General Privacy Policy

Privacy Statement Summary:

This Privacy Policy (“Policy”) explains how your information is collected, used, and disclosed by ZoomRx Inc. (“We” or “Us" or “Our”). This policy applies where we are acting as a Data Controller with respect to the personal data of the doctors, healthcare professionals, other participants involved in our market research activities, and all other individuals whose data we process. This also applies to data relating to individuals who visit our website and use other services; in other words, where we determine the purposes and means of the processing of that personal data.

We are committed to safeguarding the privacy of our data subjects. We will never sell, share, or use your personal information other than as described here.

By agreeing to be involved, and sharing your data with us, you agree to the terms of this policy.

Who will use your data?

ZoomRx Inc.

Who are we?

We are a full-service strategic healthcare consulting agency providing primary market research across all stages of the drug lifecycle. We are market leaders in Promotional Effectiveness Tracking; ATU and Brand Equity Tracking; and Chart Audits with integrated Health Care Professionals [HCPs]-Patient recorded dialogue. We also provide advanced market demand and opportunity assessment and communication testing. Our Customer Engagement Center of Excellence team offers advanced analysis, secondary data integration, and interactive real-time dashboards. Our Ferma.AI team offers an Artificial Intelligence tool for conference coverage and competitive intelligence.

What for? (Purpose)

We store and process data in order to provide our consulting and market research services. We act on behalf of pharmaceutical, biotech, and medical device companies and conduct market research campaigns to gather feedback from medical professionals relating to the use of their medical products, devices, treatments, drugs, medications, etc. We also provide consultancy services which may involve collaboration with healthcare professionals, representatives from relevant organisations, and others.

We will store and process your data only in order to allow us to provide our services as a strategic healthcare market research and consulting agency. If you contact us using our Contact Us form, by email, or by any other means, we will respond to your enquiry and may also send you information that we think you will be interested in. This may include a range of related services as stated above.

If you choose to use our services, you are agreeing to the collection, processing, storage, and use of your personal information as required to provide and improve those services. We will not use or share your data with anyone except as described in this Privacy Policy.

As per our legal obligations, we may need to send details to relevant authorities or any other organisation that requires them by law.

How do we collect your personal data?

Most of the personal information we process is provided directly by you for one of the following reasons:

Where we have an appropriate lawful reason we may also collect your data from other third parties, advertising networks, social media, or other publicly available sources.

What will happen if you contact us?

The data we collect is used by ZoomRx Inc. to provide our services to you. We may share your data with other companies / organisations / people as required to provide our services or operate our company; however, unless required to do so by law, we will not otherwise share, sell, or distribute any of the information you provide to us without your consent.

What data will be stored?

We collect and store only a limited amount of data – we collect only the data we require to manage our relationship with you, to provide our services to our clients, and to run and develop our company.

To provide you with our services, we are required to store your relevant information relating to enquiries, such as contact information, financial information,etc.

If you choose to use our strategic healthcare consulting services as a client, we will store information such as:

If you choose to apply for a job for one of our open roles through the application form, we will store your personal details such as:

With your consent we may add any testimonials or other references to our website, newsletters, our social media, or through other publicly available channels. If you visit our website we will collect only information relating to your browsing activity, obtained using our cookies and similar technology.

What data will be shared?

We will not share your data with any third parties other than as described in this policy, and as you would reasonably expect. We may need to share your information with regulators or legal bodies that request it.

We will not share your data with any third parties other than as required to fulfil our contracts and as described here. We will only share any data that is particularly relevant to our process in order to provide the services that we offer.

How long will data be stored?

Your data will be stored only for as long as strictly necessary to provide our services, to meet our obligations to you and meet our legal obligations. For more information, please contact us about our Data Retention Policy.

Who can access my data?

We will never sell, share, or otherwise distribute your data to any other third party other than as described here.

We will share your information with any regulator or legal body that requests it, as well as any parties relevant to the application process.

We ensure access is restricted to only those persons authorised by us to access your data.

Access to your data is strictly controlled. For more information, please contact us about our Information Security Policy.

Who do we share data with?

We only share your data with trusted and relevant companies which ensure an adequate level of protection and where there is an appropriate agreement in place, which includes obligations in relation to the confidentiality, security, and lawful processing of any personal data shared with them.

For example, we share your personal data with trusted companies such as:

How is my data kept secure?

We will store your data on secure based servers. We use industry-standard security protocols/technology to secure your data.

Where data is transferred from the UK and/or EU to other countries we will take all appropriate precautions to protect your data, including establishing DPA/SCCs and completing risk assessments.

We take your privacy seriously and will only use your personal information to provide the services you have requested from us and to send you information about services you may be interested in. We will never sell, share, or use your personal information other than as described here.

