Nanopetica Privacy & Data Governance Policy
Effective Date: March 20, 2026
Version: 1.4 (Enterprise Standard)
1. Data Sovereignty & Stewardship
Nanopetica operates as a Data Processor for our institutional clients. We recognize that genetic information is the most sensitive form of data.
- Ownership: All raw sequencing data (FASTQ/BAM) and processed taxonomic reports remain the exclusive property of the Client. Nanopetica does not claim ownership of any biological signatures identified.
- No Third-Party Sales: Nanopetica does not—and will never—sell, lease, or trade genomic data to pharmaceutical companies, insurers, or data brokers.
2. The “De-Identification” Protocol
To ensure maximum privacy, Nanopetica utilizes a “Double-Blind” ingestion process:
- Anonymization: All samples submitted to our load-balanced cluster are assigned a 256-bit UUID (Universally Unique Identifier).
- Metadata Siloing: Personal or institutional identifiers are stored on an isolated, encrypted server, physically and logically separated from the computational nodes performing the phylogenetic alignment.
3. Infrastructure & Security
Our computational environment is designed for high-stakes industrial and clinical security:
- Encryption: Data is encrypted at rest using AES-256 and in transit via TLS 1.3.
- Cluster Security: Our load-balancing nodes operate within a Private Virtual Cloud (VPC) with restricted SSH access and real-time intrusion detection.
- Audit Trails: Every access attempt to the Client Portal is logged, timestamped, and tied to a verified IP address for institutional auditing.
4. Retention & Destruction
- Short-Term Storage: Raw data is retained only for the duration of the analysis plus a 30-day “Verification Window” unless otherwise specified in a Service Level Agreement (SLA).
- Permanent Deletion: Upon project completion or client request, data is subjected to a “Cryptographic Erase,” rendering the files unrecoverable.
5. Compliance
Nanopetica is engineered to meet or exceed global standards, including:
- GDPR: For European Union data subjects.
- HIPAA: Regarding Protected Health Information (PHI) where applicable.
- Biosecurity Guidelines: Our phylogenetic tree filtering includes flags for regulated pathogens to ensure compliance with international biosecurity protocols.