Privacy policy
This policy explains what information Rhyos collects through this website, how we use it, and the choices you have. It applies to visitors of rhyos.life and related Rhyos subdomains.
Effective 7 September 2026
Who we are
Rhyos is an early-stage company developing an optical sensor intended to measure cerebral blood flow from outside the head. We are based in the Netherlands.
For privacy questions, the data controller is:
[Rhyos legal entity name]
[Registered street address]
[City and postal code], The Netherlands
Email: [privacy@rhyos.life]
The legal entity name, address, and privacy email will be completed once the company registration is finalized. Until then, you can reach the founders through the contact form or LinkedIn.
What information we collect
We collect different categories of information depending on how you use the site:
Information you provide directly
- Contact form. If you use the contact form, you provide your name, email address, and message. A random submission reference is generated in your browser so a retry can be recognised without sending the same message twice.
- Staff sign-in. Invited staff members sign in through Google OAuth. We receive the account identifier, email address, and session data needed to verify membership in our external identity and records service.
Information collected automatically
- Technical logs. Our hosting provider and edge network may log your IP address, browser type, requested pages, response status, referrer, and timestamp. These logs are used to keep the site secure and available.
- Essential session data. When staff sign in, our identity provider stores session tokens and access logs that are strictly necessary to maintain a secure private workspace.
We do not use advertising trackers, analytics trackers, or non-essential cookies on this version of the website.
How we use your information
We use the information above for the following purposes:
- Responding to enquiries. Contact details are used to answer your message and maintain relevant correspondence.
- Providing the staff workspace. Staff identity data is used to authenticate members, enforce access controls, and record permitted actions on company records.
- Security and abuse prevention. Technical logs help us detect attacks, spam, or other misuse of the website or staff area.
- Improving the website. Error and availability data may be used to fix problems and keep the site running.
Our legal basis for processing contact form data is our legitimate interest in communicating with prospective partners, collaborators, and other interested parties, or your consent when you submit the form. Staff data is processed on the basis of the employment or membership relationship and our legitimate interest in securing internal systems.
Cookies and similar technologies
This website does not place advertising, analytics, or non-essential cookies. We therefore do not show a cookie consent banner.
Staff sign-in relies on cookies or local storage that are strictly necessary to keep a requested private session secure. These are set by our external identity provider and are essential for the staff area to function.
If we introduce analytics or optional cookies in the future, we will update this policy and provide a consent mechanism before enabling them.
Google sign-in for staff
The private staff area uses Google OAuth through our company-controlled Supabase project. When an invited staff member signs in:
- Google shares the account identifier and email address with Rhyos.
- Our Supabase project checks whether that account has an active Rhyos membership before granting access.
- Session tokens are stored in the browser and are used only to maintain the authenticated session.
We do not use Google sign-in for public visitors, and we do not request access to Google account data beyond what is needed for authentication.
Who we share information with
We do not sell personal information. We may share data with the following recipients:
- Hosting and edge providers. Technical logs are processed by the services that serve the website and protect it from malicious traffic.
- Identity and records service. Staff authentication and authorised record access are handled by our external, company-controlled Supabase project.
- Contact receiver. If a contact endpoint is configured, your message is sent to the company-controlled receiver selected by Rhyos.
- Legal and professional advisers. We may disclose information when required by law or to enforce our rights.
Each recipient is contractually or legally bound to use personal information only for the purpose for which it was shared and to protect it appropriately.
International transfers
Our hosting and identity providers may process data in the European Union, the United States, and other countries. When personal information is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or the provider's certification under recognised transfer mechanisms.
How long we keep information
We keep personal information only as long as necessary for the relevant purpose:
- Contact messages. Retained for as long as needed to respond and maintain a business relationship, and then deleted or anonymised unless legal obligations require a longer retention period.
- Staff access logs. Retained according to our internal security and audit policy, typically for a limited period necessary to investigate incidents and satisfy compliance obligations.
- Technical logs. Retained by our hosting providers for the periods defined in their respective policies.
Security
We use HTTPS for all public pages, enforce Content Security Policy headers, and rely on our hosting and identity providers for infrastructure security. Staff access is restricted to invited members and checked against an external membership service.
No internet service can guarantee absolute security. If we become aware of a breach that affects your personal information, we will notify you and the relevant supervisory authority in accordance with applicable law.
Your rights
Depending on your location, you may have the following rights regarding your personal information:
- Access. You can ask for a copy of the personal information we hold about you.
- Correction. You can ask us to correct inaccurate or incomplete information.
- Erasure. You can ask us to delete your personal information in certain circumstances.
- Restriction. You can ask us to limit how we use your information.
- Objection. You can object to processing based on legitimate interests.
- Data portability. You can ask for your information in a structured, machine-readable format.
- Withdraw consent. Where processing is based on consent, you can withdraw it at any time.
To exercise these rights, contact us using the details in the “Who we are” section above. We will respond within the time limits set by applicable law.
Children's privacy
This website is not directed at children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
Third-party links
This website may contain links to LinkedIn profiles and other external sites. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy policies.
Changes to this policy
We may update this privacy policy when the website, our services, or legal requirements change. The “Effective date” at the top of the page shows when this version was last updated. Material changes will be noted in a revised effective date.
How to contact us
For privacy questions, data requests, or complaints, contact us at the address in the “Who we are” section, or use the contact form on this website.
If you are not satisfied with our response, you have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.