Data privacy & compliance

Your patient data is handled the way your regulators expect.

We built compliance into every process from the start โ€” not as an afterthought. Here's exactly what that means for your study data.

Certifications & standards

What we comply with

Our processes are designed for clients operating under the strictest international data privacy regimes.

๐Ÿ‡ช๐Ÿ‡บ

GDPR Compliant

All patient and HCP data collected on behalf of EU/UK clients is handled in full accordance with GDPR requirements โ€” including data minimisation, purpose limitation, and documented consent.

๐Ÿ”’

Data Security

Data is encrypted in transit and at rest. Access is role-restricted and logged. We do not sell, share, or transfer respondent data to third parties under any circumstances.

๐Ÿ“‹

Informed Consent

Every respondent provides documented informed consent before participation. Consent forms are designed for local regulatory requirements and are retained for audit purposes.

๐Ÿงพ

Anonymisation & Pseudonymisation

Personal identifiers are stripped or pseudonymised before data is shared with clients. Re-identification is not possible from deliverables without the key, which we hold separately.

๐Ÿ“

Data Retention Policy

Raw data is retained for the agreed period and then securely deleted or returned to the client. We do not retain respondent-level data beyond project close unless contractually required.

๐Ÿค

Data Processing Agreements

We execute Data Processing Agreements (DPAs) with all clients prior to study commencement โ€” a standard requirement for GDPR-regulated engagements.

How compliance is built in

Our data protection process

STEP 01 โ€” ONBOARDING

DPA & contract execution

We agree and sign a Data Processing Agreement before any data collection begins. This defines data categories, retention periods, sub-processor use, and breach notification timelines.

STEP 02 โ€” DESIGN

Privacy-by-design study setup

Only data necessary for the study objective is collected (data minimisation). Consent language is reviewed against the applicable regulatory standard for the respondent's country.

STEP 03 โ€” FIELD

Consented, secure data collection

All respondents provide documented informed consent. Data is collected on encrypted platforms. No personal identifiers are attached to response data after collection.

STEP 04 โ€” DELIVERY

Anonymised data transfer

Deliverables contain only pseudonymised or fully anonymised data. Files are transferred via encrypted channels (SFTP or secure share). Raw data is not included in client deliverables unless contractually agreed.

STEP 05 โ€” CLOSE

Secure deletion or return

At project close, raw data is securely deleted or returned per the DPA. Certificates of deletion are available on request.

Common questions

FAQ โ€” compliance & data

Can we run GDPR-regulated studies through you?

Yes. We execute DPAs with all EU/UK clients and operate under GDPR-compliant data handling processes end-to-end.

Where is data stored?

Primary data storage is within India. For EU clients requiring data residency within the EEA, we can discuss appropriate technical and contractual arrangements.

Who has access to respondent data?

Access is restricted to the project team on a need-to-know basis. Access logs are maintained and available for audit on request.

Do you use sub-processors?

Where sub-processors are used (e.g. survey platforms), they are disclosed in the DPA and held to equivalent data protection standards.

What happens if there is a data breach?

We have a documented incident response procedure. Clients are notified within 72 hours of a confirmed breach, as required under GDPR Article 33.

Questions about our compliance posture?

Speak to our team