Updated on April 4, 2026
Updated on April 4, 2026
GDPR: General Data Protection Regulation Compliance
Our clinical platforms are designed to support customers in meeting their obligations under the General Data Protection Regulation (GDPR) when processing personal data in healthcare and research settings. We focus on privacy by design, strong security controls, and clear governance so that controllers can use our services with confidence.
Our clinical platforms are designed to support customers in meeting their obligations under the General Data Protection Regulation (GDPR) when processing personal data in healthcare and research settings. We focus on privacy by design, strong security controls, and clear governance so that controllers can use our services with confidence.
Role Under GDPR: Processor and Shared Responsibility
In most deployments, our company acts as a data processor, handling personal data on behalf of our customers, who act as data controllers. Controllers determine the purposes and means of processing, select the lawful basis, provide notices to data subjects, and define retention and deletion rules.
We provide configurable technical and organisational measures that enable controllers to implement their own GDPR compliance strategies, and we enter into appropriate data processing agreements that describe our obligations, subprocessors, and data protection guarantees.
In most deployments, our company acts as a data processor, handling personal data on behalf of our customers, who act as data controllers. Controllers determine the purposes and means of processing, select the lawful basis, provide notices to data subjects, and define retention and deletion rules.
We provide configurable technical and organisational measures that enable controllers to implement their own GDPR compliance strategies, and we enter into appropriate data processing agreements that describe our obligations, subprocessors, and data protection guarantees.
Personal and Health Data in Clinical Workflows
Our platforms may process several categories of personal data, depending on customer configuration and use case. These can include identifiers (such as study IDs, patient codes, investigator details), contact information for users, and operational data relating to clinical activities and trial operations.
When used in clinical and healthcare contexts, some data may be considered “special category” personal data, including data concerning health or biometric information. The platform is built to handle these categories with enhanced safeguards, and customers control whether and how such data is stored, pseudonymised, or separated from direct identifiers.
Our platforms may process several categories of personal data, depending on customer configuration and use case. These can include identifiers (such as study IDs, patient codes, investigator details), contact information for users, and operational data relating to clinical activities and trial operations.
When used in clinical and healthcare contexts, some data may be considered “special category” personal data, including data concerning health or biometric information. The platform is built to handle these categories with enhanced safeguards, and customers control whether and how such data is stored, pseudonymised, or separated from direct identifiers.
Lawful Basis and Special Category Conditions
GDPR requires that controllers have a valid lawful basis for processing personal data (for example, consent, performance of a contract, legal obligation, or public interest), and separate conditions when processing special category data such as health information.
Our services do not determine or replace the controller’s legal basis or special category condition. Instead, we provide features that support compliant use of those bases, including configurable workflows, consent and documentation fields, audit trails, and role-based access to ensure that the use of the platform aligns with the controller’s chosen legal position.
Data Minimisation and Purpose Limitation
We design our clinical platforms around principles of data minimisation and purpose limitation. Customers can restrict data fields, separate identity data from operational data, and configure which information is mandatory for each workflow.
We encourage customers to collect only the data necessary for defined clinical, operational, or research purposes, avoid storing unnecessary health details, and use pseudonymous identifiers to reduce direct exposure of patient identity wherever feasible. Our configuration options and implementation guidance are intended to make these choices straightforward.
We design our clinical platforms around principles of data minimisation and purpose limitation. Customers can restrict data fields, separate identity data from operational data, and configure which information is mandatory for each workflow.
We encourage customers to collect only the data necessary for defined clinical, operational, or research purposes, avoid storing unnecessary health details, and use pseudonymous identifiers to reduce direct exposure of patient identity wherever feasible. Our configuration options and implementation guidance are intended to make these choices straightforward.
Privacy by Design and Default
Privacy by design and by default is embedded into our architecture, development lifecycle, and deployment practices. We apply structured controls and review processes before new features are released, with attention to how data is collected, stored, accessed, and shared.
Default settings favour restricted access, conservative sharing, and limited retention, while allowing customers to adjust configurations for their specific regulatory and operational context. We routinely review data flows, permissions, and logging to maintain a consistent privacy posture across our product portfolio.
