Privacy Policy
PRIVACY POLICY
Effective Date: September 2025
ClinCapture, Inc. (“ClinCapture,” “we,” “our,” or “us”) respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our website (www.clincapture.com), products, or services.
- Scope
This Privacy Policy applies to:
- Visitors to our website (www.clincapture.com),
- Prospective customers who request information about our products and services,
- Customers and users of our solutions (such as Captivate® EDC and related modules), and
- Job applicants and business partners who engage with ClinCapture.
This Policy does not apply to anonymized clinical trial data entered into our systems by our customers. Such data is owned and controlled by our customers (sponsors and CROs), who act as data controllers. ClinCapture processes this data strictly as a data processor/service provider under contractual agreements, in compliance with GDPR, CCPA/CPRA, HIPAA, and ISO 27001.
- Information We Collect
We may collect the following categories of information:
- Identifiers (e.g., name, email address, phone number, company name, IP address).
- Professional information (e.g., job title, employer, role in clinical research).
- Website usage data (e.g., device type, browser, pages visited, cookies and analytics).
- Transactional information (e.g., billing details, order history).
- Recruitment data (e.g., CVs, application information).
We do not sell personal information.
- How We Use Your Information
We process personal data for the following purposes:
- To provide, maintain, and improve our products and services,
- To communicate with you about inquiries, demos, contracts, or support,
- To comply with legal and regulatory obligations,
- To secure and monitor our systems in accordance with ISO/IEC 27001,
- To market our services where permitted (with opt-out rights under GDPR/CCPA).
- Legal Basis for Processing (GDPR)
Where GDPR applies, we process your personal data under the following bases:
- Contractual necessity – to provide services you requested,
- Legal obligations – to comply with tax, regulatory, or audit requirements,
- Legitimate interests – for business operations, marketing, or security, unless overridden by your rights,
- Consent – where explicitly required (e.g., for marketing communications).
- Your Rights (GDPR and CCPA/CPRA)
Under GDPR, you have the right to:
- Access your personal data,
- Rectify inaccurate data,
- Erase data (“right to be forgotten”),
- Restrict or object to processing,
- Data portability,
- Withdraw consent at any time.
Under CCPA/CPRA, California residents have the right to:
- Know what categories of personal information we collect and how we use it,
- Request access to the specific personal information we hold,
- Request deletion of your personal information (subject to exceptions),
- Opt out of “sale” or “sharing” of personal information (we do not sell personal data),
- Exercise these rights free from discrimination.
Requests may be submitted to [email protected]. We will verify your identity before fulfilling requests.
- Data Retention
We retain personal data only as long as necessary for the purposes described above, in line with our ISO 27001–compliant retention schedules, contractual obligations, and applicable laws.
- Data Security
ClinCapture maintains an Information Security Management System (ISMS) aligned with ISO/IEC 27001 and implements technical, organizational, and administrative safeguards to protect your personal data, including:
- Encryption of data in transit and at rest,
- Access controls and authentication,
- Regular penetration tests and vulnerability scans,
- Audit logging and monitoring,
- Vendor risk management.
No system is 100% secure, but we continuously monitor and improve our security practices.
- International Data Transfers
ClinCapture is headquartered in the United States. If you access our services from outside the U.S., your data may be transferred to and processed in the U.S. We implement appropriate safeguards, including Standard Contractual Clauses (SCCs) where required under GDPR.
- Third Parties
We may share your information with trusted service providers who support our operations (e.g., hosting, analytics, payment processing). All such providers are bound by contractual obligations to protect your data in line with GDPR, CCPA/CPRA, and ISO 27001.
- Cookies and Tracking
We use cookies and similar technologies for website functionality, performance, and analytics. You may manage your cookie preferences through your browser settings. For jurisdictions requiring consent, we provide cookie notices and preference tools.
- Children’s Privacy
Our Website and services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us at [email protected].
- Changes to this Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. Continued use of our Website after updates constitutes acceptance.
- Contact Us
If you have questions or wish to exercise your rights under this Privacy Policy, please contact us at:
ClinCapture, Inc.
Email: [email protected]