Privacy Policy

Last Updated: May 29, 2026  |  Effective Date: June 2, 2026  |  Version 2026.05.29

1. Introduction

PharmaIntel Intelligence Unit ("PharmaIntel," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, share, and protect your personal data when you use the PharmaIntel platform, website, APIs, and related services (the "Service").

This policy applies to all users worldwide and addresses the requirements of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the CAN-SPAM Act, and other applicable privacy laws. For region-specific rights, see Sections 10 and 11.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: First and last name, email address (work or personal), password (hashed and salted), and optional law firm or organization name.
  • Billing Information: Payment card details (processed and stored exclusively by Stripe, Inc.; PharmaIntel does not have access to your full card number), billing address, and subscription history.
  • User-Generated Content: Saved items, watchlist entries, personal notes on dossiers, and search queries entered through the Service.
  • Communications: Emails, support requests, feedback, and any other information you voluntarily provide when contacting us.
  • Consent Records: Timestamps and metadata recording your acceptance of our Terms of Service, Privacy Policy, and marketing communications preferences.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, search queries, reading history, click patterns, time spent on pages, and interaction with dossiers, news articles, court opinions, and PharmaVector reports.
  • Device Information: Browser type and version, operating system, screen resolution, language preference, and device identifiers.
  • Log Data: IP address, access timestamps, referring URLs, and server request logs.
  • Cookies & Similar Technologies: Essential session cookies, authentication tokens, and optional analytics cookies (see Section 7).

2.3 Information from Third Parties

  • Payment Processor: Stripe provides us with subscription status, billing events, and transaction confirmations (but not your full card number).
  • Public Records: Court filings, regulatory actions, and government databases used to populate dossiers and intelligence reports.

3. How We Use Your Information

We use collected information for the following purposes:

PurposeLegal Basis (GDPR)
Provide and maintain the ServiceContract performance
Process subscriptions and billingContract performance
Send transactional communicationsContract performance
Personalize your experience (saved items, history)Legitimate interest / Consent
Send marketing & intelligence digestsConsent (opt-in)
Send periodic dossier updates and alertsConsent (opt-in)
Improve and develop new featuresLegitimate interest
Prevent fraud, abuse, and security threatsLegitimate interest / Legal obligation
Comply with legal obligations (tax, regulatory)Legal obligation
Aggregate analytics and industry reportsLegitimate interest (de-identified data)

4. Email Communications & Periodic Dossiers

4.1 Types of Emails. We send the following categories of email communications:

  • Transactional (required): Account confirmations, password resets, billing receipts, security alerts, and Terms/Privacy Policy change notifications. These cannot be opted out of as they are necessary for the provision of the Service.
  • Intelligence Digests (opt-in): Morning briefings, weekly roundups, and breaking regulatory alerts containing curated litigation intelligence.
  • Periodic Dossiers (opt-in): Standalone intelligence reports on emerging product liability matters, settlement trend analyses, and MDL filing updates, delivered on a periodic basis.
  • Product Updates (opt-in): Announcements about new features, improvements, and promotional offers.

4.2 Your Choices. You can manage your email preferences at any time from your account settings or by clicking the "unsubscribe" link in any marketing email. All commercial emails comply with the CAN-SPAM Act (15 U.S.C. 7701 et seq.) and include: our physical mailing address, a clear identification as a commercial message (where applicable), a functioning unsubscribe mechanism, and accurate sender information.

5. How We Share Your Information

We do not sell your personal data. We share information only in the following circumstances:

  • Payment Processing: Stripe, Inc. processes payment information under their own privacy policy.
  • Service Providers: We use carefully vetted service providers for email delivery, cloud hosting, and analytics. These providers are contractually required to protect your data and may only process it on our behalf.
  • Legal Requirements: We may disclose information when required by law, court order, subpoena, or government investigation. We will attempt to notify you of such requests unless prohibited by law.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will provide notice before personal data is transferred and becomes subject to a different privacy policy.
  • Aggregated Data: We may share aggregated, de-identified data that does not identify individual users for research and industry analysis purposes.

We will NEVER share your PharmaVector search queries, saved items, personal notes, or reading history with opposing counsel, adverse parties, or any third party for litigation advantage purposes.

