Proprietary Data Handling

Ownership and Access

The Principal Investigator (PI) is the legal owner or delegated owner of proprietary data and has full authority over its access and management. Only users explicitly assigned by the PI may access proprietary data. This data can never be made publicly available under any circumstances. For data uploaded through a facility such as a Synchrotron, the facility staff scientists lose access to proprietary data thirty days after an experiment concludes, and employees of DECTRIS Ltd. are never permitted access.

Data Storage and Retention

Proprietary data is stored in restricted-access environments with encryption and multi-location redundancy to ensure security. The retention duration of proprietary data is determined by the PI. The default minimum storage period for archived data is 1 year, unless manually deleted. If the storage period expires and is not extended, the data will be permanently deleted.

Security & Compliance

To safeguard proprietary data, DECTRIS Ltd. implements strict security measures, including controlled access mechanisms to prevent unauthorized access through DECTRIS services, multi-location secure storage to prevent data loss, and encryption during transit and at rest to ensure data integrity. Data is not mirrored or backed up unless agreed on with DECTRIS. Further Further, any data marked as proprietary will not be used by DECTRIS to improve or extend its service capabilities.

Access & Sharing Restrictions

DECTRIS follows the best practices outlined in ISO27001 to ensure data access to DECTRIS employees is strongly restricted to essential and explicitly authorized personnel only. Sharing of data with other users of DECTRIS CLOUD is possible without restrictions, as long as both users belong to the same authenticated institution. Sharing with personnel outside the institution must be confirmed by the PI of the experiment or project.   

Data Processing & Compute Services

Software environments used for proprietary data must ensure the relevant commercial licenses are obtained before. Custom proprietary software environments can not be made publicly accessible and can only be shared with members of the same institution.

Data Modifications and Deletion

Only authorized users may modify proprietary data. The PI has sole authority to extend storage, archive, or delete data. A secure audit log records all access and modifications to ensure transparency and accountability.

Compliance and Reporting

All users handling proprietary data must adhere to this policy and comply with relevant data protection laws. The Scientific Data Officer (SDO) is available to address inquiries, concerns, or compliance issues. For further information, users may contact SDO@dectris.cloud.

 

Questions? Reach out to us here!

Was this article helpful?