This notice explains what information the DecentraLabs Marketplace handles, why it is needed, and which parties may receive it.
Information handled
- Institutional identity attributes received through SAML SSO, such as name, email, affiliation, role and stable pseudonymous identifiers.
- WebAuthn onboarding state and browser markers used to recognise completion for an institution and browser.
- Wallet and institution identifiers, reservations, lab access events, service-credit activity and intent/request identifiers.
- Provider-submitted lab metadata, including documentation, images and the registered institutional backend origin.
- Technical security data such as correlation IDs, request timestamps and bounded operational logs.
Purposes and recipients
The platform uses this information to authenticate institutional users, determine permissions, coordinate onboarding, create and enforce reservations, provide lab access, operate service-credit flows, and protect the service against abuse.
Depending on the operation, information may be sent to the user's institution, a provider's registered institutional backend, the lab gateway, blockchain infrastructure, or service providers supporting hosting and observability. Only the data required for the operation should be sent.
Retention and control
Session identity claims are kept server-side behind an opaque session cookie. Query caches and onboarding/browser markers may remain in the browser for the periods described in the Cookies notice. Reservation and on-chain records may have longer retention because they are required for accounting, auditability and the operation of the decentralized system.
Requests about access, correction, deletion, restriction or objection should be directed to the responsible institution or platform contact after the legal ownership and applicable retention duties have been confirmed.
International and institutional transfers
Institutional backends are independently operated by participating institutions. Their privacy notices and security controls also apply when the Marketplace sends an onboarding or lab-operation request to them. The Marketplace should only use origins registered and verified through the platform trust model.
Contact and governance status
The data controller is Nebulous Systems S.L. The current general contact for privacy and security questions is contact@nebsyst.com; the registered address, legal identifier, designated data protection officer, supervisory authority information and applicable legal bases must still be completed and approved by legal counsel. This page is intentionally explicit about that governance dependency.