Aurora

Privacy Policy

Last updated: July 2026

1. Introduction

This Privacy Policy is issued by Marcos Pantarotto - Prestação de Serviços, Lda. (NIPC 513 107 177), a company incorporated under Portuguese law ("Aurora", "we" or "us"), which operates the platform under the Aurora Trials brand and can be contacted at apoio@auroratrials.org. Aurora acts as the Data Controller of your personal data under Regulation (EU) 2016/679 (GDPR) and Portuguese Law no. 58/2019 of 8 August. This Policy explains transparently what personal data we collect, why we collect it, how we protect it, and what your rights are as a user of our oncology clinical trial search platform.

This policy applies to all users of the Aurora Trials platform, regardless of access region (Global, EU, Latin America).

2. Data We Collect

2.1 Data you provide at registration

  • Email address (used as your account identifier)
  • Password (stored exclusively as a cryptographic hash — never in plain text)
  • Professional profile: role (patient, doctor, nurse), specialty, institution, country

2.2 Data generated by your use of the platform

  • Clinical trial search history (filters applied, search terms)
  • Studies saved as favourites and study views
  • Conversations with the AI assistant (patient navigator)

2.3 Technical data collected automatically

  • Browser type and operating system
  • IP address and approximate location (used to determine access region)

2.4 Special categories of data (health data — Art. 9 GDPR)

Some of the information we collect may reveal data about your health, namely:

  • The content of your conversations with the AI assistant, which may include references to diagnoses, medication, symptoms or clinical history
  • The terms and filters you use when searching for clinical trials, which may reveal interest in a specific diagnosis
  • The trials you save as favourites and the studies you view

This data is treated as a special category under Article 9 of the GDPR and is subject to additional safeguards. Processing relies on your explicit consent (Art. 9(2)(a) GDPR), collected through separate options at sign-up and on the platform's consent screen. You may withdraw this consent at any time by writing to apoio@auroratrials.org, without retroactive effect on processing already carried out.

Use of the platform is restricted to those aged 18 or over. We do not knowingly collect data from minors. If a parent or guardian finds that a minor has provided us with personal data, they may request its deletion at apoio@auroratrials.org.

3. Purpose of Collection — Why We Collect Your Data

Each type of data is collected for a specific purpose:

  • Email and password hash: authentication and secure access to your account
  • Professional profile: personalising your experience based on your role (patient vs. doctor)
  • Search history: clinical trial matching — finding relevant studies based on your search criteria (only with your explicit consent)
  • Search pattern analysis: improving the platform and identifying trends in oncology (only with your explicit consent)
  • Technical data: security, abuse prevention and platform maintenance

4. Legal Basis for Data Processing

The processing of your personal data is based on the following legal grounds, in compliance with the General Data Protection Regulation (GDPR) and the Brazilian LGPD:

  • Explicit consent (Art. 6(1)(a) GDPR): for data collection for trial matching and for search pattern analysis. This consent is collected granularly at registration via separate checkboxes, and can be withdrawn at any time.
  • Performance of contract (Art. 6(1)(b) GDPR): to provide the essential platform services (authentication, access to the trial catalogue).
  • Legitimate interest (Art. 6(1)(f) GDPR): for platform security and fraud prevention.
  • Legal obligation (Art. 6(1)(c) GDPR): when required by applicable law.
  • Explicit consent for health data (Art. 9(2)(a) GDPR): where processing involves health data or data revealing aspects of your health (a special category under Article 9 of the GDPR), the legal basis is your explicit consent, collected specifically and separately for each purpose.

5. Sharing Data with Third Parties

We do not sell your personal data. Your data may be shared only in the following situations:

5.1 Subcontractors providing services to Aurora

We rely on technology providers to operate the platform. Each is bound by a processing contract under Article 28 of the GDPR to process your data only on our instructions and to apply appropriate security measures.

  • Supabase Inc. — authentication, database and storage. Accesses your account and usage data stored on the platform. The data is hosted in the European Union, in the Ireland region
  • Anthropic PBC — artificial intelligence models supporting the conversational assistant. Based in the United States, it accesses the content you submit through that feature. The transfer to the United States is covered by the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, incorporated into the data processing agreement signed with this subcontractor
  • Hostinger International Ltd. — hosting of the platform server, in France (European Union)

Apart from the transfer to the United States identified above, your data is hosted and processed within the European Union. An up-to-date list of subcontractors is available on request at apoio@auroratrials.org.

