Legal
Privacy policy
Last updated: July 25, 2026
Pharmalytics Consulting Group Inc., operating as Pharmalytics Group ("Pharmalytics Group," "we," "us," or "our"), respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you visit pharmalyticsgroup.com, communicate with us, request information, book a demonstration, apply for a position, or otherwise interact with Pharmalytics Group.
Our privacy practices are intended to reflect applicable privacy and data-protection requirements, including British Columbia's Personal Information Protection Act (PIPA), Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA), and, where applicable, European data-protection requirements. PIPA regulates the collection, use, and disclosure of personal information by private-sector organizations in British Columbia, while PIPEDA may apply to personal information handled in the course of commercial activities across provincial or national borders.
1. Information we collect
We may collect personal information that you provide directly to us, including:
- Name, job title, organization, and professional contact information
- Information submitted through contact, inquiry, or demonstration-request forms
- Communications and correspondence with our team
- Information provided during business-development discussions
- Information contained in requests for services, proposals, contracts, or related documentation
- Employment and professional information submitted in connection with a job application
- Communication and marketing preferences
When you use our website, we or our service providers may also collect certain technical and usage information automatically, such as Internet Protocol address; browser, device, and operating-system information; referring website or source; pages viewed and time spent on the website; approximate geographic location; cookie identifiers and similar technical data; and information about interactions with website features.
We do not intentionally collect patient-level information, identifiable health information, or other sensitive clinical information through our public website. Please do not submit confidential patient information or identifiable health information through a general website form.
2. How we use personal information
We may use personal information to:
- Respond to inquiries and communicate with you
- Provide information about our services, capabilities, and expertise
- Arrange consultations or demonstrations of [hta]DataMine™
- Understand your evidence, health technology assessment, reimbursement, or market access needs
- Evaluate potential engagements and prepare proposals
- Establish and manage client, supplier, consultant, and other professional relationships
- Deliver contracted services
- Operate, maintain, secure, and improve our website
- Analyze website use and engagement
- Send publications, professional updates, event information, or other communications where permitted
- Evaluate employment applications and manage recruitment
- Protect our personnel, systems, information, and business interests
- Investigate suspected fraud, misuse, or security incidents
- Meet legal, regulatory, professional, accounting, tax, and contractual obligations
We seek to identify the purposes for collecting personal information and limit its collection, use, and disclosure to appropriate and reasonable purposes. PIPEDA's fair information principles address accountability, consent, limited collection, safeguards, openness, access, and related privacy obligations.
3. Consent and other legal bases
We collect, use, and disclose personal information with consent where consent is required. Consent may be express or implied depending on the sensitivity of the information, the purpose of the interaction, and the surrounding circumstances.
Where European data-protection law applies, we may process personal information on one or more of the following legal bases:
- Your consent
- Performance of a contract
- Steps taken at your request before entering into a contract
- Compliance with a legal obligation
- Our legitimate interests in operating and developing our business, responding to inquiries, maintaining professional relationships, improving our services, and protecting our systems
- Establishment, exercise, or defence of legal claims
The General Data Protection Regulation may apply to an organization established outside the European Union where it offers goods or services to individuals in the European Union or monitors their behaviour there.
Where we rely on consent, you may withdraw it at any time, subject to applicable legal or contractual restrictions and reasonable notice.
4. Cookies and similar technologies
Our website may use cookies, pixels, local storage, and similar technologies to:
- Support essential website functionality
- Maintain security
- Remember preferences
- Understand website traffic and usage
- Measure engagement
- Improve website content and performance
- Support embedded content or third-party features
Some cookies may be necessary for the website to operate. Other cookies, such as optional analytics or advertising cookies, may require consent depending on the visitor's location and the technologies used.
You may be able to manage cookies through our cookie-preference tool or through your browser settings. Disabling certain cookies may affect website functionality.
5. Analytics and third-party services
We may use third-party providers to support:
- Website hosting and content management
- Website analytics and performance monitoring
- Cybersecurity and fraud prevention
- Email and business communications
- Customer-relationship management
- Appointment and demonstration scheduling
- Recruitment
- File storage and collaboration
- Information technology and administrative functions
These providers may process technical, usage, or contact information on our behalf. We seek to use service providers that maintain reasonable privacy and security practices and limit their use of personal information to the services they provide.
Some third-party services may collect information under their own privacy policies. We encourage you to review the privacy terms of any external platform you choose to use.
6. When we disclose personal information
We may disclose personal information to:
- Pharmalytics Group personnel who require the information for legitimate business purposes
- Affiliates, consultants, and authorized contractors
- Technology, hosting, analytics, communications, recruitment, security, and administrative service providers
- Professional advisors, including legal counsel, accountants, auditors, insurers, and compliance advisors
- Government, regulatory, judicial, or law-enforcement authorities where required or permitted by law
- A purchaser, investor, lender, successor, or other relevant party in connection with a proposed or completed financing, merger, restructuring, acquisition, sale, or transfer of all or part of our business
We may also disclose information with your consent or at your direction.
We do not sell personal information.
