Privacy Statement
(Last updated on 28 August, 2025)
1. Introduction
Harvest Integrated Research Organization (“HiRO”), is committed to maintaining your trust by protecting your personal data. Personal data is any information relating to an identified or identifiable natural person. Your name, address, phone number, or any other detail(s) that is specific to you are examples of personal data. As a global organization, HiRO operates through legal entities across multiple jurisdictions. We ensure all processing activities strictly adhere to applicable data protection laws and regulations. Where local laws impose stricter requirements for Personal Data protection, such provisions will take precedence. Any personal data you provide when interacting with HiRO will only be used in accordance with this privacy statement (“Privacy Statement”).
Privacy Statement applies to all personal data gathered for and on behalf of HiRO through the various means/methods such as link or references/attachments (such as websites or applications operated by or/ and e-mail messages) together with any and all offline activities including but not limited to sales and marketing activities. Please review this Privacy Statement to learn more about how we collect, use, share, protect and store the personal data that we have obtained.
2. Types of Personal Data We Process and Purposes
HiRO processes your personal data to ensure the efficiency and effectivity of our services and products. When you contact HiRO to request or to access information, you may be asked to provide your personal data. By providing your personal data to HiRO, you agree to the below terms of this Privacy Statement as follows:
2.1 If you register to HiRO websites (including www.harvestiro.com) and provide information about your preferences we will use such information to personalize your user experience. HiRO websites may also collect information about your computer hardware and software. This information may include your IP address, browser type, operating system, domain name, access times and referring website addresses. This information is used for the operation of the service, to maintain and monitor the quality of the service and to provide general statistics regarding the use of websites.
2.2 HiRO’s Websites use cookies. Please refer to Cookies Policy.
2.3 If you send us a resume or curriculum vitae (CV) to apply for a position with HiRO, we will use the information that you provide to match you with available HiRO job opportunities.
2.4 If you would like to register to receive customized information. This information is generally collected on “Contact Us” forms where you may choose to be contacted by HiRO. The personal data collected usually includes your name, contact details and email address.
2.5 If you are clinical trial investigators, study researchers, data safety monitoring board members, and other healthcare professionals (HCPs) having an interest to participate in a clinical trial, we will collect names, contact details, and professional information for the purpose of identifying and assessing suitability to assist in clinical trials and to provide services and may share this information with our clients.
2.6 HiRO only processes pseudonymized medical and health information about the individuals who take part in clinical trials. This information is collected by investigators and their staff at the study sites. HiRO may transmit this data abroad as documented in informed consent. The investigators overseeing the trial are responsible for ensuring that the individuals understand and consent to the gathering of sensitive personal data relating to your health, including the transfer of such pseudonymized information to third parties who may be providing services for the clinical trial.
In relation to HiRO’s delivery of services to Sponsors, the Sponsor is in control of how and why your personal data is processed and as such is the “controller,” HiRO is a “data processor”. HiRO’s role as processor may include the transfer of such personal data to the applicable Sponsor and/or its affiliates, business partners and third-party vendors performing services related to the clinical trial.
2.7 HiRO usually does not request or collect “sensitive” personal data. However, HiRO may collect “sensitive” personal data only when you voluntarily provide us with such data or where such data are required or permitted to be collected by applicable law or professional standards. Sensitive personal data include personal information regarding a person’s race, ethnicity, political beliefs, trade union membership, religious or similar beliefs, physical or mental health, criminal record, biometric identification, medical health, financial account and whereabouts and tracks. Please use your discretion when providing sensitive personal data to HiRO. Under any circumstances, you should not provide yours or any third parties’ sensitive personal data to HiRO unless we shall separately notify you (and these third parties) and you (and these third parties) have given us your (and these third parties’) explicit consent for HiRO to use or process your (and these third parties’) sensitive personal data for legitimate and necessary business purposes and you (and these third parties) have also consented for us to the transfer and store such sensitive personal data in HiRO databases.
3. Lawfulness of Processing
Processing will always be based on legitimate grounds.
