Privacy Policy

Last updated: June 2026

1. Who we are and how to contact us

PrimusReview ("we", "us", "our") is a software service operated by Daniel Thompson, trading as PrimusReview, providing AI-assisted compliance review for pharmaceutical and life sciences materials in the United Kingdom. Data controller: Daniel Thompson trading as PrimusReview Email: thompson.daniel@primusreview.com Website: https://www.primusreview.com We are registered with the Information Commissioner's Office (ICO) as a data controller. If you have any questions about this privacy policy or how we handle your personal data, please contact us at thompson.daniel@primusreview.com.

2. Scope of this policy

This privacy policy applies to all personal data we collect and process when you: - Visit our website at primusreview.com - Create an account and use our compliance review service - Contact us via our contact form or by email - Subscribe to a paid plan This policy should be read alongside our Terms of Service, which govern your use of the platform.

3. What personal data we collect

We collect the following categories of personal data: Account data: your full name, work email address, company name, and password (stored in encrypted form) when you create an account. Profile data: your subscription status, number of reviews used, and account creation date. Document data: the content of materials you upload for compliance review. This may include text, images, and structured content from PDF, PPTX, and other file formats. You should ensure you have the right to submit any materials you upload. Audio/video data: if you use our Video Review feature (available on our Professional Plus plan), we process the audio content of uploaded video or audio files, including a machine-generated transcript with timestamps. Source library data: reference documents you upload to your personal source library, including document names and extracted text content. Payment data: billing information is processed directly by Stripe. We do not store full card numbers or payment credentials on our systems. We store your Stripe customer ID and subscription status. Usage data: records of reviews you have run, material types selected, review results, and timestamps. Technical data: IP address, browser type and version, operating system, referral source, pages visited, and session duration, collected via server logs and Vercel Analytics. Communications data: any information you provide when contacting us via the contact form or by email.

4. Special category data

We do not intentionally collect special category personal data (such as health data, biometric data, or data about criminal convictions). However, promotional materials you submit for review may incidentally contain references to patient populations, clinical conditions, or other sensitive information. You should ensure that any materials you submit do not contain identifiable patient data or other special category data unless you have a lawful basis to process and share such data. If we become aware that special category data has been submitted, we will delete it promptly and notify you.

5. Legal basis for processing

Under UK GDPR, we rely on the following legal bases: Contract (Article 6(1)(b)): processing your account data, document submissions, and usage data is necessary to provide the review service you have signed up for. Legitimate interests (Article 6(1)(f)): processing technical and analytics data to maintain security, prevent fraud, improve the service, and understand how users interact with the platform. We have assessed that these interests are not overridden by your rights and freedoms. Legal obligation (Article 6(1)(c)): retaining certain records where required by applicable law, including tax and financial records. Consent (Article 6(1)(a)): where we send optional marketing communications, we will obtain your prior consent. You may withdraw consent at any time.

6. How we use your data

We use your personal data for the following purposes: - Providing the compliance review service, including processing documents through our AI model - Managing your account, subscription, and billing - Sending transactional emails (account confirmation, welcome email, billing notifications) - Responding to support and contact form enquiries - Improving the accuracy and performance of the service - Maintaining the security and integrity of the platform - Complying with legal and regulatory obligations - Enforcing our Terms of Service We do not use your data for automated decision-making that produces legal or similarly significant effects without human review.

7. AI processing and document data

When you submit a document for review, its content is transmitted to the Anthropic API for processing by the Claude AI model. This is necessary to provide the compliance analysis. Important: Anthropic does not use inputs submitted via the API to train its models by default. API inputs are not used for model training under Anthropic's standard terms. For further information, see Anthropic's privacy policy at anthropic.com/privacy. Document content is stored in our database (Supabase) to populate your review history. You may delete your review history at any time from within the platform. If you delete your account, all document content will be deleted within 30 days. You should not submit materials containing identifiable patient data, confidential third-party information you do not have the right to share, or any data subject to export controls or trade restrictions.

