Global Privacy & Data Protection Policy
At MediSights, we place privacy and data protection at the core of our operation, ensuring our AI-native insights platform respects the personal data rights of patients, healthcare professionals (HCPs) and partners.
Our data protection approach shapes how we responsibly transform real conversations into evidence-based intelligence that drives better decisions in specialty care.
Protecting People and Data
Protecting reputations while delivering actionable clinical intelligence
MediSights runs life-science compliant, AI moderated interviews with real physicians across the world. Our clients demand insight generation based on data that is collected in accordance with global best practice and meets local regulation for HCP participation and guidance for medical research.
Global and local data compliance
We apply the highest standard of data protection principles, considering lawfulness, fairness and transparency of operations, being clear about the purpose of data collection, how and where we store it (and for how long). We use technology partners that provide assurance and accuracy around data residency so we can accurately document where we store personal data and which regulatory context applies. We continually review this as part of our internal audit and compliance review process and also use The Five Safes framework.
The Five Safes
This is a set of principles enabling data services to provide safe research access to data. They are used by a range of UK Trusted Research Environments (TREs) such as Health Data Research-UK (HDR-UK) and the National Institute for Health Research Design Service (NIHR) to enable data services to provide safe research access to data.
MediSights operates globally, maintaining compliance with local and regional data protection legislation and requirements; this framework sits above our compliance, providing territory-independent guidance to ensure that we are always operating to the highest research data standards.
- Safe Projects - We ensure that the use of data is appropriate, lawful, ethical and sensible in use for both Syndicated studies operated by MediSights and with client-led Enterprise studies;
- Safe People - We ensure that the MediSights staff who handle personal data and work with aggregated insights are trained and able to use data in an appropriate way;
- Safe Data - We use anonymisation within our AI-assisted qualitative analysis and synthesis, and design our reporting to maintain the confidentiality of participant HCPs;
- Safe Settings - Our platforms are secure-by-design and we adhere to our control framework and standard operating procedures, such as managing access to derived insights;
- Safe Outputs - We do not operate large scale processing of special category data, but we recognise that output includes rare conditions, and we continually verify and consider residual risk.
What is the scope of this Privacy & Data Protection policy?
This privacy policy details who we are, how and why we collect, store, use and share personal information, your personal data rights and how to contact us and relevant authorities if you have a complaint. Since MediSights operates in many territories worldwide, different regulatory regimes apply and these are listed in this policy.
If you are a participant in MediSights research, or you are visiting this website, this policy applies to you.
We use the following terms in this policy:
- Client means the pharmaceutical, biotech, or commercial intelligence organisation that engages MediSights to conduct or platform-enable market research;
- HCP means a Healthcare Professional, including physicians, nurses, pharmacists, and allied clinical professionals participating in MediSights research;
- Interview output means any transcripts or recordings containing personal data before automated processing;
- Panel providers means organisations who recruit HCPs for studies, verifying their credentials and capturing their consent to participate in studies for the specific purpose(s) outlined;
- Personal data means any information relating to an identified or identifiable natural person, as defined under the EU GDPR, UK GDPR, and equivalent regimes;
- Processed interview output means any transcripts or recordings stripped of personal data after automated processing;
- Research outputs means the aggregated, de-identified analyses, transcripts, and insight reports produced from processed interview output(s);
- Sensitive information can include:
- Special category data: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health information, sex life or sexual orientation.
- Other information that may be sensitive or identifying: precise location, citizenship or immigration status, and payment card details or transactions.
- Studies - Individual research projects delivered by MediSights either to create research that can be syndicated to multiple clients, or on behalf of client(s) under a written research agreement;
- You - Visitors to this website, any client, HCP, panel provider, or other person who considers themselves a data subject through interaction with a MediSights platform or process.
Data controller and processor roles
Depending on the context in which personal data is processed, MediSights may act either as a data controller, joint data controller (in such territories as where that is recognised) or as a data processor.
MediSights acts as a data controller where we determine the purposes and means of processing personal data for our own business operations, including operation of our website, management of client and supplier relationships, operation of any HCP panel and recruitment activities, fraud prevention, security monitoring, compliance, audit, record-keeping, and responding to legal or regulatory obligations.
