Data Protection Considerations

April 24, 2026

version 03

Flex Databases provides software solutions supporting clinical trial conduct across all stages. One of our key priorities is ensuring the confidentiality and integrity of customer data. We are committed to maintaining high standards of data protection and privacy.

Flex Databases implements robust security controls to protect customer data, ensure compliance with applicable regulations, and mitigate potential risks. This approach is essential for building trust and delivering a high level of service.

Our security framework is designed in alignment with recognized standards and regulations, including:

  • 21 CFR Part 11
  • HIPAA
  • GDPR

Under GDPR, Flex Databases acts as a data processor, while our customers act as data controllers. The data controller determines what data is collected and how it is processed and stored. Flex Databases processes personal data strictly in accordance with the controller’s documented instructions and contractual agreements.

To support our customers in fulfilling their data protection obligations, Flex Databases provides the following technical and organizational controls:

  • robust access control mechanisms;
  • encryption of all data in transit using TLS/SSL protocols with strong cryptographic algorithms (e.g., SHA-2, AES);
  • secure access to user interfaces via HTTPS.

The Flex Databases platform is a modular, web-based system provided under contractual agreements. It is typically delivered as a Software as a Service (SaaS) solution, where applications are hosted and made available to customers via the cloud.

Cloud-based delivery means that data storage and processing take place on servers hosted by Flex Databases in subcontracted data centers. These data centers are subject to formal vendor assessment in accordance with SOP-QA-011 “Purchasing and Vendor Assessment” prior to engagement.

Personal data processing is designed in compliance with applicable data protection regulations. Data Protection Impact Assessments (DPIAs) are performed where required. Data processing details are agreed with customers, and Data Processing Agreements (DPAs) are executed using either the Flex Databases template or a customer-provided template.

For European customers, data is stored within qualified data centers located in the European Union.

The implemented technical and organizational measures (TOMs) include, but are not limited to:

Use of ISO 27001-certified data centers, verified through vendor assessment procedures;

  • Multi-layered firewall protection with a default deny-all configuration;
  • Strict network access controls, with only explicitly authorized ports and hosts permitted;
  • Segregation of environments (TEST, QA, PROD) using separate VLANs and security groups;
  • 24/7 monitoring of data center infrastructure;
  • Physical security controls, including:
    • electronic access control systems with logging;
    • secured perimeter fencing;
  • Continuous monitoring, including:
    • access logging;
    • video surveillance of entry and exit points.

A designated Data Protection Officer (DPO) provides GDPR training to staff and ongoing guidance on data protection matters.

For any data privacy-related inquiries, please contact: dl_privacy@flexdatabases.com

Blog

April 15, 2026
TMF Blinding: Removing the Complexity of Managing Blinded Studies

Blinded studies are critical for maintaining the integrity of clinical trials. But while the concept is straightforward, the operational reality is often anything but. For many clinical teams, managing blinding means dealing with: This creates a constant burden: Even with strict processes in place, a single misconfiguration can compromise the entire study. TMF Blinding in […]

April 2, 2026
CTMS for CRO Financial Management: Managing Clinical Trial Budgets and Investigator Payments

Financial management is critical because CROs must ensure that clinical trials remain within budget while generating expected revenue. Without proper financial oversight, organizations may experience delayed payments, incorrect invoicing, or reduced project profitability. A CTMS helps CROs maintain financial control and improve operational efficiency. Financial management is one of the most complex operational areas for […]

April 1, 2026
Risk-Based Monitoring (RBM) in Clinical Trials: A Comprehensive Guide to Modern Oversight

For decades, the clinical research industry operated under a manual, labor-intensive oversight model. The gold standard was 100% Source Data Verification (SDV) – a process where Clinical Research Associates (CRAs) traveled to sites to painstakingly cross-reference every data point in a Case Report Form against medical records. However, as trials have become more data-saturated and […]

March 26, 2026
Why MapLight Therapeutics Chose Flex Databases’ CTMS and eTMF

MapLight Therapeutics selected Flex Databases to support its clinical trial operations with an integrated CTMS and eTMF platform. In this interview, the MapLight team shares why they chose Flex Databases, which features stood out during the evaluation process, and how the platform will support efficient trial oversight and long-term clinical operations. What were the key […]

Contact us

Get in touch to discuss compliance, implementation, demos, pricing

We are here for all of your questions! Tell us more about yourself and we will organize a tailored live demo to show how you can power up your clinical trials processes with Flex Databases.