Personal Data Protection & Privacy Policy
Welcome to the Omicslab bioinformatics data analysis platform, a product operated by VIEOMICS COMPANY LIMITED. We are committed to protecting your personal data and the data you process on the Platform in accordance with Vietnamese law (the Personal Data Protection Law No. 91/2025/QH15, Decree No. 356/2025/ND-CP and the Cybersecurity Law) and international security standards.
Last updated: 12 October 2026
The public Omicslab Platform (cloud) does not accept and does not process non-public sensitive personal data of individuals in Vietnam, including human genomic and health-related data. Such data must not be uploaded to the public Platform; it is supported only through a separate, contracted self-hosted deployment, in which Vieomics provides the Omicslab Platform as the platform management system and the customer performs the full deployment on its own infrastructure and self-hosts it. The service is entirely the customer’s own: the customer runs, configures, operates, analyses, stores and manages the whole stack and the data in its own environment, and no customer data is automatically transmitted from a self-hosted deployment to Vieomics, except where the customer chooses to provide information or authorise access solely for the agreed support and maintenance purposes as described in Section 1. Vieomics may assist with platform operation at the customer’s request, within the agreed service scope, but does not access or analyse the customer’s data. Responsibility for personal data follows the actual processing activities, the access granted, the purposes of processing and applicable law. Publicly available human data is not automatically anonymous: lawfully published or properly de-identified data may be processed on the public Platform only after an assessment of its source, access conditions and privacy risk (see Section 1). The public Platform is otherwise intended for non-human data (microorganisms, plants, animals and environmental samples) and simulated or benchmark data, as described in Section 1.
1. Definitions, Data Processing Roles and Storage Infrastructure
Definitions
Omicslab Platform: the software product — a bioinformatics data analysis platform — developed and operated by Vieomics. Throughout this Policy, “Platform” and “Omicslab Platform” refer to this product.
Vieomics (VIEOMICS COMPANY LIMITED): the legal entity that operates the Omicslab Platform and is responsible, as described in this Policy, for the personal data we actually collect or process (“we”, “us”). Every commitment, obligation and liability for personal data stated below belongs to Vieomics — not to the “Omicslab” brand.
Personal data: information in the form of text, numbers, images, sound or similar forms that is attached to a specific individual or helps identify a specific individual, including both basic and sensitive personal data (under the Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP).
User data (data uploaded by the user): all files, datasets and resources that you (or your organisation) actively send, connect or store on the Platform, including data held in object storage and infrastructure you integrate yourself. User data is not necessarily personal data: it may be pure research data (microorganisms, plants, animals, environmental samples), or it may contain personal data belonging to other people — in which case it must not be uploaded to the public Platform, except as permitted by the rule immediately below.
Customer data: data that you (or your organisation) upload, connect, generate or process on the Platform. Customer data remains under your control and is not automatically public; it is distinct from the public and benchmark datasets described in Section 3.
Public / benchmark dataset: a dataset that Vieomics may make available from international public repositories, openly accessible scientific databases, other lawful public sources, or that is simulated or prepared for benchmarking. Public and benchmark datasets are not customer data and are covered separately in Section 3.
Personal data that does not belong to the user themselves: personal data belonging to other individuals must not be uploaded to the public Platform unless it forms part of a lawfully published or properly de-identified dataset that meets the conditions described in this Policy. Users remain responsible for assessing the lawful basis, access conditions, permitted use and privacy risks before uploading such data. Sensitive personal data (including patient, health and genomic data) must not be uploaded to the public Platform — it is handled only through the self-hosted deployment described in this Section, except data that has been lawfully published or properly de-identified such that re-identification is not reasonably possible.
Separation of Legal Roles
Personal Data Controller: The Omicslab Platform is operated by VIEOMICS COMPANY LIMITED (“we”, “us”). We act as the Personal Data Controller for information collected to operate and manage the service (including account data, usage data and technical data).
