Alcor Bio

Privacy policy

Last updated 27 September 2026

Who we are

Alcor Bio (“we”, “us”) provides a software platform that helps biotech and pharmaceutical companies identify and contact key opinion leaders (KOLs) and clinical investigators. For privacy questions or to exercise your rights, email privacy@alcorbio.com.

Two kinds of personal data

1. Professionals in our database

We maintain a database of healthcare professionals and researchers, built from publicly available professional sources such as scientific publications (for example PubMed), clinical trial registries (for example ClinicalTrials.gov and the EU Clinical Trials Register), public healthcare provider registries, institution websites and conference programmes. For each person we may hold: name, credentials, job title, institution, work location, professional email and phone, specialty, therapeutic areas, publications, clinical trial experience and industry collaborations, together with the source of the information. We do not collect health data about patients, and we do not collect information about private life.

Why and on what basis. We process this information so that life-science companies can find the right experts for clinical research and scientific collaboration. Where the EU or UK GDPR applies, our legal basis is our and our clients' legitimate interest in scientific and clinical collaboration, which we have balanced against the interests of the people concerned (professional data only, professional purpose only, easy objection).

Who receives it. Our business clients can search the database. When a client adds a person to one of its studies, that client receives their professional contact details and becomes responsible for how it contacts them.

2. Users of our platform

When our clients' staff use Alcor Bio we process their account details (name, work email, password in hashed form), their activity in the platform, and the content they create (studies, notes, campaigns, messages). We process this to provide the service under our contract with their employer, which acts as the controller of the outreach it carries out; for that outreach we act as its processor.

Your rights

You can ask us for a copy of the information we hold about you, ask us to correct it, object to its use, or ask us to delete it. Write to privacy@alcorbio.com; we answer within one month. If you ask to be deleted, we remove you from our database and from every client's copy that came from it, and we keep only an irreversible fingerprint of your email address so that you are never added again. Every email sent through Alcor Bio contains an unsubscribe link that stops that sender from contacting you. You may also complain to your data protection authority.

Google and Microsoft account data

Client users may connect a Gmail / Google Workspace or Microsoft 365 / Outlook mailbox so that Alcor Bio can send the emails they write from their own address and detect replies to those emails. With their permission we access only what this requires: sending messages on their behalf, and reading messages in the conversations started from Alcor Bio to detect and display replies. We store the access tokens encrypted. We do not use mailbox data for advertising, we do not sell it, we do not use it to train artificial intelligence models, and people at Alcor Bio do not read it except with the user's explicit permission, for security reasons, or where the law requires.

Alcor Bio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Users can disconnect a mailbox at any time in Alcor Bio or in their Google or Microsoft account settings.

Where the data is kept, and for how long

Our database is hosted by Supabase in the European Union (Frankfurt, Germany). The application runs on Vercel. These providers act as our processors under data processing agreements; where data leaves the EU, we rely on the European Commission's standard contractual clauses or an adequacy decision. We keep database entries while they remain professionally relevant and review them periodically; client content is kept for the length of the client's subscription and deleted afterwards.

Security

Each client's data is isolated at the database level, administrative access requires two-step login, mailbox tokens are encrypted, and all traffic is encrypted in transit.

Changes

We will update this page if our practices change, and change the date at the top.