Last Updated: August 2026

Your privacy is important to us. This Privacy Policy (“Policy”) describes how EpiCypher, Inc. (“EpiCypher,” “Company,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information in connection with our website, www.epicypher.com (the “Site”), our products and services, and other interactions with EpiCypher.

This Policy also describes certain practices relating to information provided to EpiCypher by customers in connection with our scientific services and online platforms. Additional terms may apply to customer information under a Master Service Agreement (“MSA”), Statement of Work (“SOW”), End User Agreement, confidentiality agreement, Data Protection Addendum, Business Associate Agreement, or other agreement with EpiCypher. If there is a conflict between this Policy and an applicable written agreement governing particular customer data, the applicable agreement will control to the extent of the conflict.

We process personal information in accordance with applicable laws and seek to ensure that personal information is collected for specified and legitimate business purposes, limited to what is reasonably necessary for those purposes, retained only as long as appropriate, and protected using safeguards appropriate to the nature and sensitivity of the information.

1. Information We Collect

Information You Provide

Personal information that you provide to EpiCypher may include:

  • Name;
  • Postal or shipping address;
  • Email address;
  • Telephone number;
  • Company or institutional affiliation;
  • Occupation or professional information;
  • Account username and other account information;
  • Product interests and preferences;
  • Order and checkout information;
  • Communications with EpiCypher;
  • Information submitted through forms, surveys, event registrations, or requests for technical support; and
  • Other information you voluntarily provide to us.

Payment information may be processed by EpiCypher or by payment-processing providers acting on our behalf, depending upon the transaction.

Information We Receive From Others

We may receive information about you from third parties that provide services to us, including distributors, marketing and analytics providers, payment processors, shipping providers, event organizers, and other business partners.

Information received from third parties may be combined with information collected through the Site or through your other interactions with EpiCypher.

Information Collected Automatically

When you visit our Site or use certain online services, we and our service providers may automatically collect technical and usage information such as:

  • Internet Protocol (IP) address and approximate geographic location;
  • Browser type and language;
  • Device and operating system information;
  • Referring website or advertisement;
  • Pages viewed;
  • Items clicked or downloaded;
  • Access dates and times;
  • Time spent on pages; and
  • Other information regarding your interaction with the Site or online services.

This information may be collected through cookies and similar technologies, subject to applicable consent requirements and your privacy choices.

2. How We Collect Information

We collect information:

  • Directly from you when you submit forms, contact us, create an account, request technical support, subscribe to communications, register for events, purchase products or services, or otherwise interact with EpiCypher;
  • Automatically when you use our Site or certain online services;
  • From service providers and other third parties that assist us with our business; and
  • In connection with customer relationships, scientific services, and other business transactions.

3. How We Use Information

EpiCypher may use personal information for legitimate business purposes, including to:

  • Provide and deliver products and services you request;
  • Process orders and transactions;
  • Establish and administer accounts;
  • Provide technical support and customer service;
  • Respond to questions, comments, and requests;
  • Communicate confirmations, invoices, technical notices, updates, security alerts, and administrative messages;
  • Communicate information regarding EpiCypher products, services, scientific content, events, and promotions;
  • Personalize and improve our Site, products, services, and marketing;
  • Analyze Site and service usage;
  • Maintain, troubleshoot, develop, and improve our systems and services;
  • Protect against, investigate, and respond to fraudulent, unauthorized, illegal, or potentially harmful activity;
  • Protect the security and integrity of our systems, networks, products, services, and information;
  • Comply with contractual, legal, regulatory, and funding requirements; and
  • Establish, exercise, or defend legal rights.

Where required by applicable law, we will obtain consent before processing personal information for particular purposes.

4. Customer Research Data and Confidential Information

In connection with scientific services and online platforms, EpiCypher customers may provide proprietary information, biological and experimental information, sequencing data, research data, and other confidential information (“Customer Data”).

Unless otherwise specified in an applicable agreement, customer-supplied data, samples, and resulting project deliverables remain the property of the customer. EpiCypher does not claim ownership of customer confidential information merely because it is provided to EpiCypher for processing or services.

