Privacy Policy

Effective date: September 28, 2026

Boston Data Science, LLC (“ApeiroM,” “we,” “us”) is the controller of the personal information described in this policy. ApeiroM is a business of Boston Data Science, LLC.

You can reach us at 36 Fairbanks Road, Lexington, MA 02421, United States, or privacy@apeirom.ai.

Sites covered

This policy applies to apeirom.ai, health.apeirom.ai, investment.apeirom.ai and partners.apeirom.ai, including their inquiry forms and partner sign-in.

It does not describe separate clinical, research, investment advisory, or client processing, which is governed by its own agreements and notices.

Information we collect

Information you submit. Our inquiry forms ask for your name, organization, work email, reason for contact, and a message; a phone number is optional. Submissions are stored in our hosting provider’s database and delivered by email to the relevant ApeiroM address. Please do not include sensitive information in free text.

Information generated when you visit. Our hosting and content delivery provider processes IP addresses, browser and device information such as user agent, and request and security logs, in order to deliver and protect the sites. A bot-protection service processes IP addresses and browser signals to detect automated form submissions.

Partner sign-in. If you sign in to partners.apeirom.ai, we process your email address, one-time sign-in codes, a session identifier, and records of sign-in and access attempts.

One-time codes are stored only in hashed form, expire automatically within minutes, and are deleted once used. We retain the fact and time of a sign-in, not the code itself.

We also keep a record of which organizations and individuals have been approved for partner access, including the approval and its expiry, so that access can be reviewed, audited and withdrawn.

What we do not do. We do not use third-party analytics, advertising or tracking cookies, or profiling and automated decision-making about individuals. Typefaces are served from our own infrastructure rather than a third-party font service. We do not sell personal information, and we do not share it for anyone else’s advertising purposes.

Why we use information

Purpose Information Legal basis where EU or UK GDPR applies
Receive, route, respond to and follow up on business inquiries Submitted contact details and message Legitimate interests in communicating with prospective partners and clients; steps taken at your request before entering a contract, where applicable
Operate, secure, troubleshoot and prevent abuse of the sites and forms Technical logs and bot-protection signals Legitimate interests in providing and protecting the sites
Verify the identity of approved partner users, control and review access, and answer partner security inquiries Email address, sign-in codes, session identifier, sign-in and access records, approval records Legitimate interests in controlled access and accountability; performance of a contract, where applicable
Meet legal obligations and establish or defend legal claims Relevant records Legal obligation where applicable; legitimate interests in protecting our rights

Where we rely on legitimate interests, we weigh them against the interests and rights of the individuals concerned. We do not use sign-in or access records for analytics or advertising.

Cookies and similar technologies

We do not use advertising or analytics cookies, and we do not use visitor information for cross-site behavioural advertising.

We set one cookie of our own: a session identifier, created when you sign in to partners.apeirom.ai and required to keep you signed in. It is not used on the public sites.

Our hosting, content delivery and bot-protection providers may set cookies or use similar browser storage where these are strictly necessary to deliver the sites securely and to distinguish human visitors from automated traffic. We do not use these for any other purpose.

We will review applicable consent requirements before introducing any non-essential cookies or similar technologies.

Service providers

We use service providers in the following categories:

These providers process information only to provide those services to us, under written agreements. The providers we currently use are listed at https://apeirom.ai/subprocessors.

Authorized personnel receive and respond to inquiries. We may disclose information where required by law, or where necessary to establish, exercise or defend legal rights.

International users and transfers

We are established in the United States. Information submitted through these sites may be processed in the United States and in other locations where our providers operate.

Where the EU General Data Protection Regulation or the UK GDPR applies to our processing, we comply with their requirements in respect of that processing.

Where a transfer from the EU or UK requires a transfer mechanism, we use an applicable adequacy decision or appropriate contractual safeguards for that transfer. You can request information about the safeguards that apply to your information by emailing privacy@apeirom.ai.

How long we keep information

Inquiry submissions are kept for as long as needed to respond and to maintain any resulting business relationship. We review them periodically and delete them when they are no longer required.

Technical and security logs are kept for the periods applied by our hosting provider and for our own security purposes.

Sign-in and access records, and records of partner access approvals, are kept for security, access control and audit purposes, including periodic access reviews and responding to partner security inquiries. We review partner access approvals on a quarterly basis and withdraw access that is no longer required.

One-time sign-in codes expire automatically within minutes and are not retained.

We may keep information longer where needed to meet a legal obligation, to resolve a dispute, or to establish, exercise or defend legal claims.

Security

We use access controls, service provider safeguards, and administrative and technical measures designed to protect information. Partner access is granted to named individuals or approved organization domains, carries an expiry date, and is recorded so that changes to access are attributable. We do not store passwords. No internet service is completely secure.

Your choices and rights

Contact privacy@apeirom.ai to request access to, correction of, or deletion of your personal information, or to exercise other rights available to you under applicable law.

Where the EU or UK GDPR applies, those rights may include access, rectification, erasure, restriction of processing, objection, and data portability, subject to legal conditions and exceptions. You may object to processing based on legitimate interests. You may also lodge a complaint with your local data protection supervisory authority.

We may need to verify your identity before responding.

If applicable law gives you additional privacy rights, you may exercise them through the same contact address.

Health information

Please do not submit protected health information, patient data, or other clinical information through our inquiry forms. These sites and forms are not intended to collect clinical records or to provide patient services. If you send such information despite this instruction, please contact us so that we can handle it appropriately. Any separate clinical or research work requires its own arrangements and notices.

Children

These sites are intended for a business audience and are not directed to children. Please contact us if you believe a child has submitted personal information.

Changes

We may update this policy as our sites and practices change. We will post the revised version here with a new effective date, and provide any further notice required by law.