Data Processor: For research and biological data that you (or your organisation) actively upload to a platform-managed Omicslab service, you act as the Data Controller and we act as the Data Processor — operating that service and performing computation and storage in accordance with your instructions, settings and requirements. Where we act as a processor, we process customer data in accordance with your documented instructions and the applicable service agreement, and we remain responsible for our own obligations under applicable law and our contractual commitments.
This role applies to infrastructure we actually operate. In a self-hosted (customer-managed) deployment, where you run the full stack yourself and we have no access to your environment or data, we do not process that data as a processor. Roles are determined by the actual processing activities, not by labels. Where Vieomics accesses your servers to operate or maintain the platform at your request, views data as needed to operate or troubleshoot the platform, receives logs, diagnostics or platform/job metadata that contain personal data, or otherwise performs platform-operation activities on infrastructure you operate, those activities may make Vieomics a processor — or, where we determine the purposes of the processing, a controller — for the data involved, and the corresponding obligations apply to that extent. Vieomics does not carry out analysis of your research data. We keep a clear boundary between (i) selling or licensing the software, (ii) limited technical support and maintenance that you request, and (iii) actually operating infrastructure or processing data. Contractual statements or disclaimers do not override obligations that applicable law makes mandatory; where such an obligation applies, we comply with it regardless of the deployment model.
Scope: Human / Health-Related Data (Not Processed on the Public Platform)
The public Omicslab Platform does not accept and does not process non-public sensitive personal data of individuals in Vietnam, including human genomic and health-related data (for example NIPT, WES, WGS, human RNA-Seq or patients’ genetic records). You must not upload such data to the public Platform. Publicly available data is not automatically anonymous: data that has been lawfully published and made openly accessible, or that has been de-identified such that re-identification is not reasonably possible in the circumstances (for example some data retrieved from public repositories such as NCBI GEO/SRA), may be processed on the public Platform. Before uploading any human dataset you must assess its source, access conditions, permitted use, metadata and privacy risk — including whether it still contains or can enable inferences about individuals — and obtain any additional authorisation required for restricted or sensitive datasets. Sample or subject identifiers are not, by themselves, direct identifiers. Do not rely on the label alone: the file format (for example FASTQ, BAM or VCF), the use of a Sample ID or subject code instead of a patient name, or availability on a public repository such as NCBI does not by itself mean that personal-data obligations have disappeared, because genomic and health data can remain linkable to, or enable inferences about, an individual. Before processing, assess the access conditions, licence, permitted purpose, accompanying metadata — and any other data that could be combined with it — and the risk of re-identification, not just the file name. The specific rules that apply to a given dataset are a legal question; Vieomics recommends that customers confirm them with qualified Vietnamese legal counsel, and nothing in this Policy is legal advice.
To process sensitive data, the customer must contact us to arrange a self-hosted deployment under a separate agreement. In this model, Vieomics provides the Omicslab Platform as the platform management system, and the customer performs the full deployment on infrastructure it owns or controls and self-hosts it. The service is entirely the customer’s own: the customer runs, configures and operates the whole stack — frontend, backend and APIs, application database, object storage, compute and workflow execution, pipelines and analysis tools, and access control — and the data is created, analysed, stored and managed only in the customer’s environment. No customer data is automatically transmitted from a self-hosted deployment to Vieomics. The customer may choose to provide specific logs, diagnostics or other information, or authorise access to its environment, solely for the agreed support and maintenance purposes. Any such access or processing remains subject to applicable law and the agreed service scope. Vieomics may assist with platform operation at the customer’s request, within the agreed service scope; any such access is authorised by the customer and limited to platform operation and maintenance — Vieomics does not analyse the customer’s data. Responsibility for personal data follows the actual processing activities, the access granted, the purposes of processing and applicable law — the customer is responsible for its own legal basis, permissions and consent requirements where applicable, the security configuration of its environment, and any personal data processing impact assessment required by law.
User-Managed Infrastructure (Bring Your Own Cloud – BYOC)
Where you choose to connect or integrate your own storage account or analysis servers (personal API credentials) into the Omicslab Platform, you are responsible for the security, access permissions and safety of the data on that infrastructure. To the extent permitted by applicable law, we are not liable for incidents arising from systems you manage. This does not affect our own obligations under applicable law or under any separate agreement with you.
