Privacy Policy
Last updated September 2026
BGI Commons, part of the SingularityNET ecosystem, respects your privacy. This policy explains what personal data we collect, how we use it, who we share it with, and the choices you have.
1. Who we are
BGI Commons (bgicommons.org) is operated by:
SingularityNET Foundation
Baarerstrasse 141, 6300 Zug, Switzerland
Swiss enterprise identification number (UID): CHE-358.649.107
A foundation (Stiftung) under Swiss law
Email: info@bgicommons.org
2. What this covers
This policy covers the BGI Commons website and platform: your account, your profile, HyperSprints, teams and submissions, and the emails we send you.
It does not cover third-party services we link to such as GitHub, Google, Telegram, Discord, Mattermost, Google Docs and similar, which run under their own privacy policies.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | Email address, password (stored only as a salted hash), account identifier, verification status | You, at registration |
| Social sign-in | Name, email, avatar and provider user ID from Google or GitHub | Google or GitHub, if you sign in that way |
| Profile | Display name, skills, bio, interests, avatar, links you add (Telegram, Discord, Mattermost), and your “open to being matched” preference | You |
| Participation | Teams you create or join, your role, sprint entries and tracks, milestones, submissions, deliverables, invites, awards | You and other members |
| Content | Messages, comments, descriptions, files and code you share | You |
| Constitution record | That you signed the BGI Commons Constitution, your display name and the date | You, at onboarding |
| Technical | IP address, browser and device type, pages viewed, timestamps | Automatically, when you visit |
| Usage | How the platform is used, see section 5 | Automatically, subject to your cookie choices |
| Correspondence | Emails you send us and our replies | You |
Please do not put sensitive information into your public profile or submissions. We do not ask for it and do not want it there.
4. Why we use it, and on what basis
| What we do | Legal basis |
|---|---|
| Create and secure your account; run the platform, profiles, teams, HyperSprints and submissions | Performance of our contract with you |
| Send transactional emails for verification, invitations, password resets, team and sprint notifications | Performance of our contract |
| Show your public profile, and match you with teams and needs where you have switched matching on | Performance of our contract |
| Keep the platform safe: prevent abuse, investigate breaches of our Terms, secure our systems | Our legitimate interests in a safe, working platform |
| Understand how the platform is used, so we can improve it | Your consent, where consent is required |
| Send a newsletter, if you sign up | Your consent |
| Verify identity and run sanctions and anti-money-laundering checks before paying a reward with monetary value | Performance of our contract |
| Establish, exercise or defend legal claims, and meet legal duties | Legal obligation and our legitimate interests |
Where we rely on consent you can withdraw it at any time, which does not affect what we did beforehand. Where we rely on legitimate interests you can object, and we will stop unless we have compelling grounds to continue.
5. Cookies and similar technologies
Cookies are small files stored on your device that help a site work and remember information about your visit. We also use similar technologies such as local storage and where this policy says “cookies” it covers those too.
BGI Commons and its providers may set cookies that:
| What they do | Why | Who may set them | Roughly how long |
|---|---|---|---|
| Essential | Sign you in and keep you signed in, protect forms against misuse, and remember your cookie choices | BGI Commons | Session to 12 months |
| Analytics | Count visits and show which pages and features get used, so we can improve them | Google (Google Analytics) | Up to 2 years |
| Session recording | Record how visitors move through the site | Microsoft (Microsoft Clarity) | Up to 1 year |
| Sign-in and embedded content | Let you sign in with another service, and load content embedded from one | Google, GitHub, Telegram and similar providers | Set by those providers |
We do not use cookies for advertising, and we do not allow advertising networks to set cookies on this site.
Your choices. Essential cookies cannot be switched off since without them you cannot sign in. Analytics and session recording run only where you have agreed to them, and you can change or withdraw that agreement at any time through account settings. You can also block or delete cookies in your browser settings.
6. Matching and AI
If you switch on “open to being matched”, we use your skills and interests to suggest you to teams and to suggest opportunities to you. You can switch matching off at any time in your profile.
