Legal

Privacy Policy

Version 2.0 — Effective March 29, 2026

business 1. Identity and Contact

This Privacy Policy is issued by:

CAGE Chemical Inc.

Incorporated in British Columbia, Canada

Privacy Officer: Cornelius van Heerden

Email: info@cagechemicals.ca

This policy applies to all personal information collected through the CAGE Research Platform ("Platform") at research.cagechemicals.ca.

database 2. Information We Collect

Account Data

Full name, email address, institution (optional), role, and password (stored as a bcrypt hash — we never store your plaintext password).

Access Request Data

If you apply via the access request form: LinkedIn URL, institution, role, research background, and intended use case. Retained until your request is processed.

Identity Verification

Verification is performed by Stripe Identity using a government-issued ID and a selfie. CAGE stores only the verification status (verified / not verified). We do not store your raw identity documents or biometric data.

Research Data

Experiment submissions, uploaded photographs, text notes, and related scientific content you contribute through the Platform.

NDA Records

When you sign the Research Contributor Agreement: your typed legal name, IP address, user agent string, and timestamp of signature.

Technical Data

IP address, browser type and version, device type, operating system, and referring URL — collected automatically via server logs.

Analytics Data

Page views, session duration, and interaction events collected via Google Analytics (Property ID: G-QWTK3BSH59), which sets its own cookies. For authenticated users, we also send pseudonymous usage properties (account role, verification status) to improve Platform analytics. No personally identifiable information is transmitted.

Date of Birth

Extracted from your identity document during Stripe verification. Used to determine eligibility and, for users under 18, to trigger parental consent requirements.

Parental/Guardian Data

For users aged 14–17: guardian name and email address, provided by the minor user, used solely to obtain and verify parental consent.

Audit Logs

Actions you take on the Platform (e.g., login, NDA signing, submissions) are logged with your IP address, user agent, and timestamp for security and compliance purposes.

Reimbursement and Financial Data

If you request reimbursement for experiment costs: estimated cost, hours spent, bill of materials, receipt images, and payment status.

Content Flags

If you report content: the type of content flagged, your reason, and any details you provide.

swap_horiz 3. How We Collect Information

  • Directly from you — when you register, sign the NDA, submit experiments, or upload content.
  • Automatically — via server logs, session cookies, and Google Analytics when you use the Platform.
  • From third parties — Stripe provides identity verification status and payment confirmation.

target 4. Purposes of Collection

Data Category Purpose
Account DataCreate and manage your account; authenticate sessions; communicate with you.
Identity VerificationVerify contributor identity for NDA enforceability and IP protection.
Research DataFacilitate collaborative research; AI-assisted experiment review; track contributions for revenue sharing.
NDA RecordsEstablish a legally binding record of agreement acceptance.
Technical DataMaintain security; diagnose technical issues; prevent abuse.
Analytics DataUnderstand usage patterns; improve Platform features and performance.

gavel 5. Legal Basis for Processing

For individuals in the European Economic Area (EEA), United Kingdom, or other jurisdictions requiring a legal basis under GDPR or equivalent legislation:

  • Contract — Processing of account data, research data, and NDA records is necessary to perform our agreement with you (the Research Contributor Agreement).
  • Consent — Analytics cookies and identity verification are processed based on your explicit consent, which you may withdraw at any time.
  • Legitimate Interest — Technical data is processed for Platform security, fraud prevention, and system reliability. We balance these interests against your rights and freedoms.

check_circle 6. Consent

We obtain your consent through the following mechanisms:

  • Account creation — By registering, you consent to the collection of account data.
  • NDA signature — By signing the Research Contributor Agreement, you consent to NDA record collection.
  • Identity verification — You initiate the Stripe Identity flow voluntarily.
  • Analytics — Google Analytics cookies are loaded only after you accept analytics cookies via the cookie consent banner. You may withdraw consent at any time by clearing your cookies, or by using the Google Analytics Opt-Out Browser Add-on.

Withdrawing consent: You may withdraw consent at any time by contacting the Privacy Officer at info@cagechemicals.ca. Withdrawal does not affect the lawfulness of processing performed before withdrawal. Note that withdrawing consent for essential account data will require account closure.

share 7. Third-Party Disclosures

We share personal information only with the following processors, and only to the extent necessary for the stated purpose:

Stripe, Inc.

Identity verification (government ID + selfie processing) and payment processing. Stripe acts as an independent controller for identity data. See Stripe's Privacy Policy.

Google Cloud Platform

Hosting, data storage (Cloud SQL, Cloud Storage), and server infrastructure. Data is processed in accordance with Google's Data Processing Addendum.

Google Analytics

Website analytics and usage tracking. Data is aggregated and pseudonymized. See Google's Privacy Policy.

Google Gemini AI

Experiment submissions — including text notes, metadata, and uploaded photographs — may be reviewed by Google's Gemini AI for scientific feedback. Researcher identities are anonymized before transmission. Gemini API (paid tier) does not use your data for model training. See Google AI Principles.

Cloudflare

Web performance and security analytics. See Cloudflare's Privacy Policy.

We do not sell, rent, or trade your personal information to any third party.

public 8. International Data Transfers

CAGE Chemical Inc. is headquartered in British Columbia, Canada. Your data may be transferred to and processed in the United States through our third-party processors (Google Cloud Platform, Stripe, Google Analytics, Google Gemini AI).

