Privacy Policy
Effective Date: July 1, 2026.
Basic information
Data Controller: SCINR DATA SL ("Scinr AI", "we", "us")
Registered address: Av. Manuel Fraga Iribarne 69, 3A, 28055 Madrid, Spain
Privacy contact: privacy@scinr.com
We do not use cookies or similar tracking technologies on our website. We do not track visitors across sites or build advertising profiles. Any data we process is described in full below.
1. Who we are
SCINR DATA SL operates Newton, an agentic memory platform for life sciences supply chain and regulatory teams, and the associated website(s) and marketing channels (together, the "Services"). We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Spanish data protection law.
2. What information we process
Depending on how you interact with us, we may process:
- Contact and prospect data: name, work email, company, job title, phone number, and the content of any message you send us through a contact form, email, or scheduling tool.
- Customer and user account data: name, work email, and role, for individuals your organization designates as users of the Newton platform, where we act as a data processor on your organization's behalf (see our Data Processing Agreement).
- Business data submitted through the Service: documents, records, and related content that a Customer organization submits to Newton for processing. We process this data as a processor, under the Customer's instructions, not as controller. If this data includes personal data belonging to a Customer's employees, suppliers, or other individuals, the Customer remains the controller of that data.
- Recruitment data: if you apply for a role with us, your CV, contact details, and application materials.
- Website usage data we do not collect via cookies: our website does not set cookies or use client-side tracking scripts. We may still receive basic server-log information (e.g., IP address, browser type, timestamp) generated automatically by standard web server operation, retained only briefly for security and troubleshooting purposes.
3. Purposes and legal basis
We process personal data for the following purposes, each under the legal basis indicated:
- Responding to inquiries and managing prospective customer relationships — legitimate interest / pre-contractual steps at your request
- Providing and maintaining the Newton platform for Customers — performance of a contract
- Processing Customer Data submitted to Newton, on Customer's instructions — processor acting under Customer's instructions (governed by the Data Processing Agreement)
- Sending product or company updates you have opted into — consent
- Complying with legal, tax, or accounting obligations — legal obligation
- Recruitment — pre-contractual steps at your request / consent
- Detecting and preventing fraud or misuse of our Services — legitimate interest
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
4. Data retention
We keep personal data only for as long as necessary for the purposes described above: for the duration of a commercial or contractual relationship plus any applicable limitation period for legal claims (generally up to 5 years under Spanish law), or until you exercise a valid deletion request, whichever is relevant. Customer Data processed on behalf of a Customer is retained and deleted in accordance with the applicable Data Processing Agreement and order.
5. Who we share data with
We share personal data only where necessary to provide the Services or comply with law:
- Infrastructure and sub-processors: cloud hosting, database, and AI model providers that support Newton (for example, cloud infrastructure providers and large language model providers), each bound by a data processing agreement.
- Business tools: CRM, email, and scheduling providers used to manage prospect and customer relationships.
- Professional advisors: accountants, auditors, or legal counsel, where necessary.
- Public authorities: where required by law or a valid legal request.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
6. International data transfers
Where a service provider is located outside the European Economic Area (EEA), we ensure an adequate level of protection through mechanisms recognized under the GDPR, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another valid transfer mechanism. Details of specific sub-processors and transfer mechanisms are available on request to privacy@scinr.com.
7. Security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure, including access controls, encryption in transit, and contractual security obligations on our providers. No system is completely secure, and we continuously review our measures as the Service evolves.
8. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure of your data, where applicable;
- request restriction of processing;
- object to processing based on legitimate interest;
- request data portability, where processing is based on contract or consent;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with a supervisory authority, in particular the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).
To exercise these rights, contact us at privacy@scinr.com or by post at our registered address above. We may request additional information to verify your identity before acting on a request.
If your personal data was submitted to Newton by a Customer organization (e.g., your employer or a business partner using the platform), that organization is the data controller for that data, and requests should generally be directed to them; we will support them in responding as required by our Data Processing Agreement.
9. Children
Our Services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under 16 years of age.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be indicated by updating the effective date above and, where appropriate, through direct notice.
11. Contact
For any question about this Privacy Policy or our data practices, contact:
SCINR DATA SL Av. Manuel Fraga Iribarne 69, 3A, 28055 Madrid, privacy@scinr.com