Privacy by design and by default is embedded into our architecture, development lifecycle, and deployment practices. We apply structured controls and review processes before new features are released, with attention to how data is collected, stored, accessed, and shared.
Default settings favour restricted access, conservative sharing, and limited retention, while allowing customers to adjust configurations for their specific regulatory and operational context. We routinely review data flows, permissions, and logging to maintain a consistent privacy posture across our product portfolio.
Privacy by Design and Default
Privacy by design and by default is embedded into our architecture, development lifecycle, and deployment practices. We apply structured controls and review processes before new features are released, with attention to how data is collected, stored, accessed, and shared.
Default settings favour restricted access, conservative sharing, and limited retention, while allowing customers to adjust configurations for their specific regulatory and operational context. We routinely review data flows, permissions, and logging to maintain a consistent privacy posture across our product portfolio.
Privacy by design and by default is embedded into our architecture, development lifecycle, and deployment practices. We apply structured controls and review processes before new features are released, with attention to how data is collected, stored, accessed, and shared.
Default settings favour restricted access, conservative sharing, and limited retention, while allowing customers to adjust configurations for their specific regulatory and operational context. We routinely review data flows, permissions, and logging to maintain a consistent privacy posture across our product portfolio.
Security of Processing
We use industry-standard security measures to protect personal data processed through our platforms. These measures typically include encryption in transit and at rest, hardened infrastructure, network isolation, key management, secure development and testing practices, and continuous monitoring.
Access to production data is strictly controlled, limited to authorised personnel with a legitimate operational need, and recorded through detailed logging. Our hosting environments and subprocessors are selected and managed under security and privacy requirements aligned with GDPR expectations.
We use industry-standard security measures to protect personal data processed through our platforms. These measures typically include encryption in transit and at rest, hardened infrastructure, network isolation, key management, secure development and testing practices, and continuous monitoring.
Access to production data is strictly controlled, limited to authorised personnel with a legitimate operational need, and recorded through detailed logging. Our hosting environments and subprocessors are selected and managed under security and privacy requirements aligned with GDPR expectations.
Access Control, Audit Trails, and Accountability
Our platforms provide flexible role-based access control so that organisations can define fine-grained permissions at the user, team, and project level. This allows controllers to ensure that only appropriate personnel can view or modify clinical and trial data.
Comprehensive audit trails record key actions in the system, including data creation, changes, exports, and administrative operations. These logs support accountability, internal review, incident investigation, and regulatory reporting when needed.
Our platforms provide flexible role-based access control so that organisations can define fine-grained permissions at the user, team, and project level. This allows controllers to ensure that only appropriate personnel can view or modify clinical and trial data.
Comprehensive audit trails record key actions in the system, including data creation, changes, exports, and administrative operations. These logs support accountability, internal review, incident investigation, and regulatory reporting when needed.
Data Subject Rights Support
GDPR grants individuals rights such as access, rectification, restriction, erasure, and data portability. Our platforms are designed to help controllers respond to these rights by making relevant records discoverable, traceable, and manageable.
Customers can search and retrieve records associated with specific identifiers, update or correct data where appropriate, and apply deletion or anonymisation workflows consistent with their regulatory and ethical obligations. We provide guidance on using product features to support rights requests, while controllers remain responsible for the legal assessment and response.
GDPR grants individuals rights such as access, rectification, restriction, erasure, and data portability. Our platforms are designed to help controllers respond to these rights by making relevant records discoverable, traceable, and manageable.
Customers can search and retrieve records associated with specific identifiers, update or correct data where appropriate, and apply deletion or anonymisation workflows consistent with their regulatory and ethical obligations. We provide guidance on using product features to support rights requests, while controllers remain responsible for the legal assessment and response.
Retention, Deletion, and Data Lifecycle
Clinical and research data often require defined retention periods driven by regulatory, contractual, or scientific requirements. Our platforms support configurable retention rules, archiving, and deletion processes that can be aligned with those obligations.
