Legal Documents
Policy index, procurement summaries, and legal contacts for BCILattice and the BCINexus platform.
Legal Documents Index
Effective date: 28 June 2026 | Last updated: 28 June 2026
| Document | Applies To | Canonical Page |
|---|---|---|
| Terms of Service | All website, platform, desktop, and cloud users | /terms |
| Privacy Policy | All users and visitors whose personal data is processed | /privacy |
| Cookie Policy | Website visitors and authenticated web users | /cookies |
| GDPR and Data Protection | Users covered by GDPR, UK GDPR, or similar laws | /gdpr |
| Refund Policy | Self-serve Researcher and Lab subscriptions | /refund |
| Data Processing Agreement | Enterprise customers | Legal review required |
| Business Associate Agreement | Eligible HIPAA covered entities and business associates | Legal review required before PHI cloud use |
| Master Service Agreement | Enterprise purchases | Contract-specific |
Scope and Roles
BCILattice is a local-first desktop research application. Signal processing, preprocessing, model training, and report generation run on the user's hardware unless a separate enterprise deployment says otherwise.
BCINexus cloud services are optional and cover account management, billing, team storage, study sharing, community publishing, review workflows, and support. For institution-managed workspaces, BCINexus may act as a processor for uploaded study data under a signed DPA.
Terms Summary
The Terms of Service govern access to BCILattice, bcinexus.xyz, the BCINexus community, and related cloud services. Users must keep account information accurate, protect credentials, follow plan limits, and use separate accounts for team members.
- Self-serve subscriptions renew automatically unless cancelled before renewal.
- Enterprise terms are controlled by signed order forms or master agreements.
- Users retain ownership of their datasets, models, reports, studies, and session files.
- Published community content must be lawful, properly authorized, and scientifically supportable.
- BCILattice is research software and is not a medical device or clinical decision product.
Full terms: bcinexus.xyz/terms
Privacy Summary
BCINexus collects account, billing status, support, workspace, active analytics, browser-storage, and operational telemetry data needed to operate and improve the platform. Local BCILattice research data stays on the user's machine unless the user intentionally uploads, syncs, shares, or publishes it.
| Data Category | Typical Purpose | Notes |
|---|---|---|
| Account data | Authentication, plan management, support | Name, email, institution, role, settings |
| Billing status | Subscription and refund handling | Raw card numbers are not stored by BCINexus |
| Workspace metadata | Teams, cloud storage, study sharing | Only when cloud features are used |
| Uploaded content | Storage, review, collaboration, publishing | User-initiated upload or sync only |
| Analytics and telemetry | Reliability, security, aggregate usage measurement, and product improvement | Designed to exclude raw research data |
Full policy: bcinexus.xyz/privacy
Cookie Summary
The website uses cookies, localStorage, and sessionStorage for authentication, security, checkout, workspace state, profile caching, preferences, and product operation. Analytics are active for product reliability and aggregate usage measurement. Authenticated application pages do not use third-party advertising cookies.
Full policy: bcinexus.xyz/cookies
Refund Summary
Self-serve Researcher and Lab subscriptions have a 7-day refund window for eligible first-time charges, upgrades, and renewals. Self-serve payment processing is handled by Paddle or another disclosed payment provider. Enterprise purchases follow the signed agreement or purchase order.
Refund requests: [email protected]
Acceptable Use
Users may not use BCILattice or BCINexus to:
- Process human-subject data without required consent, ethics approval, IRB approval, or equivalent authorization.
- Upload malware, unlawful content, or content that infringes third-party rights.
- Publish misleading, plagiarized, unsafe, or unsupported research claims.
- Share account credentials, evade plan limits, or resell access without written permission.
- Use the platform in violation of sanctions, export controls, privacy law, or clinical research rules.
- Interfere with BCINexus infrastructure or attempt unauthorized access.
Desktop EULA Summary
The desktop license allows installation and use of BCILattice according to the active plan or signed agreement. Users may not redistribute, sublicense, remove notices, or use the software to build a competing service unless a written agreement permits it.
Research outputs, trained models, reports, exported files, and session data created by users remain the property of the user or their institution.
DPA and BAA
A Data Processing Agreement can be reviewed for Enterprise customers that need processor terms for personal data handled through BCINexus cloud features. The DPA review may cover subprocessor terms, security controls, deletion/return commitments, and Standard Contractual Clauses where applicable.
A Business Associate Agreement requires legal review before any BCINexus cloud service is used with protected health information. Local-only BCILattice processing generally remains under the customer's own governance.
Requests: [email protected]
SLA and Support
| Plan | Support Channel | Target Response | Uptime Scope |
|---|---|---|---|
| Free | Community and docs | Best effort | No SLA |
| Researcher | Business days | No custom SLA unless stated | |
| Lab | Priority email | Business days | Cloud services only where offered |
| Enterprise | Named support path | As agreed | MSA or SLA specific |
Uptime commitments, downtime credits, support hours, and escalation paths apply only where included in a signed agreement. Local BCILattice functionality is not an uptime service because it runs on the user's machine.
Open Source Notices
BCILattice and BCINexus use open source components. Full license notices should be reviewed in the installed product, repository notices, or enterprise SBOM where provided.
| Component | License | Use |
|---|---|---|
| PyTorch | BSD 3-Clause | Deep learning models and training |
| scikit-learn | BSD 3-Clause | Classical machine learning |
| MNE-Python | BSD 3-Clause | Signal processing |
| NumPy / SciPy / Pandas | BSD-style | Scientific computing |
| FastAPI | MIT | Local and cloud API services |
| SQLAlchemy / Alembic | MIT | Database access and migrations |
| Next.js / React | MIT | BCINexus web application |
| Tailwind CSS | MIT | Web styling |
Enterprise SBOM requests: [email protected]
Legal Contact
Legal and contracts: [email protected]
Privacy requests: [email protected]
Security disclosures: [email protected]
Billing and refunds: [email protected]
For DPA, BAA, MSA, security questionnaire, SBOM, validation support, or custom procurement terms, include your organization name, plan, requested document, and target review date.