Privacy Policy
Effective 7 August 2026 · Byrock Technologies Limited
How we collect, use, share and protect personal data across our website, clinical trial portal, and licensing & deal room — in line with the GDPR, the UK GDPR and the ePrivacy Directive.
Summary at a glance
This policy explains, in plain terms, what personal data Byrock Technologies Limited (“Byrock”, “we”, “us”) processes, why, for how long, and the choices you have. A full detailed policy follows below.
- • We process personal data on the bases of consent, contract, legal obligation and legitimate interests.
- • We use analytics and cookies; non-essential cookies require your consent.
- • Some AI-assisted features may process inputs you submit; we do not use solely automated decisions with legal or similarly significant effects about you.
- • You can request access, correction, deletion, restriction, portability and objection at any time.
Who we are and how to reach us
Byrock Technologies Limited is the data controller responsible for your personal data when you visit this website or use our portals. We are registered in Ireland.
You may contact our Data Protection Officer / privacy team at the email above with “Privacy” in the subject line. You also have the right to lodge a complaint with the supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie).
Lawful bases for processing
We rely on the following lawful bases under Article 6 of the GDPR:
Consent (Art. 6(1)(a))
For non-essential cookies, marketing communications, and optional AI-assisted features you opt into. You may withdraw consent at any time.
Contract (Art. 6(1)(b))
To provide access to the clinical trial portal or licensing & deal room where you have applied for or entered an agreement with us.
Legal obligation (Art. 6(1)(c))
To comply with pharmaceutical, clinical trial, tax and corporate record-keeping obligations.
Legitimate interests (Art. 6(1)(f))
For site security, fraud prevention, analytics, and operational improvement, balanced against your rights and reasonably expected.
Categories of personal data we process
- • Identity & contact: name, email address, phone number, organisation.
- • Account & credentials: username, hashed password, role, access logs.
- • Professional data: professional qualifications, regulator/GMC/RCVS numbers, site affiliations (for investigators).
- • Inquiry & correspondence: content of messages you send us and our replies.
- • Usage & device: IP address, browser type, pages visited, referral URLs, approximate location.
- • Portal content: documents and data you upload to the licensing or clinical trial portal.
- • AI inputs: text or files you submit to AI-assisted features.
We do not process special-category data (Article 9) beyond what you voluntarily provide in correspondence. Where clinical trial data is processed, it is handled under the applicable clinical trial regulatory framework.
Purposes of processing
| Purpose | Lawful basis | Data |
|---|---|---|
| Provide portal access & services | Contract | Account, professional, portal content |
| Respond to inquiries | Legitimate interests | Identity, contact, correspondence |
| Analytics & improvement | Consent / Legitimate interests | Usage, device |
| Security & fraud prevention | Legitimate interests | Usage, account, logs |
| AI-assisted features | Consent / Contract | AI inputs, account |
| Legal & regulatory compliance | Legal obligation | Identity, account, records |
Artificial intelligence, automated decision-making & profiling
AI disclosure
We use, or may use, artificial intelligence (AI) systems to support site features, data analysis, content summarisation and customer communications. Where you use an AI-assisted feature, the input you submit may be processed by us and our subprocessors to generate a response.
We do not use solely automated decision-making that produces legal or similarly significant effects about you (Article 22 GDPR). Any decision that could affect you — for example access to a clinical trial portal — is reviewed by a person. Where profiling is used for analytics, it does not produce such effects and is based on consent or legitimate interests.
To the extent the EU AI Act or member-state transparency obligations apply, we provide this disclosure and ensure that AI-assisted outputs are subject to human oversight. We do not represent that any AI system we use is free from error, and you should not rely solely on AI-generated output for decisions affecting health or legal rights.
You may object to profiling for analytics, request human review of any automated processing that concerns you, and request information about the logic involved. We apply governance proportionate to the risk of each AI use and review our AI practices as the legal landscape evolves. We avoid claiming compliance beyond what can be supported by our practices and records.
Data retention
We keep personal data only as long as necessary for the purposes set out above:
- • Account & portal access: for the duration of your relationship with us, then deleted or anonymised.