Safeguards:

  • Canada has been recognized by the European Commission as providing an adequate level of data protection.
  • Our US-based processors maintain appropriate safeguards including Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework, and binding corporate rules where applicable.
  • We enter into data processing agreements with all processors that include contractual obligations to protect your data.

schedule 9. Data Retention

Data Category Retention Period
Account DataDuration of account plus 30 days after deletion request.
Identity Verification StatusDuration of account. Raw documents are held by Stripe per their retention policy.
Research DataIndefinitely, as contributions are licensed under the Research Contributor Agreement. You may request anonymization.
NDA Records7 years after termination of the agreement, or as required by law.
Technical / Server Logs90 days, then automatically purged.
Analytics Data26 months (Google Analytics default), then automatically deleted.
Reimbursement/Financial Records7 years after the relevant tax year, as required by the Canada Revenue Agency.
Breach Records24 months from the date of discovery, as required by PIPEDA.

shield_person 10. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal information:

Under PIPEDA / BC PIPA (Canada)

  • Access — Request a copy of the personal information we hold about you.
  • Correction — Request correction of inaccurate or incomplete information.
  • Withdrawal of Consent — Withdraw consent for non-essential processing, subject to legal or contractual restrictions.
  • Challenge Compliance — Challenge our compliance with applicable privacy legislation.

Under GDPR (European Economic Area / UK)

  • Access — Obtain confirmation of processing and a copy of your data.
  • Rectification — Correct inaccurate personal data.
  • Erasure — Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
  • Portability — Receive your data in a structured, machine-readable format.
  • Restriction — Request that we limit processing of your data in certain circumstances.
  • Objection — Object to processing based on legitimate interest.
  • Automated Decision-Making — You will not be subject to decisions based solely on automated processing that produce legal effects.

To exercise any of these rights, contact the Privacy Officer at info@cagechemicals.ca. We will respond within 30 days (PIPEDA/PIPA) or without undue delay and within one month (GDPR).

lock 11. Security Measures

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption in transit — All data is transmitted over TLS (HTTPS).
  • Password hashing — Passwords are hashed using bcrypt with a unique salt per user.
  • Access controls — Administrative access to data is restricted to authorized personnel on a need-to-know basis.
  • Infrastructure security — Hosted on Google Cloud Platform with managed security controls, automated patching, and monitoring.
  • CSRF protection — Origin and Referer header verification on all state-changing requests, combined with SameSite cookie attributes.

No system is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. If we become aware of a data breach that poses a real risk to your rights, we will notify you and the relevant authorities in accordance with applicable law.

warning 12. Data Breach Notification

In the event of a data breach that poses a real risk of significant harm to you, CAGE will:

  • Notify the Office of the Privacy Commissioner of Canada (OPC) as soon as feasible;
  • Notify affected individuals directly, describing the nature of the breach, the data involved, and steps being taken;
  • Maintain a record of all breaches (whether reported or not) for a minimum of 24 months, as required by PIPEDA.

If applicable, we will also notify relevant authorities under GDPR or other applicable data protection laws.

family_restroom 13. Children and Minors

The Platform is not directed at children under the age of 14. We do not knowingly collect personal information from anyone under 14. If we discover that a user is under 14, their account will be disabled and their data deleted.

Users aged 14 to 17 may use the Platform with verifiable parental or guardian consent. Our parental consent process works as follows:

  • The minor provides their guardian's name and email address;
  • We send a verification email to the guardian with a secure, time-limited link (72-hour expiry);
  • The guardian must click the link to confirm consent;
  • Until consent is verified, the minor cannot access research content.

Minors have shorter session durations (7 days vs. 30 days for adults), and certain research tracks with elevated safety requirements are restricted to users aged 18 and older.

Identity verification via Stripe Identity requires the user to be at least 16 years old. Users aged 14–15 may create accounts but cannot complete identity verification until they reach 16.

If you are a parent or guardian and believe your child has provided personal information without your consent, contact us at info@cagechemicals.ca and we will promptly delete the information.

cookie 14. Cookies and Tracking

The Platform uses the following cookies:

Cookie Type Purpose Duration
session Essential Maintains your authenticated login session. 7 days (minor users) or 30 days (adult users)
cookie_consent Essential Stores your cookie consent preference (accepted/rejected). 1 year
_ga, _ga_* Analytics Google Analytics: distinguishes unique users and sessions. Up to 2 years
flash Essential Displays temporary status messages (e.g., “Logged out successfully”). Contains no personal data. 30 seconds

You can control cookies through your browser settings. Blocking essential cookies may prevent the Platform from functioning correctly. To opt out of Google Analytics, use the Google Analytics Opt-Out Add-on.

update 15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address and/or a prominent notice on the Platform at least 30 days before taking effect. The “Version” and “Effective Date” at the top of this page will always reflect the current version. Your continued use of the Platform after the effective date constitutes acceptance of the revised policy.

report 16. Complaints

If you believe your privacy rights have been violated, we encourage you to first contact our Privacy Officer. If you are not satisfied with our response, you have the right to lodge a complaint with the appropriate supervisory authority:

Office of the Privacy Commissioner of Canada (OPC)

www.priv.gc.ca — For complaints under PIPEDA.

Office of the Information and Privacy Commissioner for BC (OIPC)

www.oipc.bc.ca — For complaints under BC PIPA.

EU / UK Supervisory Authority

If you are in the EEA or UK, you may contact your local data protection authority. A list of EU authorities is available at edpb.europa.eu.

© 2026 CAGE Chemical Inc. All rights reserved.

Privacy Policy Version 2.0 — Effective March 29, 2026