Privacy Policy
Last updated: March 31, 2026This Privacy Policy describes how Purple Directive ("we," "us," or "Nexrial") collects, uses, stores, and protects information when you use Nexrial CTMS ("the Service"). It applies to all users of the Service and to visitors of nexrial.com.
If you are using the Service on behalf of an organization, this policy applies to your use, and your organization's use, of the Service. Your organization may have additional privacy obligations under applicable law, including HIPAA, which are addressed in Section 9.
1. Who We Are
Nexrial CTMS is a product of Purple Directive, a software company specializing in compliance-focused software for regulated industries. For privacy purposes, Purple Directive is the data controller for account and usage information, and acts as a data processor for Protected Health Information (PHI) entered by subscribing organizations under an executed Business Associate Agreement (BAA).
Contact: [email protected]
2. What Data We Collect
We collect three categories of data:
Account Information. When you or your organization registers for the Service, we collect:
- Name and email address of account users
- Organization name and subdomain
- Role assignments within your organization
- Billing contact information (name, email, payment method via our payment processor)
Usage Data. When you use the Service, we automatically collect:
- IP address and browser/device type for security and audit purposes
- Session activity, including login times and page navigation, stored in the application audit log
- Feature usage to help us understand how the Service is used and improve it
- Error logs and diagnostic data to identify and resolve technical issues
Clinical Data (PHI and Study Data). If you enter Protected Health Information or clinical study data into the Service, we store it on your behalf as your data processor. This data is governed by your Business Associate Agreement with us (see Section 9). We do not use clinical data for any purpose other than operating the Service for your organization.
3. How We Use Your Data
We use the data we collect strictly to operate and improve the Service:
- Service provision. Authenticating users, enforcing role-based access controls, storing and displaying your data, and delivering features you use.
- Security and integrity. Detecting and preventing unauthorized access, fraud, or abuse. Maintaining audit logs as required by 21 CFR Part 11 and other applicable regulations.
- Communication. Sending service notifications (maintenance windows, security alerts, subscription updates) to the email address on file. We do not send marketing email without explicit opt-in.
- Improvement. Analyzing aggregate, de-identified usage patterns to improve the product. We do not use individual clinical data for this purpose.
- Legal compliance. Responding to valid legal process or regulatory requirements.
- AI-assisted features. Where you choose to invoke them, AI features process the content you submit (such as protocol text, adverse-event details, or eligibility criteria) to generate clearly-marked drafts for your review. AI runs on enterprise cloud infrastructure under contract — covered by a Business Associate Agreement where PHI is involved — your inputs are not used to train third-party models, and AI never signs, approves, or finalizes a regulated record.
We do not use your data for advertising, behavioral profiling, or sale to third parties.
4. Data Sharing
We never sell your data. We do not sell, rent, or trade any user data or Client Data to third parties under any circumstances.
We share data only in the following limited circumstances:
- Infrastructure and operations. We use a small number of trusted service providers to operate the Service (e.g., cloud hosting and AI-processing infrastructure, email delivery for notifications, payment processing for billing). These providers access only the minimum data necessary and are contractually bound to process it solely on our behalf; any provider that may process PHI does so under a Business Associate Agreement.
- Legal requirements. We may disclose data if required by a valid court order, subpoena, or other legal process, or to comply with applicable law. Where legally permitted, we will notify you before disclosing.
- Business transfers. If Purple Directive is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify affected customers with at least 30 days' notice and ensure continued protection under terms no less protective than this policy.
- With your consent. We will share data for any other purpose only with your explicit consent.
PHI is never shared with any party except as required by your BAA or by applicable law.
5. Data Security
We implement technical and organizational security measures appropriate to the sensitivity of the data we process:
- Encryption at rest. Data at rest, including PHI, is encrypted using strong, industry-standard encryption.
- Encryption in transit. All data in transit is protected by current, industry-standard transport encryption, and insecure connections are redirected to secure ones.
- Access controls. Role-based access control (RBAC) restricts each user to only the data and functions appropriate to their role. Administrative access is logged and minimized.
- Audit logging. All significant actions within the Service — including logins, data modifications, document access, and signature events — are recorded in a tamper-evident audit log.
- Infrastructure isolation. The core Service runs on access-controlled infrastructure, and each tenant's data is logically isolated so that one organization cannot access another's records. Where we use cloud services (for example, AI processing), tenant data is protected under appropriate contractual safeguards, including a Business Associate Agreement where PHI is involved.
