Cloudbyz Privacy Policy – Non-HR Personal Data

Cloudbyz Privacy Policy – Non-HR Personal Data

EU-U.S. Data Privacy Framework, UK Extension and Swiss-U.S. Data Privacy Framework

Effective Date: September 28, 2026

1. Introduction and Scope

Cloudbyz Inc. ("Cloudbyz," "we," "us," or "our"), with its United States place of business at 4320 Winfield Road, Suite 200, Warrenville, IL 60555, USA, provides cloud-based software and services to the healthcare and life sciences sector, including clinical trial management, electronic trial master file, electronic data capture, randomisation and trial supply management, and pharmacovigilance applications. Cloudbyz Inc. is the United States entity certified under the Data Privacy Framework.

This Policy explains how Cloudbyz collects, uses, discloses, retains, secures, and protects personal data, and describes the rights and recourse mechanisms available to individuals whose personal data Cloudbyz processes.

This Policy applies to non-HR personal data that Cloudbyz receives in the United States from the European Union and European Economic Area, from the United Kingdom (including Gibraltar), and from Switzerland, in reliance on the Data Privacy Framework Program described in Section 2.

This Policy does not apply to human resources data, meaning personal data concerning employees, former employees, applicants, or contractors collected in the context of an employment relationship. Cloudbyz Inc. does not receive human resources data concerning personnel based in the European Union, European Economic Area, United Kingdom, or Switzerland under its certification, and is not certified under the Data Privacy Framework for human resources data.

2. Data Privacy Framework Participation and Commitment

Cloudbyz Inc. participates in, and has certified its compliance with, the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF ("UK Extension"), and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF"). These frameworks are administered by the U.S. Department of Commerce and provide a mechanism for participating organizations in the United States to receive personal data from the European Union and European Economic Area, the United Kingdom and Gibraltar, and Switzerland respectively.

Cloudbyz is committed to processing personal data received from the European Union and European Economic Area in accordance with the EU-U.S. DPF Principles; personal data received from the United Kingdom and Gibraltar in accordance with those Principles as applied by the UK Extension; and personal data received from Switzerland in accordance with the Swiss-U.S. DPF Principles. Together, these requirements are referred to in this Policy as the "DPF Principles."

In the event of any conflict between the terms of this Policy and the applicable DPF Principles, the applicable DPF Principles shall govern to the extent of the conflict.

Cloudbyz monitors its adherence to the DPF Principles through annual self-assessment. Information about the Data Privacy Framework Program and Cloudbyz's certification is available through the official Data Privacy Framework Program website.

3. Our Role: Controller and Processor

Cloudbyz processes personal data in different capacities, and the rights and routes available to individuals differ accordingly.

Capacity Personal Data Concerned Where to Direct Requests
Controller Website visitors, individuals making enquiries, marketing contacts, customer administrative and support contacts, and platform user account records that Cloudbyz maintains for its own purposes. Directly to Cloudbyz using the contact details in Section 13.
Processor / Agent Personal data contained in customer-provided clinical research and related business records that customers load into, or generate within, the Cloudbyz platform. The customer - such as the sponsor, CRO, or site - determines the purposes of processing. Cloudbyz will assist the customer as required.

Where Cloudbyz acts as an agent, it processes personal data only on the documented instructions of the customer and in accordance with applicable contractual requirements and the DPF Principles as they apply to agents. Cloudbyz will promptly refer any request it receives directly from an individual to the relevant customer where appropriate, and will notify the customer if it determines that it can no longer meet its obligations under the applicable DPF Principles.

4. Categories of Personal Data

Depending on the individual's interaction with Cloudbyz and the services involved, Cloudbyz may process:

  • Names and contact information, including email addresses, telephone numbers, and postal addresses;
  • User and account identifiers, and authentication and access information;
  • Professional information, including job title, employer, institution, role, and professional credentials;
  • Technical and usage information, including IP address, device and browser information, log data, audit trail entries, and records of activity within the platform;
  • Customer communications, including support requests, correspondence, and associated records; and
  • Personal data contained in customer-provided clinical research and related business records, which may include sensitive personal data such as information concerning health.

