Neuratrial
PlatformWorkflowsGovernanceCompanyContact
PlatformWorkflowsGovernanceCompanyContact
    Version privacy-2026-08-16-r3

    Privacy Policy

    Last updated August 16, 2026

    Explains controller and customer-processor roles, account/content data, storage layers, service-provider sharing, retention, privacy rights, and DPO contact details.

    Legal

    Terms and ConditionsPrivacy PolicyCookie PolicyDisclaimerData rights request

    This Privacy Policy explains how Neuratrial-AI Pte. Ltd. (doing business as Neuratrial) ("we", "us", or "our") processes personal information in connection with Neuratrial, our websites at https://neuratrial.com, https://www.neuratrial.com, https://neura-trial.com and https://www.neura-trial.com, and related services that link to this Privacy Policy.

    Neuratrial determines the purposes and means of processing website, account, contact, billing and service-administration information. Where Neuratrial processes documents or other data submitted by an enterprise customer, Neuratrial processes that data on the customer's instructions and subject to the applicable customer agreement.

    TABLE OF CONTENTS

    1. 1. INFORMATION WE COLLECT
    2. 2. CUSTOMER DATA AND SENSITIVE INFORMATION
    3. 3. HOW WE USE INFORMATION
    4. 4. LEGAL BASES
    5. 5. HOW WE SHARE INFORMATION
    6. 6. AI, INFRASTRUCTURE AND RESEARCH PROVIDERS
    7. 7. COOKIES AND SIMILAR TECHNOLOGIES
    8. 8. INTERNATIONAL PROCESSING
    9. 9. RETENTION
    10. 10. SECURITY
    11. 11. CHILDREN
    12. 12. PRIVACY RIGHTS
    13. 13. UNITED STATES PRIVACY NOTICE
    14. 14. UPDATES
    15. 15. CONTACT AND DATA PROTECTION OFFICER

    1. INFORMATION WE COLLECT

    Information you provide. We collect information you provide when creating or administering an account, requesting information, contacting support, submitting forms, using the Services, or communicating with us. This may include name, email address, username, password or authentication information, multi-factor authentication setup information, job title, organisation, business contact details, billing contact details, support messages, contract information, and communication preferences.

    Service content and workflow information. Depending on the feature you use, we may process prompts, chat messages, uploaded documents, spreadsheets, document-review content, generated documents, protocol-planning inputs, clinical-operations workspace records, source/citation records, selected knowledge-base settings, file metadata, and user edits or workflow decisions.

    Billing and access-plan information. The current Services maintain subscription, access-plan, quota, and usage-limit metadata for account administration. The Services do not currently implement public card checkout or store full debit or credit card numbers. If card billing is later handled through a third-party payment processor, we would receive billing and transaction metadata needed to administer the account while card details are collected directly by that processor.

    Information collected automatically. We may collect log and usage data, IP address, browser type, device type, operating system, referring URLs, pages visited, feature usage, timestamps, diagnostic data, security events, session activity metadata, legal-acceptance metadata, cookie-consent metadata, host/origin, user-agent, and approximate location inferred from IP address. We do not request GPS or precise device location through the public website.

    Information from third parties. We may receive information from authentication, hosting, security, analytics, email, infrastructure, research-evidence, web-search and other service providers, and from enterprise customers that administer user accounts.

    2. CUSTOMER DATA AND SENSITIVE INFORMATION

    Customer Data may include documents, prompts, instructions, files, outputs, and other content submitted to or generated through the Services by or for a customer or user.

    We do not intentionally collect sensitive personal information through the public website. Customer Data may contain sensitive information only where permitted under the applicable customer agreement.

    Users must not upload Protected Health Information unless Neuratrial has expressly approved the applicable service configuration in writing and, where required, a Business Associate Agreement is in effect. A Data Processing Agreement does not by itself authorise the processing of PHI.

    The Services include best-effort PHI/PII redaction and visual privacy scanning in some document workflows. Redacted text or excerpts may be created for review, retrieval, audit, or model-input safety. These safeguards are not a guarantee that all sensitive information will be removed.

    3. HOW WE USE INFORMATION

    We use personal information to provide, secure, maintain, and support the Services; create and manage accounts; authenticate users; enforce MFA and session controls; administer access plans, quotas, orders and invoices; respond to enquiries; send transactional and administrative notices; maintain legal-consent and audit histories; monitor security and prevent abuse; comply with legal and accounting obligations; enforce agreements; improve service reliability; and, where permitted, send product or service communications.

    We may use analytics information to understand site performance and product usage trends only where permitted by law and applicable consent choices. We do not use personal information for targeted advertising unless we separately disclose that activity and obtain any required consent.

