Last Updated: February 14, 2026
1. Introduction and Our Commitment
At Patient in Research (www.patientinresearch.com), we are deeply committed to protecting the privacy and confidentiality of your personal information. As a patient collaborative, we understand the sensitive nature of the data you entrust to us, particularly health-related information. This Privacy Policy outlines how we collect, use, store, and protect your personal data, ensuring compliance with the General Data Protection Regulation (GDPR), the Danish Data Protection Act (Databeskyttelsesloven), and the Health Insurance Portability and Accountability Act (HIPAA) in the United States. Our promise to you is built on transparency, respect, and the unwavering belief that your story belongs to you. We are not here to sell your data, and we strive to ensure that any information shared is done so with your explicit consent and for the sole purpose of advancing patient-centric research.
2. Who We Are (Data Controller)
Patient in Research is the data controller responsible for the processing of your personal data collected through our website. Our contact details are:
Patient in Research. Buddingevej 60, 2800 Kongens Lyngby, Denmark
Company Registration Number (CVR):
Email: cn@patientinresearch.com
We encourage you to contact us with any questions or concerns regarding your privacy.
3. Types of Information We Collect
We collect various types of information to facilitate our patient collaborative activities and improve your experience. This data can be broadly categorized as follows:
a. Personal Identification Information
This includes data that can directly identify you, such as your name, email address, postal address, telephone number, and date of birth. We collect this information when you register on our website, subscribe to newsletters, participate in surveys, or contact us directly.
b. Special Category Data (Health Data)
Given our focus on patient engagement, we may collect sensitive health-related information, such as medical conditions, diagnoses, treatment histories, and other health experiences. This type of data is considered “special category data” under GDPR and is processed with the utmost care and only with your explicit consent.
c. Technical and Usage Data
When you visit our website, we automatically collect certain technical information, including your IP address, browser type, operating system, referral sources, pages viewed, and the duration of your visit. This data is primarily collected through cookies and similar technologies to ensure the proper functioning of our website, analyze user patterns, and enhance your browsing experience. For more detailed information, please refer to our separate Cookie Policy.
d. Communication Data
This includes information you provide when communicating with us via email, contact forms, or other channels. This data helps us respond to your inquiries and maintain a record of our communications.
4. How We Use Your Information (Purposes and Legal Basis)
We process your personal data for specific purposes and always rely on a valid legal basis as required by GDPR and the Danish Data Protection Act. The primary purposes and corresponding legal bases are:
a. To Facilitate Patient Engagement and Research Participation
•Purpose: To connect patients with relevant research opportunities, manage participation in studies, and facilitate communication between patients and researchers.
•Legal Basis: Your explicit consent (GDPR Article 6(1)(a) and Article 9(2)(a) for special category data) and the performance of a contract (GDPR Article 6(1)(b)) if you enter into an agreement to participate in a specific research project.
b. To Communicate with You
•Purpose: To send you newsletters, updates, information about new research opportunities, and respond to your inquiries.
•Legal Basis: Your consent (GDPR Article 6(1)(a)) for marketing communications, and our legitimate interest (GDPR Article 6(1)(f)) to respond to your direct communications and provide essential service-related information.
c. To Improve Our Website and Services
•Purpose: To analyze website usage, identify areas for improvement, and enhance the user experience.
•Legal Basis: Our legitimate interest (GDPR Article 6(1)(f)) in understanding how our website is used and continually improving our offerings.
d. To Ensure Security and Comply with Legal Obligations
•Purpose: To protect our website and data from unauthorized access, fraud, or other illegal activities, and to comply with applicable laws, regulations, and legal processes.
•Legal Basis: Compliance with a legal obligation (GDPR Article 6(1)(c)) and our legitimate interest (GDPR Article 6(1)(f)) in maintaining the security and integrity of our operations.
5. Sharing Your Information
We will only share your personal information under specific circumstances and with appropriate safeguards in place:
a. With Research Partners
We may share your data with pharmaceutical companies, Contract Research Organizations (CROs), academic institutions, or other research entities involved in patient engagement and clinical research. This sharing will only occur with your explicit consent and for the purposes outlined in the specific research project you agree to participate in. We ensure that all research partners are contractually bound to protect your data in accordance with GDPR and relevant data protection laws.
b. With Service Providers
We engage third-party service providers to assist us with website hosting, IT infrastructure, data analytics, email delivery, and other operational functions. These providers are carefully selected and are only granted access to the personal data necessary to perform their services. They are contractually obligated to process data only on our instructions and to implement appropriate security measures.
c. For Legal Reasons
We may disclose your information if required by law, court order, or governmental regulation, or if we believe such action is necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
6. International Data Transfers
As a global patient collaborative, your personal data may be transferred to, and stored at, destinations outside the European Economic Area (EEA), including countries that may not offer the same level of data protection as Denmark or the EU. When such transfers occur, we implement appropriate safeguards to ensure your data remains protected, such as:
•Standard Contractual Clauses (SCCs): We utilize the European Commission’s approved Standard Contractual Clauses to ensure adequate protection for data transferred outside the EEA.
•Data Privacy Framework (DPF): For transfers to the United States, we rely on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, where applicable, ensuring that the recipient organization is certified under these frameworks.
We will always inform you if your data is subject to international transfers and seek your explicit consent where required by law.
7. Data Security
We implement robust technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, access controls, regular security assessments, and employee training on data protection best practices. We continuously review and update our security practices to adapt to evolving threats and technologies.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The specific retention periods depend on the type of data and the purpose of processing. For example, certain financial records may be retained for up to five years in accordance with Danish tax and commercial laws. Once the retention period expires, your personal data will be securely deleted or anonymized.
9. Your Data Protection Rights
Under GDPR and the Danish Data Protection Act, you have several rights regarding your personal data:
•Right of Access: You have the right to request a copy of the personal data we hold about you.
•Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
•Right to Erasure (“Right to be Forgotten”): You have the right to request the deletion of your personal data under certain circumstances.
•Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data under certain conditions.
•Right to Object to Processing: You have the right to object to our processing of your personal data, particularly when based on legitimate interests or for direct marketing.
•Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
•Right to Withdraw Consent: Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us using the details provided in Section 2. We will respond to your request within one month, in accordance with GDPR requirements.
10. Cookies and Other Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and personalize content. For detailed information about the types of cookies we use, their purposes, and how you can manage your preferences, please refer to our dedicated Cookie Policy.
11. Contact Us and Complaints
If you have any questions about this Privacy Policy or our data protection practices, please do not hesitate to contact us:
Patient in Research Email: cn@patientinresearch.com
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority. In Denmark, this is the Danish Data Protection Authority (Datatilsynet):
Datatilsynet. Carl Jacobsens Vej 35, 2500 Valby, Denmark
Phone: +45 33 19 32 00
Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any significant changes by posting the updated policy on our website and, where appropriate, by other means such as email. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
