Privacy Policy
This policy explains how CDMP by NoyMed collects, uses, discloses, and safeguards personal information in connection with the cdmp.noymed.com website and our clinical and preclinical data management services.
Effective date: 1 September 2026 · Last updated: 1 September 2026
CDMP by NoyMed (“CDMP,” “we,” “us,” or “our”) is the clinical and preclinical data management practice of NoyMed and a strategic spin-off of Streamlined Lean Solutions. We respect your privacy and are committed to protecting personal information in line with the EU General Data Protection Regulation (GDPR), the Netherlands Uitvoeringswet AVG, the U.S. Health Insurance Portability and Accountability Act (HIPAA) where applicable, and other laws that apply to our activities.
Where we provide services under a Master Services Agreement, Data Processing Agreement (DPA), Business Associate Agreement (BAA), or clinical trial agreement, the terms of that contract govern our handling of study data and prevail over this policy to the extent of any conflict.
1. Who we are and how to contact us
For personal information processed through this website and our commercial and marketing activities, the data controller is CDMP by NoyMed, operating through NoyMed’s headquarters in Amsterdam, the Netherlands. Contracting for services is executed via our Netherlands headquarters for full EU and U.S. legal alignment; service delivery is performed from our EU / Armenia hub.
Privacy questions, requests, and complaints: privacy@noymed.com. General enquiries: cdmp@noymed.com. You may also write to us at NoyMed, Attn: Privacy, Amsterdam, the Netherlands.
2. Scope — two categories of data
This policy distinguishes between:
- Website & business-contact data — information about visitors, prospective clients, partners, and vendor contacts, collected when you use this site, request a proposal, or communicate with us. CDMP is the controller of this data.
- Client & study data — personal data contained in clinical or preclinical datasets, electronic data capture (EDC) systems, laboratory records, safety data, and related deliverables that we process on behalf of sponsors, CROs, and research institutions. For this data CDMP acts as a processor (and, under HIPAA, a business associate) under written agreements with our clients, who remain the controller / covered entity. Section 9 addresses this data.
3. Personal information we collect
3.1 Information you provide
- Proposal & contact requests: your name, work email address, organisation, and the study details you choose to share (study type, phase or stage, preferred platform / EDC environment, site or laboratory and subject scope, target timeline, and any free-text message).
- Correspondence: the content of emails, calls, and meetings, and records of your requests and our responses.
- Contracting & onboarding: business-contact details, signatory information, and information needed for due-diligence, invoicing, and compliance checks.
The proposal form on this site opens your own email client with the details pre-filled; the request reaches us as an email you send. If we later add a server-side form, this policy will be updated to describe it.
3.2 Information collected automatically
- Server and security logs: IP address, date and time, pages requested, referring URL, and user-agent string, retained for security, diagnostics, and abuse prevention.
- Device and usage data: approximate location (derived from IP), browser and operating system, and interactions with the site.
- Cookies and similar technologies: see Section 5.
3.3 Information from other sources
We may receive business-contact information from our clients and partners (for example, when you are named as a project contact), from public professional sources such as company websites and LinkedIn, and from service providers that support event, marketing, and compliance activities.
We do not seek to collect special-category data or children’s data through this website.
4. How we use personal information and our legal bases
| Purpose | GDPR legal basis |
|---|---|
| Responding to proposal and contact requests; preparing quotes and statements of work | Steps taken at your request prior to entering a contract; our legitimate interest in responding to enquiries |
| Providing, administering, and improving our services; account and project management | Performance of a contract; legitimate interests |
| Operating, securing, and maintaining the website; preventing fraud and abuse | Legitimate interests in a secure, functioning site |
| Sending service updates and, where permitted, business-to-business marketing about related services | Legitimate interests; consent where required by local law (you can opt out at any time) |
| Non-essential analytics or marketing cookies (if enabled in future) | Consent |
| Meeting legal, tax, accounting, and regulatory obligations; responding to lawful requests; establishing or defending legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You may object to that processing as described in Section 8.
5. Cookies and similar technologies
This website is built to run without tracking. We use only cookies and local storage that are strictly necessary for the site to function and to remember lightweight preferences (for example, dismissing a notice). These do not require consent.
If we introduce analytics or marketing technologies that are not strictly necessary, we will request your consent through a cookie banner before they are set, and you will be able to change your choice at any time. You can also block or delete cookies in your browser settings; some features may then not work as intended.
6. How we share personal information
We share personal information only as described here:
- Service providers and sub-processors: hosting and infrastructure (including our website host), email, document management, EDC and biometrics platform vendors, and professional tools — each bound by contract to process data only on our instructions and to protect it.
