Legal

Privacy Policy

Effective 7 August 2026 · Byrock Technologies Limited

How we collect, use, share and protect personal data across our website, clinical trial portal, and licensing & deal room — in line with the GDPR, the UK GDPR and the ePrivacy Directive.

00

Summary at a glance

This policy explains, in plain terms, what personal data Byrock Technologies Limited (“Byrock”, “we”, “us”) processes, why, for how long, and the choices you have. A full detailed policy follows below.

  • • We process personal data on the bases of consent, contract, legal obligation and legitimate interests.
  • • We use analytics and cookies; non-essential cookies require your consent.
  • • Some AI-assisted features may process inputs you submit; we do not use solely automated decisions with legal or similarly significant effects about you.
  • • You can request access, correction, deletion, restriction, portability and objection at any time.
01

Who we are and how to reach us

Byrock Technologies Limited is the data controller responsible for your personal data when you visit this website or use our portals. We are registered in Ireland.

You may contact our Data Protection Officer / privacy team at the email above with “Privacy” in the subject line. You also have the right to lodge a complaint with the supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie).

02

Lawful bases for processing

We rely on the following lawful bases under Article 6 of the GDPR:

Consent (Art. 6(1)(a))

For non-essential cookies, marketing communications, and optional AI-assisted features you opt into. You may withdraw consent at any time.

Contract (Art. 6(1)(b))

To provide access to the clinical trial portal or licensing & deal room where you have applied for or entered an agreement with us.

Legal obligation (Art. 6(1)(c))

To comply with pharmaceutical, clinical trial, tax and corporate record-keeping obligations.

Legitimate interests (Art. 6(1)(f))

For site security, fraud prevention, analytics, and operational improvement, balanced against your rights and reasonably expected.

03

Categories of personal data we process

  • Identity & contact: name, email address, phone number, organisation.
  • Account & credentials: username, hashed password, role, access logs.
  • Professional data: professional qualifications, regulator/GMC/RCVS numbers, site affiliations (for investigators).
  • Inquiry & correspondence: content of messages you send us and our replies.
  • Usage & device: IP address, browser type, pages visited, referral URLs, approximate location.
  • Portal content: documents and data you upload to the licensing or clinical trial portal.
  • AI inputs: text or files you submit to AI-assisted features.

We do not process special-category data (Article 9) beyond what you voluntarily provide in correspondence. Where clinical trial data is processed, it is handled under the applicable clinical trial regulatory framework.

04

Purposes of processing

PurposeLawful basisData
Provide portal access & servicesContractAccount, professional, portal content
Respond to inquiriesLegitimate interestsIdentity, contact, correspondence
Analytics & improvementConsent / Legitimate interestsUsage, device
Security & fraud preventionLegitimate interestsUsage, account, logs
AI-assisted featuresConsent / ContractAI inputs, account
Legal & regulatory complianceLegal obligationIdentity, account, records
05

Artificial intelligence, automated decision-making & profiling

AI disclosure

We use, or may use, artificial intelligence (AI) systems to support site features, data analysis, content summarisation and customer communications. Where you use an AI-assisted feature, the input you submit may be processed by us and our subprocessors to generate a response.

We do not use solely automated decision-making that produces legal or similarly significant effects about you (Article 22 GDPR). Any decision that could affect you — for example access to a clinical trial portal — is reviewed by a person. Where profiling is used for analytics, it does not produce such effects and is based on consent or legitimate interests.

To the extent the EU AI Act or member-state transparency obligations apply, we provide this disclosure and ensure that AI-assisted outputs are subject to human oversight. We do not represent that any AI system we use is free from error, and you should not rely solely on AI-generated output for decisions affecting health or legal rights.

You may object to profiling for analytics, request human review of any automated processing that concerns you, and request information about the logic involved. We apply governance proportionate to the risk of each AI use and review our AI practices as the legal landscape evolves. We avoid claiming compliance beyond what can be supported by our practices and records.

06

Data retention

We keep personal data only as long as necessary for the purposes set out above:

  • Account & portal access: for the duration of your relationship with us, then deleted or anonymised.
  • Inquiry correspondence: up to 24 months.
  • Analytics & cookie data: up to 26 months.
  • Clinical trial portal records: for the period required by the applicable clinical trial regulations and sponsor agreements.
  • Legal & tax records: for the statutory retention period (typically 6–7 years).

When data is no longer needed, we delete it or render it anonymous so it can no longer identify you.

07

Security measures

We implement appropriate technical and organisational measures to protect your data, including:

  • • Encryption in transit (TLS) and at rest
  • • Role-based access controls & least-privilege
  • • Regular security reviews & monitoring
  • • Staff confidentiality & training
  • • Vendor due diligence & DPAs
  • • Backups & incident response procedures

No system is completely secure. If a breach occurs we will act in line with our breach notification obligations (see below).

