Your data. Your control.

We handle personal and clinical data with the same care we would expect for our own families: securely, transparently, and only for the purposes you authorize.

Identity blinding

Subject identifiers are pseudonymized before any sponsor, CRO, or monitor access.

Encryption by default

AES-256 at rest and TLS 1.3 in transit for all study and personal data.

Data residency choices

Studies can be pinned to EU, US, India, Japan, Canada, or other regions.

Consent management

Granular eConsent records with version control, audit trails, and withdrawal workflows.

Effective date: August 6, 2026

ProCTTH (“we”, “us”, or “our”) provides a site-centric clinical trial platform used by clinical research sites, sponsors, contract research organizations (CROs), investigators, coordinators, and study participants (subjects).

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our websites, mobile applications, and platform services (collectively, the “Services”).

For questions about this policy or your data rights, contact us at privacy@proctth.com.

Account and profile data: name, email, phone, organization, role, credentials, and professional identifiers such as license numbers where required for regulatory workflows.

Study data: eSource, eCRF, ePRO, eDiary, telemedicine, lab, adverse event, and visit information entered by authorized site and sponsor personnel or captured via subject-facing apps.

Subject data: health information, demographic details, consent records, mobile app usage, reminder responses, and compensation preferences — collected only under study-specific consent.

Technical data: IP address, device type, browser, operating system, crash logs, and usage analytics used to maintain security and improve the Services.

Communication data: messages sent through support channels, demo requests, and marketing preferences.

To operate and secure the platform, authenticate users, enforce role-based access, and generate audit trails required by 21 CFR Part 11, GCP, HIPAA, and GDPR.

To enable study workflows: visit scheduling, form completion, data review, query management, monitoring, safety reporting, and subject engagement.

To provide AI-assisted features such as form suggestions and anomaly detection, with human oversight and without using subject data to train general models.

To communicate with users about service updates, support requests, and relevant product information, subject to communication preferences.

To comply with legal obligations, respond to lawful requests, and protect our rights and users.

Within a study, data is shared only according to role-based permissions and blinding rules configured by the study owner. Sites control what sponsors, CROs, and monitors can see.

We engage subprocessors for cloud hosting, authentication, email delivery, analytics, and customer support. A current list is available upon request and in our Data Processing Addendum.

We do not sell personal data. We do not share subject health information for advertising or unrelated commercial purposes.

We may disclose data if required by law, regulation, court order, or to protect safety and legal rights.

Study data is retained for the period required by the study protocol, sponsor agreement, and applicable regulatory obligations — typically the clinical record retention period plus any archive period mandated by local law.

After the retention period expires, data is securely deleted or anonymized in accordance with our data retention schedule.

Account and contact data is retained while your account is active and for a reasonable period afterward to resolve disputes, enforce agreements, and meet legal requirements.

AES-256 encryption at rest and TLS 1.3 in transit.

Role-based access control, multi-factor authentication, and single sign-on options.

Comprehensive audit logging, intrusion detection, and vulnerability management.

Business Associate Agreements (BAAs) and Data Processing Addenda (DPAs) available for HIPAA and GDPR-covered deployments.

Depending on your location and role, you may have rights to access, correct, restrict, delete, or port your personal data.

Subjects can exercise rights through the site that enrolled them or by contacting privacy@proctth.com. We will coordinate with the relevant study site and sponsor to respond appropriately.

To exercise your rights, email privacy@proctth.com with your request and identifying information. We respond within the timeframes required by applicable law.

ProCTTH supports region-specific hosting to keep study data in the jurisdiction selected by the study owner.

Where transfers are necessary, we use Standard Contractual Clauses and other approved transfer mechanisms to ensure adequate protection.

We may update this Privacy Policy as laws, regulations, or our Services change. Material changes will be communicated through the platform or by email.

The effective date at the top of this page reflects the most recent revision.

Questions about privacy?

Our privacy and compliance team is ready to help sites, sponsors, and subjects understand how data is protected in ProCTTH.