About This Privacy Policy

This policy sets out how we will use and share the information that you give us. This policy describes your relationship with ZoomRx Inc. The General Data Protection Regulation (GDPR) describes how organisations must collect, handle, process, and store personal information.

These rules apply regardless of whether data is stored electronically, on paper, or on other materials. To comply with the law, personal information must be collected and used fairly, stored safely, and not disclosed unlawfully. GDPR is underpinned by eight important principles. These say that personal data must:

We take these responsibilities seriously; this document describes our approach to data protection. This policy helps to protect us from data security risks, including:

Who We Are And How To Contact Us

ZoomRx Inc. is registered in the US and India. The Data Protection Lead is Kendall Anderson. You can contact us in any of the following ways:

Email: [email protected]

Address: ZoomRx, 245 Main Street, Floor 2, Cambridge, Massachusetts, 02142, US

ZoomRx, No-73, 2nd Street, Karpagam Avenue, Raja Annamalaipuram, Chennai – 600 028, IN

Our UK Representative:

Under Article 27 of the UK Data Privacy Act, we have appointed a UK Representative to act as our data protection agent. Our nominated UK Representative is: GDPR Local Ltd.

Adam Brogden: [email protected]

Tel +44 1772 217800

1st Floor Front Suite,
27-29 North Street, Brighton,

Who This Privacy Policy Applies To

Processing of your data is required in order to offer you our services. This policy relates to every data subject that chooses to share their personal data with us; data subjects whose data is provided to us by a third party; data subjects where we collect, store, or process their data in order to provide our services; and all other data subjects whose data we process in order to operate and develop our company.

It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the GDPR. This can include:

Our Lawful Basis

This section describes our lawful basis for processing:

We will only use your personal data for the purposes for which we collected it and as you would reasonably expect your data to be processed, and only where there is a lawful basis for such processing, for example:

Purpose/Activity Type of data Lawful basis for processing
To register you as a new customer a) Identity,
b) Contact,
c) Financial
a) Performance of a contract with you,
b) Consent,
c) In our legitimate interest
To process and deliver the products and services you request including digital signages, and to manage payments, fees, and charges. a) Identity,
b) Contact,
c) Financial,
d) Transaction,
e) Marketing and Communications
a) Performance of a contract with you,
b) Necessary for our legitimate interests to recover debts owed to us,
c) Consent
To manage our ongoing relationship with you which will include notifying you about changes to our terms, services or privacy policy, to maintain our records. a) Identity,
b) Contact,
c) Profile,
d) Marketing and Communications
a) Performance of a contract with you,
b) Necessary to comply with a legal obligation,
c) Necessary for our legitimate interests to keep our records updated and to study how customers use our services,
d) Consent
To administer and protect our business and our site (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data). a) Identity,
b) Contact,
c) Technical
a) Necessary for our legitimate interests for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise,
b) Necessary to comply with a legal obligation,
c) Consent
To use data analytics to improve our website, services, marketing, customer relationships and experiences. a) Technical,
b) Usage
a) Necessary for our legitimate interests to define types of customers for our services, to keep our site updated and relevant, to develop our business and to inform our marketing strategy,
b) Consent
To make suggestions and recommendations to you about services that may be of interest to you. a) Identity,
b) Contact,
c) Technical,
d) Usage,
e) Profile
a) Necessary for our legitimate interests to develop our services and grow our business,
b) Consent

Personal data we receive will be used for the purposes it was provided, including but not limited to:

In accordance with your preferences, we may also use your personal information to provide you with information about services, promotions, and offers that may be of interest to you. This document explains how you can change whether to receive this information. Please note that even if you choose not to receive this information, we may still use your personal information to provide you with important services and communications, including communications in relation to any purchases you make or services you use.

How To Change Your Preferences

We operate in line with GDPR data protection guidelines. We respect your rights and will respond to any request for access to personal information and requests to delete, rectify, or transfer data, or to stop processing. We will also advise you on how to complain to the relevant authorities. Any requests or objections should be made in writing to the Data Controller, or you can visit our website, call, or email us to contact us to change your preferences at any time.

We may from time to time use your information for marketing, account management, or relationship management purposes. The main purpose of this is to provide you with information about services which we think may be of interest to you and/or to maintain any existing relationship we may have with you. You will be able to change your preferences at any time by the methods described in this document.

Where you give your consent for us to process your data you can contact us to amend or withdraw your consent at any time. You can also choose to object to processing and request deletion of your data. We respect all user rights as defined in GDPR. If you have any comments or wish to complain, please contact us.