3.1 Consent. In cases where we need your consent to process your personal data, we will ask you to make a positive indication (for example, to tick a box, sign a document, provide written confirmation) that you agree to the processing. By providing consent, you are stating that you have been informed of the nature, purpose, scope and duration of our processing. Where we may rely on consent to process your information, you have the right to withdraw that consent for that activity at any time. You can always revoke your consent by sending an email to dataprotection@harvestiro.com.
3.2 Performance of A Contract. In such cases, we process your personal data because it is necessary to deliver a service you have requested, you are employed by us, you provide a service to us, or you will conduct a clinical trial or other medical research project.
3.3 Legitimate Interest. HiRO may process your personal data on the basis of its legitimate interests in using your personal data for the purposes described herein. Examples of our legitimate interests include the following:
- Processing in relation to employment opportunities with HiRO;
- Processing in relation to investigator opportunities with HiRO;
- To improve our services;
- To protect the security of HiRO websites;
- To protect HiRO property or rights or obligations and/or the property, rights or obligations of third parties;
- To take precautions against potential liability on the part of HiRO;
- To analyse therapeutic trends and gather anonymized geographic statistics; and
- To correct technical errors and to technically process your personal data.
You can object to us using your personal data in these legitimate ways at any time as described under Section 9 “Data Subject Rights” below.
3.4 Legal Obligation. We may need to use your personal data to comply with legal obligations, applicable laws and regulations and judicial process. For example, we are required by applicable law to keep certain records for specific periods of time. The laws vary in countries or regions, and we are bound to adhere to the local laws around the processing of personal data.
4. Profiling
We will not use your personal data for decisions based solely on automated processing if the decision produces legal effects concerning you or significantly affects you, unless otherwise you gave your explicit consent for this processing.
We may use profiling procedures to optimize and personalize our customer relationship management and our advertising measures. To do so, we create customer profiles and assign customers to specific customer groups based on these customer profiles. On the basis of this segmentation, we can manage the type, content and frequency of specific advertising measures for specific target groups. For profiling purposes and based on our legitimate interest, we use personal data that we receive from you as part of our business relationship. This includes personal data, like your browsing behavior. Profiling may also be related to usage data that we create by measuring and evaluating the customer’s interaction with electronic advertising, and in particular by measuring and evaluating the opening and click rate in email newsletters.
5. Data Sharing with Third Parties
We may disclose your personal data to clients, agents and third parties working with or on behalf of HiRO. In addition, your personal data may be transferred in the event of any reorganization, restructuring, merger or transfer of all or any portion of our business or assets, where privacy and confidentiality are maintained. Any shared data will only be used for its intended purpose.
We will not sell, distribute or lease your personal data to third parties unless we have your permission or are required by law to do so.
We may disclose your personal data without your permission to the extent that it is required to do so by European Union or local applicable laws, in connection with any legal proceedings or prospective legal proceedings, and in order to establish, exercise or defend your legal rights, which include:
- If we are restructured or sold to another organization: HiRO may also disclose personal data in connection with the sale, assignment, or other transfer of the business;
- Courts, tribunals, law enforcement or regulatory bodies: HiRO may, to the extent permitted by the local laws or subject to the fulfilment of the regulatory requirements of the applicable laws, disclose personal data in order to respond to requests of courts, tribunals, government or law enforcement agencies or where it is necessary or prudent to comply with applicable laws, court or tribunal orders or rules, or government regulations.
- Audits: disclosures of personal data may also be needed for data privacy or security audits and/or to investigate or respond to a complaint or security breach.
6. Security
We are committed to ensuring that your personal data is secure. In order to prevent unauthorized access or disclosure, we have put in place appropriate physical, technical and organizational measures to safeguard and secure the personal data we process. Despite HiRO’s best efforts, however, security cannot be absolutely guaranteed against all threats. To the best of our ability, access to your personal data is limited to those who have a need to know. Those individuals who have access to the data are required to maintain the confidentiality of such information. If, despite all our efforts, a data breach does occur, we shall do everything in our power to limit the damage. In case of a data breach that likely will result in a risk to your rights and freedoms, and depending on the circumstances, we will inform you about remedial actions to prevent any further damage. We always inform the relevant supervisory authority or authorities without undue delay.