08

International data transfers

Our infrastructure and some subprocessors are located outside the European Economic Area (EEA), for example in the United Kingdom, Switzerland or the United States. Where personal data is transferred outside the EEA, we rely on:

  • Adequacy decisions recognised by the European Commission.
  • Standard Contractual Clauses (SCCs) with transfer impact assessments where required.
  • UK International Data Transfer Agreement (IDTA) for UK transfers.
  • Binding Corporate Rules, where applicable to a group entity.

You may request a copy of the safeguards used for a specific transfer by contacting us at the email above.

09

Your data subject rights

Under the GDPR and UK GDPR you have the right to:

Access

Receive a copy of the personal data we hold about you.

Rectification

Correct inaccurate or incomplete data.

Erasure

Request deletion where there is no legal basis to retain it.

Restriction

Limit processing while a request is being reviewed.

Portability

Receive your data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interests or for direct marketing.

Withdraw consent

Withdraw consent at any time, without affecting prior processing.

Complain

Lodge a complaint with a supervisory authority.

How to exercise your rights

Email info@ptp-102-portal.com with “Data Subject Request” in the subject line. We will verify your identity and respond within one month (extendable by two months for complex requests). The service is free of charge, except where requests are manifestly unfounded or excessive.

10

How we contact you

We may contact you through our app (for example in-product messages or account notifications) and, where you have agreed, through third-party apps or services such as email providers or messaging platforms. We will only contact you for the purposes described in this policy, and you can opt out of non-essential communications at any time by following the unsubscribe link or contacting us.

Marketing communications require your consent and are sent only where you have opted in. You can withdraw consent at any time.

11

Cookies & tracking technologies

We use cookies and similar technologies (pixels, local storage) to operate the site and, with your consent, to measure usage and improve services.

Strictly necessary

Always on

Required for the site to function (e.g. session, security). No consent needed.

Functional / preferences

Consent

Remember your settings (e.g. language, theme).

Analytics & performance

Consent

Tools such as Google Analytics to understand usage in aggregate.

Marketing

Consent

Limited, only where you have opted in.

Consent mechanism

Non-essential cookies and trackers are blocked until you consent. On your first visit you see a banner offering Accept all, Reject all, and Manage preferences. No boxes are pre-ticked — optional categories are off by default until you opt in. You can reopen settings at any time via the persistent “Cookie preferences” link in the footer, or through your browser settings. Blocking some cookies may affect site functionality.

For more on how Google Analytics handles data, see the Google Privacy Policy.

12

Subprocessors & vendors

We work with trusted third-party processors who handle personal data on our behalf. Categories include:

  • Cloud hosting & infrastructure: application hosting and storage.
  • Analytics: usage measurement (e.g. Google Analytics).
  • Communications: email and notification delivery.
  • AI service providers: models used for AI-assisted features.
  • Support & customer service tools.

A current list of subprocessors is maintained and available on request. We engage new processors only after due diligence and require appropriate data protection terms.

13

Data processing agreements

We maintain written data processing agreements (Article 28 GDPR) with each subprocessor, defining the subject matter, duration, nature and purpose of processing, the type of data, and the obligations of the processor — including confidentiality, security, sub-processor controls, assistance with data subject requests, breach notification, and return/deletion of data on termination.

14

Personal data breach notification

We maintain an incident response process to detect, assess and contain personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will also notify you directly with information about the breach and the steps you can take.

15

Children & minors

Our services are not directed at children. We do not knowingly collect personal data from individuals under the age of digital consent applicable in their country of residence (16 in Ireland, unless a lower age applies locally). If you believe we have collected data from a minor, please contact us and we will delete it.

16

Policy updates

We may update this policy to reflect changes in our practices, technologies, or legal requirements. The “Effective date” at the top reflects the latest version. Where changes materially affect your rights, we will provide notice through our app or by email. This policy is version-controlled and prior versions are available on request.

Current version effective: 7 August 2026.

17

Not legal advice

This privacy policy is provided for information about how Byrock Technologies Limited handles personal data. It is not legal advice and does not create an adviser–client relationship. It should be reviewed by qualified legal counsel to ensure it meets the specific requirements of your jurisdiction and operations.

Questions about your data?

Contact our privacy team or reach out through the appropriate portal.

Cookies & privacy

We use strictly necessary cookies to operate the site and, with your consent, analytics and functional cookies. You can accept all, reject all, or manage your preferences. Non-essential trackers are blocked until you consent.