6. Data Security

We implement industry-standard security measures to protect your personal data, including: (a) 256-bit TLS/SSL encryption for all data in transit; (b) AES-256 encryption for sensitive data at rest; (c) password hashing with PBKDF2-HMAC-SHA256 using unique per-user salts; (d) regular security audits and vulnerability assessments; (e) role-based access controls for internal systems; and (f) incident response procedures for data breaches. While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

7. Cookies & Tracking Technologies

7.1 Essential Cookies: Required for authentication, session management, and security. These cannot be disabled without losing access to the Service.

7.2 Analytics Cookies: We use first-party analytics to understand usage patterns and improve the Service. No third-party advertising trackers are used.

7.3 Your Choices: You can configure your browser to reject cookies, though this may affect the functionality of the Service. We honor Do Not Track (DNT) browser signals.

8. Data Retention

  • Account Data: Retained for the duration of your account and deleted within 30 days of a verified deletion request.
  • Billing Records: Retained for seven (7) years as required by applicable tax law and accounting standards.
  • Usage Logs: Retained for up to twelve (12) months, then aggregated and de-identified.
  • Consent Records: Retained for the duration of the applicable consent period plus three (3) years, as required for compliance documentation.
  • Communication Records: Support correspondence retained for up to three (3) years after the last interaction.

9. Children's Privacy

The Service is intended for legal professionals and is not directed at children under the age of 16 (or 13 under COPPA). We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will promptly delete it.

10. Your Rights Under GDPR (EEA, UK, Switzerland)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights:

  • Right of Access (Art. 15): Obtain confirmation of whether we process your personal data and request a copy.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to Restriction (Art. 18): Request limitation of processing in certain circumstances.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller. You may exercise this right via the "Download My Data" feature in your account settings.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent (Art. 7): Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority.

Data Controller: PharmaIntel Intelligence Unit, PO Box 111, Webster, FL 33597. Contact our Data Protection Officer at admin@pharmaintelai.com.

International Transfers: Your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and other appropriate safeguards for such transfers.

11. Your Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Right to Know (1798.100): Request disclosure of the categories and specific pieces of personal information we have collected, the sources, purposes, and categories of third parties with whom we share it.
  • Right to Delete (1798.105): Request deletion of your personal information, subject to legal exceptions.
  • Right to Correct (1798.106): Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing (1798.120): We do not sell or share (as defined by CCPA/CPRA) your personal information. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link.
  • Right to Non-Discrimination (1798.125): We will not discriminate against you for exercising your CCPA rights.
  • Right to Limit Use of Sensitive Personal Information (1798.121): We only use sensitive information for purposes permitted by the CPRA.

Verification. To exercise your rights, submit a request to admin@pharmaintelai.com from the email address associated with your account, or use the in-app data export feature. We will verify your identity before processing requests.

Authorized Agents. You may designate an authorized agent to submit requests on your behalf with proper written authorization.

Metrics. We will publish annual metrics regarding the number and type of CCPA requests received and processed, as required by regulation.

12. Data Export & Portability

In compliance with GDPR Article 20 and CCPA Section 1798.100, you may download a complete copy of all personal data we hold about you at any time. Your data export includes:

  • Personal information (name, email, firm name)
  • Account details (registration date, subscription status)
  • Consent history (timestamps of all agreements)
  • Email communication preferences
  • Saved items and bookmarks
  • Watchlist entries
  • Reading history
  • Search history
  • Personal notes on dossiers and articles
  • User preferences and settings

The export is provided in JSON format, a structured, commonly used, and machine-readable format. You may access this feature from your .

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will: (a) update the "Last Updated" date; (b) send email notification to your registered email address at least thirty (30) days before the changes take effect; and (c) post a prominent notice on the Service. We encourage you to review this policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

14. Contact Us

For privacy-related inquiries, data subject requests, or complaints:

PharmaIntel Intelligence Unit

Data Protection Officer

PO Box 111

Webster, FL 33597

Email: admin@pharmaintelai.com

We aim to respond to all privacy-related requests within thirty (30) days. For GDPR requests, we may extend this period by two additional months for complex requests, with notification to you.