Privacy Policy
-
Who We Are
Thalocan (“Thalocan,” “Company,” “we,” “us,” or “our”) is a clinical technology software-as-a-service provider headquartered in Indianapolis, Indiana. We provide cloud-based software platforms and related services that support clinical research, life sciences operations, and regulated workflows for sponsors, contract research organizations, research sites, and other life sciences partners.
We are committed to protecting the privacy, confidentiality, and security of personal information entrusted to us. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal data when you visit our websites, interact with our business, or use our services. By accessing our website and using our products or services, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree to this Policy, please do not access or use our website, products, or services.
-
Scope and Applicability
This Privacy Policy applies to personal data processed by Thalocan in connection with:
- Our websites and online services;
- Our hosted software platforms and applications;
- Support services, professional services, implementation services, training, and certifications;
- Sales, marketing, events, and business communications;
- Vendor, supplier, and partner relationships;
- Recruitment, hiring, and employment-related activities.
If you have entered into a written contractual agreement with Thalocan, this Privacy Policy does not replace or modify the contractual commitments contained in customer agreements, Data Processing Agreements, or other written contracts. If there is a conflict between this policy and a signed agreement, the agreement governs.
-
Roles and Responsibilities
Because Thalocan operates in regulated clinical research environments, our role may vary depending on the context.
3.1 Thalocan as a Data Processor
Thalocan processes “Customer Data” (defined below in sec. 4.2) as a data processor when we host or process data on behalf of our customers through our platforms. In this role:
- The customer acts as the data controller and determines the purposes and means of processing;
- Thalocan processes Customer Data solely in accordance with the customer’s documented instructions and applicable contracts;
- Thalocan does not use Customer Data for its own independent purposes, except as necessary to provide, secure, and support the services, comply with law, and meet contractual obligations.
3.2 Thalocan as a Data Controller
Thalocan acts as a data controller for personal data processed for its own business and operational purposes, including:
- Website visitors and marketing contacts;
- Customer account administration and billing contacts;
- Vendor, supplier, and business partner contacts;
- Recruitment and employment data;
- Corporate IT and security logs related to internal operations.
-
Personal Data We Collect
Personal Data means information that is linked or reasonably linkable to an identified or identifiable individual. The categories of personal data we collect depend on how you interact with Thalocan.
4.1 Website Visits and Communications
- Name, job title, employer, and business contact information;
- Information you submit through forms, emails, or other communications;
- Marketing preferences and subscription choices.
4.2 Platform and Service Use
When customers and authorized users access our platforms, we may collect or process:
- User account and authentication information;
- Role-based access permissions;
- Audit logs and access records;
- IP address, device, browser, and operating system information;
- Usage, performance, and diagnostic data;
- Content, operational data, and study-related identifiers uploaded or entered by customers (“Customer Data”).
Clinical note: Customers control what study participant or patient information is included in Customer Data. To the extent such data is processed, Thalocan acts as a processor under contract.
4.3 Marketing and Events
- Name and email address;
- Organization and professional role;
- Engagement data related to emails or events, either with your consent or where permitted by law.
You may opt out of marketing communications at any time.
4.4 Recruitment and Employment
Where permitted by law or with your consent, we may collect:
- Resume, CV, application materials, and cover letters;
- Employment history, education, qualifications, and references;
- Interview notes and communications;
- Background check information, where legally permitted and with appropriate disclosures.
4.5 Vendors and Business Partners
- Business contact information;
- Contract, billing, and payment information;
- Communications related to performance and relationship management.
-
Sensitive Personal Data
Sensitive personal data means categories of personal data as defined under applicable privacy laws as requiring heightened protection, which may include information revealing race, ethnicity, religion, citizenship and immigration status, sexual orientation, health-related information including mental or physical diagnoses, biometric data, genetic data, or precise geolocation data.
We request that sensitive personal data not be submitted unless necessary and authorized. When sensitive data is processed as part of Customer Data, it is handled solely under customer instructions and applicable contractual safeguards.
-
How We Use Personal Data
We use personal data for the following purposes:
6.1 Service Delivery and Operations
- To provide, operate, and maintain our platforms and services;
- To provision accounts and manage access controls;
- To perform support, implementation, and professional services;
- To manage customer relationships and billing.
6.2 Security and Audit Readiness
- To protect our platforms, systems, customers, and users;
- To maintain audit trails and logs appropriate to regulated environments;
- To detect, prevent, and respond to security incidents or misuse.
6.3 Communications
- To respond to inquiries and requests;
- To send service-related communications;
- To send marketing communications where permitted.
6.4 Compliance and Legal Obligations
- To comply with applicable laws and regulations;
- To enforce contractual obligations;
- To respond to lawful requests from public authorities.
6.5 Product Improvement
- To analyze performance and improve services;
- To develop new features using aggregated or de-identified data where appropriate.
Thalocan does not sell personal data or share personal data for targeted advertising.
-
Legal Bases for Processing
Where required by law, personal data is processed based on:
- Performance of a contract;
- Legitimate business interests;
- Compliance with legal obligations;
- Consent, where required.
