Data protection

Privacy & data policy

CredPass is built so that nothing about a volunteer is visible by default. This policy explains what we hold, who can see it, and how a volunteer stays in control.

Three-layer separation

Identity, eligibility signals and clinical source records are kept apart. A CRO can evaluate de-identified eligibility signals without seeing identity documents or medical files. Identity and supporting information are released only after an explicit volunteer decision. Clinical source records stay with the CRO or site that created them.

What we collect

  • Volunteers: account details, KYC and identity document references, self-declared eligibility and screening information, documents you upload to your wallet, applications, participation history, consent grants and access events.
  • CROs, sites and sponsors: organisation profile, capability and regulatory-history claims, study listings, briefs, messages and billing records.
  • Public marketplace visitors: anonymous study-view events recording only the study identifier, whether the viewer was signed in, the entry surface and a timestamp. No name, email, IP address or health information is stored with these events.
  • Operational data: authentication events, audit-trail entries, and verification-token usage.

Consent, purpose and duration

Every application to a study raises a specific data-access request. A grant states what may be seen, for what purpose, and for how long. Grants expire automatically and can be revoked at any time from your consent controls. Verification tokens presented by QR code are short-lived and each use is logged.

Audit trail

Access to volunteer data is recorded: who accessed it, under which grant, and when. Volunteers can review these events. Administrators can review consent, access and verification activity for compliance oversight without gaining default access to the underlying personal or clinical content.

Retention and erasure

Records are kept while your account is active and for as long as needed for the purpose they were collected or as required by law. Volunteers can erase their passport data from their passport screen; this removes tokens, wallet documents, consent grants, participation entries and the profile, while an audit record of the erasure itself is retained. Erasure on CredPass does not delete clinical source records held by a CRO or site, which are governed by that organisation's own regulatory retention duties.

Notifications

Volunteers may receive washout-countdown and study-match alerts. These can be paused, marked read or dismissed at any time from the alerts screen.

Security

Access is enforced at the database level by row-level policies in addition to application checks, so a role can only read the rows its permissions allow. Passwords are subject to leaked-credential screening. No system is perfectly secure; report suspected issues to us promptly.

Your rights

You may access, correct, export or erase your data, withdraw a consent grant, or object to a specific processing activity. Requests are handled through your account screens where possible, or by contacting us. Sponsors, CROs and sites act as independent controllers for any personal data they lawfully retain outside CredPass. See also the terms of service.