Document DPA-01
Data Processing
How Thallyx handles case data. Adverse-event reports contain health information about identifiable people, and pharmacovigilance is one of the few settings where that data must be retained for decades.
Effective 15 August 2026
1. Roles
The marketing authorisation holder is the controller of its safety data. It holds the regulatory obligation, determines the purposes, and remains accountable to its competent authorities. Thallyx is a processor acting on documented instructions under an executed data processing agreement.
Where a client is itself a processor — a CRO running case processing for a sponsor — Thallyx acts as a subprocessor, and the sponsor's approval rights under the head agreement are respected.
We have no independent right to use case data. Every permitted use flows from the client's instructions and the DPA's terms.
2. What we do with case data
We read the report and produce a case: validity assessment, MedDRA coding, seriousness and expectedness assessment, causality per your convention, narrative, and the follow-up requests the record indicates. That is the permitted purpose and there is no other.
Source documents are retained unaltered and linked to every field derived from them, because in this setting traceability is a regulatory requirement rather than a nicety.
3. Special category data
Adverse-event reports are special category data under Article 9 of the UK and EU GDPR, and may constitute protected health information under HIPAA where a US covered entity is involved. Processing relies on the public-interest-in-public-health basis at Article 9(2)(i), which exists precisely so pharmacovigilance can function.
That basis is narrow. It permits processing for pharmacovigilance and nothing else, and it does not extend to product development, model training, benchmarking or analytics beyond the case.
4. Model training and confidentiality
- Case data is never used to train or fine-tune models.
- Case data is never pooled across clients for any purpose.
- Any model provider in the processing path is contractually bound to zero data retention and to no training on submitted data.
- Personnel access is least-privilege, logged, and reviewed; nobody has standing access to case data they are not working.
5. Retention
Pharmacovigilance retention periods are long — commonly the life of the marketing authorisation plus ten years, and longer in some jurisdictions. Retention is therefore set by the client's schedule as a contractual term, not by a platform default, and deletion on termination is subject to the statutory periods the client must observe.
6. Security and audit
Encryption in transit and at rest, segregated client environments, unique user identification, secure computer-generated and time-stamped audit trails that do not obscure prior entries, and documented change control over the system and the models within it.
Clients may audit, and we support regulatory inspections of our clients as a term of the agreement — including making documentation, systems and personnel available.
7. Personal data breach
On becoming aware of a personal data breach affecting case data we notify the affected client without undue delay and within the period the DPA specifies, with the information they need to make their own notifications. The client, as controller, notifies the supervisory authority and any data subjects.
8. Patients and reporters
If you are a patient or a reporter with a question about a report concerning you, contact the company that markets the medicine, or the regulator you reported to. They are the controller and the right party to answer. Thallyx cannot verify your identity and will route any request to the relevant client.