7. Worldwide Transfer of Your Personal Data
Your personal data may be transferred to, stored, and processed in a country other than the one in which it was provided (i.e., a ‘Recipient’ country). When HiRO does so, it transfers the personal data in compliance with applicable data protection laws. HiRO will follow the applicable laws to use such lawful mechanisms for the transfer as are approved by the applicable data protection authority of your jurisdiction prior to transferring any of your personal data (e.g., the Standard Contractual Clauses for transfers from the European Economic Area (EEA), the United Kingdom’s International Data Transfer Agreement, Switzerland’s Transborder Data Flow Agreement as applicable, to name a few).
8. Data Retention
HiRO retains personal data for as long as is necessary in accordance with its business, contractual, legal and regulatory requirements. We will not store your personal data longer than necessary for the purpose for which we have processed your data. Records of payments made and received will, likewise, have a statutory period in the country/region where we must store it for any inspection from the authorities or regulators.
9. Data Subject Rights
You have rights in respect of your personal data. HiRO’s policy is to extend the rights listed below to all our data subjects worldwide, unless the local law states otherwise.
- The right to be informed – if we are processing your personal data, we must inform you of the who, why, what of the processing including who else may view the personal data or use it, how long we will retain it for, and if we are transferring the data to another country or region.
- The right of access to your personal data – you can request a copy of the personal data we hold about you.
- The right to corrections or updates – you have the right to request that we make corrections or updates to your personal data we hold about you to make such data accurate and complete.
- The right to erase your personal data – You have the right to request the deletion of your personal data in certain circumstances including, for example, where the personal data are no longer needed for the purpose for which they were collected, it is impossible to achieve such purpose, or it is no longer necessary to achieve such purpose, or you withdraw your consent, however, the withdrawal of your consent will not invalidate any processing we carried out prior to the withdrawal of your consent. This right does not apply where, for example, processing is necessary to comply with a legal obligation, or for the establishment, exercise, or defense of legal claims.
- The right to restrict the processing of your personal data – You have the right to ask us to restrict certain processing activities in some circumstances, including, for example, where the accuracy of the data in question is contested. Where processing has been restricted, we can only process it for limited purposes such as, for example, the establishment, exercise or defense of legal claims.
- The right of data portability – You have the right to have your data returned to you or to a third party in certain cases.
- The right to object – You have a right to object to the processing of your personal data in certain cases. In such a case we will stop processing your personal data unless we can demonstrate compelling legitimate grounds which override your interest.
- The right in relation to automated decision making and profiling – You have the right to not be the subject of automated decision-making where the decision has a significant effect on you and can insist on human intervention where appropriate.
To exercise any of the above rights, please notify us at the address provided in Section 12 “Further Information”. Please note, if you are a participant at a trial site and wish to exercise any of the above rights, please contact your trial site directly. We may request proof of identification to verify your identity. Where HiRO is the data controller, we will assess your request and, subject to applicable laws and exceptions, respond within the relevant legal time limits.
10. Links to Other Websites
Please be aware that HiRO websites may contain links to other websites, that are not governed by this Privacy Statement but by other privacy policies that may differ somewhat. We encourage you to review the Privacy Statement of each website visited before disclosing any personal data.
11. Changes to Privacy Statement
HiRO may modify this Privacy Statement from time to time to reflect our current privacy practices. When we make changes to this Privacy Statement, we will revise the “last updated” date at the top of this page. We encourage you to periodically review this Privacy Statement to be informed about how HiRO is protecting your personal data.
12. Further Information
If you have any questions about this Privacy Statement or questions or complaints about the processing of your personal data by HiRO, please contact:
Data Protection Officer (DPO)
Email: dataprotection@harvestiro.com