EpiCypher uses Customer Data only for purposes authorized by the customer, necessary to provide requested products or services, or otherwise permitted under an applicable agreement or by law.

Access to Customer Data is limited to personnel and authorized service providers with a legitimate business need to access the information.

EpiCypher does not sell Customer Data or use confidential Customer Data for unrelated research without authorization.

EpiCypher will not disclose confidential Customer Data to third parties except:

  • As authorized by the customer;
  • As required or permitted under an applicable agreement;
  • As necessary for approved service providers or subcontractors supporting EpiCypher’s services and subject to appropriate confidentiality obligations;
  • As required by applicable law or legal process; or
  • As otherwise authorized by the customer.

Customer Data may be subject to additional or different requirements contained in an applicable NDA, MSA, SOW, End User Agreement, Data Protection Addendum, Business Associate Agreement, or other contract.

5. CUTANA Cloud and Other Online Services

Certain EpiCypher online services, including CUTANA Cloud, may allow customers to upload research information or other data for processing and analysis.

Client Data submitted to CUTANA Cloud is governed by the applicable EpiCypher End User Agreement and any other applicable written agreements. Customers retain ownership of their Client Data as provided in the End User Agreement.

EpiCypher and its authorized service providers may process Client Data as necessary to provide, maintain, support, and operate the applicable service in accordance with the applicable agreement.

Customers are responsible for ensuring that they have appropriate rights, permissions, and authorizations to submit information to EpiCypher.

Protected Data

Unless EpiCypher has expressly agreed otherwise in writing, customers should not submit protected health information subject to HIPAA, personal data of European Union data subjects subject to the GDPR, or other regulated personal information to CUTANA Cloud where the applicable End User Agreement prohibits or restricts such submission.

If a customer wishes to use an EpiCypher service to process such regulated information, EpiCypher and the customer may enter into an appropriate Data Protection Addendum, Business Associate Agreement, or other agreement as applicable before such information is submitted.

6. How We Disclose Information

EpiCypher may disclose personal information:

  • With your consent or at your direction;
  • To service providers that perform functions on our behalf, such as hosting, cloud services, payment processing, order fulfillment, shipping, analytics, marketing, technical support, and other business operations;
  • In connection with a business transaction, including a merger, financing, acquisition, reorganization, bankruptcy, or sale or transfer of some or all of our business or assets;
  • For legal, compliance, protection, and safety purposes, including complying with applicable law, lawful requests, court orders, or legal processes and protecting the rights, property, and safety of EpiCypher, our employees, customers, or others; and
  • As otherwise permitted or required by law.

We may also disclose aggregated or de-identified information that does not reasonably identify an individual.

EpiCypher does not sell Customer Data.

7. How We Protect Information

EpiCypher maintains administrative, technical, and physical safeguards designed to protect personal and confidential information from unauthorized access, use, disclosure, alteration, loss, or destruction.

Our information-security program uses a risk-based approach and includes measures such as:

  • Access controls based on business need and least-privilege principles;
  • Multi-factor authentication for designated systems;
  • Encryption of sensitive information in transit and at rest where appropriate and supported;
  • Endpoint and network security controls;
  • Logging and monitoring;
  • Vulnerability and patch management;
  • Security awareness and phishing training;
  • Backup and recovery procedures;
  • Incident-response procedures;
  • Periodic cybersecurity risk assessments and security-control assessments; and
  • Controls governing third-party access to company systems and information.

EpiCypher’s cybersecurity program is designed to align with recognized information-security practices, including the intent of applicable NIST SP 800-171 controls where appropriate to EpiCypher’s operations and regulatory or funding requirements.

No method of transmission over the Internet or electronic storage is completely secure. Accordingly, while EpiCypher maintains safeguards designed to protect information, we cannot guarantee absolute security.

Users are responsible for maintaining the confidentiality of passwords, account credentials, and other authentication information associated with their accounts.

8. Privacy and Security Governance

EpiCypher maintains a risk-based privacy, data-governance, and information-security program.

