Privacy policy
This policy covers two different things: what this website collects about visitors, and how Clinplex handles the regulated records customers send during an engagement. The second is governed primarily by the NDA and, where executed, a Data Processing Agreement — this page summarizes it.
What this website collects
- Contact form submissions: name, work email, organization, and whatever you write. Forms are processed by Squarespace and delivered to Clinplex by email (Google Workspace).
- Standard server logs and analytics collected by Squarespace as the site host.
- No advertising trackers are placed by Clinplex.
We use contact information to respond to you and for no other purpose. We do not sell or share visitor data for advertising.
Customer records during engagements
- Records are exchanged only after a mutual NDA is signed.
- Processing is read-only: nothing is written back to your systems.
- Your records are never used to train, fine-tune or evaluate any model, ours or a provider's.
- Records are retained for the duration of the engagement, then deleted. Deletion on request at any time, confirmed in writing.
- Do not send protected health information. Clinplex does not offer a BAA; redact records before transfer.
Hosting, encryption, sub-processors and 21 CFR Part 11 controls are documented on the Security and trust page. The sub-processor list and a DPA are available to customers on request at security@clinplex.com.
Your choices
Email security@clinplex.com to access, correct or delete personal information we hold about you, or to ask anything this page doesn't answer. We reply within one business day.
Changes
This policy is versioned like a controlled document. Material changes update the version and effective date above; customers under a DPA are notified of changes affecting them.