry does not itself authorize transfer of sensitive or controlled research data. Agree an appropriate transfer process first.

  • Human or clinical information: Do not submit patient-identifiable or directly identifying clinical information through the public website forms.
  • Research-use context: The website describes research and bioinformatics services; it does not present the public forms as a clinical diagnostic or treatment platform.
PURPOSE · PROCESSING

4. Why the Website Uses Information

Information submitted through the website is used to operate the requested feature and support BioMacLab’s communication, security, and administration processes.

The specific legal basis that may apply to a person or engagement depends on the relevant legal entity, jurisdiction, relationship, and processing activity. This website does not make a blanket GDPR, PIPEDA, or other jurisdiction-specific legal-basis claim before those facts are confirmed.

Jurisdiction-specific wording is not assumed

Where a specific privacy law applies, the relevant rights and legal basis should be assessed against the actual BioMacLab legal entity and activity involved.

  • Responding to enquiries: To review, route, and reply to research, service, collaboration, training, internship, campus-workshop, privacy, or general messages.
  • Account operation: To authenticate users, enforce roles and permissions, support email verification, and provide the relevant account or administrative functions.
  • Security and abuse prevention: To apply CSRF protection, throttling, authentication controls, permissions, and limited request metadata used for abuse prevention or troubleshooting.
  • Operational records: To maintain the message or account history needed to understand prior communications and administer the website.
APPLICATION SECURITY

5. Website Security Measures

The current application includes technical controls intended to reduce common web-security and account risks. These controls apply to the website application and should not be interpreted as claims about a dedicated research-compute cluster or regulated clinical infrastructure.

No unsupported infrastructure claim

This policy does not claim BioMacLab-owned HPC/Slurm infrastructure, container isolation, a particular encryption-at-rest system, regulatory certification, or a dedicated clinical-security environment.

  • Form protection: Laravel CSRF protection is used for state-changing forms, and public submission routes use validation and rate limiting where configured.
  • Account credentials: Passwords are stored as hashes rather than readable passwords.
  • Authorization: Administrative functionality is protected through separate admin authentication plus role and permission checks.
  • Optional admin two-factor authentication: Privileged administrators can enable time-based two-factor authentication; it is optional by current policy rather than universally required.
  • Media access: The application distinguishes public and private media and applies authorization to protected administrative media actions.
DATA LIFECYCLE

6. Retention & Deletion

The current website does not implement the fixed 30-day, 90-day, or one-year automatic purge schedules that appeared in the earlier prototype copy. Records should be kept only for as long as they are reasonably needed for the purpose for which they were collected, website administration, security, or applicable legal obligations.

A formal retention schedule requires owner and legal review. Until that schedule is approved and automated where appropriate, retention or deletion is handled administratively rather than being presented as a guaranteed automatic purge.

No automatic 30-day genomic purge is claimed

The public website has no genomic-file upload workflow, and the application does not implement the prototype’s automatic research-file purge schedule.

Data Category Current Retention Position Lifecycle Approach
General Contact Messages No fixed automated period Retained for communication, operational context, security, or legal needs and may be deleted administratively when no longer required.
Training Enquiry Messages No fixed automated period Stored through the contact-message system for enquiry handling; programme-specific external registration platforms have their own policies.
User Account & Authentication Data While needed for the account / administration Used to provide authentication, authorization, verification, and security functions. Removal depends on account and operational requirements.
Consent & Abuse-Prevention Metadata No fixed automated period May be retained with the associated submission to document consent and help review abuse or security issues.
THIRD PARTIES · EXTERNAL LINKS

7. Hosting, External Services & Links

The website depends on third-party infrastructure and may link visitors to external services. Data you provide directly to an external platform is handled under that platform’s own terms and privacy practices.

External services are separate

Following an external link can cause the destination provider to collect information according to its own policy. BioMacLab does not control those external services.

