Legal
Information Protection Agreement
Last updated October 6, 2026
This Information Protection Agreement (“IPA”) describes the obligations that apply to confidential, proprietary, and protected information exchanged with [Legal entity name] (“4xlabs”). It applies to visitors, partners, vendors, collaborators, and applicants, and forms the baseline standards we apply to information entrusted to us. It supplements, and does not replace, any separately executed nondisclosure agreement.
1. Purpose
4xlabs' work depends on the integrity of information: unpublished research data, experimental protocols, partner data, personnel records, and business information. This IPA establishes uniform standards for how such information is classified, handled, protected, and — when no longer needed — returned or destroyed.
2. Scope & acceptance
By submitting information to us, interacting with our systems, or receiving information from us under a collaboration, you agree to the obligations in this IPA. Where a signed NDA, collaboration agreement, or data use agreement imposes stricter requirements, that agreement controls for the information it covers.
3. Information classification
Information exchanged with 4xlabs is classified into the following tiers:
- Public — information approved for publication, including this site and published research outputs.
- Internal — operational information not intended for the public (schedules, internal documentation).
- Confidential — proprietary research data, protocols, partner data, personnel records, and business information.
- Restricted — regulated or highly sensitive information (including protected health information, biometric identifiers, or personally identifiable research-participant data), which is handled only under a written agreement and applicable law.
4. Confidentiality obligations
Each party will use information of the other party solely for the agreed purpose, will disclose it only to personnel and contractors with a need to know who are bound by confidentiality obligations no less protective than this IPA, and will protect it using at least reasonable care. Neither party will use the other's confidential information to compete against it or to interfere with its relationships.
These obligations do not apply to information that is or becomes public without breach, was lawfully known to the recipient without restriction, is independently developed without use of the discloser's information, or must be disclosed by law (with prompt prior notice to the discloser where lawful).
5. Safeguards
For Confidential and Restricted information, the minimum safeguards include:
- U.S.-based hosting with SOC 2 Type 2 attested infrastructure and encryption in transit.
- Role-based access control, least-privilege access, and multi-factor authentication for administrative access.
- Segregation of research and participant data from public-facing systems.
- Logging of access to Restricted information and periodic access reviews.
- Confidentiality agreements and security awareness training for personnel.
6. Information security incidents
A party that becomes aware of unauthorized access to, or acquisition, use, or disclosure of, the other party's Confidential or Restricted information will notify the other party without undue delay (target: within 72 hours of confirmation), will investigate and remediate the cause, and will cooperate in any required notifications to regulators or affected individuals. Notification is not an admission of fault or liability.
7. Visitors & the lab environment
Visitors to 4xlabs facilities agree not to photograph, record, copy, or remove Confidential or Restricted information, samples, or materials without written authorization, and to follow all posted safety and information-handling rules. Filming and photography requests must be approved in advance by 4xlabs.
8. Human participant data
4xlabs conducts research only with the voluntary, informed participation of human subjects under applicable ethical and regulatory requirements. Research-participant data is classified as Restricted, is de-identified wherever the science permits, and is shared outside the study team only under an approved data use agreement and consistent with the original consent.
9. Third-party flow-down
Partners, vendors, and contractors who receive Confidential or Restricted information from 4xlabs must impose equivalent obligations on their own personnel and subcontractors before further disclosure, and remain responsible for their compliance.
10. Return or destruction
Upon request or upon conclusion of the purpose for which information was shared, the recipient will promptly return or destroy the discloser's Confidential and Restricted information, certify destruction on request, and may retain copies only where required by law or routine backup, subject to continuing confidentiality.
11. No guarantee; remedies
The parties acknowledge that no security program can guarantee absolute protection. The safeguards in this IPA represent commercially reasonable measures, not a warranty of perfect security. Because unauthorized use or disclosure of Confidential or Restricted information may cause harm not fully compensable by money damages, the discloser may seek equitable relief, including injunctive relief, in addition to any other remedies available.
12. Governing law & contact
This IPA is governed by the laws of the State of [State]. Security questions, incident reports, or requests related to information protection may be directed to [legal@4xlabs.com].