“ClinicalOS”
The clinical trial operating system developed and operated by ClinicalOS, Switzerland.
“Platform”
The ClinicalOS web application, APIs, and all associated services accessible at clinicalos.com.
“User”
Any individual who accesses the Platform through an authorized account.
“Organization”
The legal entity (pharmaceutical company, CRO, research institution) that holds a subscription to the Platform.
“Service”
The decision support, data aggregation, AI scoring, and trial management features provided by the Platform.
“Data”
Any information processed, generated, or stored within the Platform, including public registry data, user inputs, and AI-generated outputs.
ClinicalOS is classified as a Decision Support Tool. The Platform is designed to assist clinical operations professionals by providing data aggregation, AI-powered scoring, and analytical insights.
ClinicalOS is not validated for GxP-regulated use as a system of record.
All outputs are recommendations requiring human review and validation before use in clinical decisions.
ClinicalOS provides recommendations and decision support. Clinical decisions remain the sole responsibility of the sponsor and their qualified personnel.
ClinicalOS processes data in accordance with applicable data protection laws, including the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
Module 1 — Site and Investigator Intelligence
Uses publicly available data only (ClinicalTrials.gov, PubMed, EudraCT, WHO ICTRP). No patient-identifiable data is processed in this module.
Data Hosting
All data is hosted in Switzerland on Google Cloud Platform (region europe-west6, Zurich). Data does not leave Swiss or EU jurisdiction.
Future Patient Modules
Modules involving patient data will comply with GDPR Article 9 (special categories of personal data) and require explicit consent and a documented legal basis for processing.
Data Processing Agreement
A Data Processing Agreement (DPA) is available on request for Organizations requiring formal data processing documentation.
ClinicalOS implements industry-standard security measures to protect user data and platform integrity.
Encryption in Transit
TLS 1.3 for all data in transit between client and server.
Encryption at Rest
AES-256 encryption for all data stored at rest.
Tenant Isolation
Multi-tenant isolation enforced via org_id on all database queries.
Access Control
Role-based access control (RBAC) with 4 permission levels: Super Admin, Org Admin, User, Read Only.
A comprehensive audit trail is maintained for all user actions within the Platform. Audit logs are immutable and retained in accordance with applicable regulatory requirements.
These Terms of Service shall be governed by and construed in accordance with the substantive laws of Switzerland, without regard to its conflict of law provisions.
Any disputes arising out of or in connection with these Terms shall be submitted to the exclusive jurisdiction of the courts of Zurich, Switzerland.
If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
Effective Date: April 1, 2026
ClinicalOS, Switzerland
© 2026 ClinicalOS. All rights reserved.