Data Protection Considerations

April 24, 2026

version 03

Flex Databases provides software solutions supporting clinical trial conduct across all stages. One of our key priorities is ensuring the confidentiality and integrity of customer data. We are committed to maintaining high standards of data protection and privacy.

Flex Databases implements robust security controls to protect customer data, ensure compliance with applicable regulations, and mitigate potential risks. This approach is essential for building trust and delivering a high level of service.

Our security framework is designed in alignment with recognized standards and regulations, including:

  • 21 CFR Part 11
  • HIPAA
  • GDPR

Under GDPR, Flex Databases acts as a data processor, while our customers act as data controllers. The data controller determines what data is collected and how it is processed and stored. Flex Databases processes personal data strictly in accordance with the controller’s documented instructions and contractual agreements.

To support our customers in fulfilling their data protection obligations, Flex Databases provides the following technical and organizational controls:

  • robust access control mechanisms;
  • encryption of all data in transit using TLS/SSL protocols with strong cryptographic algorithms (e.g., SHA-2, AES);
  • secure access to user interfaces via HTTPS.

The Flex Databases platform is a modular, web-based system provided under contractual agreements. It is typically delivered as a Software as a Service (SaaS) solution, where applications are hosted and made available to customers via the cloud.

Cloud-based delivery means that data storage and processing take place on servers hosted by Flex Databases in subcontracted data centers. These data centers are subject to formal vendor assessment in accordance with SOP-QA-011 “Purchasing and Vendor Assessment” prior to engagement.

Personal data processing is designed in compliance with applicable data protection regulations. Data Protection Impact Assessments (DPIAs) are performed where required. Data processing details are agreed with customers, and Data Processing Agreements (DPAs) are executed using either the Flex Databases template or a customer-provided template.

For European customers, data is stored within qualified data centers located in the European Union.

The implemented technical and organizational measures (TOMs) include, but are not limited to:

Use of ISO 27001-certified data centers, verified through vendor assessment procedures;

  • Multi-layered firewall protection with a default deny-all configuration;
  • Strict network access controls, with only explicitly authorized ports and hosts permitted;
  • Segregation of environments (TEST, QA, PROD) using separate VLANs and security groups;
  • 24/7 monitoring of data center infrastructure;
  • Physical security controls, including:
    • electronic access control systems with logging;
    • secured perimeter fencing;
  • Continuous monitoring, including:
    • access logging;
    • video surveillance of entry and exit points.

A designated Data Protection Officer (DPO) provides GDPR training to staff and ongoing guidance on data protection matters.

For any data privacy-related inquiries, please contact: dl_privacy@flexdatabases.com

Blog

May 19, 2026
Clinical Trials Management Software: Key Features for CROs

CROs work in a fast-moving and highly complex environment. They manage multiple studies at the same time, often for different sponsors, across different countries, sites, and timelines. Each study comes with its own processes, reporting needs, and regulatory expectations. As this complexity grows, it becomes harder to keep everything aligned using separate tools or spreadsheets […]

Speaker Announcement Anna Petrovskaya at QA Virtual Conerence

Risk management used to live in spreadsheets, scattered documents, and endless review meetings.Not anymore 👀 That’s exactly what our QA Director, Anna Petrovskaya , will be speaking about at the International QA Virtual Conference. Her session,▶️ “Risk Management Automation in the GCP R3 Era,”will explore why traditional, document-based risk management approaches are no longer enough, and […]

April 28, 2026
Flex Databases x SOLTI taking the stage at #OCT2026

We’re heading to Barcelona for OCT 2026. And this time, we’re bringing a real story with us! Our colleague Evgenia will be speaking alongside Jaume Costa from SOLTI, our dear client and long-term partner, about the question many teams still struggle with: Who should own your eClinical systems: sponsor or CRO? Stream B: AI & […]

April 15, 2026
TMF Blinding: Removing the Complexity of Managing Blinded Studies

Blinded studies are critical for maintaining the integrity of clinical trials. But while the concept is straightforward, the operational reality is often anything but. For many clinical teams, managing blinding means dealing with: This creates a constant burden: Even with strict processes in place, a single misconfiguration can compromise the entire study. TMF Blinding in […]

Contact us

Get in touch to discuss compliance, implementation, demos, pricing

We are here for all of your questions! Tell us more about yourself and we will organize a tailored live demo to show how you can power up your clinical trials processes with Flex Databases.