    4. LEGAL BASES

    Where a legal basis is required, we may process personal information because processing is necessary to perform a contract, comply with legal obligations, protect legitimate interests such as security and service administration, protect vital interests where strictly necessary, or because you have given consent. You may withdraw consent where processing is based on consent.

    5. HOW WE SHARE INFORMATION

    We may share personal information with service providers, professional advisers, enterprise customers that administer user accounts, affiliates, parties involved in corporate transactions, regulators, courts, law enforcement, or others where required by law or necessary to protect rights, safety, and security.

    We do not sell personal information. We do not share personal information for cross-context behavioural advertising unless we separately disclose that activity and provide any legally required choice.

    6. AI, INFRASTRUCTURE AND RESEARCH PROVIDERS

    Depending on the feature and customer configuration, Customer Data may be processed by selected AI, infrastructure, security, analytics, email, search, and research-evidence service providers used to provide that feature.

    Current service-provider categories may include OpenAI and configured OpenAI-compatible enterprise LLM gateways for AI model, embedding, file-processing, and code-interpreter-style processing; Amazon Web Services, including S3, S3 Vectors, SES, SQS and CloudTrail where configured, MongoDB and Vercel for hosting, object storage, vector storage, database, deployment, email delivery, queueing, and audit infrastructure; Google reCAPTCHA for contact-form bot protection; Vercel Speed Insights for optional performance analytics where enabled; and PubMed/NCBI, PubMed Central/NCBI, ClinicalTrials.gov, doi.org, Unpaywall and Serper where web search is enabled for public research, literature, trial-registry, citation, and web-search retrieval.

    Customer Data is routed only to providers needed for the relevant feature or configuration.

    7. COOKIES AND SIMILAR TECHNOLOGIES

    We use cookies and browser storage as described in the Cookie Policy at https://www.neuratrial.com/cookies. Necessary technologies support sign-in, security, session management, consent records, and service operation. Optional analytics technologies run only after the visitor or user chooses them.

    8. INTERNATIONAL PROCESSING

    We are incorporated in Singapore and the Services may be hosted, supported, or processed in Singapore, the United States, and other locations where our service providers operate. Where required, we use contractual, organisational, and technical safeguards for international transfers.

    9. RETENTION

    Data is retained only for as long as required to provide the Services, comply with the applicable customer agreement, meet legal or accounting obligations, resolve disputes and complete ordinary backup-deletion cycles. Large uploaded documents, extracted text, generated artifacts, and vectorized content may be stored in object or vector storage, while MongoDB is used for account records, metadata, workflow state, compact histories, and legal/cookie consent records.

    10. SECURITY

    We use administrative, technical, and organisational safeguards designed to protect personal information and Customer Data. No internet or storage system can be guaranteed to be completely secure. Users are responsible for maintaining account security and promptly reporting suspected unauthorised access.

    11. CHILDREN

    The Services are intended for professional and enterprise use and are not directed to children. We do not knowingly collect personal information from children through the public website.

    12. PRIVACY RIGHTS

    Depending on your location and the context of processing, you may have rights to access, correct, delete, restrict, object to, port, or withdraw consent for personal information. Enterprise users should understand that requests involving Customer Data may need to be handled by the relevant enterprise customer as controller or business owner.

    To submit a request, email admin@neuratrial.com with the subject line "Data Rights Request" or visit https://www.neuratrial.com/dsar. We may need to verify your identity and authority before acting on a request.

    13. UNITED STATES PRIVACY NOTICE

    Depending on applicable US state law, the categories of personal information we may process include identifiers, account information, commercial or billing metadata, internet or other electronic network activity, approximate geolocation inferred from IP address, professional or employment-related information, service-content metadata, and inferences related to service preferences or usage. Customer Data may include sensitive or health-related information only where the applicable customer agreement permits that processing.

    We do not collect precise GPS location through the public website. We do not sell personal information and do not process personal information for targeted advertising unless we separately disclose that activity and provide any legally required opt-out.

    14. UPDATES

    We may update this Privacy Policy from time to time. The date at the top indicates when it was last updated. Material updates may be communicated through the Services, email, or another appropriate notice.

    15. CONTACT AND DATA PROTECTION OFFICER

    Questions about this Privacy Policy or privacy requests may be sent to:

    Neuratrial-AI Pte. Ltd.
    458 Corporation Rd, Singapore 649814
    Parc Vista Tower 5 Unit 10-07
    Singapore 649814
    Singapore
    Phone: (+65)97377240
    Email: admin@neuratrial.com

    Data Protection Officer
    Neuratrial-AI Pte. Ltd.
    Email: admin@neuratrial.com