🇬🇧UK clinical trials — updated daily from ClinicalTrials.gov
TrialConnect
Legal

Data Protection & GDPR

Last updated: 31 July 2026

1. Our Commitment

TrialConnect is committed to protecting your personal data, especially health-related information which is classified as "special category data" under UK GDPR. We go beyond minimum compliance to build trust through transparency and robust safeguards.

2. Data Controller

TrialConnect is the data controller for personal data processed through this platform. For data protection enquiries, contact us at admin@trialconnect.co.uk.

3. Lawful Basis for Processing Health Data

Some information you provide to TrialConnect, such as selected health conditions or matching questionnaire answers, may be health-related information and is treated as special category data under UK GDPR.

For this processing, we rely on:

  • Article 6(1)(a) UK GDPR — consent, where you choose to provide information so TrialConnect can provide trial alerts, account features or matching results.
  • Article 9(2)(a) UK GDPR — explicit consent, where we process health-related information such as selected conditions or matching questionnaire answers.

You can withdraw your consent at any time. If you withdraw consent, we will stop processing the relevant data and delete or deactivate it in line with our Privacy Policy.

TrialConnect does not confirm eligibility for clinical trials, make clinical decisions, provide medical advice, or determine whether you can join a trial. Matching results are informational only and formal eligibility is always confirmed by the relevant trial team.

4. Data Protection Impact Assessments

We carry out a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals. This includes new or materially changed processing involving health-related matching data, profiling, referral workflows, or sponsor-facing analytics.

Our DPIAs assess the nature, scope, context and purpose of the processing, the risks to individuals, and the safeguards we use to reduce those risks.

5. Technical & Organisational Measures

Encryption

TLS encryption in transit (HTTPS) for all data between your browser and our servers

Access controls

Admin endpoints protected by authentication keys; admin actions are audit-logged in the analytics database

Data minimisation

We collect only data necessary for trial matching, alerts, and platform improvement

Server-side validation

API validation blocks raw questionnaire answers, email addresses, and postcodes from being stored in analytics events

Database isolation

Operational data (subscriptions) and analytics data are stored in separate databases with independent retention policies

Consent gating

Health-derived analytics events require explicit analytics consent; aggregate counters contain no user identifiers

6. Data Subject Rights

You have the following rights under UK GDPR:

  • Right of access (Article 15): request a copy of all personal data we hold about you.
  • Right to rectification (Article 16): correct inaccurate or incomplete data.
  • Right to erasure (Article 17): request deletion of your data when no longer necessary.
  • Right to restriction (Article 18): limit how we process your data in certain circumstances.
  • Right to data portability (Article 20): receive your data in a structured, machine-readable format.
  • Right to object (Article 21): object to processing based on legitimate interests.
  • Right regarding automated decisions (Article 22): request human review of algorithmic matching decisions.

To exercise any right, visit our contact page. We respond to all requests within 30 days.

7. Data Breach Procedures

In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours where the breach is likely to result in a risk to your rights. If the breach is likely to result in a high risk, we will also notify affected individuals directly without undue delay.

8. Data Processors

Third-party processors who handle data on our behalf are bound by GDPR-compliant data processing agreements. We vet all processors for security standards and UK/EEA data residency before engagement.

9. Complaints

If you believe your data has been mishandled, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). We encourage you to contact us first so we can resolve any issues promptly.

10. Cookies & Local Storage

We use a small number of cookies and local storage entries to operate the platform:

  • Essential cookies: required for security, session management, theme preference, and trial journey tracking (the tc_session cookie links your trial interest records to your browser). These cannot be disabled.
  • Analytics cookies: help us understand how the platform is used so we can improve it. These are optional and only activated with your consent.
  • Local storage: we store your cookie consent preference and theme choice locally on your device. No personal data is stored in cookies.

When you first visit the site, you will see a cookie consent banner allowing you to accept all cookies or essential-only cookies. You can change your preferences at any time using the Cookie settings link in the site footer, which re-displays the consent banner.

10.1. Analytics Preference

We operate two analytics systems:

  • Aggregate counters — de-identified counters (e.g. total page views per route, total matching requests per condition) that contain no user identifiers whatsoever. No cookies, no user IDs, no session IDs are linked to these counters.
  • Consented product analytics — events (such as match started/completed, trial viewed, contact clicked) linked to an anonymous session identifier. If you have granted analytics consent, these events may include the condition slug and trial identifiers you viewed. Raw questionnaire answers, email addresses, names, and postcodes are blocked by server-side validation and never stored in analytics. You can opt out at any time using the toggle below — when analytics is off, we collect nothing.

Analytics does not use cookies. You can opt out at any time using the toggle below — when analytics is off, we collect nothing.

10.2. International Data Transfers

Our hosting provider (Vercel Inc.), email delivery service (Resend), managed Redis provider (Upstash), and DNS/CDN/database provider (Cloudflare) may process data in the United States. Personal data you provide may be processed in the US under the protection of the UK-US Data Bridge (the UK Extension to the EU-US Data Privacy Framework). Vercel, Resend, and Cloudflare hold active certifications under the UK-US Data Bridge.

Upstash does not currently hold UK-US Data Bridge certification. For transfers to Upstash, we rely on the UK International Data Transfer Agreement (IDTA) as the appropriate safeguard. We review certifications and safeguards annually.

11. Related Documents