Deployment models
Omicslab builds a trusted operating layer for scientific computing and is offered through different deployment models. Platform-Managed (Marketplace): Omicslab provides and manages the application services, compute and storage that we operate, and processes data within that infrastructure on your instructions. Self-hosted (customer-managed / Bring Your Own Infrastructure): Vieomics provides the Omicslab Platform as the platform management system, and you perform the full deployment and self-host the complete Omicslab stack — frontend, backend and APIs, application database, object storage and other storage, compute and workflow execution, pipelines and third-party analysis tools, plus your credentials, access policies, backups and operational security — on infrastructure you own or control. The service is entirely your own, and no customer data is automatically transmitted from a self-hosted deployment to Vieomics, except where you choose to provide information or authorise access solely for the agreed support and maintenance purposes as described below. We supply the software, documentation, updates and licensing, and may assist with platform operation at your request; we do not access your environment or data unless you authorise access for a defined platform-operation or maintenance purpose, and we do not analyse your research data. The public, platform-managed (Marketplace) service is intended only for non-human data (microorganisms, plants, animals and environmental samples), simulated or benchmark data, and public data that has been lawfully published or properly de-identified — the latter only after the assessment described in this Section. Non-public sensitive personal data — including human genomic, genetic and health data — must not be uploaded to the public Platform and is handled only through a separate, contracted customer-managed (self-hosted) deployment.
2. Data We Collect & Responsibility Rules by Data Type
We collect and classify data into the following categories:
- Account data: representative full name, email address, phone number, contact/billing address, login credentials and account preferences.
- Service usage data: activity logs on the Platform, including analysis jobs, storage history and storage usage — used for billing reconciliation, system audits and technical support.
- Technical data: IP address, browser information, device type and connection information — used to keep the service secure, prevent cyberattacks and diagnose errors.
- Website access data: aggregated traffic data collected through Google Analytics on this website (the landing page) — the Platform itself does not use Google Analytics — to improve the user experience, processed as described in Section 11.
- Bioinformatics analysis data (uploaded to or processed on the system):
- Non-human data (microorganisms, plants, animals, environmental samples): generally classified as scientific research data. In typical cases, and provided it does not contain personal data, this data is not personal data under the Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP. Users may upload, store and analyse this data without applying personal-data privacy procedures, unless it contains personal data.
- Human / health-related data: the public Platform does not accept and does not process non-public sensitive personal data of individuals in Vietnam, including human genomic and health-related data (for example NIPT, WES, WGS, human RNA-Seq or patients’ genetic and clinical records). Such data must not be uploaded to the public Platform. For sensitive data, the customer must contact us to arrange a self-hosted deployment under a separate agreement, in which Vieomics provides the Omicslab Platform as the platform management system and the customer performs the full deployment on its own infrastructure and self-hosts it, running, configuring, analysing, storing and managing the data itself; no customer data is automatically transmitted from a self-hosted deployment to Vieomics except where the customer chooses to provide information or authorise access solely for the agreed support and maintenance purposes as described in Section 1, and Vieomics does not analyse it. Publicly available data is not automatically anonymous: data that has been lawfully published and made openly accessible, or that has been de-identified such that re-identification is not reasonably possible in the circumstances, may be processed on the public Platform after the assessment described in Section 1.
Which categories apply depends on the deployment model. In a customer-managed deployment the deployment is fully independent: no data from your environment — research files, analysis outputs, job metadata, logs, diagnostics or telemetry — is automatically transmitted to or stored by Vieomics. In that case the information we hold is limited to the account, billing and support information you provide to us directly, together with anything you choose to send us as part of a support request. In a platform-managed service, data is processed within the infrastructure we operate.
3. Public and Benchmark Datasets
In addition to processing customer data, Vieomics may provide access to public, open-access, simulated or benchmark datasets to support demonstrations, education, research, benchmarking, and the testing and validation of pipelines and platform functionality.