- Within the NoyMed group and Streamlined Lean Solutions: affiliated entities that support contracting, delivery, and administration, under intra-group data protection terms.
- Clients and partners: where you are a project contact, your business-contact details may be shared with the relevant sponsor, CRO, site, or vendor to run the engagement.
- Professional advisers: lawyers, auditors, insurers, and accountants, where reasonably necessary.
- Authorities and regulators: where required by law, regulation, legal process, or a lawful government request, or to protect our rights, safety, and property.
- Corporate transactions: in connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to appropriate confidentiality protections.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
7. International data transfers
We operate across the Netherlands, other EU/EEA countries, Armenia, and the United States, and our service providers may process data in other countries. When we transfer personal data outside the EEA or the UK to a country without an adequacy decision, we put in place a lawful transfer mechanism — typically the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) — together with technical and organisational supplementary measures such as encryption and access controls. You can request information about these safeguards using the contact details in Section 1.
8. Your rights
Subject to applicable law, you have the right to access your personal data; to rectify inaccurate data; to erase data; to restrict or object to processing (including direct marketing and processing based on legitimate interests); to data portability; and to withdraw consent at any time without affecting processing carried out before withdrawal.
To exercise these rights, contact privacy@noymed.com. We may need to verify your identity. We respond within the timeframes required by law (generally one month under the GDPR, extendable for complex requests). There is normally no fee.
If you are in the EEA, you may lodge a complaint with your local supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to address your concerns first.
U.S. residents. Depending on your state, you may have rights to know, access, correct, delete, and obtain a portable copy of personal information, and to appeal a decision on your request. We do not sell personal information or process it for targeted advertising, so no opt-out of those activities is required. Submit requests to privacy@noymed.com; we will not discriminate against you for exercising your rights.
9. Clinical trial, preclinical, and other client data
When we build EDC or LIMS environments, clean data, perform medical coding, reconcile safety data, produce CDISC / SEND datasets, or run biostatistics for a client, we process personal data — which may include health data of clinical trial participants — as a processor on documented instructions from our client, who is the controller (and, under HIPAA, the covered entity or its business associate). Our processing is governed by the applicable DPA and/or BAA and by the study protocol, informed consent, and ethics approvals maintained by the client.
- We process such data only for the client’s documented purposes and do not use it for our own purposes.
- Study datasets are typically pseudonymised (identified by subject codes, not names) before they reach us.
- We maintain a 21 CFR Part 11, GCP, and GLP-validated environment with role-based access, audit trails, and controlled electronic signatures.
- We assist clients in responding to data-subject requests, regulatory enquiries, and personal-data-breach obligations, and we engage sub-processors only with the client’s authorisation.
- On completion of services we return or delete client data in accordance with the contract and applicable retention requirements.
If you are a clinical trial participant and have questions about your data or wish to exercise your rights, please contact the study team, sponsor, or site named in your informed consent form; they are responsible for that data and can involve us as needed.
10. Data retention
We keep website and business-contact data only as long as necessary for the purposes above: proposal and enquiry records for the duration of discussions and a reasonable period afterwards; contract and financial records for the periods required by tax and company law (generally up to seven years in the Netherlands); security logs for a short period; and marketing data until you opt out or we determine it is no longer needed. Client and study data are retained and destroyed according to the relevant contract, protocol, and regulatory retention rules.
11. How we protect information
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, network and endpoint security, least-privilege and role-based access controls, logging and audit trails, secure software development and change control, vendor due-diligence and contractual safeguards, staff confidentiality obligations and training, and incident-response procedures. No method of transmission or storage is completely secure, but we work to protect personal information and to notify affected people and regulators of a personal data breach where the law requires.
12. Third-party links
This site links to noymed.com and may reference third-party platforms (such as EDC vendors). Those sites have their own privacy practices, and this policy does not apply to them.
13. Children’s privacy
This website and our services are directed to organisations and professionals, not to children. We do not knowingly collect personal information from children through this site. Any processing of a minor’s health data in a clinical study is handled under the study protocol and consent arrangements maintained by the sponsor or site.
14. Changes to this policy
We may update this policy to reflect changes in our practices or the law. We will post the revised version here with a new “Last updated” date and, for material changes, provide a more prominent notice. Please review it periodically.
15. Contact us
Privacy office: privacy@noymed.com
General enquiries: cdmp@noymed.com
Post: NoyMed, Attn: Privacy, Amsterdam, the Netherlands
If you are not satisfied with our response, you may contact your local data protection supervisory authority as described in Section 8.