LABMEMO PRIVACY POLICY
Last Updated: 12/07/2026
1. Introduction
Welcome to LabMemo.
LabMemo (“LabMemo”, “we”, “our” or “us”) is a cloud-based platform designed to help researchers, students, laboratory professionals and other scientific users organise research projects, laboratory work and scientific information.
We recognise that the information stored within LabMemo may be valuable, confidential and, in some cases, commercially sensitive. Protecting your privacy and safeguarding your information are fundamental to how we design and operate the Service.
This Privacy Policy explains what Personal Data we collect, why we collect it, how we use and protect it, when it may be shared, how long it is retained, and the rights available to you under applicable data protection laws.
This Privacy Policy applies whenever you access or use LabMemo through our website, web application or any future mobile application that links to this Privacy Policy.
By creating an Account or using the Service, you acknowledge that you have read this Privacy Policy.
2. Definitions
For the purposes of this Privacy Policy:
Account means your registered LabMemo account.
Content means all information, files and materials that you create, upload or store within the Service, including but not limited to laboratory notes, projects, experiments, protocols, images, voice recordings, publications and attachments.
Personal Data means any information relating to an identified or identifiable natural person as defined under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR.
Processing means any operation performed on Personal Data, including collection, storage, organisation, use, disclosure, deletion or any other processing activity as defined by applicable law.
Service means the LabMemo platform and all associated services provided by us.
User, “you” or “your” means any individual using the Service.
3. Who We Are
LabMemo is operated by:
Aziqo
Business Form: Sole Proprietorship (Enskild Firma)
Organisation Number: 001110-5053
Registered Address:
Varmfrontsgatan 8, Skarpnäck
Sweden
Email:
For the purposes of applicable data protection laws, including the GDPR and the UK GDPR, Aziqo acts as the Data Controller for the Personal Data described in this Privacy Policy.
4. Who Can Use LabMemo
LabMemo is intended for individuals who are at least 16 years of age, unless a higher minimum age is required under the laws of your country.
The Service is intended primarily for researchers, students, laboratory professionals, educators and other individuals engaged in scientific, academic or biotechnology-related work.
If you are using LabMemo on behalf of an organisation, university, research institute or employer, you confirm that you have the authority to use the Service on behalf of that organisation where required.
5. Information We Collect
The information we collect depends on how you use the Service.
5.1 Account Information
When you create an account, we may collect information such as:
- your name;
- your email address;
- your country or region of residence;
- your account identifier;
- your authentication provider.
Authentication is provided through Supabase Authentication. LabMemo does not store your password, which is managed securely by our authentication provider.
5.2 Subscription Information
If you subscribe to LabMemo, we may process information relating to your subscription, including:
- subscription status;
- billing status;
- free trial eligibility;
- subscription renewal information;
- Stripe Customer ID;
- Stripe Subscription ID;
- invoices or payment status.
Payment card information is processed directly by Stripe. LabMemo never receives or stores your full payment card details.
5.3 Scientific Content
You may voluntarily create, upload or store Content within LabMemo.
Depending on how you use the Service, this may include:
- research projects;
- laboratory experiments;
- experimental methodologies;
- laboratory notes;
- meeting notes;
- protocols;
- images;
- voice recordings;
- CSV files;
- exported reports;
- scientific publications;
- references;
- other files that you choose to upload.
You retain ownership of all Content you create or upload. We process this Content solely to provide and operate the Service.
5.4 Technical Information
To operate, maintain and secure the Service, certain technical information may be processed when you use LabMemo. We do not use this information for advertising purposes or to build marketing profiles.
Information stored by LabMemo
LabMemo does not store IP addresses, browser type, device type or operating system information in its application database.
We do store:
- timestamps relating to your account and Content (such as when projects, experiments or log entries are created or updated);
- authentication session information stored locally on your device to keep you signed in until you sign out or clear your application data.
Information processed by our infrastructure provider
LabMemo is hosted on Supabase. As part of operating the Service, Supabase may automatically process certain technical information, including:
- IP address;
- request metadata (such as HTTP method, request path and response status);
- authentication events (such as sign-in, sign-out, registration and password resets);
- authentication session and token activity;
- timestamps relating to authentication and API requests; and
- user agent and similar request headers.
This information is processed solely to authenticate users, maintain security, prevent abuse, diagnose technical issues and ensure the reliable operation of the Service.
Under our current hosting configuration, authentication audit logs are retained for approximately one hour and platform logs for approximately one day before they are automatically removed by Supabase. LabMemo does not maintain its own separate logging system.
We do not use third-party analytics, crash reporting or advertising services that collect technical information about your use of the Service.
Waitlist data is retained until you request its deletion or until you create a LabMemo account, whichever occurs first.
5.5 Communications
If you contact us, we may process:
- your name;
- email address;
- correspondence;
- support requests;
- information you voluntarily provide.
This information is used primarily for customer support, responding to enquiries and improving the Service.