- Sources: these datasets may be obtained from international public repositories, openly accessible scientific databases, other lawful public sources, and may include simulated or benchmark data.
- Not necessarily collected by Vieomics: where a dataset is obtained from a public repository or another lawful source, Vieomics does not necessarily collect the underlying data directly from the individuals concerned, and is not necessarily the original data controller or collector of that dataset.
- Provenance and licensing: use of these datasets is subject to the licence, attribution and usage terms of the applicable repository or source. Where applicable, provenance and licensing information is provided together with the dataset.
- Intended purposes: these datasets are intended for demonstration, education, research, benchmarking and pipeline or platform testing. They are not presented as, and must not be confused with, private customer datasets.
- Human data that is lawfully public: some human research data is lawfully accessible but may still contain personal data or enable inferences about individuals. Uploading it to the public Platform requires the assessment described in Section 1; sensitive or restricted human datasets that require additional authorisation must instead be handled in a customer-managed environment.
- No reclassification of customer data: private customer datasets are not made public and are not converted into public or benchmark datasets unless the customer has separately authorised it and it is legally permitted. Vieomics does not publish, redistribute or reuse customer data as a public dataset without such authorisation.
4. Legal Bases for Processing
We process personal data on the legal bases set out in the Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP (and other applicable regulations):
- Performance of a contract: processing account and payment data to provide and operate the services and features you have signed up for.
- Consent of the data subject: applied when you subscribe to professional newsletters, product notices or feature updates.
- Legal obligation: retaining data or disclosing information at the request of competent state authorities, as required by Vietnamese law.
- Information security: implementing technical measures to prevent fraud and unauthorised access, and to protect Omicslab’s infrastructure.
5. How We Use Personal Data
Personal data is used to: create and manage accounts, authenticate users, provide bioinformatics analysis infrastructure, ensure cybersecurity, issue invoices and provide technical support.
We commit to:
- Never selling, renting or otherwise commercialising users’ personal data in any form.
- Never accessing, mining or sharing customer data (including research data and pseudonymised human data) for any purpose other than delivering the analysis service you request. We do not make private customer datasets public unless you have separately authorised it and it is legally permitted.
6. Data Retention
- Account data: stored for as long as the account is active. After the account is closed, the account and its related data are only deactivated and retained for the period required by law (limitation periods, and statutory obligations to retain records, documents and invoices), so that the date on which any issue, dispute or legal incident arose can still be traced and evidenced at the request of a competent authority or the parties concerned. Once that period expires, the data is deleted or anonymised, under the exception already stated in Section 9.
- Usage & audit data: retained for the periods required by Vietnamese accounting, tax and cybersecurity law.
- Research data in platform-managed storage: data held in the platform’s object storage service (Marketplace) is stored on a pay-as-you-go basis, billed in monthly cycles, and only for the cycle you have paid for. If you no longer subscribe to any plan, or do not renew the storage cycle, workspace access is blocked when the cycle ends and the data is retained for a 7-day window; after those 7 days the data is permanently deleted — only the audit log is kept for tracing purposes. You may also delete data yourself at any time on the Platform; a workspace you delete is recoverable during the same 7-day window before its data is deleted.
- Top-up balance (organization wallet): prepaid credit can only be spent while your organization has a live subscription. Once the subscription lapses — expired or cancelled, with no renewal in flight — the remaining balance is forfeited and reset to zero, so a top-up cannot be spent without an active plan. Organizations that have never subscribed keep any balance they hold. The forfeiture sweep runs automatically every day. Payment terms, advance email notices and all deadlines are set out in Section 13 of our Terms of Service.
- Research data in a customer-managed deployment: data held in an environment you own or control is stored and deleted under your own storage lifecycle and configuration, subject to your own legal obligations. Vieomics does not hold a copy of that data and cannot delete it from your environment.
- Deletion and retained copies: deleting an account, workspace or dataset does not necessarily erase backups, transaction records or audit logs immediately; these are overwritten or removed under the applicable retention and backup cycles.