- • Inquiry correspondence: up to 24 months.
- • Analytics & cookie data: up to 26 months.
- • Clinical trial portal records: for the period required by the applicable clinical trial regulations and sponsor agreements.
- • Legal & tax records: for the statutory retention period (typically 6–7 years).
When data is no longer needed, we delete it or render it anonymous so it can no longer identify you.
Security measures
We implement appropriate technical and organisational measures to protect your data, including:
- • Encryption in transit (TLS) and at rest
- • Role-based access controls & least-privilege
- • Regular security reviews & monitoring
- • Staff confidentiality & training
- • Vendor due diligence & DPAs
- • Backups & incident response procedures
No system is completely secure. If a breach occurs we will act in line with our breach notification obligations (see below).
International data transfers
Our infrastructure and some subprocessors are located outside the European Economic Area (EEA), for example in the United Kingdom, Switzerland or the United States. Where personal data is transferred outside the EEA, we rely on:
- • Adequacy decisions recognised by the European Commission.
- • Standard Contractual Clauses (SCCs) with transfer impact assessments where required.
- • UK International Data Transfer Agreement (IDTA) for UK transfers.
- • Binding Corporate Rules, where applicable to a group entity.
You may request a copy of the safeguards used for a specific transfer by contacting us at the email above.
Your data subject rights
Under the GDPR and UK GDPR you have the right to:
Access
Receive a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete data.
Erasure
Request deletion where there is no legal basis to retain it.
Restriction
Limit processing while a request is being reviewed.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests or for direct marketing.
Withdraw consent
Withdraw consent at any time, without affecting prior processing.
Complain
Lodge a complaint with a supervisory authority.
How to exercise your rights
Email info@ptp-102-portal.com with “Data Subject Request” in the subject line. We will verify your identity and respond within one month (extendable by two months for complex requests). The service is free of charge, except where requests are manifestly unfounded or excessive.
How we contact you
We may contact you through our app (for example in-product messages or account notifications) and, where you have agreed, through third-party apps or services such as email providers or messaging platforms. We will only contact you for the purposes described in this policy, and you can opt out of non-essential communications at any time by following the unsubscribe link or contacting us.
Marketing communications require your consent and are sent only where you have opted in. You can withdraw consent at any time.
Subprocessors & vendors
We work with trusted third-party processors who handle personal data on our behalf. Categories include:
- • Cloud hosting & infrastructure: application hosting and storage.
- • Analytics: usage measurement (e.g. Google Analytics).
- • Communications: email and notification delivery.
- • AI service providers: models used for AI-assisted features.
- • Support & customer service tools.
A current list of subprocessors is maintained and available on request. We engage new processors only after due diligence and require appropriate data protection terms.
Data processing agreements
We maintain written data processing agreements (Article 28 GDPR) with each subprocessor, defining the subject matter, duration, nature and purpose of processing, the type of data, and the obligations of the processor — including confidentiality, security, sub-processor controls, assistance with data subject requests, breach notification, and return/deletion of data on termination.
Personal data breach notification
We maintain an incident response process to detect, assess and contain personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will also notify you directly with information about the breach and the steps you can take.
Children & minors
Our services are not directed at children. We do not knowingly collect personal data from individuals under the age of digital consent applicable in their country of residence (16 in Ireland, unless a lower age applies locally). If you believe we have collected data from a minor, please contact us and we will delete it.
Policy updates
We may update this policy to reflect changes in our practices, technologies, or legal requirements. The “Effective date” at the top reflects the latest version. Where changes materially affect your rights, we will provide notice through our app or by email. This policy is version-controlled and prior versions are available on request.
Current version effective: 7 August 2026.
Not legal advice
This privacy policy is provided for information about how Byrock Technologies Limited handles personal data. It is not legal advice and does not create an adviser–client relationship. It should be reviewed by qualified legal counsel to ensure it meets the specific requirements of your jurisdiction and operations.
Questions about your data?
Contact our privacy team or reach out through the appropriate portal.