EDC Platform Privacy Policy

Privacy Policy for Authorized Users of the Enlighten Clinical Solutions EDC Platform

Effective Date: January 25, 2025
Last Updated: October 30, 2025

1.0 Introduction

This Privacy Policy outlines how Enlighten Clinical Solutions (“Company,” “we,” “our,” or “us”) collects, processes, acts as a controller for, and protects the information of individuals (“Users”) who are authorized to access our Electronic Data Capture (EDC) Platform (“Platform”).

Users of the Platform are authorized individuals designated by the Sponsor or Contracting Entity (which may be the Sponsor itself or a third party acting on its behalf, such as a CRO or SMO). This Privacy Policy is specific to system users and does not apply to patient data or general website visitors.

By accessing the Platform, Users acknowledge their understanding of this Privacy Policy and agree to the terms outlined herein.

2.0 Scope & Purpose

This Privacy Policy applies to:

  • Authorized Users who have been granted access to the Platform by a Sponsor or Contracting Entity.
  • The processing of account-related data necessary for Platform access and system functionality.

This Privacy Policy does not govern the anonymized clinical trial participant data entered into the Platform, which remains the property and responsibility of the Sponsor or Contracting Entity in accordance with applicable regulations such as GDPR, HIPAA, and 21 CFR Part 11.

Legal Basis for Processing:
We process personal data under (Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) (compliance with legal obligations), and Art. 6(1)(f) GDPR (legitimate security interests).

3.0 Information We Collect

Enlighten Clinical Solutions only collects, is the Controller of, processes the minimum necessary data required for User authentication, access control, and system functionality.
The types of data we collect include:

3.1 User Account Data

  • Full Name
  • Email Address
  • Username & Password (encrypted and secured)
  • Role & Access Level (as assigned by the Sponsor or Contracting Entity)

3.2 System Usage Data

  • Login timestamps & access logs (for security and audit purposes)
  • IP Address & Device Information (for fraud prevention and system integrity)
  • Activity Logs (e.g., actions performed in the system for compliance tracking)

3.3 Communications Data

  • If a User contacts technical support, we collect the content of the inquiry to provide assistance.
  • Email notifications related to system updates, security alerts, or compliance requirements may be sent as part of system functionality.

Providing this information is necessary for account creation, security verification, and fulfillment of contractual obligations. If you choose not to provide it, we will be unable to create your account or ensure it meets required security measures.

If your account information was provided by a Sponsor or Contracting Entity, we process it for the purposes and legal bases outlined in Section 4.0. You were informed of this at the time of account creation or first login.

No automated decision-making or profiling occurs in compliance with Article 22 of the GDPR.

4.0 How We Use User Data

User data is collected only for system operation, security, and regulatory compliance. We do not process personal data for marketing, advertising, or commercial purposes.

We use collected data to:

  • Authenticate users & manage access to the Platform. Legal Basis: (GDPR (Art.6(1)(b)) – Contract)
  • Maintain security & audit trails for regulatory compliance (e.g., 21 CFR Part 11) Legal Basis: (GDPR (Art.6(1)(c)) – Legal obligation)
  • Detect and prevent unauthorized access or security breaches. Legal Basis: (GDPR (Art.6(1)(f)) – Legitimate Interest)
  • Provide customer support and respond to technical inquiries. Legal Basis: (GDPR (Art.6(1)(b)) – Contract)
  • Ensure compliance with Sponsor-imposed trial protocols regarding system usage. Legal Basis: (GDPR (Art.6(1)(b)) – Contract)

5.0 Data Sharing & Disclosures

We do not sell, rent, or commercially share User data. However, we may disclose Recipients include:

  • Sponsor or Contracting Entity (for compliance reporting)
  • Infrastructure Providers & Sub-processors (names and purpose detailed below)
  • Sub-processor list available at https://enlightenclinical.com/eu-gdpr/
  • Regulatory Authorities (when legally required)

6.0 Data Security & Protection

Enlighten Clinical Solutions implements industry-standard security measures to protect User data, including:

  • Encryption: All stored passwords and sensitive data are encrypted.
  • Role-Based Access Controls (RBAC): Users are assigned permissions based on their designated trial role.
  • Audit Logs: All system activities are logged and cannot be altered to ensure data integrity.
  • Multi-Factor Authentication (MFA): Enforced where applicable for enhanced security.

Users are responsible for maintaining the confidentiality of their login credentials and must report any suspected unauthorized access immediately.

7.0 International Transfers & Safeguards

If personal data is transferred outside the EU, we implement safeguards such as:

  • EU-U.S. Data Privacy Framework (where applicable)
  • Standard Contractual Clauses (SCCs) for other transfers

Anonymized data is primarily stored on secure servers located within the United States. However, alternative storage locations may be arranged through contractual agreement to meet specific client requirements.

8.0 Data Retention Policy

  • User Account Data: Retained for the duration of the clinical trial and in accordance with the Sponsor’s retention policy.
  • System Logs & Audit Trails: Maintained as required by 21 CFR Part 11, applicable regulations, and contractual obligations.
  • Post-Trial Handling: Upon trial completion, user accounts are either deactivated or anonymized in line with regulatory and Sponsor requirements.
  • Email Correspondence: Automatically deleted after five (5) years to ensure security and minimize data exposure.
  • Legal and Financial Records: Retained for seven (7) years to comply with audit, contractual, and statutory obligations.

9.0 User Rights & Responsibilities

Users may not request deletion of their account if required for regulatory record-keeping. However, Users may:

  • Verify and update account details through the Sponsor or Contracting Entity.
  • Request access logs related to their personal usage if permitted under applicable law.
  • Report security concerns directly to our support team.

For all data-related inquiries, Users should first contact the Sponsor or Contracting Entity, as they are the party responsible for system access and compliance. Details for further inquiries are contained within section 11.0.

10.0 Your Rights Under GDPR

As a data subject, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access – You can request confirmation that we process your personal data and obtain a copy of that data.
  • Right to Rectification – You can ask us to correct inaccurate or incomplete personal data.
  • Right to be Forgotten – You can request deletion of your personal data under certain conditions.
  • Right to Restrict Processing – You can request that we limit processing of your data under certain conditions, for example, while accuracy is being verified.
  • Right to Object to Processing – You can object to processing based on legitimate interests or direct marketing.
  • Right to Data Portability – You can request your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
  • Right to Withdraw Consent – If processing is based on your consent, you can withdraw it at any time without affecting prior lawful processing.
  • Right to Lodge a Complaint – Users may lodge a complaint with their local supervisory authority if they believe their rights are infringed.

11.0 Contact Information

For technical support, please visit the Enlighten EDC Support Page within the platform. For any other inquiries, please visit our website at: https://enlightenclinical.com/contact/  

For compliance-related requests, Users should first contact the Sponsor or Contracting Entity overseeing their access.

For GDPR related inquiries, including DSAR/SAR requests, please visit: https://enlightenclinical.com/eu-gdpr/

12.0 Changes to This Privacy Policy

Enlighten Clinical Solutions may update this Privacy Policy periodically to reflect changes in regulatory requirements or system functionality.
Users will be notified of any significant changes.
Continued use of the Platform after such updates constitutes acceptance of the revised Privacy Policy.

Shopping Basket