  • Web hosting: The current production plan uses third-party shared web hosting rather than BioMacLab-owned web-server infrastructure.
  • External training registration: Some historical Training records link to Google Forms used for programme registration. Those links are external to the BioMacLab website.
  • Social and scholarly platforms: The website may link to Facebook, LinkedIn, Google Scholar, ResearchGate, DOI pages, journals, or other external resources. Their data practices are controlled by their operators.
  • Email delivery: Email communications may pass through the email service or hosting infrastructure configured for BioMacLab.
ACCESS · CORRECTION · DELETION

8. Privacy Requests & Applicable Rights

Depending on where you are located, the BioMacLab legal entity involved, and the applicable law, you may have rights concerning personal information held about you.

You can contact BioMacLab to ask what personal information from the website is associated with your enquiry or account, request correction, or ask for deletion where appropriate. BioMacLab may need to verify the requester’s identity before acting on a request.

Rights depend on applicable law

This page does not state that every GDPR, PIPEDA, or other statutory right applies to every BioMacLab interaction. Applicable rights should be evaluated for the real entity, jurisdiction, and activity.

  • Access: Ask for information about personal data associated with your website enquiry or account, where applicable.
  • Correction: Ask to correct inaccurate contact or account information.
  • Deletion: Ask for deletion of information where appropriate and where retention is not required for another legitimate or legal reason.
  • Other statutory rights: Additional rights may exist under the law that applies to the actual processing activity. Those rights are not limited by this summary.
BROWSER · SESSION DATA

9. Cookies & Web Telemetry

The Laravel website can use cookies and session data needed to operate forms, authentication, CSRF protection, security, and user sessions.

The current codebase contains configuration fields for analytics identifiers, but the public application does not by itself justify a statement that analytics or advertising tracking is active. If analytics, tag-management, advertising, or other non-essential tracking is enabled later, this notice and any required consent controls should be updated before relying on that processing.

Tracking disclosures must match production

Do not add claims about analytics, advertising pixels, consent banners, or cookie categories unless those technologies are actually deployed.

  • Necessary session and security data: Session/authentication and CSRF-related mechanisms are used where required for secure website operation.
  • Public contact submissions: The application can record a keyed IP hash and user-agent string with a contact submission for security and abuse review.
  • Analytics: Analytics configuration should be treated as inactive unless the corresponding tracking implementation is intentionally enabled and reviewed.
CONTACT · POLICY REVIEW

10. Privacy Contact & Policy Updates

For website privacy questions or requests concerning information submitted to BioMacLab through this site, contact the public email address below or use the Contact page.

No designated Data Protection Officer, EU representative, Canadian privacy officer, or legal privacy office is claimed by this website unless such a role is formally appointed and the relevant details are added after review.

This notice may be updated when website features, data practices, service providers, legal identity, or applicable obligations change. The effective date, review date, and revision number at the top of the page identify the published version.

Public privacy contact

Email info@biomaclab.com or use the Contact page. A privacy enquiry does not require you to send the sensitive material that the request concerns.

  • Privacy email: info@biomaclab.com
  • Secondary public email: biomaclab16@gmail.com
  • Contact page: Use the public Contact form for a high-level privacy enquiry; do not include sensitive datasets or credentials.

ACADEMIC AFFILIATIONS REPRESENTED IN THE BIOMACLAB TEAM

University of Prince Edward Island Alma Mater Studiorum – Università di Bologna Institute of Biotechnology, Bangladesh Agricultural University Jahangirnagar University Department of Fisheries, University of Dhaka Independent University, Bangladesh Mawlana Bhashani Science and Technology University Jashore University of Science and Technology (JUST)

These are individual academic affiliations from published BioMacLab team profiles and do not imply institutional partnership, endorsement, sponsorship, accreditation, client status, a legal BioMacLab office, or responsibility for this website Privacy Policy.

PRIVACY · WEBSITE DATA · QUESTIONS

Have a Privacy or Data-Handling Question?

Contact BioMacLab about information submitted through this website or to discuss project-specific confidentiality and data-transfer requirements before sensitive research material is exchanged. Any NDA, data-transfer agreement, security control, or retention term must be confirmed for the specific engagement rather than assumed from this public page.

Website Privacy Requests No Public Genomic Upload Versioned Policy Review