GDPR is here and Flex Databases got your back!

May 23, 2018

GDPR is here and Flex Databases got your back!

Flex Databases is always ready to support you in any challenging situation. And today, when GDPR came into effect,  we are here to demonstrate that with us you are fully prepared to it in terms of our partnership. Here  are some key  GDPR requirements with explanation on how Flex Databases meet them:

GDPR: Article 28.2 ‘The processor shall not engage another processor without prior specific or general written authorization of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.

Flex Databases: Only customers are the data controllers who decide which data is collected and how it is processed and stored. Flex  Databases is the data processor and strictly fulfills the agreements with the customers and ensures that data is processed following  the instructions by data controller. If our Clients want to put on paper the rights and obligations in terms of GDPR, we are ready to  sign Data Processing Agreement to capture the roles of data processor and data controller and to formalize the measures taken to  protect the data.

GDPR: Article 17 ‘The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay.’

Flex Databases: in terms of clinical trials, there is no obligation to erase the subjects’ data as GDPR says that the right to erasure does not apply in case of scientific research purposes. If you need to delete the personal data of a dismissed employee, just write to our Helpdesk and this will be done.

GDPR: Article 32 ‘The controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: the pseudonymisation and encryption of personal data.’

Flex Databases: All traffic into and out of the Flex Databases Platform is encrypted using TLS/SSL protocol that leverages either SHA-2 or AES algorithms. Access to the user interfaces is encrypted via HTTPS/SSL We provide tools for data pseudonymization and ensure strong control of the system access rights.

GDPR: Transfers to third countries and international organisations may only be carried out in full compliance with this Regulation. A transfer could take place only if, subject to the other provisions of this Regulation, the conditions laid down in the provisions of this Regulation relating to the transfer of personal data to third countries or international organisations are complied with by the controller or processor.’

Flex Databases: our system is provided as ‘Software as a Service’ (SaaS) which is a software distribution model in which we as system supplier host applications and make them available to customers cloud-based over the Internet. Cloud-based means that storage and processing take place on servers hosted by Flex Databases in subcontracted data centers which are evaluated before contracting and reassessed periodically. We store and backup the data of our European clients in the qualified data centers located in the EU.

GDPR: Article 37 ‘The controller and the processor shall designate a data protection officer.’

Flex Databases: We have appointed Data Protection Officer who trains the staff in the GDPR and provides guidance in the related issues. In case of any data privacy concerns please contact: dl_privacy@flexdatabases.com

Blog

April 28, 2026
Flex Databases x SOLTI taking the stage at #OCT2026

We’re heading to Barcelona for OCT 2026. And this time, we’re bringing a real story with us! Our colleague Evgeniya will be speaking alongside Jaume Costa from SOLTI, our dear client and long-term partner, about the question many teams still struggle with: Who should own your eClinical systems: sponsor or CRO? Stream B: AI & […]

April 15, 2026
TMF Blinding: Removing the Complexity of Managing Blinded Studies

Blinded studies are critical for maintaining the integrity of clinical trials. But while the concept is straightforward, the operational reality is often anything but. For many clinical teams, managing blinding means dealing with: This creates a constant burden: Even with strict processes in place, a single misconfiguration can compromise the entire study. TMF Blinding in […]

April 2, 2026
CTMS for CRO Financial Management: Managing Clinical Trial Budgets and Investigator Payments

Financial management is critical because CROs must ensure that clinical trials remain within budget while generating expected revenue. Without proper financial oversight, organizations may experience delayed payments, incorrect invoicing, or reduced project profitability. A CTMS helps CROs maintain financial control and improve operational efficiency. Financial management is one of the most complex operational areas for […]

April 1, 2026
Risk-Based Monitoring (RBM) in Clinical Trials: A Comprehensive Guide to Modern Oversight

For decades, the clinical research industry operated under a manual, labor-intensive oversight model. The gold standard was 100% Source Data Verification (SDV) – a process where Clinical Research Associates (CRAs) traveled to sites to painstakingly cross-reference every data point in a Case Report Form against medical records. However, as trials have become more data-saturated and […]

Contact us

Get in touch to discuss compliance, implementation, demos, pricing

We are here for all of your questions! Tell us more about yourself and we will organize a tailored live demo to show how you can power up your clinical trials processes with Flex Databases.