Where Cloudbyz processes sensitive personal data as an agent on behalf of a customer, it does so solely in accordance with that customer's documented instructions, and the customer is responsible for establishing the applicable lawful basis and for obtaining any affirmative express consent required under the DPF Principles. Where Cloudbyz acts as a controller and the DPF Principles require affirmative express consent for the use or disclosure of sensitive personal data for a materially different purpose or to a non-agent third party, Cloudbyz will obtain such consent.

5. Purposes of Processing

Cloudbyz processes personal data in order to provide, operate, maintain, secure, and support its cloud-based software and services. Specifically, personal data may be processed to provide the services contracted for by customers; create and manage user accounts and control access to the platform; support clinical research and related business activities; provide customer support and respond to enquiries; maintain the security, availability, integrity, and performance of Cloudbyz systems; prevent, detect, and investigate unauthorised access, fraud, misuse, or security incidents; troubleshoot, maintain, and improve the services; manage business relationships and contractual obligations; and meet applicable legal, regulatory, and contractual requirements.

Cloudbyz does not sell personal data and does not use personal data contained in customer records for its own marketing purposes.

6. Choice

Where Cloudbyz acts as a controller, individuals may object to the disclosure of their personal data to a third party that is not acting as Cloudbyz's agent, and to the use of their personal data for a purpose materially different from the purpose for which it was originally collected or subsequently authorised. Requests may be submitted using the contact information in Section 13, and individuals may unsubscribe from marketing communications at any time using the mechanism provided in the applicable communication.

Where sensitive personal data is concerned, Cloudbyz will obtain affirmative express consent, where required by the DPF Principles, before disclosing it to a third party that is not acting as Cloudbyz's agent or using it for a materially different purpose. Where Cloudbyz processes such data solely as an agent, that responsibility rests with the customer to the extent provided under the DPF Principles and applicable law.

7. Accountability for Onward Transfer

Cloudbyz may disclose personal data to third parties that provide services on its behalf, including hosting, infrastructure, platform and technology providers; customer support and communications providers; professional service providers; and auditors and consultants.

Where Cloudbyz transfers personal data received in reliance on the DPF to a third party acting as an agent, Cloudbyz transfers it only for limited and specified purposes; ascertains that the agent is obligated to provide at least the same level of privacy protection as required by the applicable DPF Principles; takes reasonable and appropriate steps to ensure the agent processes the personal data consistently with Cloudbyz's obligations; requires the agent to notify Cloudbyz if it can no longer meet that obligation; and, upon such notification, takes reasonable and appropriate steps to stop and remediate unauthorized processing.

Cloudbyz Inc. remains responsible under the applicable DPF Principles for personal data transferred to agents acting on its behalf, except where Cloudbyz demonstrates that it is not responsible for the event giving rise to the damage.

8. Security, Data Integrity and Retention

Cloudbyz takes reasonable and appropriate administrative, technical, and physical measures to protect personal data from loss, misuse, unauthorised access, unauthorised disclosure, alteration, and destruction, appropriate to the nature of the personal data and the risks associated with its processing.

Cloudbyz limits the personal data it processes to information relevant to the purposes for which it is processed, does not process personal data in a manner incompatible with those purposes except where permitted or required by applicable law, and takes reasonable steps to ensure that personal data is reliable for its intended use, accurate, complete, and current where necessary.

Cloudbyz retains personal data only for as long as necessary to fulfil the purposes for which it was collected, and thereafter for such additional period as may be required to comply with applicable legal, regulatory, contractual, or business requirements. Where Cloudbyz acts as an agent, retention and deletion of customer-provided personal data are governed by the customer's documented instructions and applicable contractual requirements, subject to applicable legal obligations.

9. Access, Correction and Deletion

Individuals have the right, subject to the DPF Principles and applicable law, to obtain confirmation as to whether Cloudbyz processes personal data relating to them; to request access to such personal data; to request correction or amendment of inaccurate personal data; and to request deletion of personal data where it has been processed in violation of the DPF Principles or where otherwise required by applicable law. Requests should be submitted using the contact details in Section 13.

Cloudbyz will respond within 30 days of receipt, or will inform the individual within that period of the reason for any delay and the expected date of response. Cloudbyz may require reasonable information to verify the identity of the requester.

