Skip to content
BenchLogBack to home
PRIVATE BETA

Privacy notice

Updated 1 August 2026

Who is responsible

Sönke Morrow
BenchLog
c/o MDC#1264
Welserstraße 3
87463 Dietmannsried
Germany

Email: hello@benchlog.de

Sönke Morrow is responsible for beta access, accounts, service operation, support and security data. A participating lab may be responsible for scientific records its researchers enter. Those roles must be clarified with the lab before broader or regulated use.

What we collect

For an access request, we collect your name, work email, optional institution, work context and message, plus the request time and a limited abuse-prevention value derived from request information.

When you use BenchLog, we handle account details, lab membership, protocols, experiment records, notes, deviations, timers, outcomes, short voice notes and the event history needed for a traceable record. Your device keeps a local working copy and queued changes in browser storage so the app can work through weak or missing connectivity.

When you contact us, we keep the message and the details needed to investigate and answer it.

Purposes and legal bases

  • Access requests and beta participation: reviewing requests, creating accounts, providing the app, synchronization, lab sharing, exports and support. Legal basis: steps requested before, and performance of, the beta arrangement (Article 6(1)(b) GDPR).
  • Service and security: preventing misuse, diagnosing reliability problems, protecting accounts and keeping an auditable service record. Legal basis: our legitimate interests in operating a secure and dependable research service (Article 6(1)(f) GDPR).
  • Operational messages: access acknowledgements, invitations, onboarding and material service notices. Legal basis: the beta arrangement and our legitimate interest in administering it (Article 6(1)(b) and (f) GDPR). BenchLog does not use these addresses for unrelated advertising.
  • Legal duties: preserving or disclosing limited information where law requires it (Article 6(1)(c) GDPR).
  • Optional browser transcription: if you actively enable it before recording, the browser or device may use its own speech-recognition service. Legal basis for BenchLog enabling that optional function: your consent (Article 6(1)(a) GDPR). You can record without it.

You may object to processing based on legitimate interests. We then stop unless compelling legitimate grounds or legal claims require continued processing.

Device storage and tracking

BenchLog uses local storage, IndexedDB and a service worker for sign-in continuity, theme settings, offline records, queued synchronization and installation as a PWA. These functions are necessary to provide the app you request. The public landing page does not use advertising trackers, analytics pixels or optional marketing cookies. For that reason BenchLog currently shows no cookie-consent banner.

Voice notes and browser transcription

Audio recording requires microphone permission. Saved voice notes are uploaded to private storage and linked to the relevant run. Browser transcription is off by default and is not required to record.

If you switch browser transcription on, your browser or operating system may send speech to a service operated by its vendor. BenchLog cannot select, verify or contractually control that vendor service. The interface warns you before activation and labels the result as a browser-generated draft that must be checked. Do not enable it for confidential or special-category data unless your organization has approved the browser service.

Providers, locations and transfers

BenchLog uses Supabase for authentication, database and private voice storage in the Frankfurt region; GitHub Pages to deliver the public site and application files; Resend for beta-request and onboarding email; and IONOS for the domain, DNS and role-address mail services.

Core application content is configured for the Supabase Frankfurt region. Provider account data, delivery metadata, security logs and support data may also be processed outside the European Economic Area, particularly in the United States. Where required, transfers rely on an applicable adequacy decision or contractual safeguards such as the European Commission’s Standard Contractual Clauses. You may request information about the safeguard relevant to your data at hello@benchlog.de.

Who can see it

Within the product, access is limited by account and lab permissions to the record owner and authorized members of the relevant lab. The BenchLog operator may access backend data when needed to provision an account, answer support, investigate a security or synchronization problem, recover the service, or comply with a valid legal request. Service providers receive only the data needed for their stated function.

How long we keep it

Active scientific records remain while the account or beta relationship is active. Removing a run makes it recoverable and eligible for administrative review after 90 days; the beta does not currently purge it automatically. Ask us to delete an account or eligible records when they are no longer needed.

We review access requests at least every six months and plan to delete declined or unanswered requests after 12 months unless you ask to remain under consideration or a legal reason requires a limited record. Support data is kept only as long as needed to resolve the matter and document material security decisions. Provider logs follow the applicable provider plan and contract.

Is providing data required?

Requesting beta access is voluntary. A name, reachable email address and issued login are needed to review a request and provide an account; without them we cannot offer the beta. Scientific content is entered at the researcher’s or lab’s choice, but some fields are required to complete a reviewed run. Do not enter patient data or other special-category personal data unless a separate written agreement and approved safeguards are in place.

Automated decisions and AI

BenchLog does not score researchers, interpret scientific results, profile users, or make decisions with legal or similarly significant effects. No access decision is made solely by automated processing. Optional browser speech recognition only drafts editable text; it does not make a scientific decision and must be checked by the researcher.

Your rights

Subject to the legal conditions, you may request access, correction, deletion, restriction and portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

Email hello@benchlog.de. We may need to verify your identity. If your request concerns research content controlled by your lab, we may direct the request to that lab.

You may lodge a complaint with a data-protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. The supervisory authority responsible for BenchLog’s operator is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (LfDI RLP), Hintere Bleiche 34, 55116 Mainz, Germany.

Security and beta limits

BenchLog uses sign-in, database Row Level Security, private voice storage, server-controlled event provenance, protected releases and local recovery queues. No system eliminates risk.

BenchLog is an early, invitation-only beta for non-regulated research and development. It is not a medical device, clinical record system or validated regulated-laboratory system.

Changes

We update the date at the top when this notice changes. If a material change affects active beta participants, we will communicate it through the service or the contact address associated with the account.

BenchLog · Private Beta
ImpressumPrivacyAccessibility