-
Cookies and Similar Technologies
Thalocan uses cookies and similar technologies on its websites to support functionality, security, analytics, and performance. Users may manage cookies through browser settings. Disabling cookies may impact certain features.
Our website does not currently respond to Do Not Track signals.
-
Data Sharing and Disclosure
We may share personal data:
- With authorized Thalocan personnel;
- With service providers and subprocessors supporting our services;
- With professional advisors such as legal and audit firms;
- With regulators, authorities, law enforcement, the judiciary or parties involved in legal proceedings with us where legally required;
- In connection with corporate transactions such as mergers, acquisitions, or other business transfers.
All subprocessors are subject to contractual confidentiality and data protection obligations.
-
Accountability for Onward Transfers
When personal data is transferred to third parties, Thalocan:
- Limits transfers to what is necessary for the stated purpose;
- Requires equivalent privacy and security protections by contract;
- Remains accountable for the protection of transferred personal data as required by applicable data protection principles.
-
International Data Transfers and Data Privacy Framework Readiness
Personal data may be transferred to and processed in the United States and other jurisdictions where Thalocan or its service providers operate. When personal data from the European Economic Area, the United Kingdom, or Switzerland are transferred to the U.S. or other jurisdictions that have not been deemed to provide an adequate level of data protection, Thalocan relies on the appropriate mechanisms to safeguard the information, including use of the Standard Contractual Clauses as approved by the European Commission, the UK International Data Transfer Addendum, and other supplementary measures where required.
Thalocan has implemented and is committed to maintaining internal policies, contractual safeguards, and technical and organizational measures that are designed to align with the principles of the EU-US, UK Extension, and Swiss-US Data Privacy Frameworks (collectively as the “Frameworks”) as set forth by the U.S. Department of Commerce.
11.1 Data Privacy Framework Status
Thalocan is currently undergoing the self-certification process for the EU-US, UK Extension, and Swiss-US Data Privacy Frameworks. We will update our certification status as we become certified. Upon certification, this policy will be updated to reflect formal participation, enforcement authority, independent recourse mechanisms, and arbitration rights.
-
Data Security
Thalocan maintains administrative, technical, and physical safeguards appropriate for regulated clinical technology environments, including:
- Role-based access controls and least-privilege principles;
- Encryption in transit and at rest where appropriate;
- Logging, monitoring, and audit trails;
- Secure development lifecycle and change management;
- Incident response and escalation procedures.
Thalocan hosts its production infrastructure on Amazon Web Services (AWS) and leverages AWS security controls in combination with internal safeguards.
-
Data Retention
Personal data is retained only for as long as necessary to:
- Provide services and meet contractual obligations;
- Support audit, validation, and compliance requirements;
- Comply with legal and regulatory obligations;
- Resolve disputes and enforce agreements.
Retention periods vary based on data type and context.
-
Your Rights and Choices
Depending on applicable law, individuals may have rights to:
- Obtain confirmation that Thalocan is processing your personal data;
- Access personal data;
- Correct inaccurate or incomplete data;
- Request deletion, subject to legal and contractual limitations;
- Restrict or object to certain processing;
- Receive your personal data collected by us in a readily usable format;
- Withdraw consent where processing is based on consent.
14.1 Privacy Rights Requests; Identity Verification
You may request to exercise your privacy rights once a calendar year at no charge by contacting us by email at support@thalocan.com and using the subject line “Privacy Rights Request.” For security reasons, we require you to verify your identity prior to processing your request. This may include verifying some elements of your personal data. If we are unable to verify your identity, we may decline to process your request. If you are making a request on behalf of another person, we may require proof of authorization.
We will respond to verified requests within the timeframes required by applicable law (generally 30-45 days). If we need additional time to respond to your request, we may extend the time by another 30-45 days, depending on the applicable law. We will inform you of the reason prior to the expiration of the initial time frame.
14.2 Requests Related to Customer Data
If your personal data is processed as Customer Data, requests should generally be directed to the customer that controls the data. Thalocan will assist customers in responding to verified requests as required.
-
US State Privacy Rights
Residents of certain US states may have additional rights under state privacy laws, including rights to access, correct, delete, or obtain information about the use and disclosure of personal data. Thalocan will respond to verified requests in accordance with applicable law.
-
Children’s Privacy
Thalocan’s services are not directed to children under 13, and we do not knowingly collect personal data from children. We have no actual knowledge of having collected any personal data from anyone under the age of 13. If we learn that we have collected personal data from a child under 13 without proper parental consent, we will take steps to delete that information as soon as possible. If you believe we have collected information from a child, please contact us at privacy@thalocan.com.
-
Changes to This Privacy Policy
We may update this Privacy Policy periodically. Updates will be reflected by the “Last Updated” date above. Material changes will be communicated where required by law or contract. We encourage you to periodically review this Privacy Policy. The changes are effective when posted. Your continued access of the website and use of our products and services after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.
-
Contact Information
For privacy questions, requests, or complaints, contact:
Privacy Office
Thalocan
Indianapolis, Indiana, United States
Email: support@thalocan.com
Mailing Address: 1321 Lexington Avenue, Indianapolis, IN 46203