- Backup encryption. Backups are encrypted and retained on a schedule designed to meet regulatory requirements. Access to backups is restricted to authorized personnel.
No system is perfectly secure. If we become aware of a data breach that affects your data, we will notify you promptly in accordance with applicable law and your BAA.
6. Data Retention
We retain your data for as long as your subscription is active. Specifically:
- Account and usage data is retained for the duration of your subscription plus 90 days following termination.
- Clinical data and audit logs are retained for the duration of your subscription. Upon termination, data is available for export for 90 days and then securely deleted from active systems. Encrypted backup copies may persist on standard backup rotation schedules as required by law.
- Billing records are retained for 7 years as required by applicable financial regulations.
You may request early deletion of specific data by contacting us, subject to our obligations under applicable law and your BAA (which may require retention of certain audit records for regulatory purposes).
7. Your Rights
With respect to your personal account information (not clinical data, which is governed by your BAA), you have the right to:
- Access. Request a copy of the personal data we hold about you.
- Correction. Request correction of inaccurate or incomplete personal data.
- Deletion. Request deletion of your personal data, subject to our legal retention obligations.
- Export. Request a structured, machine-readable export of your account data.
- Objection. Object to certain uses of your data, such as for product analytics.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing certain requests.
For rights related to PHI under HIPAA (access, amendment, accounting of disclosures), contact us and reference your organization's BAA.
8. Cookies
The Service uses a minimal set of cookies:
- Session cookie (
ctms_session). A single, server-set session cookie is used to authenticate logged-in users. This cookie contains a cryptographically random token with no personally identifiable information embedded. It expires when your session ends or after the configured inactivity timeout. This cookie is strictly necessary for the Service to function.
We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. The nexrial.com marketing site may use privacy-respecting, cookieless analytics to count page visits; it does not set tracking cookies or store personally identifiable information.
You can disable cookies in your browser, but the authenticated Service will not function without the session cookie.
9. HIPAA & Your PHI
Nexrial is designed to support clinical research operations subject to HIPAA. Where you use the Service to store or process Protected Health Information (PHI), the following applies:
- We function as your Business Associate under HIPAA. A signed BAA must be in place before any PHI is entered into the Service.
- PHI is encrypted at rest and in transit using strong, industry-standard encryption. Access is role-based and every access event is audit-logged.
- We implement administrative, physical, and technical safeguards aligned with the HIPAA Security Rule (45 CFR Part 164, Subpart C). The Service runs on access-controlled infrastructure located in the United States. Physical and environmental safeguards for the underlying hosting infrastructure are provided by our infrastructure providers under contract; administrative and technical safeguards over the Service are maintained by Purple Directive. Where a third party operates any part of that infrastructure or may otherwise access PHI, that party is bound by a Business Associate Agreement consistent with our obligations to you.
- We do not use PHI for any purpose other than providing the Service to your organization, as specified in your BAA.
- In the event of a breach of unsecured PHI, we will notify you in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D) and the terms of your BAA.
You, as the HIPAA Covered Entity or upstream Business Associate, are responsible for ensuring your own HIPAA compliance, including obtaining appropriate patient authorizations, maintaining your Notice of Privacy Practices, and fulfilling your obligations under your BAA with sponsors and IRBs.
To request a BAA or ask about our HIPAA safeguards, contact [email protected].
10. Children's Privacy
The Service is intended exclusively for use by licensed clinical research professionals and authorized staff of clinical research organizations. The Service is not directed at, and should not be used by, individuals under the age of 18.
We do not knowingly collect personal information from minors. If you believe a minor has registered for an account, please contact us immediately at [email protected] so we can investigate and remove the account.
Note: the Service may store clinical data about minor research subjects as part of a clinical trial. This is distinct from a minor using the Service, and is governed by your BAA and applicable regulations.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email to the address on file and by posting the updated policy at nexrial.com/privacy at least 30 days before the changes take effect.
Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes. If you do not agree, you may terminate your subscription before the effective date.
The "Last updated" date at the top of this page reflects when the policy was most recently revised.
12. Contact
If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, please contact us:
Purple Directive — Nexrial CTMS
Email: [email protected]
Web: purpledirective.com
We aim to respond to all privacy inquiries within 5 business days and to resolve them within 30 calendar days.