LEGAL
Privacy Policy
Effective 26 August 2026 · Last updated 26 August 2026
Dark Helix, LLC, doing business as Exigyn ("Exigyn", "we", "us"), provides financial planning and analysis software for biotechnology and pharmaceutical companies. This policy explains what we collect, why, who we share it with, and the choices available to you.
Exigyn is a business-to-business product. Our customers are companies. Most of the data we process is entered or authorized by a customer; for that data the customer is the controller and Exigyn acts as processor or service provider.
1. Information we collect
Account and identity information
Name, email address, role, and organization membership. Authentication is handled by Clerk; we do not store passwords.
Customer financial data
Financial records our customers load or connect, including general-ledger actuals, budgets and forecasts, vendor and purchase-order records, compensation-planning figures, and balance-sheet snapshots.
Clinical operational data
Study, site, and subject identifiers, enrollment counts, visit dates, and per-visit costs, used to forecast and accrue clinical trial spend.
We do not collect protected health information. The system has no fields for patient names, dates of birth, government identifiers, medical records, or clinical outcomes. Subjects appear only as the subject identifier the customer supplies (for example, "S-014").
Integration credentials
When a customer connects an accounting system such as QuickBooks Online or NetSuite, we store the OAuth tokens that system issues. Tokens are encrypted at rest using AES-256-GCM. We never receive or store the customer's accounting-system password.
Usage and diagnostic data
Product analytics events (page views, feature usage, import and export actions) and a sampled session replay. Event properties are limited to identifiers, category values, counts, and booleans — they exclude names, email addresses, subject identifiers, and dollar amounts. Approximately 10% of sessions are recorded, and all on-screen text and all form inputs are masked in those recordings. The analytics user profile does include name and email address.
Audit records
Actions taken in the application are recorded with the acting user, a timestamp, and a description, so customers can meet their own audit obligations.
2. How we use information
· To provide, operate, and secure the service
· To authenticate users and enforce per-organization access control
· To synchronize data from accounting systems a customer has connected
· To produce the forecasts, accruals, and reports customers request
· To maintain the audit trails customers rely on for financial close
· To diagnose faults and improve reliability and usability
· To communicate about the service, including billing and support
· To meet legal and contractual obligations
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We do not use customer financial or clinical data to train machine-learning models, and we do not permit our providers to do so.
3. Artificial intelligence features
Exigyn includes AI-assisted features. When a user invokes one, the relevant context is sent to our AI provider, Anthropic, to generate a response. Anthropic processes that content to return the response and does not use it to train its models.
4. Sub-processors
We use the following providers. Each is bound by contract to protect the data it processes on our behalf.
Vercel — application and API hosting
Supabase — primary database and serverless functions
Clerk — authentication and identity
Anthropic — AI-assisted features
Stripe — subscription billing
Resend — transactional email
Mixpanel — product analytics and session replay
Intuit (QuickBooks Online) — customer-authorized accounting integration
Oracle NetSuite — customer-authorized accounting integration
Cloudflare — bot protection
Google — web fonts and optional single sign-on
Microsoft — Excel add-in distribution and runtime
5. International transfers and data location
Our infrastructure is hosted in the United States. Data is stored and processed in United States regions of our hosting providers.
Customers located in the European Economic Area, the United Kingdom, or Switzerland should also refer to our Data Processing and Compliance with European Data Protection Laws addendum, available on our Legal page, which governs transfers of personal data outside those jurisdictions.
6. Retention
Customer data is retained for the life of the customer's subscription. Because Exigyn is an audit-oriented system, budget versions, amendments, and audit records are retained rather than overwritten, so that prior periods remain reproducible for financial close and audit.
After termination, a customer may request export or deletion of its data. We delete customer data within 30 days of a verified deletion request, except where we are required to retain it by law.
Product analytics data and session recordings are retained for 12 months. Server logs are retained for 30 days.
7. Security
· Encryption in transit (TLS), and encryption of integration credentials at rest (AES-256-GCM)
· Per-organization isolation enforced in the database through row-level security
· Role-based access control, with sensitive actions restricted to administrators
· Session replay masks all text and all form inputs
· A Content-Security-Policy restricting which external services the application may contact
Further detail is available in our Information Security Controls document on our Legal page. No system is perfectly secure, and we cannot guarantee absolute security.
8. Your rights and choices
Where a customer is the controller of the data, requests to access, correct, export, or delete personal information should be directed to that customer; we assist our customers in responding to such requests.
For personal information where Exigyn is the controller — for example, your account profile — you may request access, correction, deletion, or a portable copy by contacting us at angus@exigyn.com. Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the UK and EU GDPR, including the right to lodge a complaint with a supervisory authority.
We respond to verifiable requests within 30 days. Where permitted by applicable law and where a request is complex, we may extend that period and will tell you if we do. We may need to verify your identity before acting on a request.
9. Cookies and similar technologies
We use cookies and similar technologies for two purposes. Strictly necessary cookies sign you in, keep you signed in, and protect the service against abuse; these cannot be disabled. Analytics cookies measure product usage so we can improve the service.
Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in.
10. Children
Exigyn is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
We will post any changes on this page and update the "Last updated" date. For material changes, we will notify customers by email to their account contact at least 30 days before the change takes effect.
12. Contact
For any privacy question, request, or complaint, contact angus@exigyn.com. For security and vulnerability disclosure, contact security@exigyn.com.
Dark Helix, LLC (DBA Exigyn)
131 Continental Drive, Suite 305
Newark, DE 19713
United States