How Coordinare collects, stores, and protects your clinical research site data.
Effective Date: April 8, 2026Coordinare ("we," "our," or "us") is a clinical research site operations platform operated by DSCS (Data-Driven Site & Contract Services). This policy applies to all services at coordinare.co and coordinare.polsia.app.
When you register or use our email-gated tools, we collect:
When you use the Feasibility Autopilot or Site Profile tools, we may collect:
We use your data to provide, maintain, and improve our services. This includes:
To support the continued development of clinical research tools, Coordinare may "sell" or "share" certain data (as defined by the CCPA/CPRA and GDPR) to third-party partners, including CROs, Sponsors, and research analytics firms.
Data is isolated by domain (e.g., @westlakeoncology.com). Users sharing the same non-generic email domain are grouped into the same workspace and can see shared data (study lists, tasks, contacts). Users with generic email domains (Gmail, Yahoo, Hotmail, Outlook, iCloud) remain in individual personal workspaces.
We may use aggregate, non-identifying patterns (e.g., "Average enrollment for Phase II Oncology") to train models, but this data is stripped of all site-identifying markers.
Coordinare administrators (DSCS team members) can access aggregated platform data for operational purposes. Admin access is protected by a secret key and rate-limited to prevent unauthorized access. Admin activities are logged. Administrators access the minimum data necessary to operate the platform.
All data is stored in a PostgreSQL database hosted on Neon (a managed cloud database provider). Connections to the database use TLS encryption. The database is not publicly accessible.
User passwords are hashed using the scrypt algorithm with a random salt before storage. Plaintext passwords are never stored or logged.
Bookmark credentials (sponsor portal passwords, EDC login passwords) stored in the Study Organizer are encrypted at rest using AES-256 encryption before being written to the database. The encryption key is stored separately from the database.
Files uploaded to the Project Board are stored via Polsia's R2 cloud storage (Cloudflare R2-compatible). File access requires authentication — direct file URLs are served only to authenticated users who belong to the same workspace as the task they were attached to.
All connections between your browser and Coordinare servers use HTTPS (TLS 1.2+). Data is encrypted in transit.
We share data with the following categories of providers:
We do not use advertising networks, remarketing pixels, or social media tracking on any authenticated pages.
The Chat AI assistant answers questions about clinical research using Dan Sfera's video library and clinical research knowledge base. Chat messages are stored associated with your account. Chat sessions are scoped to your individual user account — your conversation history is not visible to other users.
When you use the Feasibility Autopilot, your site profile data is retrieved from our database and used to generate responses. This data is only sent to OpenAI as part of your specific request and is not used to populate responses for other sites. AI-generated responses are not guaranteed to be accurate and should be reviewed before submission.
Budget AI insights are generated based on phase, therapeutic area, and visit/subject counts you provide. Budget-specific insights may be cached to improve response times — cached results are based on aggregated parameters only, not site-specific data.
All AI-generated content is provided for informational purposes only. AI responses may not be accurate, complete, or appropriate for your specific situation. Always review AI output before use. Coordinare and DSCS are not liable for decisions made based on AI-generated content.
| Data Type | Retention Period |
|---|---|
| Account and site profile data | Retained indefinitely |
| Study Organizer data (studies, bookmarks, contacts) | Retained indefinitely |
| Project Board tasks and attachments | Retained indefinitely |
| Chat messages | Retained indefinitely |
| Analytics events | Retained indefinitely |
| Session tokens | Automatically expire (30-min idle / 8-hour absolute) but are not manually deleted |
| Password reset tokens | Single-use; expire after 1 hour but are not manually deleted |
| GCP training records and certificates | Retained indefinitely |
If you wish to request removal of your data, contact us at admin@dscssweatequity.com. Coordinare does not automatically delete any user data.
Under GDPR and CCPA, you have specific rights:
To exercise your right to opt-out of data sales, please email admin@dscssweatequity.com with the subject line "Do Not Sell My Personal Information."
We will respond within 30 days.
In the event of a data breach that may affect your personal information, we will:
To report a suspected security vulnerability or incident, contact us immediately at admin@dscssweatequity.com.
Questions about this privacy policy or our data practices? We're here to help.
Coordinare / DSCS
Privacy inquiries: admin@dscssweatequity.com
Security reports: admin@dscssweatequity.com
General: admin@dscssweatequity.com
We aim to respond to all privacy-related inquiries within 5 business days.
This policy may be updated from time to time. Material changes will be communicated by email to registered users. Continued use of Coordinare after an update constitutes acceptance of the revised policy. The "Effective Date" at the top of this page reflects the most recent revision.