Skip Navigation

Frontier Clinical Trials – Privacy Notice


Version 1.2 – 18 June 2025



1) Who we are


• We are Frontier Clinical Trials Ltd, a UK company that runs and supports medical research sites. Our registered office is 32 Willoughby Road, London N8 0JG (company no. 15778656).



2) How to reach us


• E-mail: dpo@frontiertrials.com


• Post: Data Protection Officer, Frontier Clinical Trials, 32 Willoughby Road, London N8 0JG, United Kingdom



3) The information we collect and why


Administrative – Customer Support


• Purpose of processing: Responding to website and e-mail enquiries


• Personal data processed: Name, e-mail, phone


• Lawful basis: Consent – Art 6 (1)(a)


• Retention: Until deletion request



Recruitment – Participant matching


• Purpose of processing: Matching volunteers to clinical trials; sending pre-screening questions


• Personal data processed: Name, contact details, DOB, ethnicity, sex, medical condition of interest


• Lawful basis: Consent – Art 6 (1)(a)


• Retention: Until the person unsubscribes or 2 years after last contact



Sales – Marketing to clients


• Purpose of processing: E-mail marketing to GPs & industry reps


• Personal data processed: Work e-mail, name, job title


• Lawful basis: Consent – Art 6 (1)(a)


• Retention: Until deletion request



Clinical Trial Conduct


• Purpose of processing: Enrolment, safety monitoring, data analysis, payment


• Personal data processed: Full contact data, ID, health data, genetic data, payment info


• Lawful basis: Public task – Art 6 (1)(e) OR Contract – Art 6 (1)(b)


• Retention: Per protocol (usually 25 yrs)



HR & Recruitment (employees)


• Purpose of processing: Hiring, payroll, training, compliance


• Personal data processed: CV, contact, right-to-work, bank, health (OH)


• Lawful basis: Contract – Art 6 (1)(b); Legal obligation – Art 6 (1)(c)


• Retention: 6 yrs after employment



Finance & Supplier Mgmt.


• Purpose of processing: Paying suppliers, invoicing clients


• Personal data processed: Contact, bank details


• Lawful basis: Contract – Art 6 (1)(b)


• Retention: 7 yrs (tax law)



Website & Analytics


• Purpose of processing: Site security, performance, cookies


• Personal data processed: IP, device info, cookie IDs


• Lawful basis: Legitimate interests – Art 6 (1)(f)


• Retention: Varies by cookie (see Cookie Policy)



4) Who we share your data with


• Cloud e-mail and storage: Microsoft 365 (UK and USA)


• Email marketing: Mailchimp (USA)


• Study sponsors, contract research organisations (CROs) and regulators, when you are in a clinical trial


• Professional advisers (lawyers, auditors), banks and payment providers.


• HMRC and other authorities when the law requires it.


• All suppliers are bound by contract to keep your data safe. When they are outside the UK/EEA we use the UK International Data Transfer Agreement or EU Standard Contractual Clauses plus extra safeguards.



5) How long we keep your data


• Enquiry & marketing data – until you ask us to delete it.


• Volunteer matching – until you unsubscribe or two years after our last contact, whichever comes first.


• Clinical-trial data – as specified in the study information sheet, usually 25 years.


• Employee records – six years after you leave.


• Finance records – seven years (tax law).


After these periods the data are securely deleted or anonymised to a UK legal definition.



6) Your rights


You have the right to ask us to:


• give you a copy of your data;


• correct or complete it;


• delete it;


• restrict or object to our use of it;


• move it to another service (data portability);


• withdraw your consent.


To exercise any of these rights, e-mail our DPO using the contact details at the top of this notice.


NOTE: We are committed to upholding your rights, but in some instances your rights may not apply. For example, if we have a legal obligation to retain data, we will retain that data even if you request it to be erased. We will always tell you if there are limits to your rights and our lawful basis for them.


We will respond within one month to any request. If you are unhappy with our reply you can complain to the UK Information Commissioner’s Office: www.ico.org.uk | 0303 123 1113.



7) Keeping your data secure


• We use encryption in transit (TLS), access controls, multi-factor authentication, regular backups and staff training. Access is limited to people who need it for their job.


• Suppliers we work with are vetted, and copies of their compliance credentials are reviewed.


• We have the right to conduct audits on our processors, which we keep under review.


• Data is stored at locations with ISO 27001 and SOC II level security.



8) Children


• Our sites and services are aimed at adults aged 18 or over. We do not knowingly collect data from anyone under 13. Please contact us if you think a child has given us data.



9) Changes to this notice


• When we update this notice we will change the version number and date. The latest version is always available at https://frontiertrials.com/privacy_policy.