Skip to content

Privacy Policy

Last updated: August 26, 2026

This Privacy Policy describes how Enjamb Labs, Inc., a Delaware corporation (“Enjamb,” “we,” “us,” or “our”), handles personal data in connection with enjamb.ai, app.enjamb.ai, and the software, APIs, agents, and related services we provide (together, the “Services”).

Enjamb is enterprise software for biopharma research and development. Organizations enter into a written agreement with us, we provision a workspace for them, and their administrators invite named users. There is no consumer sign-up and no self-serve plan.

Three commitments sit behind everything below. We do not sell personal data. We do not train models on customer content. An organization's data belongs to that organization, and we hold it to deliver the Services and for no other purpose.

1. What This Policy Covers

This Policy applies to personal data we handle as a controller, meaning data where we decide the purpose and the means of processing. In practice that is the data of website visitors, of people who contact us or request a demonstration, and the account and usage records of users inside a customer workspace.

This Policy does not govern the content an organization puts into the Services, or the data our agents read from the systems that organization connects. That material is Customer Data. We process it as a processor on the customer's documented instructions, under their agreement and data processing addendum, and this Policy does not vary those terms. Where the two ever conflict, the customer's agreement controls.

If you are an employee or contractor of a customer and want to exercise a right over Customer Data, your own organization is the right place to start, because it decides what happens to that data. We will support them in responding.

2. Personal Data We Collect

Data you give us directly. When an organization is onboarded we receive the name, work email address, role, and organization of each person to be provisioned, along with the administrators who manage the workspace. When you contact us, request a demonstration, or apply for a role, we receive whatever you choose to send, including your message and any attachments.

Data we collect automatically. When you use the Services we record log and device data such as IP address, browser and operating system, timestamps, features used, and errors encountered. Inside a workspace we record which user took which action, on which system, at what time, because attribution is a function of the product rather than an analytics extra.

Data from other sources. Where an organization uses single sign-on or directory synchronization, we receive identity and group membership from that identity provider. Where an organization connects a system such as an electronic lab notebook, a document vault, or a clinical data platform, we receive credentials or tokens for that connection and whatever data the connection is scoped to return.

Sensitive categories. We do not ask for and do not want government identifiers, financial account numbers, or health information about identifiable individuals. Customers control what enters their own workspace and their agreement governs it, but nothing in the Services requires that category of data about a named person in order to work.

3. How We Use Personal Data

  • To provide the Services: provisioning workspaces, authenticating users, running agents under the identity of the person who asked, and connecting to the systems an organization has authorized.
  • To keep the Services secure: detecting and investigating abuse, unauthorized access, and vulnerabilities, and maintaining the audit record behind each run.
  • To support customers: answering questions, diagnosing problems, and communicating about incidents, changes, and availability.
  • To improve the Services: understanding which features are used and where work fails, using aggregated and de-identified usage data rather than customer content.
  • To meet legal and contractual obligations, including record-keeping obligations that apply to us or to a customer we serve.

We do not use personal data for advertising, we do not sell it, and we do not share it for cross-context behavioral advertising as those terms are defined under United States state privacy laws.

4. Models, Agents, and Training

The Services use large language models, some operated by us and some by model providers we engage as subprocessors. When an agent runs, the content it needs is sent to the selected model to produce the result, and is retained only as long as the run and its audit record require.

We do not train, fine-tune, or otherwise improve any model on customer content or on the personal data described in this Policy, and our agreements with model providers prohibit them from doing so with data we send on a customer's behalf. Where a provider's terms differ for a particular model, that model is presented as an explicit choice with its terms stated, and it is not enabled by default.

Agents act with the authority of the person who asked. An agent reaches a connected system as that user, inside the permissions that user already holds, so it cannot open a study, a document, or a dataset the requester could not open themselves. Actions that change a system of record can be placed behind human approval by an administrator.

Model output can be wrong. The Services are built so that a result carries the sources, actions, and assumptions behind it, and they are intended to support the judgment of a qualified professional rather than replace it. Nothing the Services produce is medical, legal, or regulatory advice.

