Skip to content

Document PRV-01

Privacy Policy

How Thallyx handles information about the people who use this website and who work at our clients. Case data — which contains health information about patients — is governed separately; see Data Processing.

Effective 15 August 2026

1. Scope, and an important distinction

This policy covers information about you as a visitor to thallyx.com, someone who submits a request, or a named user at a client organisation. It is about business contact data and website analytics.

It does not cover case data. Adverse-event reports made available to Thallyx by a client contain health information about identifiable patients, and are processed under a data processing agreement as set out in the Data Processing document. Where the two appear to conflict on case data, the DPA controls.

2. What we collect

Information you give us. When you submit a request we collect your name, work email address, organisation, role, organisation type, and the case volume, safety database and free-text detail you choose to provide.

Information we collect automatically. Standard server logs (IP address, user agent, requested path, timestamp) and privacy-preserving page analytics. We run no advertising trackers and do not sell or share data for cross-context behavioural advertising.

Information from your employer. If your organisation becomes a client, we receive the account details needed to provision your access — typically name, work email, role, and the permissions your administrator assigns.

3. Why we use it

  • To evaluate and respond to your request.
  • To provide, secure and support the service for your organisation.
  • To meet legal, regulatory and contractual obligations, including the record-keeping duties that attach to pharmacovigilance infrastructure.
  • To understand, in aggregate, which parts of this website are useful.

We rely on legitimate interests for business-contact processing, contract performance for service provision, and legal obligation where retention is mandated. Where consent is the basis — optional analytics in jurisdictions requiring it — you may withdraw it at any time without affecting prior processing.

4. Who we share it with

Service providers processing on our behalf under written terms: hosting, error monitoring, email delivery and customer relationship management. Each is bound to confidentiality and to processing only on our instructions. The current list is published on the Subprocessors page.

Regulators, auditors and legal counsel where we are compelled, or where a client's own regulatory obligation requires it.

An acquirer, in a merger, acquisition or asset sale — with notice to you, and this policy continuing to apply until superseded.

We do not sell personal information and have not done so in the preceding twelve months.

5. International transfers

Pharmacovigilance is inherently cross-border: a case reported in one country is frequently reportable in several. Where personal data leaves its country of origin we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision.

Clients with data-residency requirements should raise them during contracting; regional processing arrangements are agreed in the order form rather than assumed here.

6. How long we keep it

Requests that do not become accounts: 24 months, then deleted.

Account and contact records: for the life of the client relationship, plus the period our contractual and statutory retention duties require.

Server logs: 90 days in hot storage.

Records relating to pharmacovigilance activity are subject to substantially longer statutory retention, and those periods override the above.

7. Your rights

Depending on where you live you may have the right to access, correct, delete, port, restrict or object to our processing of your personal information, and to complain to a supervisory authority.

Write to privacy@thallyx.com and we will respond within the period your law allows — one month under the UK and EU GDPR, 45 days under the CCPA, extendable where the request is complex. We will verify your identity before acting.

If your request concerns case data processed for a client, we will route it to that client, who is the controller. We cannot action it directly.

8. Automated processing

Thallyx uses artificial intelligence, including language models, to read adverse-event reports and produce coded, assessed case files. Where that processing involves case data it is governed by the DPA, not by this policy.

No decision producing a legal or similarly significant effect about any individual is made solely by automated means. The system produces an assessment and its supporting evidence; the client's accountable person makes the decision. Where the UK or EU GDPR applies you retain the Article 22 rights in any event.

Personal information collected through this website is not used to train any model.

9. Security

Encryption in transit and at rest, role-based access control, least-privilege internal access, audit logging, and background checks for personnel with production access. The full posture, including its current limits, is described on the Compliance page.

No system is perfectly secure. Where a breach affects your personal information we will notify you and the relevant authority within the timeframes our obligations require.

10. Children

This website is directed at professionals and is not intended for anyone under 18. We do not knowingly collect personal information from children through it. Paediatric adverse-event reports reaching the service are case data under the DPA, not website data under this policy.

11. Changes and contact

We will post any material change here and update the effective date. Where the change is significant and we hold your contact details, we will tell you directly.

Thallyx — privacy@thallyx.com. A postal address and the identity of our data protection officer will be listed here once entity details are finalised.