7. International processing and transfers
Pharmalytics Group operates internationally and has offices in Canada and India. Our clients, personnel, contractors, and service providers may also be located in other jurisdictions.
Personal information may therefore be stored, accessed, or processed outside the province, state, or country in which it was collected. Information processed in another jurisdiction may be subject to that jurisdiction's laws and may be accessible to courts, regulators, governments, or law-enforcement authorities in accordance with local law.
Where required, we use contractual, organizational, and technical measures designed to protect personal information transferred internationally. European data-protection rules provide mechanisms for international transfers, including adequacy decisions and standard contractual clauses.
8. Data retention
We retain personal information only for as long as reasonably necessary to:
- Fulfil the purpose for which it was collected
- Manage an inquiry, professional relationship, or contracted engagement
- Maintain appropriate business and professional records
- Meet legal, regulatory, contractual, accounting, tax, and insurance requirements
- Resolve disputes
- Establish, exercise, or defend legal claims
- Protect our legitimate business interests
Retention periods vary depending on the nature of the information, the purpose for which it was collected, and applicable legal or contractual requirements.
When information is no longer required, we may securely delete, destroy, anonymize, or de-identify it in accordance with our practices and applicable law.
9. Information security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information against:
- Loss or theft
- Unauthorized access
- Unauthorized collection, use, or disclosure
- Alteration
- Destruction
- Accidental or unlawful processing
Our safeguards may include access controls, authentication requirements, encryption, secure hosting, system monitoring, confidentiality obligations, staff training, vendor-management processes, and secure disposal procedures.
PIPA requires organizations to protect personal information against unauthorized use or disclosure, and PIPEDA requires safeguards appropriate to the sensitivity of the information.
No internet transmission, electronic communication, or storage system can be guaranteed to be completely secure.
10. Your privacy rights
Depending on your location and the law that applies, you may have the right to:
- Request access to personal information we hold about you
- Ask how your information has been used or disclosed
- Request correction of inaccurate or incomplete information
- Withdraw consent where processing is based on consent
- Request deletion of certain personal information
- Request restriction of certain processing
- Object to certain processing
- Object to direct marketing
- Request information in a portable format
- Submit a complaint to an applicable privacy or data-protection authority
British Columbia's PIPA gives individuals a right to request access to their personal information held by a private-sector organization. European data-protection law may provide additional rights, including rights relating to deletion, restriction, objection, and portability.
These rights may be subject to statutory limitations, exceptions, identity-verification requirements, and obligations to retain certain records.
To submit a request, contact our Privacy Officer using the details below.
11. Marketing communications
We may send professional updates, publications, event information, or information about our services where you have consented or where otherwise permitted by law.
You may unsubscribe from promotional emails by:
- Using the unsubscribe link included in the message
- Contacting us directly
- Updating your communication preferences, where available
We may continue to send non-promotional communications relating to an existing engagement, inquiry, contractual relationship, security matter, or legal obligation.
Canada's Anti-Spam Legislation generally requires prior express or implied consent, sender identification and contact information, and a working unsubscribe mechanism for commercial electronic messages.
12. Recruitment information
When you apply for a position, we may collect information such as:
- Contact details
- Résumé or curriculum vitae
- Employment history
- Education and professional qualifications
- References
- Work authorization information
- Interview notes and correspondence
- Other information you choose to provide
We use this information to evaluate your application, communicate with you, verify information where appropriate, and manage recruitment.
With your consent, we may retain application information for consideration in relation to future opportunities.
13. External links
Our website may contain links to:
- Third-party websites
- Journal and publication websites
- Professional profiles
- Social-media platforms
- Regulatory or health technology assessment agency websites
- Other external resources
We do not control and are not responsible for the privacy, security, availability, or content practices of third parties. Accessing an external link is subject to the third party's terms and privacy policy.
14. Automated processing and artificial intelligence
We may use automation, artificial intelligence, machine learning, and other computational tools to support internal operations, website functionality, analytics, research workflows, or service delivery.
Where personal information is involved, we seek to use these tools in a rigorous, transparent, and responsible manner and apply appropriate human oversight, confidentiality requirements, and security controls.
We do not use information submitted through our public website to make solely automated decisions that produce legal or similarly significant effects about website visitors, unless this is specifically disclosed and permitted by applicable law.
Please do not submit confidential, proprietary, patient-identifiable, or otherwise sensitive information through general website forms.
15. Changes to this privacy policy
We may update this Privacy Policy periodically to reflect changes in:
- Our business practices
- Website functionality
- Technology and service providers
- Legal or regulatory requirements
- Privacy and security practices
The revised policy will be posted on this page with an updated effective date. Where appropriate, we may provide additional notice of material changes.
16. Contact us
Questions, concerns, complaints, or requests relating to this Privacy Policy or our handling of personal information may be directed to:
Privacy Officer
Pharmalytics Consulting Group Inc., operating as Pharmalytics Group
Email: privacy@pharmalyticsgroup.com
General inquiries: info@pharmalyticsgroup.com
Telephone: +1 778 620 2505
Vancouver, British Columbia
Canada
