Data policy
Data handling and privacy
Identifying material is held apart from operational research records and is reachable only by the roles a protocol authorizes.
Separation and coding
Names and identifying details are stored in restricted tables. Operational records refer to participants by opaque codes only.
Access control
Access is granted per role and, where applicable, per study. Researcher access does not include private target information. Administrators can manage permissions but not read restricted material silently.
Logging
Every sensitive operation writes an append-only entry recording the user, acting role, timestamp, action, resource, study and request metadata where available. Log entries cannot be edited or deleted.
Storage
Recordings, transcripts and signed consent documents are kept in private storage with per-role access rules. Nothing is publicly readable.
Withdrawal and deletion
Participants may withdraw at any time. On request, identifying material is deleted while coded, non-identifying research records may be retained for the integrity of published analyses; the retention state is recorded.