MediSights acts as a data processor where we process personal data on behalf of a Client in connection with the delivery of a specific Study or the provision of our platform and related services, and the Client determines the purposes and means of that processing.
In some cases, MediSights and a Client may each act as an independent controller for different stages of the same overall engagement. Where required, our contracts describe the allocation of responsibilities between the parties, including instructions, confidentiality, security, sub-processing, international transfers, and support with data subject rights.
What is the MediSights research platform?
Overview
The MediSights platform allows for the generation of research outputs through the following process:
- HCP is recruited to participate (either by MediSights or panel providers) for a specific study and is given access to the platform (for that study);
- HCP consents to be interviewed by an Artificial Intelligence (AI) conversational interface that adapts to responses, including generating follow-up questions;
- Interview output is transcribed and AI is used to translate the audio recordings;
- AI-assisted tools are used to detect and redact direct identifiers, such as names, locations, and other obvious identifying information, from interview output. Depending on the context and the effectiveness of the controls applied, this process may result in data that is pseudonymised, de-identified, or anonymised. Where data can still be linked, directly or indirectly, to an identifiable individual using reasonably available means, we treat it as personal data and apply appropriate safeguards.
- Processed interview output is then further minimised, aggregated, and used to generate research outputs intended not to identify individuals. This includes a further use of AI to apply thematic coding, conduct sentiment analysis, and summarise - including benchmarking - using qualitative synthesis.
- The research outputs are made available to MediSights staff and clients.
AI & Automated Processing
AI outputs that materially inform research outputs are subject to human review by trained MediSights research staff before they are delivered to Clients. The platform does not produce decisions that have legal or similarly significant effects on data subjects.
We do not use Client-confidential data, raw transcripts of an identified study, or any data subject’s personal data to train general-purpose third-party AI models. Where we improve our own internal models, we do so on de-identified data, on data lawfully obtained for that purpose, or on data for which the data subject has provided specific consent. Client agreements may further restrict our internal use of project data, and those restrictions take precedence over this Policy.
Where we use third-party AI services to process personal data, we contract for enterprise-grade terms that prohibit the provider from using our inputs or outputs to train its models, and maintain appropriate security and confidentiality.
What personal information is used?
Information provided voluntarily
HCP and research participant data includes identifiers and contact data (name, professional email, professional address, phone number, and where required for verification, professional registration or licence number such as NPI, GMC, RPPS, or ONK); professional and demographic data (specialty, sub-specialty, years in practice, institutional affiliation, country of practice, prescribing volume estimates where self-declared, and patient population descriptors); screening data used to confirm eligibility for a study; research interaction data (audio and, where consented, video recordings of interviews; transcripts; chat-based or asynchronous responses; survey responses; and free-text answers); and honoraria and tax data, including payment details and, where required by law, tax identifiers necessary for fair-market-value compensation and transparency reporting.
In the course of describing clinical experience, HCPs may refer to patient cases, which may meet the criteria of being considered personal data if individuals are identifiable in the interview output before it is processed This will cease to be personal data by virtue of anonymisation later in our process as it is aggreged into research outputs.
Client user data includes account and authentication data (name, business email, role, organisation, address and authentication credentials).
Information we automatically collect
When you browse one of our websites, use the MediSights platform or interact with an email we send to you, we may collect information about your web browsing and use of the site or platform. This may include details of your operating system, location, IP address, browser ID, browsing activity, and other information about how you interacted. We may collect this information as a part of log files and through cookies or other tracking technologies. We use this information to help improve the website, security purposes or to monitor the performance of our survey platform.
Both MediSights and our third-party partners may use assorted technologies to collect and store information when you use the platform, visit our website, or interact with an email from us. This may include using cookies and similar tracking technologies (e.g. web beacons such as pixels) to analyse behaviour, track movements around the website, and gather demographic information.
You can control the use of cookies on this website using the CookieYes tool installed on this website, or through your browser settings.
