Legal

What still needs drafting, and what we can tell you now

This is a status page, not a policy. Ligara is preparing for commercial launch and its legal documents are being drafted with advice. Rather than publish something invented, this page lists what is coming, what each document will have to cover, and how to get the current position in writing in the meantime.

Nothing on this page is a contract, a policy or legal advice. No privacy notice, terms of service or data-processing agreement is in force yet. If you need a binding position today, ask us for it in writing through the contact page.

In preparation

The documents a customer will need

Each is being drafted with legal advice rather than assembled from a template, because a platform holding proprietary chemistry deserves better than a generic agreement.

Legal documents needed before commercial launch, and their status
Document What it will have to cover Status
Privacy notice What account and usage data is collected, the lawful basis for it, retention periods, where it is stored, and how to exercise a data-subject right In preparation
Terms of service Licence scope, acceptable use, who owns customer data, availability expectations, liability limits, suspension and termination, and what happens to data afterwards In preparation
Data processing agreement Roles as controller and processor, processing instructions, security measures, sub-processor list with a change-notification commitment, international transfer mechanism, audit and deletion obligations In preparation
Acceptable use policy Prohibited uses, limits on automated access, and rules on sharing an account or a tenancy In preparation
Service level terms For enterprise engagements only: availability targets, support response commitments, maintenance windows and remedies Per engagement
Security overview for procurement The technical position is already published — see security — including an open register of what is not yet built Published

No compliance certification or attestation exists. Ligara is not SOC 2 attested, not ISO 27001 certified, not 21 CFR Part 11 validated, and there is no such thing as being “GDPR certified”.

In the meantime

What we can tell you now

These are descriptions of how the software behaves, verifiable against the product. They are not legal commitments, and a signed agreement will supersede them.

  • Analysis happens on your device. Plate-file parsing, curve fitting, statistics and chemistry run in your browser, so the data being analysed is not transmitted to us in order to be analysed.
  • ADMET prediction runs locally. The model executes as a process on your own machine rather than through a third-party interface, so structures submitted for prediction do not leave the device.
  • Records are held in a Postgres database with Row-Level Security applied to every table, which is how one organisation's data is kept from another's.
  • You can get your data out. Full export of runs, compounds and inventory as XLSX and CSV is available on every plan, including the free one.
  • No telemetry, no advertising, no third-party analytics are present in the application itself, and your data is not used to train any model. This marketing website is separate and does use one storage-free analytics tool, which is set out on the cookies page.
  • Enterprise engagements can run on dedicated or customer-controlled infrastructure, which moves the residency question into your own estate.

Where you are a data controller and Ligara processes personal data on your behalf, your own obligations are yours to assess. We can describe what the software does and provide the agreement once it is drafted; we cannot advise you on your compliance position.

Open source

Third-party software

Ligara is built on open-source components and ships their attribution and licence notices with the product.

The main categories are the chemistry toolkit compiled to WebAssembly, the charting and molecular-visualisation libraries, the spreadsheet and PDF generation stack, the statistical distribution functions, the database client, the desktop shell, and the build tooling. The prediction sidecars bring their own model and framework licences.

The complete list, with each component's licence, is maintained in the product rather than here, so it stays accurate as dependencies change. Ask if you need a copy for a review.

For a procurement review

If you are assembling a vendor pack, the useful things to ask for are:

  • The third-party component and licence list
  • The security position in writing, beyond the published page
  • A completed security questionnaire
  • The sub-processor list as it stands
  • The draft data processing agreement, once available

We will send what exists and be explicit about what does not, rather than sending a document that implies more than is true.

Request the pack

Need a position in writing?

Tell us what your review requires and we will send what exists today, with the gaps named rather than glossed over.