5.6 Information We Do Not Intentionally Collect
LabMemo is not designed for the storage of:
- payment card information;
- government-issued identification numbers;
- regulated medical records;
- protected health information subject to healthcare-specific legislation;
- special categories of Personal Data unless voluntarily uploaded by you.
If you upload Personal Data relating to other individuals, you are responsible for ensuring that you have a lawful basis for doing so and that your use of the Service complies with applicable law.
6. Legal Bases for Processing Personal Data
Where the GDPR or UK GDPR applies, we process Personal Data only where we have a lawful basis to do so.
Depending on the circumstances, our legal basis may include:
| Purpose | Legal Basis |
|---|---|
| Creating and maintaining your account | Performance of a contract |
| Providing the Service | Performance of a contract |
| Synchronising your data | Performance of a contract |
| Processing subscriptions | Performance of a contract |
| Sending password reset and verification emails | Performance of a contract |
| Customer support | Performance of a contract and legitimate interests |
| Protecting accounts and preventing abuse | Legitimate interests |
| Maintaining security logs | Legitimate interests |
| Improving reliability and stability | Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Responding to lawful requests from public authorities | Legal obligation |
| Marketing communications (if introduced in the future) | Consent |
Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
7. How We Use Your Personal Data
We use your Personal Data only where necessary to operate, maintain and improve the Service.
Depending on how you use LabMemo, we may process your Personal Data to:
- create and manage your Account;
- provide, maintain and secure the Service;
- synchronise and store your Content;
- generate exports and other requested functionality;
- process subscriptions and Premium access;
- provide customer support;
- detect, investigate and prevent fraud, abuse and unauthorised access; and
- comply with legal obligations or protect our legal rights.
We do not sell or rent your Personal Data, share it with advertisers or use it for targeted advertising.
8. Your Research Data
One of LabMemo’s primary purposes is to help users organise scientific work.
We recognise that research data may be confidential, unpublished or commercially valuable. You retain ownership of all Content you create or upload, and LabMemo claims no intellectual property rights over it. We process your Content only to provide and operate the Service and do not routinely access it except where necessary to:
- respond to a support request initiated by you;
- investigate technical or security issues;
- comply with applicable law or a valid legal request; or
- protect the rights, safety or security of LabMemo, our users or others.
Administrative database access is restricted to authorised personnel.
8.1 Artificial Intelligence
LabMemo does not use your Personal Data or your Content to train artificial intelligence or machine learning models.
If AI-powered features are introduced in the future, this Privacy Policy will be updated before those features process your Content.
8.2 Responsibility for Uploaded Content
You are responsible for ensuring that your use of the Service complies with applicable law and any contractual or institutional obligations.
Where your Content contains Personal Data relating to other individuals, confidential information or regulated data, you are responsible for ensuring that your use of the Service complies with applicable laws and any contractual or institutional obligations.
LabMemo is not intended for the storage of patient medical records, classified information or other data subject to sector-specific regulatory requirements unless expressly supported by the Service.
9. Payments
Premium subscriptions are processed securely through Stripe.
When you purchase a subscription, payment information is collected and processed directly by Stripe.
LabMemo does not receive or store your full payment card details.
Depending on your subscription, we receive limited billing-related information from Stripe, such as:
- Stripe Customer ID;
- subscription status;
- payment status;
- invoice status;
- billing country;
- subscription renewal dates.
This information is used solely to manage your subscription and provide Premium functionality.
For further information regarding Stripe’s processing of Personal Data, please refer to Stripe’s own privacy documentation.
10. Email Communications
We use Resend to deliver essential transactional emails, including account verification, password resets, security notifications, subscription updates, service announcements and customer support communications.
These communications are necessary for operating the Service and cannot be opted out of where they are required to provide your Account or comply with legal obligations.
We do not send marketing communications without your consent where required by applicable law.
Should marketing communications be introduced in the future, users will be able to opt out at any time.
11. Security
Protecting scientific information is a core design principle of LabMemo.
We implement technical and organisational measures designed to protect Personal Data and user Content against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Our security measures include, where applicable:
- encrypted communications using HTTPS and TLS;
- secure authentication and password management through Supabase Authentication;
- Row Level Security (RLS) to isolate user data;
- private cloud storage with time-limited signed URLs for uploaded files;
- access controls based on the principle of least privilege; and
- security monitoring and logging where necessary to protect the Service.
No method of transmitting information over the Internet or storing information electronically can be guaranteed to be completely secure.
Accordingly, while we take reasonable measures to protect your information, we cannot guarantee absolute security.
We regularly review and improve our security measures as the Service evolves.
If we become aware of a Personal Data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will respond in accordance with applicable law.
Where legally required, we will notify the relevant supervisory authority and affected users within the timeframes prescribed by applicable law.
12. Third-Party Service Providers
To provide the Service, we rely on selected third-party service providers that process Personal Data on our behalf or independently as separate data controllers.
Our current service providers include:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database and storage |
| Stripe | Payment processing |
| Resend | Transactional emails |
| Vercel | Hosting of the LabMemo website and web application |
These providers process Personal Data only to the extent necessary to perform the services requested by us.