How we use personal information
We use personal information to:
- Recruit and verify HCPs for participation in research, including credential verification;
- Operate the MediSights research platform, as an input into de-identified research output;
- Improve the MediSights research platform and this website, such as processing usage logs;
- Perform our obligations to clients under agreed contracts or applicable law (e.g. to enforce our terms, communicate with clients and provide support), or to respond to requests made;
- Protect, investigate and deter against fraudulent, harmful, unauthorised or illegal activity;
- Bill clients (e.g. to send invoices, process payment, notices).
- Send notifications about the platform to clients or participating HCPs;
- Bring or defend legal proceedings, meet legal requirements (e.g. complying with court orders, enforcement actions, or other legally valid mechanisms) or respond to lawful requests by public authorities or law enforcement requests; and
- Inform our professional advisors and auditors.
Pharmacovigilance & Adverse Events Reporting
Where, in the course of a research engagement, a participant spontaneously reports information that meets the definition of an adverse event, product complaint, or suspected misuse relating to a Client product, MediSights will report that information to the relevant Client (or, where required, to the relevant regulator) in accordance with the BHBIA Adverse Event Reporting Guidelines and the terms of the applicable engagement.
Such reporting is limited to information necessary for pharmacovigilance and will preserve the personal data rights of the individual; for example, seeking additional consent for facilitated contact/reporting if required.
Third parties
The MediSights platform relies on the following categories of third parties:
- Cloud hosting providers
- AI-as-a-Service agents processing interview output
- Analytics services processing user behaviour data
All third parties used for these purposes are considered sub-processors where there is the transfer of personal data.
For information on our use of third parties when processing your data, please contact: privacy@medisights.com
International transfers of personal data
Because MediSights operates internationally, personal data may be accessed from, stored in, or transferred to countries outside the country in which it was originally collected. Where we transfer personal data internationally and transfer restrictions apply, we will ensure that an appropriate transfer mechanism is in place.
Depending on the destination and the nature of the transfer, this may include:
- A finding that the destination country benefits from an adequacy decision or equivalent recognised adequacy mechanism;
- The use of designated transfer agreements, recognised in the source country and naming the destination;
- Other lawful safeguards recognised under applicable data protection law; or
- Where permitted by law, reliance on a specific derogation for the relevant transfer.
Where required, we also assess whether supplementary technical, contractual, and organisational measures are appropriate to protect personal data transferred internationally.
Details of the safeguards applicable to a specific transfer are available on request via: privacy@medisights.com
How long is personal information kept?
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, audit, or contractual requirements. The retention periods set out below may be extended where a longer period is required by law, by a Client agreement, or to defend or pursue legal claims.
Raw audio and video recordings of HCP interviews are retained for up to 180 days following project completion, to support quality assurance, transcription verification, and dispute resolution; they are deleted thereafter unless a Client agreement specifies otherwise.
De-identified transcripts are retained for up to 7 years to support research integrity, audit trail, and BHBIA- and MRS-aligned record-keeping. HCP panel records, including contact and credentialing data, are retained for the duration of panel membership plus 24 months, to support ongoing engagement and re-contact for follow-up research, subject to consent withdrawal at any time.
Honoraria and fair-market-value payment records are retained for 7 years to meet tax, anti-bribery, and pharma transparency reporting obligations, including the U.S. Sunshine Act and the EFPIA Disclosure Code. Aggregated, de-identified research outputs are retained indefinitely; they no longer constitute personal data and are used for syndicated benchmarks and comparative analysis. Client account and contractual records are retained for the term of the agreement plus 7 years, to support contract performance, audit, and limitation periods. Website analytics and cookie data are retained for up to 13 months.
On expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised. Anonymised data may be retained indefinitely as it no longer constitutes personal data.
Personal data breaches
The anonymisation process used to create processed interview output ensures MediSights minimises the use of personal data in the core platform, and in our overall operations. Alongside this, we maintain procedures for identifying, assessing, escalating, and responding to suspected personal data breaches.
Where required by applicable law, we will notify the relevant supervisory authority and/or affected individuals where a personal data breach is likely to result in a risk, or a high risk, to the rights and freedoms of individuals. We document relevant facts relating to personal data breaches, their effects, and the remedial action taken.