5. When We Share Personal Data

We share personal data only in the circumstances below, and never in exchange for money or other valuable consideration.

  • Subprocessors. Vendors that host, secure, or operate parts of the Services, including cloud infrastructure, model providers, and communication and support tooling. Each is bound by written terms limiting them to processing on our instructions. The current list is published at Subprocessors, and where a customer's agreement requires it we give notice before changes.
  • The customer organization. Where you use the Services as a member of an organization, that organization's administrators can see your account details and your activity in the workspace, because they are accountable for the work done in it.
  • Connected systems. Where you or your administrator connects an external system, we exchange data with that system as directed. What it does with that data is governed by your agreement with its provider, not by this Policy.
  • Legal and safety. Where required by law, legal process, or a binding request from a public authority, or to establish or defend legal claims, or to address a threat to the security of the Services or the safety of a person. We push back on requests that are overbroad and, unless legally prohibited, we tell the affected customer.
  • Corporate transactions. In connection with a merger, financing, acquisition, or sale of assets, subject to the acquirer honoring the commitments in this Policy for the data it receives.

6. Security and International Transfers

We encrypt data in transit and at rest, isolate customer workspaces from one another, support single sign-on and multi-factor authentication, restrict internal access to personnel who need it for a documented reason, and keep a record of that access. Our controls, certifications, and current status are described on our security page.

No system is perfectly secure. If a breach affects personal data we hold, we will notify affected customers without undue delay and within the timeframes their agreement and applicable law require, with the facts we have established rather than a holding statement.

We are established in the United States and our infrastructure is operated there unless a customer's agreement specifies another region. Where personal data moves from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses and the United Kingdom Addendum, together with the supplementary measures described in our data processing addendum. A copy of the mechanism relied on for a particular transfer is available on request.

7. Data Retention

We keep personal data for as long as it is needed for the purpose it was collected for, and then delete or de-identify it.

  • Account and workspace records: for the term of the customer's agreement, and then per the deletion terms in that agreement.
  • Audit and activity records: for the retention period the customer configures, which regulated customers often set to meet their own record-keeping obligations rather than ours.
  • Support and enquiry correspondence: for as long as needed to resolve the matter and keep a record of it, then on a routine deletion schedule.
  • Security and log data: for a limited period sufficient to investigate incidents.

Customer Data is deleted on the customer's terms. On termination we return or delete it as their agreement provides, and backups age out on a documented cycle after that.

8. Your Rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, to withdraw consent where we relied on it, and not to be treated differently for exercising any of these.

To exercise a right, write to privacy@enjamb.ai. We will verify your identity before acting and respond within the period applicable law requires. You may use an authorized agent where the law allows it. If you are unhappy with our response you may complain to your supervisory authority, which in the United Kingdom is the Information Commissioner's Office.

If your data reached us as Customer Data, we will refer your request to the organization that controls it and support them in responding, because they, not we, decide what happens to it.

Legal bases for processing in the European Economic Area, the United Kingdom, and Switzerland: performance of a contract, where processing is needed to provide the Services; legitimate interests, in securing and improving them; compliance with a legal obligation; and consent, where we ask for it, which you can withdraw at any time.

9. Cookies

On enjamb.ai we use cookies that are strictly necessary to serve the site and keep it secure, and a limited set of analytics cookies that tell us which pages are read. In the product we use cookies that keep you signed in and preserve your session.

We do not use advertising cookies and we do not allow third parties to track you across other sites through our properties. You can refuse non-essential cookies through the banner or your browser, and the site will work.

10. Children

The Services are business software sold to organizations and are not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it.

11. Changes to This Policy

We may update this Policy as the Services or the law change. The date at the top reflects the current version. Where a change materially affects how we handle personal data, we will give notice through the Services or by email before it takes effect, and customers with a written agreement will receive the notice that agreement requires.

Contact

Privacy questions and rights requests: privacy@enjamb.ai. Security reports: security@enjamb.ai. Contractual and legal notices: legal@enjamb.ai.

Enjamb Labs, Inc., a Delaware corporation, United States. Written notice may also be sent to the registered address named in your agreement.

Bring Biopharma-Class AI Into Your Company

Request a demo