01 / MASCOPE PRIVACY POLICY
Mascope Privacy Policy
This notice explains how personal data is processed when you use the Mascope service, operated by Ultra Trace Systems Oy, A.I. Virtasen aukio 1 A 318, 00560 Helsinki, Finland ("Ultra Trace", "we").
Privacy contact: privacy@ultratrace.eu
This notice covers the Mascope service. Personal data collected through the ultratrace.eu website - enquiries you send us, cookies and site analytics - is covered by our separate website privacy notice.
03 / INFORMATION
The personal data processed when using the service consists of the following:
Account data: name, email address, password (stored only as a cryptographic hash), role and workspace membership.
Usage and log data: IP addresses, timestamps and actions performed in the service, kept in technical server logs; technical error reports, which may include your user identifier.
Support and contact data: the content of messages you send us.
Your account is normally created by your organisation's Mascope administrator, so most account data reaches us from your organisation rather than from you directly.
Mass-spectrometry measurement data and analysis results processed in Mascope are your organisation's scientific data, not personal data about you.
04 / PURPOSE AND LEGAL BASIS
Purpose
Legal basis
Providing, operating and securing the service
Your organisation's contract with Ultra Trace; our legitimate interest in keeping the service secure
Support and communication
Legitimate interest / performance of the customer contract
Backups and disaster recovery
Legitimate interest in service continuity
We do not use your data for advertising or profiling, we do not sell it, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
06 / RETENTION
We keep personal information only as long as needed for the purpose collected, applicable legal requirements and legitimate record-keeping:
Account data: for as long as your organisation's contract is active. After the contract ends, data is deleted within 30 days.
Server logs: 14 days.
Backups: encrypted backups rotate out on a 7-daily / 4-weekly / 6-monthly schedule; deleted data disappears from all backups within 6 months at the latest.
07 / LOCATION AND ACCESS
The service runs on dedicated servers operated by our hosting sub-processors (currently Contabo GmbH and Hetzner Online GmbH - the full list is published at ultratrace.eu/mascope/subprocessors). Servers are located in data centres within the EU, unless your organisation has chosen hosting in the USA, in which case its instance runs in a US data centre. Traffic to and from the service passes through Cloudflare, which provides content delivery, firewall and DDoS protection; its edge network handles data in transit and may do so outside the EU. Encrypted backups are always stored on Ultra Trace's own infrastructure within the EU. Error monitoring runs on our own infrastructure; nothing is sent to third-party monitoring services.
Ultra Trace support personnel may view data in the service when operating it or providing support to your organisation, under the terms agreed with your organisation. Such access is limited to what the task requires and is covered by confidentiality obligations.
Support communications reach us by email, handled through Google Workspace, and - where your organisation has chosen that channel - through its private channel on our community Discord server. Discord is operated by Discord Inc. under its own terms and privacy policy; your Discord account and anything you post there are governed by Discord's terms, not ours, and using it is voluntary. We ask that files and screenshots containing personal data be sent by email rather than through Discord.
Some of this processing takes place outside the EU/EEA: traffic in transit through Cloudflare's edge network, support email handled in Google Workspace, and - where your organisation has chosen it - hosting of its instance in the United States. Each is covered by an appropriate safeguard under Chapter V of the GDPR: the EU Standard Contractual Clauses and, where applicable, the provider's EU-US Data Privacy Framework certification. Personal data is otherwise stored and processed within the EU/EEA, and the safeguards described in this notice apply regardless of location.