Legal
Privacy Policy
Effective August 22, 2026 · Last updated August 22, 2026
In short
- This site sets no cookies and runs no analytics, advertising, or session-recording trackers.
- The only personal information we ask for is what you type into the demo request form. It is emailed to our team — the site has no visitor database.
- We do not sell personal information and do not share it for cross-context behavioral advertising.
- Please do not send patient, subject, or study data through this website. See section 3.
This summary is for orientation only. The sections below are the policy.
1. Scope
This policy explains how CTipAI ("CTipAI", "we", "us", "our") handles personal information collected through our public website at www.ctipai.com and ctipai.com (the "Site"), including the demo request form.
It does not cover the CTipAI product itself. If you use the CTIP application (for example at ctip.app) as a customer or an authorized user of a customer, the handling of data in that application is governed by the agreement between CTipAI and that customer — typically a subscription agreement and a data processing agreement — and not by this policy. Where CTipAI processes clinical or study data on behalf of a customer, the customer is the controller of that data and CTipAI acts on the customer's documented instructions.
For personal information collected through the Site, CTipAI is the controller (EEA/UK terminology) and the business (US state-law terminology).
2. Information we collect
2.1 Information you give us
The Site's demo request form asks for your name and work email address (both required), and optionally your organization, your primary interest, and a message. When you submit the form, the contents are delivered to CTipAI as an email. The Site is a static website: it does not store your submission in a website database.
If you email us directly — for example at support@ctipai.com — we receive your email address, your message, and anything you choose to include in it.
2.2 Information collected automatically
Like any website, the Site is served by infrastructure that processes technical request data in order to deliver pages and to keep the service available and secure. This includes your IP address, browser and device type (user agent), the page or asset requested, the referring page, and the date and time of the request. This data is processed by our hosting and content delivery provider (Cloudflare) for delivery, error diagnosis, rate limiting, and protection against abuse and denial-of-service attacks.
2.3 Cookies and similar technologies
The Site sets no cookies of its own, and we do not use analytics, advertising, retargeting, social media, or session-recording tools.
The Site stores a single value in your browser's localStorage under the key ctip-theme, which records whether you chose the light, dark, or system color theme. It is a preference, not an identifier, it is never transmitted to us, and clearing your browser storage removes it.
Our infrastructure provider may set strictly necessary cookies for security and abuse prevention. If we ever add analytics or any non-essential technology, we will update this policy and, where the law requires consent, ask for it first.
2.4 What we do not collect
We do not knowingly collect special category or sensitive personal information through the Site — no health data about you, no government identifiers, no precise geolocation, no biometric data, no payment card data. We do not build advertising profiles and we do not buy personal information about visitors from data brokers.
3. Please do not send clinical data through this website
The demo request form and our general inbox are ordinary business contact channels. They are not an approved route for regulated clinical information.
Do not include patient or subject data, protected health information, identifiable subject listings, raw or derived clinical datasets, unblinding information, or confidential protocol documents in a form submission or an unsolicited email. If you need to share study material with us, contact us first and we will agree an appropriate channel and the necessary confidentiality and data protection terms.
If you send such information anyway, we will delete it as soon as we reasonably can and will not use it for any purpose other than managing its deletion.
4. How we use information
We use the information described above only to:
- respond to your demo, early access, or general inquiry, and continue that conversation;
- evaluate and administer participation in early access and design partner programs;
- send you information about CTipAI that is relevant to what you asked about, where this is permitted or where you have consented;
- operate, maintain, secure, and improve the Site;
- detect and prevent spam, fraud, and abuse — the form includes a hidden anti-spam field that legitimate browsers leave empty;
- comply with our legal obligations and establish, exercise, or defend legal claims.
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use it to train machine learning models.
5. Legal bases for processing (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
- Steps taken at your request prior to entering into a contract (Art. 6(1)(b)) — handling your demo or early access request.
- Legitimate interests (Art. 6(1)(f)) — running and securing the Site, preventing abuse, keeping records of business correspondence, and business-to-business communication with professional contacts who have shown interest in our product. We balance these interests against your rights and expectations, and you may object at any time (see section 9).
- Consent (Art. 6(1)(a)) — where consent is required for marketing communications. You can withdraw it at any time, without affecting processing carried out before withdrawal.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information to comply with the law.
7. How long we keep it
- Demo requests and correspondence — kept while we are in contact with you and for up to 24 months after our last meaningful interaction, unless you ask us to delete them sooner or we have a legal reason to keep them longer.