Responsibility for information security and data protection is shared among company management, IT/security personnel, designated data owners, and employees according to their respective responsibilities.

Our governance program includes:

  • Defined responsibility for system and data access;
  • Data classification and designated data ownership;
  • Periodic access reviews;
  • Cybersecurity risk assessments;
  • Security-control assessments;
  • Security awareness training;
  • Incident reporting and escalation procedures;
  • Vulnerability management;
  • Third-party security controls;
  • Management review of identified security risks and control deficiencies; and
  • Periodic review and updating of cybersecurity and data-governance policies.

EpiCypher reviews and updates its security practices as appropriate in response to changes in its systems, business operations, identified risks, security incidents, and applicable regulatory, contractual, and funding requirements.

9. Data Transfers and Third-Party Service Providers

EpiCypher may transfer or provide access to personal information and Customer Data to authorized third-party service providers where reasonably necessary to provide our products and services or support our business operations.

Third-party access is limited to appropriate business purposes and is subject to applicable confidentiality, contractual, and security requirements.

Sensitive and confidential information must be protected during transmission using appropriate security measures. EpiCypher restricts external sharing of sensitive information and maintains controls designed to prevent unauthorized disclosure.

EpiCypher remains responsible for appropriate oversight of third-party access to company and customer information under its information-security program.

International Transfers

EpiCypher is a United States-based company. Information collected through our Site and services may therefore be transferred to, processed, or stored in the United States or other jurisdictions in which EpiCypher or its authorized service providers operate.

Where applicable law requires specific safeguards for international transfers of personal information, EpiCypher will implement appropriate measures or contractual arrangements as required.

10. Data Retention and Destruction

EpiCypher retains personal information only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy applicable business, contractual, legal, regulatory, accounting, and reporting requirements.

Customer Data is retained in accordance with applicable contractual obligations, regulatory requirements, scientific or operational needs, and the terms applicable to the relevant EpiCypher service.

When information is no longer required, EpiCypher takes reasonable steps to securely delete, destroy, anonymize, or otherwise dispose of it using methods appropriate to the sensitivity and format of the information.

Specific EpiCypher services may have separate retention and deletion provisions. Where applicable, those contractual provisions control.

11. Security Incidents

EpiCypher maintains procedures for identifying, reporting, investigating, containing, remediating, and documenting cybersecurity incidents.

If a cybersecurity incident involves customer or personal information, EpiCypher will evaluate the nature and scope of the incident and take appropriate corrective action.

EpiCypher will provide notifications to affected customers, individuals, governmental authorities, or other parties when required by applicable law or contractual obligations.

12. Your Privacy Rights

Depending on where you reside and applicable law, you may have rights regarding your personal information, which may include the right to:

  • Request access to personal information we maintain about you;
  • Request correction of inaccurate personal information;
  • Request deletion of personal information, subject to applicable exceptions;
  • Request restriction of certain processing;
  • Object to certain processing;
  • Request portability of certain personal information;
  • Withdraw consent where processing is based upon consent;
  • Opt out of certain marketing communications; and
  • Exercise other privacy rights provided under applicable law.

These rights are not absolute and may differ depending upon your jurisdiction and our relationship with you.

To exercise an applicable privacy right, contact us using the information provided below. We may need to verify your identity before fulfilling a request.

13. European Union and European Economic Area

Individuals located in the European Union or European Economic Area may have additional rights under the General Data Protection Regulation (“GDPR”), where applicable, including rights relating to:

  • Access;
  • Rectification;
  • Erasure;
  • Restriction of processing;
  • Objection to processing;
  • Data portability;
  • Certain automated decision-making and profiling; and
  • Withdrawal of consent where consent is the basis for processing.

EpiCypher’s role under the GDPR may vary depending upon the circumstances. For example, when EpiCypher processes certain customer data solely on behalf of a customer under an applicable Data Protection Addendum, EpiCypher may act as a processor and the customer may act as the controller.