8. Third-party processors (sub-processors)

We use the following third-party processors to operate the service. Each has been assessed for compliance with UK GDPR: Supabase (database and authentication): data stored in EU region. Supabase is SOC 2 Type II certified. Privacy policy: supabase.com/privacy Anthropic (AI model provider): document content is transmitted to Anthropic's API for processing. Anthropic is based in the United States. Data transfers are made under Anthropic's standard commercial and data protection terms. Privacy policy: anthropic.com/privacy AssemblyAI (audio/video transcription): used exclusively for the Video Review feature. Uploaded audio/video content is transmitted to AssemblyAI to generate a timestamped transcript. AssemblyAI is based in the United States. Privacy policy: assemblyai.com/legal/privacy-policy Vercel (hosting and content delivery): infrastructure provider for the web application. Privacy policy: vercel.com/legal/privacy-policy Stripe (payment processing): handles all payment card data. Stripe is PCI DSS Level 1 certified. Privacy policy: stripe.com/gb/privacy Resend (transactional email): used to send account and system emails. Privacy policy: resend.com/legal/privacy-policy Google Workspace (business email): used for business communications. Privacy policy: policies.google.com/privacy We maintain a current sub-processor list and will notify customers of material changes to sub-processors with reasonable notice.

9. International data transfers

For transfers to Anthropic and AssemblyAI (both US-based), data is processed under each provider's standard commercial and data protection terms.

10. Data retention

We retain your personal data for the following periods: Account data: retained for the duration of your account. Deleted within 30 days of account deletion. Review data and document content: retained for the duration of your account. Deleted within 30 days of account deletion. Source library documents: retained until you delete them or delete your account. Payment and billing records: retained for 7 years to comply with HMRC requirements. Server logs and technical data: retained for up to 90 days. Contact form submissions: retained for up to 12 months. Where we are required by law to retain data for longer periods, we will do so and will inform you where possible.

11. Your rights under UK GDPR

You have the following rights in relation to your personal data: Right of access: you may request a copy of the personal data we hold about you. Right to rectification: you may request correction of inaccurate or incomplete data. Right to erasure: you may request deletion of your personal data in certain circumstances. You can delete your account directly from the Settings page. Right to restriction: you may request that we restrict processing of your data in certain circumstances. Right to data portability: you may request a machine-readable copy of data you have provided to us. Right to object: you may object to processing based on legitimate interests. Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. To exercise any of these rights, contact us at thompson.daniel@primusreview.com. We will respond within one calendar month. We may ask you to verify your identity before processing your request. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

12. Cookies and tracking

We use the following cookies and tracking technologies: Strictly necessary cookies: a single session cookie used to keep you logged in. This cookie is essential for the service to function and cannot be disabled. Analytics: we use Vercel Analytics to collect anonymised usage data (page views, visitor counts, referral sources). Vercel Analytics does not use cookies and does not track individual users across sessions or websites. No personal data is collected by our analytics implementation. We do not use advertising cookies, third-party tracking pixels, or behavioural targeting technologies. You may decline non-essential cookies via our cookie consent banner. Declining analytics cookies will not affect your ability to use the service.

13. Data security

We implement the following technical and organisational security measures: - Encrypted connections (TLS 1.2 and above) for all data in transit - Encryption at rest for database storage via Supabase - Row-level security (RLS) ensuring users can only access their own data - Password hashing via Supabase Auth (bcrypt) - Access controls limiting administrative access to authorised personnel only - Regular dependency updates and security patching In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and will notify affected individuals without undue delay where required.

14. Children

Our service is intended for use by professionals working in the pharmaceutical, healthcare, and related industries. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly.

15. Changes to this policy

We may update this privacy policy from time to time. We will notify registered users of material changes by email with at least 14 days notice before the changes take effect. The current version will always be available at primusreview.com/privacy. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

16. Contact and complaints

For any questions, data subject requests, or complaints regarding this privacy policy or our data practices, contact us at: thompson.daniel@primusreview.com If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office: Information Commissioner's Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF Tel: 0303 123 1113 Website: ico.org.uk