Overview
TrialBridge is operational software for clinical research sites. We process two broad categories of information: account and organization data we hold about the people who use the product, and operational study records that sites enter or upload to manage their enrollment pipeline.
We are a processor for the operational study records and a controller for account and product usage data. This policy describes both. Where the same fact is governed by a sponsor agreement or site SOP, that agreement controls.
Data we collect
Account details. Name, email, role, password hash, multi-factor settings, login activity, and notification preferences.
Organization and site details. Organization name, site name, membership, assigned roles (admin, principal investigator, coordinator, auditor), invitations, and membership audit entries.
Protocol files. Protocol documents and supporting files you upload, plus extracted structured fields such as eligibility criteria, visit schedule, and schedule of assessments.
Candidate import fields. The record fields your site imports for screening, including identifiers your site chooses to map into the workspace.
EHR-source eligibility inputs. Where an integration is configured, inbound demographic data, allergy flags, and concurrent medication lists used as eligibility inputs.
Eligibility scores. Generated criterion-level results, confidence values, and the cited protocol evidence attached to them.
Visit-window workflow records. Scheduled visits, window boundaries, confirmations, reschedules, and related coordinator tasks.
Retention workflow records. Drop-off signals, reminder history, and follow-up actions logged by the site team.
Sponsor update drafts. Draft and approved summary reports, export scope, and export history including actor and timestamp.
Support messages. Messages, attachments, and correspondence you send to our support team.
Usage logs and communication preferences. Feature events, request timing, diagnostic logs, and your marketing and notification choices. We do not sell this data.
AI feature usage
AI features support review workflows and produce cited outputs for human confirmation. TrialBridge does not use AI output as the final eligibility decision.
Critical Risk red/orange flags require human sign-off before action. Manual overrides are recorded in immutable audit trails.
AI requests are routed through a vendor gateway under contract. Inputs and outputs are logged for audit and debugging on our infrastructure, scoped to your site, and not used for external model training.
Email preferences
Transactional, account, and security emails (verification, password reset, invitation, security notice, report ready) are sent as part of the service and cannot be opted out of while the account is active.
Marketing categories (newsletter, product updates, educational content, announcements) are off by default and require opt-in. You can change these any time at Email preferences or via the unsubscribe link in any marketing email.
Third-party services
We use a managed cloud platform for application hosting, database, authentication, and file storage. We use a managed AI gateway to route AI feature requests. We use an outbound email service for transactional and (when you opt in) marketing email delivery. Each vendor processes only the data needed to perform its function and is bound by a written agreement.
Data retention
Operational records are retained for the active life of each study and for the period required by the sponsor's data retention agreement. Audit logs are append-only and retained per the site's regulatory policy.
Clinical data logs may be retained for 7 years where required by customer agreements and applicable clinical-record obligations.
Account data is retained while the account is active and for a short window after deactivation to support recovery, legal hold, and audit. Marketing suppression entries (unsubscribes, bounces) are retained indefinitely so we do not re-contact addresses that have opted out.
Security practices
Access is gated by authenticated sessions, role-based permissions enforced at the API gateway level, and database row-level security. Data is encrypted with TLS 1.3 in transit and AES-256 at rest. Secrets are stored in a managed secret store and never exposed to client code.
Manual override paths are logged in immutable audit trails, and clinical data logs may be retained for the period described above. See Security for detail.
Your rights
You can ask for a copy of, correction of, or deletion of personal data we hold about you as a user of the product. For operational study records held on behalf of a site, please contact your site administrator — we act on the site's instructions for those records.
Contact
TrialBridge, Inc
525 3rd St Ste 200, Lake Oswego, OR 97034, United States
privacy@trialbridge.co