Privacy policy
mZero collects personal data from people who apply to join the network, members of labs that use the portal, and primary laboratory contacts whose details coordinate compound delivery. This page says what we hold, why, and how to get it back or deleted.
Version 1.9 · Effective 26 August 2026
What we collect
If you apply to join the network
Through the request access form: your email address, laboratory or institution name, mosquito colony access and strain or source where applicable, controlled-room availability, the assay formats you can run, and the free-text description of your research you choose to write. The same application collects the physical delivery address, the primary laboratory contact’s name, work email address and phone number, and delivery restrictions or special instructions. We also record your results-sharing confirmation and when you gave it.
If your lab joins and you use the portal
Your approved work email address and Lab ID; your lab membership and role; and a record of the files you upload, including filename, size, type, timestamp, and the lab folder they landed in. Sign-in uses your Lab ID.
If you register for an onboarding session
Your name, work email, institution, role, and the session you chose.
What we do not collect
- No advertising or analytics trackers. The site sets no advertising cookies and runs no third-party analytics.
- No special category data. Do not send health, biometric, or other special category personal data through this site.
- No human-subject data. The mZero assay uses heat as the attractant. If your own work involves human volunteers, that data stays with you under your own ethics approval and must never be uploaded to the corpus.
Why, and on what legal basis
| Data | Purpose | Legal basis (UK/EU GDPR Art. 6) |
|---|---|---|
| Request Access application, including compound delivery details | Assess whether a lab can run the assay, contact you, and coordinate safe compound delivery | Steps you ask us to take before a participation arrangement, our legitimate interests in assessing and operating the lab network, and compliance with legal obligations where delivery, customs, or import law requires. |
| Portal account and lab membership | Authenticate you, attribute uploads to the right lab, keep the corpus auditable | Performance of the participation arrangement with your institution and our legitimate interests in a secure, attributable research record. |
| Upload records and receipts | Data provenance: tracing any value in the atlas to the file it came from | Legitimate interests in research integrity and reproducibility. |
| Onboarding registration | Send you the invitation and joining details | Consent. |
| Server and security logs | Keep the service running and detect abuse | Legitimate interests in security and availability. |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time through the contact details under Your rights.
How long we keep it
- Applications that are not accepted: 12 months from the decision, then deleted.
- Applications that are accepted: kept for the duration of participation, then 24 months, as the record of how the lab entered the network.
- Portal accounts: for as long as your lab participates. Deleted within 90 days of a lab leaving or of you leaving the lab.
- Upload provenance records: retained indefinitely, because the corpus's audit trail depends on them. These identify the lab and the file, not you personally.
- Onboarding registrations: 12 months.
- Server and security logs: 90 days.
Your rights
If you are in the UK or EEA, the GDPR gives you the rights below. We extend them to every applicant, lab member, and shipping contact regardless of location, because operating two standards is not worth the complexity.
- Access. Get a copy of the personal data we hold about you.
- Rectification. Have anything inaccurate corrected.
- Erasure. Have your personal data deleted. Published assay results attributed to your lab are not personal data and stay in the corpus.
- Restriction and objection. Ask us to pause processing, or object where we rely on legitimate interests.
- Portability. Receive the data you gave us in a machine-readable format.
- Withdraw consent. Where we rely on consent, withdraw it at any time. This does not affect processing already carried out.
The data controller is Monarch Crops Inc, 4701 Doyle Street, Suite 14, Emeryville, California 94608, United States. To exercise these rights or ask about this policy, contact support@mzerolab.org. We respond within one month. There is no charge.
If you think we have handled your data badly, you can complain to your national data protection authority. In the UK that is the Information Commissioner's Office at ico.org.uk.
Security
Traffic is encrypted in transit. Applications, including compound delivery details, remain in private Google Cloud Firestore, and lab workspaces remain in private Google Cloud Storage. Access to stored applications is limited to the people who review them. The authenticated portal limits each lab's upload and file-management operations to its assigned Metadata/ and Video Footage/ paths; the browser does not receive Google Cloud credentials or request a storage token from the user. Research uploads are available to registered mZero network labs through the authenticated portal, while direct Google Cloud Console access requires a separate bucket-level permission. None of these files is anonymously readable on the public internet. Sessions are signed and expire. Our backend authenticates to Google Cloud using short-lived federated credentials rather than long-lived keys.
Changes to this policy
Material changes are versioned and dated here, and participating labs are told. Continuing to use the portal after a change means the updated policy applies to you.
Version 1.2 · Effective 15 August 2026 · See also the governance terms.