- Marketing contact records — kept until you opt out or withdraw consent, after which we keep the minimum record needed to honor that choice.
- Infrastructure and security logs — kept for the short retention periods set by our hosting provider, generally measured in days to a small number of months.
When a retention period ends, we delete the information or aggregate it so that it no longer identifies you.
8. International transfers
CTipAI operates from the United States, and our service providers may process information in the United States and other countries. If you are in the EEA, the UK, or Switzerland, this means your information may be transferred outside your home jurisdiction to a country whose data protection laws differ from your own.
Where we make such a transfer, we rely on an appropriate safeguard under Chapter V of the GDPR — in most cases the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and supplementary measures where needed. You may request further information about the safeguards we use by contacting us.
9. Your rights (EEA, UK, Switzerland)
Subject to the conditions and exemptions in the law, you have the right to:
- request access to the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing, including any processing based on legitimate interests and any direct marketing;
- receive your data in a portable format and have it transmitted to another controller, where the processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these, contact us using the details in section 16. We respond within one month, and may extend that by two further months for complex requests, telling you why.
You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.
10. Your rights (California and other US states)
Depending on where you live — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws — you may have the right to:
- know what personal information we have collected about you, the categories of sources, the business purposes, and the categories of third parties to whom we disclose it;
- access a copy of that information;
- correct inaccurate personal information;
- delete personal information we collected from you;
- opt out of the sale or sharing of personal information and of targeted advertising — we do none of these, so there is nothing to opt out of;
- limit the use of sensitive personal information — we do not collect sensitive personal information through the Site;
- be free from discrimination for exercising your rights. We offer no financial incentives in exchange for personal information.
To make a request, use the details in section 16. We will verify your request by asking you to confirm information we already hold, such as the email address used to contact us; we ask for no more than we need to verify you. An authorized agent may submit a request on your behalf with written proof of authorization, and we may still contact you to confirm it. We will not charge a fee for a reasonable request.
Do Not Track and Global Privacy Control. The Site does not track visitors across sites, so there is no cross-site tracking for a Do Not Track or Global Privacy Control signal to stop. We honor such signals in the sense that we neither sell nor share personal information for advertising in the first place.
California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing purposes.
11. Categories of personal information
In the twelve months before the date of this policy, we have collected the following categories of personal information through the Site. Each category is disclosed only to the service providers listed in section 6, and none of it is sold or shared for advertising.
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, work email address, IP address | You, through the demo request form; automatically from your browser | Answering your request, delivering and securing the site |
| Professional or employment information | Organization, role, primary interest, anything you write in the message field | You, through the demo request form | Understanding what you are asking about and replying usefully |
| Internet or network activity | Pages requested, referring page, browser and device type, request timestamps | Automatically, in hosting and CDN logs | Serving the site, diagnosing errors, preventing abuse |
| Electronic correspondence | Emails you send us and our replies | You | Responding to you and keeping a record of the conversation |
We collect no other statutory categories through the Site — in particular no biometric information, no precise geolocation, no financial account information, and no sensitive personal information.
12. Security
The Site is served over HTTPS. Form submissions are transmitted over an encrypted connection and delivered to a limited number of CTipAI staff. Credentials for our email delivery provider are held as encrypted secrets and are never exposed to your browser. Access to inquiry records is limited to people who need it to do their job.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. This is one of the reasons for the request in section 3.
13. Children
The Site is a business-to-business website intended for clinical development professionals. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
14. Other sites and services
The Site links to other locations, including the CTIP application sign-in page and occasional third-party references. Those destinations have their own privacy practices, and this policy does not apply to them. We encourage you to read the notices of any site you visit.
15. Changes to this policy
We may update this policy as the Site, our services, or the law changes. When we do, we will revise the "last updated" date at the top of this page. If a change materially affects how we handle information you have already given us, we will take reasonable steps to tell you directly — for example by email — and, where required, ask for your consent.
16. How to contact us
For any privacy question, or to exercise any right described above, email support@ctipai.com with "Privacy" in the subject line. Tell us what you are asking for and the email address you used to contact us, so we can locate your records.
We aim to acknowledge privacy requests within 10 business days and to resolve them within the periods described in sections 9 and 10.
This policy describes our practices. It is not legal advice, and it does not create rights beyond those the applicable law gives you.
