We built compliance into every process from the start โ not as an afterthought. Here's exactly what that means for your study data.
Our processes are designed for clients operating under the strictest international data privacy regimes.
All patient and HCP data collected on behalf of EU/UK clients is handled in full accordance with GDPR requirements โ including data minimisation, purpose limitation, and documented consent.
Data is encrypted in transit and at rest. Access is role-restricted and logged. We do not sell, share, or transfer respondent data to third parties under any circumstances.
Every respondent provides documented informed consent before participation. Consent forms are designed for local regulatory requirements and are retained for audit purposes.
Personal identifiers are stripped or pseudonymised before data is shared with clients. Re-identification is not possible from deliverables without the key, which we hold separately.
Raw data is retained for the agreed period and then securely deleted or returned to the client. We do not retain respondent-level data beyond project close unless contractually required.
We execute Data Processing Agreements (DPAs) with all clients prior to study commencement โ a standard requirement for GDPR-regulated engagements.
We agree and sign a Data Processing Agreement before any data collection begins. This defines data categories, retention periods, sub-processor use, and breach notification timelines.
Only data necessary for the study objective is collected (data minimisation). Consent language is reviewed against the applicable regulatory standard for the respondent's country.
All respondents provide documented informed consent. Data is collected on encrypted platforms. No personal identifiers are attached to response data after collection.
Deliverables contain only pseudonymised or fully anonymised data. Files are transferred via encrypted channels (SFTP or secure share). Raw data is not included in client deliverables unless contractually agreed.
At project close, raw data is securely deleted or returned per the DPA. Certificates of deletion are available on request.
Yes. We execute DPAs with all EU/UK clients and operate under GDPR-compliant data handling processes end-to-end.
Primary data storage is within India. For EU clients requiring data residency within the EEA, we can discuss appropriate technical and contractual arrangements.
Access is restricted to the project team on a need-to-know basis. Access logs are maintained and available for audit on request.
Where sub-processors are used (e.g. survey platforms), they are disclosed in the DPA and held to equivalent data protection standards.
We have a documented incident response procedure. Clients are notified within 72 hours of a confirmed breach, as required under GDPR Article 33.