Privacy policy
What we collect, why we have it, who else touches it, how long we keep it, and what you can make us do about it.
Effective 13 September 2026
Who this is about
KemJet (“we”, “us”) operates the KemJet workspace and the website at kemjet.org. This policy covers both.
For your account and for how the service runs, we are the controller. For the chemistry you put into a workspace, we are a processor acting on your organisation’s instructions: it is your data, we hold it to run the service, and we do not decide what to do with it.
Questions, and any request under the rights below, go to admin@kemjet.org.
What we collect, and on what basis
| Category | Why we have it | Lawful basis |
|---|---|---|
Account Email address, display name, and a one-way hash of your password. | To create your account, sign you in, and reach you about the service. | Performance of a contract |
Workspace content Structures, projects, runs, results, notes and files you or your colleagues put into a workspace. | This is the service. We hold it so the workspace can show it back to you. | Performance of a contract |
Audit records Who did what, when, and whether it succeeded. Identifiers and outcomes only, never payloads. | So a workspace owner can see who changed what, and so we can investigate abuse. | Legitimate interests, and legal obligation where one applies |
Technical IP address, user agent, and timestamps of requests. | Rate limiting, fraud and abuse prevention, and diagnosing faults. | Legitimate interests |
Usage telemetry Counts and outcomes: runs started, runs failed, Palba turns and how they ended. Never the content of either. | To see what is used, what breaks, and what to build next. | Legitimate interests |
Correspondence What you send us by email, and our replies. | To answer you, and to keep a record of what was agreed. | Legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and can explain the balance on request. You can object, and we will stop unless we have grounds that override the objection.
What we do not do
Stated because the absence is the point, and because it is checkable:
- No cookies. The workspace keeps your session in your browser’s local storage, which is strictly necessary to keep you signed in and is never sent anywhere but our own API. There is no consent banner because there is nothing to consent to.
- No third-party analytics. No Google Analytics, no tag manager, no session recording, no heat maps, no advertising or social pixels. The product analytics we do have are counts computed from our own database.
- No selling or sharing. We do not sell personal data, share it for advertising, or disclose it to data brokers. We do not train models on your chemistry.
- No payload logging. Our logs record identifiers and outcomes, not request or response bodies.
Palba and the model behind it
Palba is powered by a third-party language model reached over an API. When you talk to Palba, the conversation leaves our infrastructure to reach that provider, and so does anything the conversation is about: a structure you paste, a result you ask it to interpret, the name of a target you are working on.
If a compound is unpublished and you are not comfortable with it reaching a third party, do not put it in a Palba conversation. The rest of the workspace, including every prediction, docking run and route search, runs on our own infrastructure and does not reach the model provider.
The current provider is named in the table below, along with where it operates. We will update that table before changing providers, not after.
Who else receives data
These are our sub-processors. Each one receives only what its purpose requires.
| Who | What they receive | Where |
|---|---|---|
| Amazon Web Services Application hosting, database, model inference, outbound email | All account and workspace data, at rest and in transit | United States and Ireland |
| Language model provider The model behind Palba | The text of a Palba conversation, including any structures, results or project details it refers to | Named on request. May change; customers are told before it does |
| EMBL-EBI (Europe PMC) Literature search, when Palba is asked for published evidence | The search terms only. No account, workspace or structure data | United Kingdom |
Beyond these, we disclose data only where the law requires it, and where we are permitted to tell you, we will.
Where data goes
The service runs on Amazon Web Services. Some of the recipients above are outside the UK and the European Economic Area, including the model provider behind Palba.
Where a transfer leaves the UK or the EEA, we rely on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, together with the technical measures on the security page. We can provide the relevant terms on request.
How long we keep it
We do not delete your work on a timer. Your chemistry stays in your workspace for as long as the workspace exists, and it goes when you decide it goes.
- Workspace content is kept until you delete it. Deleting a project removes that project; deleting the workspace removes everything in it. There is no expiry date after which your structures, runs or results disappear on their own.
- Account data is kept while the account is open, and removed when it is closed.
- Audit records outlive the resources they describe. A trail that vanishes when somebody deletes what they did is not a trail. They hold identifiers and outcomes, not content.
- Backups roll off on their own schedule, so a deletion reaches them within 35 days rather than instantly.
If your organisation needs data destroyed on a defined schedule, which some regulated environments require, tell us and we will agree one with you.
Your rights
Under the UK GDPR and the EU GDPR you can ask us to do the following, and we answer within one month:
- Tell you what we hold about you, and give you a copy.
- Correct anything that is wrong.
- Erase it, where we have no overriding reason to keep it.
- Restrict what we do with it while a dispute is resolved.
- Give you a portable copy in a machine-readable form.
- Stop processing you have objected to, including anything based on legitimate interests.
Write to admin@kemjet.org. We do not charge, and we will not make you justify the request.
If your data is in a workspace your employer owns, some of these are properly addressed to them rather than to us. Ask us either way and we will point you to the right place.
You can also complain to your national data protection authority, whichever country you are in. We would rather you came to us first, but it is your right and not conditional on that. In the UK that is the Information Commissioner’s Office: how to complain.
Automated decisions
We make no automated decisions producing legal or similarly significant effects about you. The models in the workspace predict properties of molecules; they do not evaluate people.
Children
KemJet is a tool for professional and academic research and is not directed at anyone under 16. We do not knowingly collect their data, and we will delete it if we find we have.
Changes
When this policy changes materially, we change the effective date at the top and tell account holders by email before it takes effect. Adding a sub-processor is a material change. Rewording a sentence is not.