[LIKE THIS] below. See LEGAL-TODO.md in this repository.
This notice explains how CatalystIQ handles personal data. It is written to describe what the software actually does in its default configuration, which is deliberately minimal, and it now includes optional user accounts for alerts, watchlists and plan association — the dashboard itself is open and needs no account. CatalystIQ is a self-hosted dashboard for public clinical and regulatory information. It does not use analytics or advertising trackers, and it sets exactly one cookie — a strictly necessary session cookie described below. If you create an account, we hold the details set out here. We do not hold any personal health data: the clinical information indexed is about trials, drugs and companies, never about patients or their records.
The data controller is [COMPANY LEGAL NAME], company number
[COMPANY NUMBER], registered office [REGISTERED OFFICE ADDRESS]
(“we”, “us”). Privacy contact: [PRIVACY CONTACT EMAIL].
CatalystIQ is distributed as open-source software. If you run your own copy, you are the controller for that deployment and this notice serves as a template for the processing it performs.
| Category | Detail | Lawful basis |
|---|---|---|
| Account and profile data | Your name, email address and (optionally) your company, plus a hashed password. We never store your password itself — only a salted scrypt hash, which cannot be reversed. | Performance of a contract (Art. 6(1)(b)) — providing the account you asked for |
| Session cookie | A single first-party cookie, cq_session, is set when you sign in. It is
HttpOnly, SameSite=Lax, and Secure over HTTPS. It holds an opaque random token; only
its SHA-256 hash is stored server-side. It exists solely to keep you signed in. Because
it is strictly necessary it is not consent-based, and there is
therefore no cookie banner. |
Strictly necessary / performance of a contract |
| Transactional email | We send address-verification and password-reset messages to the address on your account. Delivery is handled by the mail provider the operator has configured, which sees the recipient address and the message content. | Performance of a contract; security of the account |
| Security and audit records | Authentication events (sign-in, failed sign-in, password change, consent given) are recorded with a one-way hash of your IP address — never the raw address. These records exist to detect abuse and to evidence your consent. | Legitimate interests (Art. 6(1)(f)) — account security; legal obligation for consent evidence |
| Consent record | When you create an account we record which version of these documents you accepted, and when. Optional product emails are recorded separately and can be withdrawn at any time from your account page. | Legal obligation (Art. 7(1)) — demonstrating consent; consent for marketing email |
| Subscription data (paid plans only) | If you subscribe, payment is processed by Stripe. Card details are entered on Stripe's own hosted page and never reach our servers. We store only the resulting customer and subscription identifiers, and your plan name. | Performance of a contract |
| No personal health data | The clinical content indexed is public trial, drug and company information. We do not process patient records, and we do not process health data about you. | Not applicable |
| No local storage, no trackers | We write nothing to localStorage or sessionStorage, and
load no analytics, advertising or tag-manager scripts. The cookie above is the only
value we store in your browser. |
Not applicable |
| Server access logs | When CatalystIQ is reachable on the internet, the web server in front of it (for example nginx) records each request: IP address, timestamp, requested path, user agent and response code. This is used only to operate, secure and troubleshoot the service. | Legitimate interests (Art. 6(1)(f)) — service security and availability |
| Optional alert webhook | If the operator configures WEBHOOK_URL, a summary of detected pipeline changes is
POSTed to that URL. The payload contains public clinical and regulatory data only; it
contains no personal data about visitors or account holders. |
Legitimate interests / the operator's own configuration |
Depending on how this deployment is configured, the following third parties may process data on our behalf. Each is bound by its own terms, and only the data described above is disclosed to it:
To build the dashboard, the CatalystIQ server requests publicly available information from third-party publishers — including the ClinicalTrials.gov API, openFDA, the FDA Orange Book bulk download, the Google Patents query endpoint, Europe PMC, pharma news feeds and Yahoo Finance. These are server-to-server requests for public data. No personal data about you is transmitted in them. Those operators will see the IP address of the server making the request, as with any HTTP request.
CatalystIQ can optionally send a compact summary of the current sweep to a third-party large-language-model provider, in order to generate an analyst brief. That summary consists solely of public pipeline data — trial identifiers, phase and status, application numbers, patent numbers, dates, tickers and price movements. It contains no personal data and no data about visitors to the dashboard.
The AI layer is disabled unless the operator sets LLM_PROVIDER. If enabled,
the chosen provider becomes a sub-processor, and its own terms and privacy policy apply to
that transfer. Output produced by the AI layer is labelled as such in the interface.
Server access logs are retained for [LOG RETENTION PERIOD, e.g. 14 days] and
then deleted or rotated. Sweep results are stored locally as JSON files and contain public
clinical and regulatory data, not personal data.
Account data is retained for as long as the account exists. Verification
and password-reset tokens are single-use and expire automatically (24 hours and 1 hour
respectively), and expired sessions are purged. When you delete your account, your profile,
password hash, active sessions, tokens and consent records are deleted, and free-text audit
entries are detached from your identity. Records we are legally required to keep for tax or
accounting purposes are retained for
[FINANCIAL RECORD RETENTION PERIOD]; nothing else is kept.
You have the right to: access the personal data we hold about you; have it rectified; have
it erased; restrict or object to its processing; and receive it in a portable form. You can
change your name, company and email preferences directly from your account page. To exercise
any other right, or to ask us to delete your account, contact
[PRIVACY CONTACT EMAIL].
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national authority.
CatalystIQ displays information about clinical trials and medicines, including trial titles, sponsors, conditions and regulatory decisions. This is public information about products and organisations, not health data about individuals. The software does not collect, process or store any personal health data, and it is not intended to be used as a source of medical advice.
The application sets a strict Content-Security-Policy, transport security headers and cross-origin protections, verifies the origin of every state-changing request, and rate-limits authentication attempts. Access records are written with a one-way hash of the IP address rather than the address itself. Passwords are stored only as salted scrypt hashes and are never written to logs, and sessions use opaque random tokens of which only a SHA-256 hash is stored.
No system is perfectly secure. If you believe your account has been compromised, reset the
password and contact [PRIVACY CONTACT EMAIL].
We will update this notice if the software's behaviour changes in a way that affects personal data, and will update the version and effective date above.