7. Data Security Measures
Security is shared between the parties. For the services and infrastructure Vieomics directly operates and controls, we implement the technical and operational measures below to protect the personal data and service data we hold there:
- Encryption of data in transit (TLS/SSL) and, where the platform directly stores it, encryption at rest for the services and resources Vieomics manages — using the encryption supported by the underlying infrastructure provider and configuration (for example AES-256).
- Least-privilege access control (RBAC), multi-factor authentication (MFA) and system audit logs.
- Workspace isolation, and separation of customer mapping keys from the analysis environment where technically configured.
- Security monitoring and incident detection across platform-managed resources, together with regular security reviews and vulnerability assessments.
- Only assigned personnel bound by strict confidentiality obligations may access technical support information, and only upon your written request.
- Credential handling: in the services Vieomics directly operates, credentials used to launch jobs are encrypted and transferred securely to the execution environment; they are never shown to end users or stored in plain text there.
- Architecture separation: the control plane (job orchestration, credentials, quotas) is kept separate from the data plane.
These controls apply only to the services and infrastructure Vieomics directly operates and controls. Cloud and infrastructure providers are responsible for the measures in their own layer — physical and environmental security, the hypervisor, and the encryption, storage, network and logging primitives they supply — under their own terms and certifications. In a customer-managed or BYOC deployment, you are responsible for the infrastructure you operate or connect (your S3-compatible storage, database, compute, backups, access policies, logging and the analysis environment) and for verifying that those measures meet your requirements; where data sits in storage or a database you run or connect, Vieomics cannot guarantee the encryption, backup, access control or logging of that system. We remain responsible for the security of the software we supply.
These measures are designed toward the GDPR (EU) and HIPAA (US) so that the platform is ready for stricter requirements in the future; as of the date of this Policy, Omicslab holds no certification under any of those frameworks. Administrative penalties for cybersecurity and personal data protection violations are set out in Decree No. 330/2026/ND-CP, in force since 19 August 2026.
If a personal data breach affecting information we control is detected (leakage, loss or unauthorised access to personal data), we activate our internal incident-response procedure and, where applicable law requires notification, notify the competent authority and/or the affected data subjects in accordance with the applicable statutory triggers, recipients and deadlines. Incident records are kept at least for the period required by applicable law after the incident has been remediated.
The Platform’s security commitments and the allocation of responsibility between the parties are set out in Section 12 of this Policy.
9. Rights of Data Subjects
For personal data (account and payment information), Vietnamese law grants you the following rights:
- The right to be informed, and to give or withdraw consent.
- The right to access, view, edit or request correction of your data.
- The right to request deletion, restriction or objection to processing — except data that must be retained by law, or that is needed to resolve disputes or legal incidents (see Section 6).
- The right to request a copy of your data.
- The right to lodge complaints, file reports or claim compensation as permitted by law.
To exercise these rights for information we control, you can act directly in your account settings or contact us. We acknowledge a complete and valid request promptly and aim to resolve it within 72 working hours; where a request is complex or affects legally retained data, we may need longer and will keep you informed. This is our service target, not a statutory deadline. Where personal data is held exclusively in a customer-managed deployment that we do not control or access, we cannot directly access, modify, export or delete that data — such requests must be directed to the organisation that controls the environment (see Section 12).
10. Storage and Data Location
Vieomics currently operates the Omicslab Platform only in Vietnam, not abroad. For services and infrastructure that Vieomics provides, the location of storage and processing depends on the service configuration and the infrastructure region you select. On the Vietnam region (default), data and compute provided by Vieomics are stored and processed in Vietnam (see the table below).
