Last updated: 6 October 2026. We review this policy every year, and whenever the site changes in a way that matters for your data.
This policy explains how Bioscience Institute processes the personal data of people who visit helixafe.com and of people who write to us through its contact form, under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and San Marino Law no. 171/2018 (“RSM Law”). The HELIXAFE programme itself has its own privacy notice, which you receive when you join it.
1. Data controller and contacts
Bioscience Institute S.p.A. Strada Rovereta, 42 – 47891 Falciano, Republic of San Marino Email: privacy@bioinst.com
Representative in the European Union: Bioscience Genomics S.r.l., Via della Ricerca Scientifica, 1 – 00133 Rome, Italy, amministrazionegenomics@bioinst.com.
Data Protection Officer (DPO): dpo.bioinst@novapoesis.it, Via Pomposa 43/i – 47924 Rimini, Italy.
2. The data we process
When you browse. The systems that run the site receive the technical data of every visit: IP address, browser and device, the page requested, date and time, and the page you came from. We use them to show you the pages, to protect the site from abuse and to find faults. The site uses no statistics or advertising tools.
When you write to us. The contact form asks for your first and last name, email, phone number, country, age and your message; we also record the page you write from. Please do not include health information in your message: we will ask for what we need when we answer.
Anti-spam check. To tell people from automated programs, the form uses Cloudflare Turnstile, which analyses technical signals from your browser, such as the IP address and device characteristics.
3. Why we process your data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Answering your request and sending you the information you ask for | Steps taken at your request before a contract (Art. 6(1)(b) GDPR; Art. 5(1)(b) RSM Law) |
| Running the site, protecting it from abuse and spam, fixing faults | Our legitimate interest (Art. 6(1)(f) GDPR; Art. 5(1)(f) RSM Law) |
| Meeting legal obligations and defending our rights | Legal obligation (Art. 6(1)(c) GDPR) and legitimate interest (Art. 6(1)(f) GDPR) |
The data marked as required are needed to answer you: without them we cannot reply.
4. Who receives your data
Your data are processed by our authorised staff and, when your request concerns them, by the companies of the Bioscience Institute group. We also use providers who process data on our behalf, as processors:
- Cloudflare, Inc.: hosting and delivery of the site, security and the anti-spam check (Turnstile);
- The Rocket Science Group LLC (Mailchimp Transactional, “Mandrill”): sending the emails generated by the form;
- Google Ireland Limited: Google Fonts and the YouTube video player;
- Vimeo.com, Inc.: the video player on some pages;
- the providers that support our IT systems.
Data may be disclosed to authorities when the law requires it. We do not sell your data and we do not publish it.
5. Transfers outside the European Union
Some providers are based in the United States (Cloudflare, Mailchimp, Vimeo) or may access data from there (Google). In those cases the transfer relies on the EU-U.S. Data Privacy Framework, for certified providers, or on the standard contractual clauses approved by the European Commission (Articles 44 onwards of the GDPR and the corresponding provisions of the RSM Law). You can ask us about the safeguards in place.
6. How long we keep your data
- Requests sent through the form: for as long as needed to handle the request and any follow-up; we then delete or anonymise them, unless the law requires us to keep them longer or we need them to protect our rights.
- Technical browsing data: for short periods, as long as needed for security and fault finding.
7. Your rights
At any time you can ask us to:
- tell you whether we process data about you, and give you a copy (access);
- correct or complete them (rectification);
- delete them when they are no longer needed or when the processing is unlawful (erasure);
- limit their use (restriction);
- give them to you in a structured, commonly used format and send them to another controller (portability);
- stop processing based on our legitimate interest (objection);
- withdraw any consent you gave, without affecting processing already carried out.
Write to privacy@bioinst.com or send a registered letter to the controller, or contact our EU representative or the DPO at the addresses in section 1. We answer free of charge within one month. You can also lodge a complaint with the data protection authority of the Republic of San Marino (Autorità Garante per la protezione dei dati personali) or with the supervisory authority of the EU country where you live or work (in Italy, the Garante per la protezione dei dati personali).
8. Cookies
The site uses only technical cookies. The details are in the Cookie policy.
9. Security
Communication with the site is encrypted (HTTPS), access to data is limited to the people who need it for their work, and our providers apply appropriate security measures. If a data breach occurs, we follow the procedures set by the GDPR and the RSM Law.
10. Minors
The contact form is meant for adults. If you are under 18, please ask a parent or guardian to contact us for you.
11. Changes
We may update this policy; the date at the top shows the version in force.
Opening in the United States
Be first to hear when HELIXAFE opens
Register for the waitlist. About one email a week, only about the science.
Join the US waitlist