We may run a community matching agent that runs as a bot in our Telegram group rather than on this website. If you post a need or an offer to it, it stores that post so it can match it later against posts made at other times, and shares a match privately with the people involved. Because it runs inside Telegram, Telegram’s privacy policy governs the messages themselves.
We do not use your personal data, your profile or your submissions to train AI or machine-learning models, and we do not make them available to others for that purpose.
Some tools and material here are produced with AI. Their output can be wrong, and it is not professional advice.
7. What other people can see
Your display name is public, and reputation attaches to it. Team names, project titles and descriptions, submissions, and the names of winning teams and their members appear publicly on sprint pages and stay there as a record of that sprint, including after you close your account.
Your email address, password and account settings are not shown to other members.
If you join our Telegram, Discord or Mattermost spaces, what you post there is visible to others in those spaces and governed by that platform’s policy as well as this one.
8. Who we share it with
We do not sell your personal data, and we do not share it for advertising.
We share it with other members as described in section 7, with mentors and judges taking part in a sprint so they can give feedback and judge, and with service providers who help us run the platform under contracts requiring them to process it only on our instructions:
| Provider | Entity and location | What they do for us |
|---|---|---|
| Google Ireland Ltd / Google LLC (US) | Google Analytics; Google sign-in | |
| Microsoft | Microsoft Ireland Operations Ltd / Microsoft Corp (US) | Microsoft Clarity — session recording and heatmaps |
| GitHub | GitHub Inc. (US) | GitHub sign-in |
| Render | Render Services, Inc. (US) | Application hosting, PostgreSQL database, and file/content delivery (uploads are served from Render) |
| Brevo | Sendinblue SAS (France, EU) | Transactional email (verification, invites, team key + congratulations emails) via SMTP |
| Mailchimp | The Rocket Science Group, LLC / Intuit (US) | Newsletter / HyperSprint subscribe list (double opt-in) |
| Error monitoring / support desk | N/A | None in use. No Sentry, Intercom, Zendesk, etc. are integrated |
We may also disclose data to professional advisers and auditors, to courts or authorities where legally required or to defend legal claims, and to a successor if the platform is transferred or reorganised.
9. Sending data abroad
Some of our providers are in the United States or elsewhere outside Switzerland, the EEA and the UK. Where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards, i.e. the European Commission’s Standard Contractual Clauses with the Swiss and UK addenda, or the provider’s Data Privacy Framework certification. Ask us at info@bgicommons.org if you want details of the safeguards for a particular provider.
10. How long we keep it
We keep your account and profile while your account is open, and for a short period afterwards so an accidental deletion can be reversed.
Sprint records such as team records, submissions, awards and the names attached to them are kept as part of the public record of that sprint, including after you close your account.
Correspondence is kept for about two years from the last message. Usage and analytics data is kept for the retention period configured in the tools described in section 5, which does not exceed two years. Where a reward with monetary value has been paid, we keep identity and anti-money-laundering records for ten years, as Swiss law requires.
Where we need to keep something to meet a legal duty or defend a claim, we keep it for as long as that lasts.
11. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or stop certain processing, object to processing based on our legitimate interests, or send it to you or another provider in a portable format. You can withdraw consent you have given at any time.
Most of your information you can change yourself in your profile. For anything else, email info@bgicommons.org.
If you are unhappy with how we handle your data, please tell us so we can put it right. You can also complain to the Swiss Federal Data Protection and Information Commissioner.
12. Security
We take reasonable technical and organisational measures to protect your data, including encryption in transit, hashed passwords, access controls limiting who can reach personal data, and security obligations on our providers.
No online service is completely secure. Use a strong, unique password, keep your login details private, and tell us at info@bgicommons.org if you think someone else has accessed your account.
13. Age
BGI Commons is for people aged 18 and over. Please do not create an account if you are under 18. If we learn that someone under 18 has one, we will close it.
14. Links to other services
The platform links to GitHub, Google, Telegram, Discord, Mattermost and others. We do not control them and are not responsible for how they handle your data.
15. Changes
We will update this policy as the platform develops. When we make a material change we will update the date above and, where it significantly affects you, tell you by email or a notice on the platform.