Cloudbyz may limit or decline access where the burden or expense of providing it would be disproportionate to the risks to the individual's privacy, where the rights of other persons would be violated, or where access is otherwise restricted or permitted to be denied under the DPF Principles or applicable law. Where Cloudbyz declines a request in whole or in part, it will explain the reason and provide an appropriate contact point for further enquiries. Where the personal data is processed by Cloudbyz as an agent, the request will be referred to the applicable customer, which is responsible for responding.

10. Complaints, Independent Recourse and Enforcement

10.1 Contact Cloudbyz first

Any question or complaint concerning Cloudbyz's handling of personal data should first be raised with the Cloudbyz Inc. Privacy / Data Protection Team at privacy@cloudbyz.com, or by post to Cloudbyz, Inc., 4320 Winfield Road, Suite 200, Warrenville, IL 60555, USA. Cloudbyz will acknowledge and respond to privacy complaints within 45 days of receipt and will investigate them in accordance with its applicable privacy procedures and the DPF Principles.

10.2 Independent recourse mechanism

Cloudbyz has selected the European Union Data Protection Authorities (EU DPAs) as its independent recourse mechanism, and commits to cooperate with the competent EU Data Protection Authorities and comply with their advice with respect to unresolved complaints concerning personal data transferred from the EU/EEA in reliance on the EU-U.S. DPF. Individuals may contact the competent authority in the EU Member State where they reside, work, or believe an alleged violation occurred; information is available through the European Data Protection Board.

For personal data received from the United Kingdom and Gibraltar in reliance on the UK Extension, individuals may contact the UK Information Commissioner's Office (ICO) or the Gibraltar Regulatory Authority (GRA), as applicable. For personal data received from Switzerland in reliance on the Swiss-U.S. DPF, individuals may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC). Cloudbyz commits to cooperate with and comply with the advice of the ICO and the GRA with respect to unresolved complaints concerning personal data transferred in reliance on the UK Extension, and of the FDPIC with respect to unresolved complaints concerning personal data transferred in reliance on the Swiss-U.S. DPF. There is no cost to individuals for using these independent recourse mechanisms.

An individual who has not received a timely acknowledgement of a complaint, or whose complaint has not been satisfactorily addressed, may also contact the U.S. Department of Commerce's International Trade Administration, which administers the Data Privacy Framework Program.

10.3 Binding arbitration

Under certain conditions, and as a last resort where other applicable recourse mechanisms have not resolved the matter, an individual may invoke binding arbitration before the Data Privacy Framework Panel in respect of residual claims under the applicable DPF Principles. The governing conditions and procedures are set out in Annex I of the EU-U.S. Data Privacy Framework Principles. Arbitration is available at no cost to the individual other than the individual's own legal representation, should the individual choose to be represented.

10.4 Regulatory oversight

Cloudbyz Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC) with respect to its compliance with the applicable DPF Principles. Cloudbyz has elected self-assessment as its method of verifying compliance, carries out that verification annually, and maintains a statement verifying its compliance signed by an authorised corporate officer, which is made available upon request in connection with an enquiry or complaint concerning compliance.

11. Disclosure to Public Authorities

Cloudbyz Inc. may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Where Cloudbyz receives such a request in respect of personal data processed on behalf of a customer, it will, unless legally prohibited from doing so, notify the customer, and will disclose only the minimum personal data necessary to comply.

12. Changes to This Policy

Cloudbyz may amend this Policy from time to time to reflect changes in its privacy practices, products or services, applicable laws or regulatory requirements, or the DPF Principles. Any amendment will be managed under Cloudbyz's applicable document-control process, will include an updated version number and effective date, and will be published at the location where this Policy is made available.

Where an amendment is material, Cloudbyz will take reasonable steps to bring the change to the attention of affected individuals and, where Cloudbyz acts as an agent, the relevant customers. Personal data collected before an amendment will continue to be handled in accordance with the Policy applicable at the time of collection, unless the individual consents to the revised processing or the applicable DPF Principles or law requires otherwise.

13. Contact Us

Privacy enquiries privacy@cloudbyz.com
Postal address Cloudbyz, Inc.
4320 Winfield Road, Suite 200
Warrenville, IL 60555, USA
DPF Program Data Privacy Framework Program

Still can't find what are you looking for?

We are always happy to help with any questions