Table of Contents

  1. Overview & Scope
  2. Data We Collect
  3. How We Use Your Data
  4. Data Sale & Commercial Disclosure
  5. Data Isolation & Site-Level Access
  6. Storage & Security
  7. Third-Party Services
  8. AI Features & Data Use
  9. Data Retention
  10. Your Rights (Including Opt-Out)
  11. Breach Notification
  12. Contact Us

1. Overview & Scope

Coordinare ("we," "our," or "us") is a clinical research site operations platform operated by DSCS (Data-Driven Site & Contract Services). This policy applies to all services at coordinare.co and coordinare.polsia.app.

Important: Coordinare is not HIPAA-compliant. Do not enter Protected Health Information (PHI).

2. Data We Collect

Account Information

When you register or use our email-gated tools, we collect:

Site Profile Information

When you use the Feasibility Autopilot or Site Profile tools, we may collect:

Study Organizer & Project Board Data

Usage & Analytics Data

AI Interaction Data

3. How We Use Your Data

We use your data to provide, maintain, and improve our services. This includes:

4. Data Sale & Commercial Disclosure

To support the continued development of clinical research tools, Coordinare may "sell" or "share" certain data (as defined by the CCPA/CPRA and GDPR) to third-party partners, including CROs, Sponsors, and research analytics firms.

What We May Sell/Share

What We NEVER Sell

GDPR Compliance Note: For users in the EU/EEA, our legal basis for this processing is Legitimate Interest (improving clinical trial efficiency) or Consent, where applicable. You have the absolute right to object to the sale of your personal data.

5. Data Isolation & Site-Level Access

Core principle: Your site's sensitive operational data is never shared with other sites.

Workspace Model

Data is isolated by domain (e.g., @westlakeoncology.com). Users sharing the same non-generic email domain are grouped into the same workspace and can see shared data (study lists, tasks, contacts). Users with generic email domains (Gmail, Yahoo, Hotmail, Outlook, iCloud) remain in individual personal workspaces.

Aggregate Learning

We may use aggregate, non-identifying patterns (e.g., "Average enrollment for Phase II Oncology") to train models, but this data is stripped of all site-identifying markers.

What Is Shared Within a Workspace

What Is Never Shared Across Sites

Admin Access

Coordinare administrators (DSCS team members) can access aggregated platform data for operational purposes. Admin access is protected by a secret key and rate-limited to prevent unauthorized access. Admin activities are logged. Administrators access the minimum data necessary to operate the platform.

6. Storage & Security

Database

All data is stored in a PostgreSQL database hosted on Neon (a managed cloud database provider). Connections to the database use TLS encryption. The database is not publicly accessible.

Password Storage

User passwords are hashed using the scrypt algorithm with a random salt before storage. Plaintext passwords are never stored or logged.

Study Organizer Passwords

Bookmark credentials (sponsor portal passwords, EDC login passwords) stored in the Study Organizer are encrypted at rest using AES-256 encryption before being written to the database. The encryption key is stored separately from the database.

File Attachments

Files uploaded to the Project Board are stored via Polsia's R2 cloud storage (Cloudflare R2-compatible). File access requires authentication — direct file URLs are served only to authenticated users who belong to the same workspace as the task they were attached to.

Data in Transit

All connections between your browser and Coordinare servers use HTTPS (TLS 1.2+). Data is encrypted in transit.

Session Security

7. Third-Party Services

We share data with the following categories of providers:

We do not use advertising networks, remarketing pixels, or social media tracking on any authenticated pages.

8. AI Features & Data Use

Chat AI

The Chat AI assistant answers questions about clinical research using Dan Sfera's video library and clinical research knowledge base. Chat messages are stored associated with your account. Chat sessions are scoped to your individual user account — your conversation history is not visible to other users.

Feasibility Autopilot

When you use the Feasibility Autopilot, your site profile data is retrieved from our database and used to generate responses. This data is only sent to OpenAI as part of your specific request and is not used to populate responses for other sites. AI-generated responses are not guaranteed to be accurate and should be reviewed before submission.

Budget Generator

Budget AI insights are generated based on phase, therapeutic area, and visit/subject counts you provide. Budget-specific insights may be cached to improve response times — cached results are based on aggregated parameters only, not site-specific data.

AI Output Disclaimer

All AI-generated content is provided for informational purposes only. AI responses may not be accurate, complete, or appropriate for your specific situation. Always review AI output before use. Coordinare and DSCS are not liable for decisions made based on AI-generated content.

9. Data Retention

Coordinare does not delete user data. All data listed below is retained indefinitely unless you explicitly request its removal.
Data Type Retention Period
Account and site profile data Retained indefinitely
Study Organizer data (studies, bookmarks, contacts) Retained indefinitely
Project Board tasks and attachments Retained indefinitely
Chat messages Retained indefinitely
Analytics events Retained indefinitely
Session tokens Automatically expire (30-min idle / 8-hour absolute) but are not manually deleted
Password reset tokens Single-use; expire after 1 hour but are not manually deleted
GCP training records and certificates Retained indefinitely

If you wish to request removal of your data, contact us at admin@dscssweatequity.com. Coordinare does not automatically delete any user data.

10. Your Rights & "Do Not Sell My Info"

Under GDPR and CCPA, you have specific rights:

To exercise your right to opt-out of data sales, please email admin@dscssweatequity.com with the subject line "Do Not Sell My Personal Information."

We will respond within 30 days.

11. Breach Notification

In the event of a data breach that may affect your personal information, we will:

To report a suspected security vulnerability or incident, contact us immediately at admin@dscssweatequity.com.

12. Contact Us

Questions about this privacy policy or our data practices? We're here to help.

Coordinare / DSCS

Privacy inquiries: admin@dscssweatequity.com

Security reports: admin@dscssweatequity.com

General: admin@dscssweatequity.com

We aim to respond to all privacy-related inquiries within 5 business days.

This policy may be updated from time to time. Material changes will be communicated by email to registered users. Continued use of Coordinare after an update constitutes acceptance of the revised policy. The "Effective Date" at the top of this page reflects the most recent revision.