14. Cookies and Similar Technologies

Cookies are small text files stored on a device that allow websites to recognize browsers or devices and collect information regarding website activity.

EpiCypher and its authorized service providers may use cookies and similar technologies to operate our Site, remember preferences, understand Site usage, improve functionality, measure marketing effectiveness, and provide relevant content or advertising.

Our Site may use:

  • Essential cookies, necessary for operation and security of the Site;
  • Functional cookies, which support preferences and Site functionality;
  • Analytics cookies, which help us understand Site usage and performance; and
  • Advertising or marketing cookies, which may be used to measure marketing activities or provide relevant advertising.

Some cookies may be set by third-party service providers.

Where required by applicable law, non-essential cookies or similar technologies will be used subject to applicable consent requirements.

You may manage cookies through available Site privacy controls and through your browser settings. Blocking certain cookies may affect the functionality of the Site.

Where required by applicable law, EpiCypher provides mechanisms to exercise applicable choices regarding the use or disclosure of personal information for targeted or cross-context behavioral advertising.

15. California Residents

California residents may have certain rights under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), subject to applicable definitions, thresholds, exemptions, and exceptions.

Depending upon applicability, these rights may include the right to:

  • Know the categories and specific pieces of personal information EpiCypher has collected about you;
  • Know the categories of sources from which personal information is collected;
  • Know the business or commercial purposes for collecting, using, selling, or sharing personal information;
  • Know the categories of third parties to whom personal information is disclosed;
  • Request correction of inaccurate personal information;
  • Request deletion of personal information, subject to applicable exceptions;
  • Obtain certain personal information in a portable format;
  • Opt out of the sale or sharing of personal information, where applicable;
  • Limit certain uses or disclosures of sensitive personal information, where applicable; and
  • Exercise applicable privacy rights without unlawful discrimination.

EpiCypher will verify privacy requests as required by applicable law. California residents may also designate an authorized agent to submit a request where permitted by law, subject to appropriate verification.

Where applicable, EpiCypher provides a “Do Not Sell or Share My Personal Information” mechanism for privacy choices.

The terms “sell,” “share,” “personal information,” and “sensitive personal information” have the meanings provided by applicable California privacy law.

16. Browser-Based Privacy Signals

Some browsers and devices provide privacy preference signals.

EpiCypher will process browser-based opt-out preference signals where required by applicable law. Other “Do Not Track” signals may not be recognized where no legal requirement to honor the particular signal applies.

17. Communications

You may unsubscribe from promotional email communications at any time by following the unsubscribe instructions contained in the communication or by contacting EpiCypher.

Even if you opt out of promotional communications, EpiCypher may continue to send transactional, administrative, technical, security, account, or other non-promotional communications relating to products or services you have requested or your relationship with EpiCypher.

18. Links to Other Websites

Our Site may contain links to websites operated by third parties. EpiCypher does not control those websites and is not responsible for their privacy practices.

We encourage you to review the privacy policies of third-party websites before providing personal information to them.

19. Children’s Privacy

EpiCypher’s Site, products, and services are not directed to children under the age of 18, and we do not knowingly collect personal information directly from children under 18 through the Site.

If we become aware that a child has provided personal information to us in circumstances where collection is not appropriate, we will take reasonable steps to delete the information.

20. Changes to This Privacy Policy

We may update this Policy periodically to reflect changes in our practices, services, technology, legal requirements, or other factors.

If we make changes, we will update the Last Updated date above. Where required by applicable law, we will provide additional notice regarding material changes.

We encourage you to review this Policy periodically to understand how EpiCypher collects, uses, and protects information.

21. Contact Information

If you have questions about this Privacy Policy, wish to exercise an applicable privacy right, or have concerns regarding EpiCypher’s handling of personal information, please contact us:

EpiCypher, Inc.
6 Davis Drive, Suite 755
Durham, NC 27713
United States
Telephone: +1-855-374-2461
Privacy email: itadmin@epicypher.com

Privacy requests and complaints will be reviewed and addressed in accordance with applicable law and EpiCypher procedures.

Scroll to Top