Children and other vulnerable groups
The MediSights platform, website, and research services are not directed to children, and MediSights does not knowingly seek to collect personal data directly from children. If we become aware that we have collected personal data from a child in circumstances where this was not intended or not permitted, we will take steps to delete that information or otherwise bring the processing into compliance with applicable law.
Your personal information rights and choices
Your choices
MediSights complies with all regulatory requirements for data subject rights in the territories in which those data subjects reside. Applicable legislation and guidance for countries in which MediSights operates is listed later in this policy, including the named rights that apply in that territory.
As a Client, HCP, panel provider, website user, or other person who considers themselves a data subject through interaction with a MediSights platform or process, and where applicable law provides such rights, you may have the right to:
- Request access to your personal information;
- Request correction of inaccurate or incomplete personal information;
- Request deletion of your personal information;
- Request restriction of processing;
- Object, or otherwise seek to restrict further processing of personal data;
- Request the transfer of your personal information to you or another organisation in a structured, commonly used and machine-readable format, where this right applies;
- Withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
These rights are not absolute and may be subject to exemptions, limitations, or conditions under applicable law, including where continued processing is necessary for compliance with legal obligations, the establishment, exercise or defence of legal claims, or scientific/statistical research subject to appropriate safeguards. Other rights may be available in your territory, but the above are considered relevant in context of MediSights operations.
To exercise your rights, please contact our Data Protection Officer using privacy@medisights.com, providing sufficient detail for us to identify you, understand your request, and locate the relevant data. We may ask for additional information to verify your identity before responding. Where required by applicable law, we will respond within the relevant statutory timeframe.
Your right to lodge a complaint
You also have the right to lodge a complaint with the supervisory authority or privacy regulator in the country, state, or territory where you live, work, or where the relevant processing took place.
The relevant authorities for regions / countries where MediSights operate are listed later in this policy.
Cookies
Cookies are small files stored on your device to help websites function and improve your experience. Here are the types of Cookies we use on this website:
- Necessary - Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
- Functional - Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
- Analytics - Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
- Performance - Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.
- Advertisement - Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.
We use the CookieYes platform to allow you to configure your consent on this website - click on the blue icon in the bottom left of your browser, titled ‘Consent Preferences’ - or you can determine cookie use through settings in your web browser.
How to contact us
If you have questions or comments about this Global Privacy & Data Protection Policy or our practices, please contact us: privacy@medisights.com
Or by post via:
MediSights Holdings, Inc.
Attn: 1111B S Governors Ave, STE 58872
Dover, DE 19904, United States
Region and territory-specific terms
Below is a list of all the countries that MediSights operates in; which legislation applies; and any other relevant guidelines applied during MediSights operations, or national / regional bodies connected to the regulation and oversight of (personal) data management.
| Country (Territory) |
Legislation | Guidelines / Memberships / Regulators | Regulator | Last reviewed |
|---|---|---|---|---|
| Canada (Federal) |
Digital Privacy Act (2015) amending The Personal Information Protection and Electronic Documents Act (PIPEDA) | Office of the Privacy Commissioner of Canada - Office of the Privacy Commissioner of Canada | June 2026 | |
| Europe (All member states) |
EU REGULATION (EU) 2016/679 (GDPR) | European Pharmaceutical Market Research Association (EPHMRA) Code of Conduct | Data protection - European Commission | June 2026 |
| Europe (Germany) |
Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG) | The Federal Commissioner for Data Protection and Freedom of Information for Germany (BfDI) | June 2026 | |
| Europe (Spain) |
LOPDGDD (Ley Organica 3/2018 de Proteccion de Datos Personales y garantia de los derechos digitales | Agencia Española de Protección de Datos | AEPD | June 2026 | |
| United Kingdom (England, Scotland, Wales) |
The Data (Use and Access) Act 2025 (DUAA) - amending The Data Protection Act 2018 (DPA 2018) | British Healthcare Business Intelligence Association's Legal & Ethical Guidelines (BHBIA) including the BHBIA Adverse Event Reporting Guidelines | Information Commissioner's Office | June 2026 |
| USA (New York State) |
Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) amending New York’s 2005 Information Security Breach and Notification Act. | Home | New York State Attorney General | June 2026 |