We carefully select service providers based on factors including security, reliability and compliance with applicable data protection laws.
For more information about how these providers process Personal Data, please refer to their respective privacy policies available on their official websites.
13. International Data Transfers
LabMemo is primarily hosted within the European Union using Supabase’s Central EU (Frankfurt, Germany) region.
Personal Data stored in the Service, including account information, research projects, experiments, uploaded files, images and voice recordings, is primarily processed and stored within the European Union.
However, some of our service providers, including Supabase and its authorised subprocessors, may process limited Personal Data outside the European Union for purposes such as infrastructure support, email delivery, security operations or technical support.
Where Personal Data is transferred to countries that are not subject to an adequacy decision, appropriate safeguards are used, including where applicable:
• Standard Contractual Clauses approved by the European Commission;
• the UK International Data Transfer Addendum;
• adequacy decisions; or
• other lawful transfer mechanisms recognised under applicable data protection law.
Further information regarding these safeguards is available upon request.
14. Data Retention
We retain Personal Data only for as long as it is reasonably necessary to fulfil the purposes described in this Privacy Policy, including providing the Service, complying with legal obligations, resolving disputes and enforcing our agreements.
In general:
- Account information is retained while your Account remains active.
- Research Content is retained while your Account remains active.
- Subscription information is retained as necessary for accounting, tax and legal obligations.
- Customer support correspondence may be retained for a reasonable period to improve support quality and resolve future enquiries.
- Security logs may be retained for a limited period where necessary to maintain the security and integrity of the Service.
Where Personal Data is no longer required, we will securely delete or anonymise it unless continued retention is required or permitted by applicable law.
Security logs are retained only for the limited periods described in Section 5.4
Customer support correspondence may be retained for up to 24 months after the matter has been resolved in order to provide consistent customer support and maintain support history.
Subscription and billing information may be retained for as long as required under applicable accounting and tax legislation.
14.1 Backups
LabMemo relies on the backup and recovery capabilities provided by its hosting infrastructure where applicable. We do not currently use Point in Time Recovery (PITR).
15. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
- request access to your Personal Data;
- request correction of inaccurate or incomplete Personal Data;
- request deletion of your Personal Data;
- request restriction of certain processing activities;
- object to certain processing activities based on legitimate interests;
- receive a copy of your Personal Data in a structured, commonly used and machine-readable format where applicable;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local supervisory authority.
These rights may be subject to certain legal exceptions and limitations.
To exercise your rights, please contact us using the contact details provided in this Privacy Policy.
We may request reasonable information to verify your identity before responding to your request.
Where required by applicable law, we will respond within the applicable statutory timeframe.
For users located within the European Economic Area and the United Kingdom, this is generally within one month.
16. Cookies and Similar Technologies
LabMemo currently uses only essential cookies, local storage and similar technologies required to authenticate users, maintain secure sessions, remember essential preferences and operate the Service.
LabMemo does not currently use advertising cookies.
If analytics or optional cookies are introduced in the future, this Privacy Policy and any applicable Cookie Policy will be updated before such technologies are deployed where required by law.
17. Account Deletion
Users may permanently delete their Account through the Service or by contacting us. We aim to process verified deletion requests without undue delay.
For security reasons, we may require reasonable verification of identity before processing an account deletion request.
Once an Account deletion request has been completed:
- active access to the Account will be permanently removed;
- Personal Data stored within active systems will be deleted or anonymised where appropriate;
- user-generated Content will no longer be accessible through the Service;
- subscription access will end in accordance with applicable billing terms.
Once a verified account deletion request has been processed, the Account and associated Personal Data stored within LabMemo’s active systems are deleted immediately. Residual copies may temporarily remain in secure backup systems until they expire or are overwritten.
18. Children’s Privacy
LabMemo is intended for users aged 16 or older unless a higher minimum age applies under local law. We do not knowingly collect Personal Data from children below the applicable minimum age. If we become aware that such data has been collected, we will delete it as soon as reasonably practicable.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our providers, applicable law or our privacy practices. Material changes will be communicated through the Service, by email or by another appropriate method where required by law.
20. Contact Us
If you have any questions about this Privacy Policy, your Personal Data, or the way we process information, or if you wish to exercise any of your privacy rights, please contact us using the details below.
Aziqo
Business Form: Sole Proprietorship (Enskild Firma)
Organisation Number: 001110-5053
Registered Address:
Varmfrontsgatan 8
128 38 Skarpnäck
Sweden
Privacy Email:
Aziqo.studio@outlook.com
We may request reasonable information to verify your identity before responding to privacy-related requests. Where required by applicable law, we will respond within the applicable statutory timeframes.
If you are located within the European Economic Area (EEA) or the United Kingdom and believe that we have processed your Personal Data unlawfully, you have the right to lodge a complaint with the competent supervisory authority in your country. If you are located in Sweden, you may also contact the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY).
We encourage you to contact us first so that we have the opportunity to resolve your concerns directly whenever possible.