5.2 Legal obligations

We may share data where required by a competent authority in compliance with a legal obligation, in particular in response to a court order, a request from the CNPD, or to meet tax or accounting obligations.

5.3 With your consent

For any other purpose, including any sharing with partner organisations as part of specific features, sharing always depends on your explicit consent, given on an informed and specific basis when you use the relevant feature.

6. How We Protect Your Data

We implement rigorous technical and organisational security measures:

  • Encryption in transit: all communications are protected by TLS/SSL (HTTPS mandatory)
  • Encryption at rest: the database uses AES-256 encryption for stored data
  • Passwords are never stored in plain text — we use cryptographic hashing (bcrypt) via Supabase Auth
  • Restricted access: Row Level Security (RLS) in PostgreSQL ensures each user can only access their own data
  • Administrative access is limited and audited via aurora_audit_logs
  • In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will inform you without undue delay under Article 34 of the GDPR, and notify the CNPD within 72 hours as required by Article 33

7. Your Rights

In accordance with the GDPR (EU) and LGPD (Brazil), you have the following rights:

  • Right of access: view all personal data we hold about you
  • Right to rectification: correct incomplete or inaccurate data
  • Right to erasure ('right to be forgotten'): request deletion of your data
  • Right to withdraw consent: you may withdraw any consent given at any time, without affecting the lawfulness of prior processing
  • Right to data portability: request your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interest
  • Right not to be subject to solely automated decisions (Art. 22 GDPR): the platform uses artificial intelligence to suggest relevant clinical trials. While these suggestions do not replace clinical decisions, which always rest with your doctor, you have the right to obtain human intervention, to express your point of view and to contest any automated recommendation
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): if you believe the processing of your data breaches applicable law, you may complain to the Portuguese Data Protection Authority (CNPD), at Av. D. Carlos I, no. 134, 1.º, 1200-651 Lisbon, or through the form at https://www.cnpd.pt. This is without prejudice to any other administrative or judicial remedy

To exercise any of these rights, contact us at apoio@auroratrials.org. We will reply within one month, extendable by a further two months in complex cases, under Article 12 of the GDPR.

8. Cookies

The platform uses no third-party tracking cookies and no advertising cookies. Your session and preferences are not stored in cookies but in your browser's local storage: the session data generated by the authentication service, which keeps you signed in between visits, and your selected language. This data stays on your device and you can delete it at any time by clearing your browsing data, which ends the session.

9. Data Retention

Your data is kept only for as long as strictly necessary for the purposes described. In summary:

CategoryRetention period
Account and authentication credentialsWhile the account is active. After a deletion request, credentials are destroyed at 30 days — during which the request can still be reversed
Professional profile and uploaded documentsWhile the account exists; 90 days after the deletion request
Trial search history24 months, then anonymised: the filters and date remain, without the terms you typed or any link to you
Conversations with the AI assistant12 months, then anonymised. The content of the messages is not stored on our servers
Clinical description entered into the assistant90 days
Recorded IP addresses (page views and security logs)7 days, then replaced by a code that cannot be traced back to you
Access and security logs12 months
Page visits and sign-in records90 days
Saved studies and their notesWhile the account exists
Study shares sent by email30 days, or the share's expiry date if earlier; never more than 90 days
Messages in the professional forumWhile the account exists; messages you delete are removed after 30 days
Trial enrolment assistance requests12 months, then anonymised
Partner link usage statistics24 months
Tax data, where applicable10 years, by legal obligation (Art. 123 of the Portuguese Corporate Income Tax Code)

These periods are enforced automatically: a daily process deletes or anonymises data whose period has ended. You may also request erasure before these periods expire, by exercising the right to erasure described in Section 7, without prejudice to the minimum retention required by law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email and by publishing the new version on this page. The "last updated" date shown at the top will always be updated. We keep a history of previous versions of this Policy, which you can consult on request at apoio@auroratrials.org.

11. Contact and DPO

Data Protection Officer (DPO): Pedro Duarte Vaz, PhD, who can be contacted at pedro.vaz@auroratrials.org. Requests concerning the processing of your personal data should preferably be addressed to the Officer, who coordinates the response within the statutory deadlines — one month, extendable by two further months in complex cases.

For questions about this Privacy Policy or the processing of your personal data, contact the Data Controller, Marcos Pantarotto - Prestação de Serviços, Lda. (NIPC 513 107 177):

Email: support@auroratrials.org