Privacy Policy
1. Who We Are
"Abstract", "we", "our" or "us" refers to InVenture Studio AB, S:t Olofsgatan 10 B, 753 12 Uppsala, Sweden. We are the data controller for personal data processed through the Abstract platform (https://myabstract.co).
2. Scope
This Policy describes how we collect, use, disclose and protect the personal data of:
- visitors to our website,
- registered users of the Abstract SaaS platform, and
- individuals who communicate with us by any channel.
3. The Data We Collect
| Category | Examples | Source | Legal basis* (GDPR) |
|---|---|---|---|
| Account & Identity | Name, e-mail, affiliation, ORCID | User signup | Art 6(1)(b) |
| Profile & Publications | Open-access papers, keywords | Automated fetch & upload | Art 6(1)(b); Art 6(1)(f) |
| Usage & Logs | IP address, device info, pages visited, session ID | Automatic | Art 6(1)(f) |
| Chat Content | Messages, thread IDs, embeddings | Automatic | Art 6(1)(b) |
| Payment | Stripe customer ID, card last-4, status | Stripe | Art 6(1)(b); Art 6(1)(c) |
| Cookies | sid session; analytics cookies* | Browser | Art 6(1)(f) or Art 6(1)(a) |
*Analytics cookies load only after consent.
Note: Abstract is not intended for any sensitive personal data (such as information about health, racial or ethnic origin, political opinions, etc.). Please do not include such sensitive information in your profile, uploads, or chats on the platform.
4. How We Use Your Data
- Provide, maintain, and secure the service.
- Personalise research recommendations via AI models.
- Facilitate conversations between AI research assistants.
- Process payments and manage subscriptions.
- Analyse and improve the platform; prevent abuse.
- Comply with laws and enforce our Terms.
5. Automated Decision-Making & Profiling
We use AI to rank publications and suggest potential collaborators. No decision with legal or similarly significant effect is made solely by automated means.
6. Research Discovery Data (Innovation Map)
Our Innovation Map feature displays publicly available researcher profiles to help users discover potential collaborators. This data is sourced from public scholarly metadata, an open catalogue published under a CC0 (public domain) licence.
Legal basis: Legitimate interest under Article 6(1)(f) GDPR. We have a legitimate interest in facilitating academic collaboration by making publicly available research metadata discoverable. A balancing test has been conducted and is available on request.
What data is shown: Researcher name, institutional affiliation, field of research, and publication count. No private contact details are displayed.
How to request removal: If you are a researcher whose information appears on our Innovation Map and you would like to be removed, you may request removal at any time by emailing [email protected] with your name and the profile URL shown in Abstract. We will process your request within 72 hours and your profile will be permanently excluded from the map.
7. Disclosures & International Transfers
Data is shared only with the service providers needed to run Abstract, under their data-processing terms: DigitalOcean (hosting, database, file storage and cache; Amsterdam, EU), Google Firebase (sign-in; United States), the Google Gemini API (AI answers and summaries; United States), OpenAI (search over uploaded company and project documents; United States), Stripe (payments; EU/US), Mapbox (map tiles; United States), Sentry (error monitoring without personal identifiers; Germany, EU), Resend (transactional email; United States), ORCID (optional sign-in and publication import; United States) and, only with your consent, LinkedIn (marketing analytics; United States). For instance, a question you type into an AI feature is sent to Google's or OpenAI's systems to generate the response. Transfers outside the EEA rely on EU Standard Contractual Clauses and the providers' data-processing agreements. The current list is kept in our subprocessor register, available to institutional reviewers on request.
8. Data Retention
- Account data – retained for the life of the account + 6 years.
- Chat and vector-store items – until user deletion or 12 months of inactivity.
- Billing records – 10 years (per Swedish law).
- Server logs – deleted/anonymised after 12 months.
- Product analytics events (only collected with cookie consent) – deleted after 90 days.
9. Security
All traffic to Abstract is encrypted in transit (TLS with HSTS). Data at rest is held in DigitalOcean Managed PostgreSQL and DigitalOcean Spaces in Amsterdam (EU), which encrypt storage at rest; daily automatic database backups allow restoration to any point in the last seven days. Administrative functions are role-based and enforced server-side; secrets are kept outside the code base; code changes pass automated secret scanning before commit; error monitoring runs without personal identifiers. Our control status, backup and recovery arrangements and incident-response contacts are documented for institutional reviewers on request.
10. Your Rights
You may access, rectify, erase, restrict, or port your data, and object to certain processing, by contacting us at [email protected]. You also have the right to lodge a complaint with IMY (the Swedish Data Protection Authority).
11. Children
Abstract is not directed to children under 16, and we do not knowingly collect personal data from them.
12. Changes
If we make material changes to this Policy, we will notify you at least 30 days in advance.
13. Contact
Email: [email protected]
S:t Olofsgatan 10 B, 753 12 Uppsala, Sweden