How We Store & Process Your Data

Your data will be collected, stored, and processed primarily in the US and India. Where we transfer your data outside our borders, we will ensure we take appropriate precautions to protect this data. Your data will be stored only for as long as strictly necessary to ensure we have records of services and other interactions. For more information, please contact us about our Data Retention Policy.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to find out more about how the processing for the new purpose is compatible with the original purpose, please email us. If we need to use your personal data for a purpose unrelated to the purpose for which we collected the data, we will notify you and we will explain the legal ground for processing.

We may be legally obliged to disclose your personal information without your knowledge to the extent that we are required to do so by law; in connection with any ongoing or prospective legal proceedings; in order to establish, exercise, or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk); to any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information.

You will only receive marketing communications from us if you have:

We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.

Our Obligations

We are a Data Controller. In relation to the information that you provide to us, we are legally responsible for how that information is handled. We will comply with the GDPR in the way we use and share your personal data.

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Third Parties

We may have to share your personal data with the parties set out below for the purposes described in this document:

Under the GDPR, we are also permitted to share some information with third parties who use such data for non-marketing purposes (including credit and risk assessment and management, identification and fraud prevention, debt collection, and returning assets to you).

We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.


We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know such data. They will only process your personal data per our instruction, and they are subject to a duty of confidentiality.

We will report any breaches or potential breaches to the appropriate authorities within 24 hours and to anyone affected by a breach within 72 hours. If you have any queries or concerns about your data usage, please contact us.

This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.


A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added, and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes, and dislikes by gathering and remembering information about your preferences. We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes, and then the data is removed from the system.

Overall, cookies help us provide you with a better website experience by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.

As well as your ability to accept or reject cookies, we also require your permission to store cookies on your machine, which is why when you visit our site, you are presented with the ability to accept our terms of use, including the storage of cookies on your machine. Should you not accept, then you are free to leave our website at any time.

For California, Virginia, Colorado, Utah, and Connecticut residents

Your Rights Under the California Consumer Protection Act, Virginia Consumer Data Protection Act, Colorado Privacy Act, Utah Consumer Privacy Act, and Connecticut Data Privacy Act pursuant to the state regulations, and subject to certain exceptions and limitations, residents of the above states can contact ZoomRx to exercise the rights described below with respect to certain personal information that ZoomRx holds about them. To the extent those rights apply to you, they are described below. ZoomRx also handles certain personal information on behalf of ZoomRx customers. You should contact those customers to exercise any rights you may have with respect to that personal information.

Right to Know About Personal Information Collected, Disclosed, or Sold

You have the right to request that we provide you with details about the personal information we collect, use, disclose and sell. ZoomRx reserves the right to verify your identity to our satisfaction, including by asking you to log into your account if you have one.

You are entitled to receive the following:

Because ZoomRx has disclosed or sold personal information to third parties in the last 12 months, you are also entitled to receive:

Right to Request Deletion of Personal Information

You have the right to request deletion of the personal information we have collected about you (subject to some exceptions). You can submit your request as described above, and we reserve the right to conduct the verification described above.

Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights

You have the right not to receive unlawful discriminatory treatment by ZoomRx for the exercise of your privacy rights.

Right to Opt-Out of Sale of Personal Information

You have the right to opt-out of the sale of your personal information by ZoomRx. You may request to opt-out by sending an email to [email protected].

List of Categories of Personal Information to be Collected and May Have Been Sold or Disclosed
Categories of Personal Information Collecte

ZoomRx collects personal information from research participants during and after registration with a panel, including, without limitation, during participation in a survey and in connection with the receipt and redemption of rewards and incentives and/or during the Application/Services registration and download process.

The categories of personal information we may collect include:

“Identifiers” such as:

All of the information above was collected for the purposes described. These purposes, which are described further in that section of our Privacy Policy, include but are not limited to the following examples:

Categories of Personal Information that May Have Been Sold

ZoomRx sold all of the above categories of personal information in the last 12 months.

Categories of Personal Information that Were Disclosed

ZoomRx disclosed all of the above categories of personal information in the last 12 months.

Contacting Us, Exercising Your Information Rights & Complaints

If you have any questions or comments about this Privacy Policy, wish to exercise your information rights in connection with the personal data you have shared with us, or wish to complain, please contact:

Email: [email protected]

Address: ZoomRx, 245 Main Street, Floor 2, Cambridge, Massachusetts, 02142, US

ZoomRx, No-73, 2nd Street, Karpagam Avenue, Raja Annamalaipuram, Chennai – 600 028, IN

We will process data protection requests within 30 days. Subject Access Requests (SARs) are usually free, but we reserve the right to charge for excessive or unfounded requests. We fully comply with Data Protection legislation and will assist in any investigation or request made by the appropriate authorities. If you remain dissatisfied, then you have the right to apply directly to the relevant Supervisory Authority.