This Privacy Policy describes how Enjamb Labs, Inc., a Delaware corporation (“Enjamb,” “we,” “us,” or “our”), handles personal data in connection with enjamb.ai, app.enjamb.ai, and the software, APIs, agents, and related services we provide (together, the “Services”).
Enjamb is enterprise software for biopharma research and development. Organizations enter into a written agreement with us, we provision a workspace for them, and their administrators invite named users. There is no consumer sign-up and no self-serve plan.
Three commitments sit behind everything below. We do not sell personal data. We do not train models on customer content. An organization's data belongs to that organization, and we hold it to deliver the Services and for no other purpose.
1. What This Policy Covers
This Policy applies to personal data we handle as a controller, meaning data where we decide the purpose and the means of processing. In practice that is the data of website visitors, of people who contact us or request a demonstration, and the account and usage records of users inside a customer workspace.
This Policy does not govern the content an organization puts into the Services, or the data our agents read from the systems that organization connects. That material is Customer Data. We process it as a processor on the customer's documented instructions, under their agreement and data processing addendum, and this Policy does not vary those terms. Where the two ever conflict, the customer's agreement controls.
If you are an employee or contractor of a customer and want to exercise a right over Customer Data, your own organization is the right place to start, because it decides what happens to that data. We will support them in responding.
2. Personal Data We Collect
Data you give us directly. When an organization is onboarded we receive the name, work email address, role, and organization of each person to be provisioned, along with the administrators who manage the workspace. When you contact us, request a demonstration, or apply for a role, we receive whatever you choose to send, including your message and any attachments.
Data we collect automatically. When you use the Services we record log and device data such as IP address, browser and operating system, timestamps, features used, and errors encountered. Inside a workspace we record which user took which action, on which system, at what time, because attribution is a function of the product rather than an analytics extra.
Data from other sources. Where an organization uses single sign-on or directory synchronization, we receive identity and group membership from that identity provider. Where an organization connects a system such as an electronic lab notebook, a document vault, or a clinical data platform, we receive credentials or tokens for that connection and whatever data the connection is scoped to return.
Sensitive categories. We do not ask for and do not want government identifiers, financial account numbers, or health information about identifiable individuals. Customers control what enters their own workspace and their agreement governs it, but nothing in the Services requires that category of data about a named person in order to work.
3. How We Use Personal Data
- To provide the Services: provisioning workspaces, authenticating users, running agents under the identity of the person who asked, and connecting to the systems an organization has authorized.
- To keep the Services secure: detecting and investigating abuse, unauthorized access, and vulnerabilities, and maintaining the audit record behind each run.
- To support customers: answering questions, diagnosing problems, and communicating about incidents, changes, and availability.
- To improve the Services: understanding which features are used and where work fails, using aggregated and de-identified usage data rather than customer content.
- To meet legal and contractual obligations, including record-keeping obligations that apply to us or to a customer we serve.
We do not use personal data for advertising, we do not sell it, and we do not share it for cross-context behavioral advertising as those terms are defined under United States state privacy laws.
4. Models, Agents, and Training
The Services use large language models, some operated by us and some by model providers we engage as subprocessors. When an agent runs, the content it needs is sent to the selected model to produce the result, and is retained only as long as the run and its audit record require.
We do not train, fine-tune, or otherwise improve any model on customer content or on the personal data described in this Policy, and our agreements with model providers prohibit them from doing so with data we send on a customer's behalf. Where a provider's terms differ for a particular model, that model is presented as an explicit choice with its terms stated, and it is not enabled by default.
Agents act with the authority of the person who asked. An agent reaches a connected system as that user, inside the permissions that user already holds, so it cannot open a study, a document, or a dataset the requester could not open themselves. Actions that change a system of record can be placed behind human approval by an administrator.
Model output can be wrong. The Services are built so that a result carries the sources, actions, and assumptions behind it, and they are intended to support the judgment of a qualified professional rather than replace it. Nothing the Services produce is medical, legal, or regulatory advice.
6. Security and International Transfers
We encrypt data in transit and at rest, isolate customer workspaces from one another, support single sign-on and multi-factor authentication, restrict internal access to personnel who need it for a documented reason, and keep a record of that access. Our controls, certifications, and current status are described on our security page.
No system is perfectly secure. If a breach affects personal data we hold, we will notify affected customers without undue delay and within the timeframes their agreement and applicable law require, with the facts we have established rather than a holding statement.
We are established in the United States and our infrastructure is operated there unless a customer's agreement specifies another region. Where personal data moves from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses and the United Kingdom Addendum, together with the supplementary measures described in our data processing addendum. A copy of the mechanism relied on for a particular transfer is available on request.
7. Data Retention
We keep personal data for as long as it is needed for the purpose it was collected for, and then delete or de-identify it.
- Account and workspace records: for the term of the customer's agreement, and then per the deletion terms in that agreement.
- Audit and activity records: for the retention period the customer configures, which regulated customers often set to meet their own record-keeping obligations rather than ours.
- Support and enquiry correspondence: for as long as needed to resolve the matter and keep a record of it, then on a routine deletion schedule.
- Security and log data: for a limited period sufficient to investigate incidents.
Customer Data is deleted on the customer's terms. On termination we return or delete it as their agreement provides, and backups age out on a documented cycle after that.
8. Your Rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, to withdraw consent where we relied on it, and not to be treated differently for exercising any of these.
To exercise a right, write to privacy@enjamb.ai. We will verify your identity before acting and respond within the period applicable law requires. You may use an authorized agent where the law allows it. If you are unhappy with our response you may complain to your supervisory authority, which in the United Kingdom is the Information Commissioner's Office.
If your data reached us as Customer Data, we will refer your request to the organization that controls it and support them in responding, because they, not we, decide what happens to it.
Legal bases for processing in the European Economic Area, the United Kingdom, and Switzerland: performance of a contract, where processing is needed to provide the Services; legitimate interests, in securing and improving them; compliance with a legal obligation; and consent, where we ask for it, which you can withdraw at any time.
10. Children
The Services are business software sold to organizations and are not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it.
11. Changes to This Policy
We may update this Policy as the Services or the law change. The date at the top reflects the current version. Where a change materially affects how we handle personal data, we will give notice through the Services or by email before it takes effect, and customers with a written agreement will receive the notice that agreement requires.
Contact
Privacy questions and rights requests: privacy@enjamb.ai. Security reports: security@enjamb.ai. Contractual and legal notices: legal@enjamb.ai.
Enjamb Labs, Inc., a Delaware corporation, United States. Written notice may also be sent to the registered address named in your agreement.


