Skip to main content

GDPR Compliance

ResearchArk, operated by Mycel UG (haftungsbeschränkt), is committed to protecting the privacy and rights of our users. We comply with the General Data Protection Regulation (GDPR) of the European Union. This document outlines our approach to GDPR compliance.

Data Collection and Processing

  1. We only collect and process personal data that is necessary for the functioning of our platform and the provision of our services. This includes data provided during account creation, usage data, research-related information, AI interaction data, collaboration data, and document content uploaded for processing.
  2. Personal data is processed lawfully, fairly, and transparently. We process data based on legitimate interests, user consent, and contractual necessity.
  3. Where consent is the legal basis for processing (e.g., marketing communications), we obtain explicit consent from users before collecting their personal data. Users can withdraw consent at any time. For essential cookies required for the Service to function (such as authentication and locale preference cookies), we rely on the "strictly necessary" exemption under ePrivacy regulations and do not require separate consent.
  4. We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. After this period, data is securely deleted or anonymized.
  5. We may use aggregated, anonymized data for research and statistical purposes, which does not identify individual users.
  6. Document content uploaded for analysis is processed securely and in accordance with the purposes specified at the time of upload.

Data Subject Rights

As per GDPR, our users have the following rights:

  • Right to access their personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing (handled by our team upon request to dpo@researchark.eu)
  • Right to data portability
  • Right to object to processing
  • Right to not be subject to automated decision-making

Data Security

We implement appropriate technical and organizational measures to ensure the security of personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage. These measures include encryption, access controls, and regular security assessments.

Data Breach Notification

In the event of a data breach that is likely to result in a high risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority (the Berlin Commissioner for Data Protection and Freedom of Information) within 72 hours of becoming aware of the breach, where feasible. We will also notify affected users without undue delay. Our incident response procedures include investigation and assessment by our technical team.

Data Protection Officer

Our Data Protection Officer can be contacted at dpo@researchark.eu for any GDPR-related inquiries, including exercising your data subject rights.

Data Processing Records

We maintain comprehensive records of our data processing activities as required by Article 30 of the GDPR. These records include:

  • Categories of personal data processed
  • Purposes of processing
  • Legal bases for processing
  • Data retention periods
  • Technical and organizational security measures

Supervisory Authority

The competent supervisory authority for Mycel UG (haftungsbeschränkt) is: Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstraße 219
10969 Berlin, Germany
Website: https://www.datenschutz-berlin.de

You have the right to lodge a complaint with this supervisory authority if you believe your data protection rights have been violated.

Cross-Border Data Transfers

Our primary infrastructure is hosted within the European Economic Area. Certain service providers are based in the United States:

  • Firebase (Google LLC): Authentication services
  • Stripe (Stripe Inc.): Payment processing
  • ORCID (ORCID Inc.): Researcher identity verification
  • Google Gemini API, OpenAI API, Anthropic API: AI-assisted features (prompts and responses are retained by these providers for limited periods for safety monitoring only and are not used for model training; see our Privacy Policy for details)

These providers operate under their respective terms of service, which include data protection commitments consistent with GDPR requirements. We select providers that offer no-training guarantees and minimal data retention for API usage.

For details on our service providers, see our Privacy Policy.


ResearchArk is a product of Mycel UG (haftungsbeschränkt), Kollwitzstraße 76, 10435 Berlin, Germany.
Company Website: https://mycel-ai.de

Version 2.0
Last Updated 24.02.2026

Have questions about our legal documents? Contact us for clarification.

Navigate across policies instantly from the legal submenu without reloading document text.