Governance Document

Privacy Policy &
Data Governance

Excelion Research is committed to clinical-grade transparency. We protect patient confidentiality and research integrity through robust governance practices and industry-aligned security controls.

Introduction

At Excelion Research, we recognize that the foundation of clinical research is trust. This Privacy Policy outlines our approach to data governance, ensuring that participant information, clinical research data, and partner-related information are handled with the highest degree of confidentiality and integrity.

As a research services provider supporting clinical research organizations (CROs), pharmaceutical companies, and clinical trial sites, Excelion implements responsible data governance practices aligned with applicable regulatory and ethical standards.

We are committed to transparent, secure, and responsible processing of information entrusted to us.

Data Collection & Usage

Personal Identity Data

Includes names, professional contact details, institutional affiliations, and professional credentials required for account administration, collaboration management, and regulatory verification where applicable.

Clinical Research Data

May include pseudonymized research data such as study-related results, biometric measurements, and longitudinal health indicators processed strictly in accordance with approved research protocols and sponsor requirements.

Excelion does not independently determine clinical trial protocol design and processes research data only within the scope of authorized service engagements.

We collect and process personal data only for the specific, itemised purposes disclosed to you at the point of collection (such as responding to an enquiry, evaluating a job application, or sending newsletter updates), and only on the basis of your consent or another lawful basis recognized under applicable data protection law.

Regulatory Compliance

Excelion Research operates in India and follows applicable data protection and confidentiality requirements relevant to research services.

India Data Protection

Excelion processes personal information in accordance with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and relevant provisions of the Information Technology Act, 2000. We are aligning our data governance practices ahead of the Act's phased enforcement timeline.

GDPR Compliance Statement

Where services involve organizations or data subjects within the European Economic Area, Excelion follows privacy practices aligned with the General Data Protection Regulation, including lawful processing principles, confidentiality safeguards, and data subject rights where applicable.

HIPAA Compliance Statement

Where projects involve U.S. healthcare partners or regulated health information, Excelion may implement safeguards consistent with the requirements of the Health Insurance Portability and Accountability Act of 1996, including administrative, physical, and technical protections for health-related information.

Your Rights & Additional DPDP Commitments

In line with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (India), Excelion recognizes the following rights for every data principal whose personal data we process. To exercise any of these rights, contact our Grievance Officer below — we aim to acknowledge requests within a reasonable time and resolve grievances within 90 days.

Right to Access
Request a summary of the personal data we hold about you, the purposes for which it is processed, and the identities of any third parties it has been shared with.
Right to Correction & Erasure
Request correction of inaccurate or incomplete personal data, or erasure of personal data that is no longer necessary for the purpose it was collected for, subject to any legal or contractual retention requirements.
Right to Withdraw Consent
Withdraw consent at any time for processing that relies on consent. Withdrawal does not affect the lawfulness of processing carried out before it, and may limit our ability to continue providing certain services.
Right to Grievance Redressal
Raise a complaint about how your personal data is handled and receive a response from our Grievance Officer, before escalating the matter to the Data Protection Board of India.
Right to Nominate
Nominate another individual to exercise these rights on your behalf in the event of death or incapacity, by writing to our Grievance Officer.

Data Retention

We retain personal data only for as long as necessary to fulfil the purpose it was collected for, to comply with our legal, regulatory, and contractual obligations (including sponsor and audit-related recordkeeping requirements common in clinical research), or until you withdraw consent and no overriding retention obligation applies — whichever is later.

Personal Data Breach Notification

In the event of a personal data breach, Excelion will notify the Data Protection Board of India and affected data principals as required under the DPDP Act and Rules, including a description of the breach, the likely consequences, and the steps we are taking in response.

Children's & Persons with Disability's Data

We do not knowingly collect personal data from individuals under 18 years of age, or process such data without verifiable consent from a parent or lawful guardian, except where processing relates to a lawful purpose exempted under the DPDP Rules.

Cross-Border Data Transfer

Personal data may be transferred outside India where necessary to deliver our services (for example, to sponsors, regulators, or subcontractors in other jurisdictions), subject to appropriate safeguards and in accordance with Section 16 of the DPDP Act, which permits such transfers except to countries restricted by the Government of India.

Data Security Architecture

Our defense-in-depth security model utilizes multiple layers of technical and administrative safeguards designed to protect information throughout its lifecycle.

Encryption at Rest

Stored information may be protected using industry-standard encryption methods such as AES-256 or equivalent security mechanisms depending on the hosting environment.

Transit Security

Data transmission is protected using secure transport protocols such as TLS 1.2 or higher to maintain confidentiality and integrity between endpoints and service infrastructure.

Access Control

Access to sensitive systems and research-related information is restricted using role-based access control principles and authentication safeguards.

Audit Trails

System activity logs and access monitoring mechanisms are maintained to support operational accountability and traceability.

Cookie Usage & Tracking

Our website uses essential cookies necessary for platform functionality and performance, and analytics cookies to understand aggregated site usage. Excelion does not sell personal data or use cookies for behavioral advertising. Analytics cookies are only set after you accept them via the cookie banner shown on your first visit; you can change this choice at any time by clearing your browser's site data for this domain.

Cookie CategoryPurposeDuration
Strictly NecessaryAuthentication & Session SecuritySession
PerformanceLoad balancing and service optimization24 Hours
Analytics (Google Analytics, via Google Tag Manager)Aggregated and anonymized usage insights (e.g. _ga, _ga_*, _gid cookies)Up to 14 months

We use Google Tag Manager to deploy Google Analytics 4 on this site. Google Analytics collects information such as pages visited, time on site, device/browser type, and approximate location, and transmits it to Google for processing. This data is used in aggregate to understand site usage and is not used to identify individual visitors. Google acts as a data processor for this purpose; see Google's Privacy Policy for details on how Google handles this data. You can opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on, or by disabling cookies in your browser settings.

Grievance Officer (Digital Personal Data Protection Act, 2023)

[Grievance Officer Name], [Designation]

For requests to access, correct, or erase your personal data, to withdraw consent, to report a potential data security issue, or to raise any other privacy grievance, contact our Grievance Officer directly. We aim to resolve grievances within 90 days.

bd@excelionresearch.comResponse time: Within 24 hours