Skip to main content
Trust Center

Privacy Notice

This Notice describes how PrismCDM collects, uses, and protects personal information. PrismCDM is the Trusted Operating System for Clinical Development; privacy is part of the same architectural discipline as Source Fidelity and Provenance.

1. Who we are

PrismCDM Inc. (“PrismCDM”, “we”, “us”) is the entity responsible for the website at prismcdm.com and the PrismCDM operating platform. For any privacy inquiry, the contact is /contact with reason “Compliance Review”.

2. Scope: website and platform

This Notice covers two distinct surfaces, governed by different controls.

  • Website (prismcdm.com). The marketing and evaluation surface. Covers cookies, analytics, the Generate a Brief funnel, the Strategy Session intake, and the Contact form. Limited personal information is collected for the purpose of operating the website and responding to inquiries.
  • Platform (the PrismCDM operating system). The regulated surface where customers operate clinical development workloads. Customer data, clinical data, audit, and Protected Health Information are processed under the executed commercial agreement (including the Data Processing Addendum and Business Associate Agreement where applicable). This Notice describes the platform posture at a summary level; the executed agreements control.

3. The information we collect

We collect different categories of information depending on how you interact with us.

  • Identity and contact information. Name, work email, company, and role when you generate a Brief, book a Strategy Session, request a Compliance Review, or contact us through the website.
  • Protocol material. Public NCT identifiers you submit through the Generate a Brief funnel; sponsor protocols you share under NDA during a Strategy Session or Compliance Review.
  • Usage information. Pages visited, links clicked, time on page, browser, device, and approximate location, collected via privacy-respecting analytics where you have consented (see Section 11).
  • Communications. The content of emails, forms, and notes you send us.
  • Customer data and PHI (platform only). When the customer operates on the platform under an executed agreement, customer-source data and Protected Health Information are processed strictly within tenant scope per the agreement, the Data Processing Addendum, and the Business Associate Agreement.

We do not knowingly collect personal information from children. The PrismCDM website and platform are designed for professional use by clinical development teams.

4. How we use information

  • To respond to inquiries and provide requested artifacts (the Brief, Compliance Review packages, contractual documents).
  • To deliver and improve the PrismCDM platform, including operating the website, the funnels, and the product.
  • To communicate with you about evaluation, design partner programs, scheduled Strategy Sessions, and other commercial conversations you have initiated.
  • To meet legal and regulatory obligations, including those of clinical research customers operating under 21 CFR Part 11, ICH GCP, and HIPAA.
  • To protect the PrismCDM platform, our customers, and our employees against fraud, abuse, and security incidents.

5. Sharing information

We share information narrowly and for stated purposes.

  • Service providers (subprocessors). Hosting, email delivery, authentication, analytics, customer support, and payments. Each processor is under contract with confidentiality and security obligations consistent with PrismCDM's own. The current subprocessor list is maintained in the Trust Center and shared during the Compliance Review.
  • Customers. Customer-source material processed on the platform stays within the customer's tenant scope.
  • Legal and safety. When required by applicable law, regulation, or legal process, or to protect the rights, property, or safety of PrismCDM, our customers, or others.
  • Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to comparable privacy protections.

We do not sell personal information.

6. AI models and customer data

PrismCDM does not use customer protocols, study documents, trial data, or tenant information to train foundation models or shared machine-learning models across customers.

AI features operate within the customer's tenant boundary. Where third-party AI providers are used, requests are transmitted only for the purpose of providing the requested functionality and are governed by contractual and technical safeguards. Customers retain ownership of their data and generated outputs unless otherwise agreed in writing. See also the Security page section on Responsible AI at /trust/security.

7. Data ownership

Customers retain all right, title, and interest in their protocols, clinical data, documents, metadata, and other customer content. PrismCDM acquires no ownership rights in customer data. Upon termination, customer data may be exported or deleted in accordance with the applicable commercial agreement and retention obligations.

8. Regulatory boundary

PrismCDM provides software that supports regulated clinical development activities. Compliance with applicable regulations, including those administered by the FDA, EMA, MHRA, PMDA, HIPAA, and other authorities, remains the responsibility of the customer operating validated processes on the platform.

The platform is architected to support customer compliance (see /trust/security), but it is not itself an attestation of customer compliance.

9. Protected Health Information (HIPAA)

When PrismCDM processes Protected Health Information on behalf of a covered entity or business associate, we do so under a Business Associate Agreement and only for the purposes the customer has authorized. The platform is architected for HIPAA-aligned handling of PHI, including tenant isolation, encryption at rest and in transit, least-privilege access, comprehensive audit, and key management. Specific coverage is shared during the Compliance Review.

10. International transfers

PrismCDM is based in the United States. Where information is transferred from another jurisdiction (including the EEA, United Kingdom, or Switzerland), we rely on appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) issued by the European Commission.
  • UK International Data Transfer Agreement and UK Addendum to the SCCs.
  • Data Processing Agreements with subprocessors that flow through equivalent safeguards.
  • Technical and organizational measures described elsewhere in this Notice and in the Security page.

11. Cookies and tracking

The website uses two categories of cookies.

  • Essential cookies. Required for authentication, session management, and core website functionality. These cannot be disabled.
  • Analytics cookies. Used to understand how the site is used. Set only after consent where required by applicable law (including the GDPR and ePrivacy Directive).

We do not use third-party advertising cookies. You can control cookies through your browser settings; doing so may affect certain website features.

12. Security

PrismCDM operates the platform with engineering disciplines including:

  • Encryption at rest and in transit (TLS 1.2+).
  • Multi-factor authentication (MFA) for customer and internal access.
  • Role-based access control (RBAC) with least-privilege defaults.
  • Immutable, append-only audit trails aligned with 21 CFR Part 11 architectural primitives.
  • Tenant isolation enforced at the data layer.
  • Encrypted backup with tested disaster recovery procedures.
  • Secure software development lifecycle, including code review, automated security scanning, and dependency monitoring.
  • Vulnerability management with prioritized remediation.
  • Security logging and continuous monitoring.
  • Centrally managed key management.

Full details are documented at /trust/security and shared during the Compliance Review.

13. Subprocessors

Current subprocessors are listed within the Trust Center and include cloud infrastructure, email delivery, authentication, analytics, and support providers. Each subprocessor is under contract with confidentiality and security obligations consistent with our own. Material changes to the subprocessor list are communicated through the platform where required by the applicable commercial agreement.

14. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict our use of personal information about you, and to object to certain processing. To exercise any of these rights, contact us through /contact. We respond within the time required by applicable law. You also have the right to lodge a complaint with a supervisory authority in your jurisdiction.

15. Retention

We retain personal information for as long as needed to provide the platform and the commercial relationship, comply with legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed for those purposes, we delete or de-identify it using methods appropriate to the sensitivity of the information.

16. Changes to this Notice

We may update this Notice from time to time. The version in force at any time is the version published at this URL. For material changes that affect your rights, we notify you through the platform or by email.

17. Contact

For privacy questions, requests, or concerns, contact us through /contact with reason “Compliance Review”.

Version
1.0
Effective Date
July 2026
Last Updated
July 2026