Stranded — Privacy Policy
1. Who We Are
Stranded is a web-based molecular biology platform operated by VerCan ApS ("we", "us", "the Company"). This Privacy Policy explains what information we collect, why we collect it, how we use it, and what choices you have.
When we say "Services", we mean app.strandedapp.eu and any product created and maintained by VerCan.
This Privacy Policy should be read alongside our Terms of Service, Data Processing Agreement, and EU Data Act Addendum.
2. What This Policy Covers (and What It Does Not)
This Privacy Policy covers the handling of personal data — information that relates to an identified or identifiable natural person, as defined by Article 4(1) GDPR.
Scientific data (sequences, alignments, assemblies, annotations, chromatograms, phylogenetic trees, and other biological datasets) is generally non-personal and is not the focus of this Privacy Policy.
However, whether data is personal data under GDPR depends on context and identifiability. Stranded is not intended for storing or processing identifiable personal data inside scientific datasets, and our Use Restrictions prohibit uploading it. If you upload scientific content that contains personal data (for example, names or identifiers in file metadata or headers), it may be treated as personal data.
Your rights regarding non-personal scientific data — including export, portability, and deletion — are described in our EU Data Act Addendum.
3. What Personal Data We Collect
We collect a minimal amount of personal data:
| Data |
How collected |
Purpose |
| Full name |
Provided at registration |
Account identification, display within the platform |
| Email address |
Provided at registration |
Authentication, account recovery, service communications |
| Avatar photo |
Optionally uploaded by you |
Display within the platform interface |
| Log files |
Collected automatically |
Security monitoring, debugging, abuse prevention |
Log files may include your IP address, session identifiers, browser type, timestamps, and records of actions performed within the platform.
We do not collect:
- Payment or financial data (payments are handled by our Merchant of Record — see Section 8 and our Terms of Service.
- Special categories of personal data under Article 9 GDPR.
- Tracking cookies for advertising or third-party analytics.
4. How We Use Your Data
| Purpose |
Legal basis (GDPR) |
| Providing and operating your account |
Performance of a contract — Art. 6(1)(b) |
| Sending service-related communications (e.g., password resets, critical notices) |
Performance of a contract — Art. 6(1)(b) |
| Displaying your avatar |
Consent — Art. 6(1)(a) |
| Security monitoring and abuse prevention via log files |
Legitimate interests — Art. 6(1)(f) |
We do not send marketing, promotional, or newsletter emails. All email communications from Stranded are strictly transactional (for example: login verification, password resets, onboarding, and critical service notices).
We will never sell, rent, or trade your personal data to third parties for marketing or advertising.
5. How Long We Keep Your Data
| Data |
Retention |
| Name & email |
For the lifetime of your account; deleted immediately when you delete your account |
| Avatar photo |
Until you remove it, or upon account deletion |
| Log files |
Rolling 22-day window; automatically purged thereafter |
You can delete your account at any time through your account settings. We delete data from active systems promptly. Residual copies may persist in backups for a limited period as part of routine backup rotation.
6. Where Your Data Is Stored
All personal data is stored and processed exclusively within data centres located in the European Union. We do not transfer personal data outside the European Economic Area. Should this ever change, we will update this policy.
7. Who Has Access to Your Data
Access to personal data is restricted to:
- You — through your account settings and profile.
- VerCan staff — only when strictly necessary, specifically:
- To respond to a support request you have made (with your express consent).
- To resolve a technical error that cannot be fixed without inspecting minimal account data.
- To investigate a security incident or abuse report.
We do not provide any third party with direct access to your personal data except as described in Section 8.
8. Third-Party Service Providers
We use third-party vendors only for infrastructure (hosting, storage, and related compute). These providers process data solely on our instructions and are bound by data processing agreements that meet or exceed the protections described in our Data Processing Agreement.
A current list of sub-processors is available upon request.
8A. Merchant of Record (Payments)
Payments, invoicing, taxes (including VAT), and refunds are handled by our Merchant of Record (MoR) as described in our Terms of Service. The MoR will process personal data related to billing and payment as an independent controller under its own privacy policy. Stranded does not receive your full payment card details.
8B. Sharing and Public Links
Stranded may allow you to create share links (optionally protected with a password) to make specific content available to people you choose.
If you create a share link, you are instructing us to disclose the linked content to anyone who has the link (and password, if enabled). You are responsible for ensuring you have the rights and legal basis to share that content.
9. Cookies
Stranded uses only strictly necessary cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
10. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Access (Art. 15) — Request a copy of the personal data we hold about you.
- Rectification (Art. 16) — Correct inaccurate data via your account settings.
- Erasure (Art. 17) — Delete your account and all personal data instantly via your account settings.
- Restriction (Art. 18) — Request restricted processing in certain circumstances.
- Portability (Art. 20) — Receive your personal data in a structured, machine-readable format.
- Objection (Art. 21) — Object to processing based on legitimate interests.
- Withdraw consent — Remove your avatar at any time; withdrawal does not affect prior lawful processing.
To exercise any right not available through your account settings, contact us at the address in Section 13.
11. Children
You must be at least 16 years of age to use Stranded. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected data from a child under 16, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in law or our practices. We will notify you of material changes by email or in-platform notification at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
For privacy-related questions or to exercise your data subject rights:
VerCan — Data Protection Contact
Email: compliance@strandedapp.eu
If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with the supervisory authority in your EU member state of residence.
This document should be read alongside the Terms of Service and EU Data Act Addendum.
Acknowledgment
VerCan policies are open source, licensed under CC BY 4.0. Adapted from the Basecamp open-source policies / CC BY 4.0.