Controllers can set policies for how long different categories of data are kept, when they are archived, and when they are permanently removed or anonymised. We provide tools to implement these rules at scale and ensure that deletion or anonymisation is logged and auditable.
Clinical and research data often require defined retention periods driven by regulatory, contractual, or scientific requirements. Our platforms support configurable retention rules, archiving, and deletion processes that can be aligned with those obligations.
Controllers can set policies for how long different categories of data are kept, when they are archived, and when they are permanently removed or anonymised. We provide tools to implement these rules at scale and ensure that deletion or anonymisation is logged and auditable.
International Transfers and Hosting Locations
We recognise that hosting location and cross-border data transfers are critical considerations under GDPR. Our platforms can be deployed in selected regions, and we maintain clear visibility of where data is stored and processed.
Where international transfers occur, we use appropriate safeguards as required by GDPR, such as standard contractual clauses or equivalent mechanisms, and keep customers informed about relevant subprocessors and data flows. Information about hosting regions and transfer safeguards is available in our data processing and security documentation.
We recognise that hosting location and cross-border data transfers are critical considerations under GDPR. Our platforms can be deployed in selected regions, and we maintain clear visibility of where data is stored and processed.
Where international transfers occur, we use appropriate safeguards as required by GDPR, such as standard contractual clauses or equivalent mechanisms, and keep customers informed about relevant subprocessors and data flows. Information about hosting regions and transfer safeguards is available in our data processing and security documentation.
Governance, Audits, and Certifications
GDPR compliance is supported by internal governance frameworks that cover security, privacy, and risk management. Our organisation maintains policies and controls covering access, incident handling, vendor management, secure development, and data protection.
We may align our practices with recognised frameworks and certifications where appropriate (for example, ISO security standards or healthcare-specific requirements) and make summary information available to customers through security white papers, audit reports, or questionnaires.
GDPR compliance is supported by internal governance frameworks that cover security, privacy, and risk management. Our organisation maintains policies and controls covering access, incident handling, vendor management, secure development, and data protection.
We may align our practices with recognised frameworks and certifications where appropriate (for example, ISO security standards or healthcare-specific requirements) and make summary information available to customers through security white papers, audit reports, or questionnaires.
Working With Customers on GDPR
We see GDPR as an ongoing collaboration with our customers. While controllers maintain legal responsibility for their processing activities, we work closely with them to understand data flows, assess risk, and configure our platforms in ways that support compliant clinical and research operations.
Our teams are available to discuss deployment models, configuration options, and documentation that may assist with internal reviews, data protection impact assessments, and regulator or ethics committee engagement.
We see GDPR as an ongoing collaboration with our customers. While controllers maintain legal responsibility for their processing activities, we work closely with them to understand data flows, assess risk, and configure our platforms in ways that support compliant clinical and research operations.
Our teams are available to discuss deployment models, configuration options, and documentation that may assist with internal reviews, data protection impact assessments, and regulator or ethics committee engagement.
Alignment with the EU General Data Protection Regulation
Our clinical platforms are operated in alignment with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), which sets out rules on the protection of natural persons with regard to the processing of personal data and on the free movement of such data within the European Union.
Under GDPR, controllers must ensure that personal data are processed lawfully, fairly and in a transparent manner, collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes, limited to what is necessary in relation to the purposes, kept for no longer than necessary, and processed with integrity and confidentiality. These principles guide the design and operation of our SaaS clinical platforms.
Our clinical platforms are operated in alignment with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), which sets out rules on the protection of natural persons with regard to the processing of personal data and on the free movement of such data within the European Union.
Under GDPR, controllers must ensure that personal data are processed lawfully, fairly and in a transparent manner, collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes, limited to what is necessary in relation to the purposes, kept for no longer than necessary, and processed with integrity and confidentiality. These principles guide the design and operation of our SaaS clinical platforms.
Changes to this policy
We may update this policy to reflect changes in our services or the law. We will notify you of significant changes.
We may update this policy to reflect changes in our services or the law. We will notify you of significant changes.
Contact us
If you have questions or concerns, please email us at compliance@qtis.ai
If you have questions or concerns, please email us at support@q