Privacy Notice
Last engineering verification: 5 September 2026
1. Who is responsible for personal data
Emerging Pharma Tech is the controller responsible for the personal data described in this notice and operates the Emerging Pharma Tech service.
Privacy enquiries and requests can be sent to admin@emergpharma.com.
Emerging Pharma Tech, Innovation One, Level 1, DIFC, Dubai, UAE
2. Scope
This notice applies to personal data processed through the Emerging Pharma Tech web application, including account registration and authentication, user profiles, intelligence workspaces, support and upgrade requests, administration, imports and exports, security monitoring, and transactional email.
3. Personal data we process
- Account and authentication data: email address, encrypted password-related records, verification and account status, authentication and refresh token identifiers, and security state.
- Profile and professional data: name, display name, company, job title, country, phone number, biography, and avatar URL where provided.
- Upgrade and contact data: the contact details and optional message submitted with an upgrade request or support communication.
- Workspace and product-use data: saved searches, shortlist and comparison selections, filters, revisions, and actions used to provide requested intelligence features.
- Administrative and submitted-content data: import files, status and validation results, exports, and administrative audit records.
- Technical, security, and diagnostic data: IP address where recorded, timestamps, request identifier, user agent, route without query values, redacted error and stack information, performance timing, and release/environment metadata.
- Communication-delivery data: recipient and sender addresses, message content, and delivery metadata needed for account and service email.
We do not intentionally collect special-category health data about users through account or profile fields. Users and administrators should not submit health data or other sensitive personal data that is unnecessary for the service.
4. Where data comes from
Data comes directly from users and authorized organization administrators, from use of the service, and from an enabled identity provider when a user chooses social sign-in. Technical data is generated by the browser, application servers, security controls, and approved infrastructure and diagnostic providers.
5. Why we process data and legal bases
The legal basis depends on the purpose, the relationship, and applicable law.
- Provide and administer accounts and requested intelligence features.
- Protect accounts, prevent misuse, investigate incidents, and maintain auditability.
- Diagnose errors, monitor performance, and maintain availability.
- Send verification, password-reset, security, account, and service messages.
- Review and respond to upgrade or support requests.
- Meet applicable legal, regulatory, security, and dispute obligations.
These purposes rely, as applicable, on contract performance or requested pre-contract steps, legitimate interests in a secure and reliable business service, and legal obligations or claims. Optional uses will not be enabled until their required basis and controls are established.
6. Processors and other recipients
We do not sell personal data. We do not disclose it for unrelated third-party advertising. We use approved processors and disclose only the limited data required for them to provide contracted infrastructure, communications, identity, and diagnostic services under applicable contractual and security controls.
- Amazon Web Services (AWS) provides infrastructure, private storage, encrypted backups, network, and key-management services. Verified direct-import staging uses private KMS-encrypted storage in Frankfurt.
- Amazon Simple Email Service (SES) processes addresses, message content, and delivery metadata needed for transactional service email.
- Sentry processes redacted application errors and sampled performance traces when diagnostics are enabled.
- An enabled social sign-in provider processes an OAuth request only when configured and chosen by the user.
- Professional advisers, authorities, or transaction parties receive data only where reasonably necessary for legal compliance, claims, security, or a transaction.
Account-specific provider settings, contractual records, subprocessors, and retention details are maintained and reviewed internally rather than guessed in this notice.
7. Sentry diagnostic safeguards
Sentry diagnostics require explicit enablement and a project DSN. Browser and backend configurations set send_default_pii=False. Application controls remove cookies, request bodies, query strings, unauthorized request headers, browser user identity and context, authorization values, email-like text, tokens, secrets, credentials, and presigned URLs before transport. Session Replay is disabled.
Error events can still contain technical exception details, stack information, route paths, release/environment identifiers, and other redacted metadata needed to diagnose a fault. Default performance sampling is 10%; profiling defaults to 0%. Diagnostic events follow contracted account retention settings and are kept only as long as needed for reliability and security purposes.
8. International transfers
Providers and their subprocessors may process data outside the user's country. The verified direct-import storage Region is Frankfurt, but server location alone does not determine applicable law or establish where every processor handles data.
Where required, transfers rely on an adequacy decision or safeguards such as an applicable Data Processing Addendum and Standard Contractual Clauses, with any required transfer assessment and supplementary measures.
9. Retention
We retain personal data only for as long as needed for the purposes described, security and legal requirements, and claims. Access authentication cookies last 15 minutes, rotating refresh cookies last up to 14 days, the CSRF cookie lasts up to 364 days, and thesessionid security access-log cookie lasts up to 14 days. The strictly necessary messages cookie carries transient verification feedback until consumed or the browser session ends; it is first-party, host-only, path /,HttpOnly, Secure and SameSite=Lax (verified 5 September 2026). Verified direct-import staged objects expire after 7 days, incomplete multipart uploads are aborted after 1 day, and local database-backup retention defaults to 14 days.
Account, workspace, audit, diagnostic, email, identity-provider, and protected backup records follow documented purpose, account, provider, legal-hold, security, and deletion criteria where no fixed period is encoded. We do not publish a guessed duration.
10. Security
Controls include HTTPS transport, production Secure cookies,HttpOnly authentication cookies, CSRF protection, rotating and blacklisted refresh tokens, password controls, tier-scoped authorization, private KMS-encrypted storage, restricted roles, encrypted backups, and structured diagnostic redaction.
No security measure eliminates all risk. Report suspected misuse to admin@emergpharma.com.
11. Rights and choices
Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a supervisory authority. Some rights are conditional and exceptions may apply. Requests may be sent to admin@emergpharma.com. We may verify identity and authority without collecting disproportionate data.
12. Children
Emerging Pharma Tech is a professional business intelligence service and is not directed to children. If we learn that a child has provided personal data where processing is not permitted, we will take appropriate steps under applicable law.
13. Changes to this notice
We review this notice when material processing, processors, cookies, storage, retention, security behavior, or applicable requirements change. Material changes will be communicated as required by applicable law.