The Platform also supports a global region for Vietnamese people or persons living in Vietnam, and multinational collaboration; for services and infrastructure provided by Vieomics, data and compute remain located in Vietnam and users simply access from abroad. Because data and compute provided by Vieomics are located in Vietnam, no transfer of personal data abroad arises in our current operation. For infrastructure you operate or connect yourself, the location depends on your configuration, as described below.
| Region | Instance | Framework | Data residency |
|---|---|---|---|
| Vietnam (default) | platform.omicslab.vn | PDPL (Law 91/2025 + Decree 356/2025) | Data and compute provided by Vieomics are stored in Vietnam |
| Global | platform.omicslab.vn | PDPL for personal data in Vietnam | Still in Vietnam; for Vietnamese people or residents of Vietnam, and multinational collaboration |
Customers that need to process non-public sensitive personal data must arrange a separate, contracted customer-managed (self-hosted) deployment as described in Section 1. In a customer-managed deployment, data residency and any international transfers depend on the infrastructure and services you select — not on Vieomics. We do not control and cannot guarantee the physical location of infrastructure that you select, connect or operate — including Bring Your Own Cloud (BYOC) storage, compute or analysis servers — so we do not represent that a customer-managed or BYOC configuration stores data in Vietnam. The contact details in Section 12 apply.
On this website (the landing page) — the Platform itself does not use Google Analytics — traffic data (including IP addresses) is processed by our analytics provider as a processor and is not used for advertising. That service runs only after you press Accept in the cookie notice (Section 11); if you decline, no such data is transferred.
12. Allocation of Responsibility
Security is a shared responsibility. The table below shows who controls each area for each deployment model.
Data accepted on each model. The public, platform-managed (Marketplace) service is intended only for non-human data (microorganisms, plants, animals and environmental samples), simulated or benchmark data, and public data that has been lawfully published or properly de-identified after the assessment described in Section 1. The platform security commitments below apply only to that data. Non-public sensitive personal data — including human genomic, genetic and health data — must not be uploaded to the public Platform and is handled only through a separate, contracted customer-managed (self-hosted) deployment.
| Control / Infrastructure | Self-hosted (customer-managed) | Platform-managed (Marketplace) |
|---|---|---|
| Data storage | Your own cloud / object storage infrastructure | Storage partitioned per workspace; encryption at rest for resources the platform directly operates, using the encryption supported by the underlying provider and configuration (for example AES-256) |
| Version control | Your own source repository (GitHub) | Source repositories integrated in the Marketplace |
| Compute infrastructure | Your own HPC / cloud cluster | Compute infrastructure managed directly by Omicslab |
| Infrastructure access | Managed by the customer | Managed by the platform |
| Credentials | Managed by the customer | Secured by the platform (never shown in plain text) |
| Application stack (frontend, backend, database) | Deployed and operated by the customer | Operated by the platform |
| Infrastructure compliance | Customer’s responsibility | Managed by the platform within its own scope |
Platform security commitments
- Architecture separation: separation of the control plane from the data plane, where configured.
- Least privilege: short-lived credentials with tightly scoped access for every cross-boundary connection.
- Environment isolation: data isolated per workspace, with role-based access control (RBAC).
- Audit transparency: audit logging maintained to support security review.
- Vulnerability management: security incident and misconfiguration reports are received and patched promptly.
The commitments above apply only to the resources Vieomics directly operates. Cloud and infrastructure providers are responsible for their own layer, and where you operate or connect your own infrastructure (BYOC) its encryption, backup, access control and logging are your responsibility — Vieomics cannot guarantee them.
Mandatory customer responsibilities
- Account security: protect your login credentials and enforce strong authentication (MFA/2FA) across your organization.
- Legal and ethical compliance: where you process human genomic or health data, do so only in a customer-managed (self-hosted) environment, and obtain full approval from an ethics board (IRB), voluntary informed consent from data subjects and any other lawful rights required. Such data must not be processed on the public Platform.
- Data access control: classify your data and set appropriate access permissions for each workspace and storage resource.
- Backup and validation: maintain independent backups and take responsibility for validating analysis outputs under your organization’s own research data management policy.
13. Contact
For any question, suggestion or support request related to privacy and personal data protection, please contact us:
- Responsible legal entity: VIEOMICS COMPANY LIMITED
- Data protection contact (DPO): Nguyen Tan Thanh Giang — giangnguyen@omicslab.io
- Website: the Contact page
- Email: contact@omicslab.io (please state “Privacy Request” in the subject line)