Last Updated: June 15, 2025
At RAN BIOLINKS CANADA LTD, the developers of MAESTRO, we are committed to ensuring the highest standards of data protection and privacy for all our users, particularly in relation to the European Union's General Data Protection Regulation (GDPR). As a Canadian company providing a platform that facilitates clinical research globally, we understand the critical importance of handling personal data with the utmost care and in full compliance with applicable data protection laws, both Canadian and international.
In accordance with GDPR requirements, RAN BIOLINKS CANADA LTD adheres to the following key principles when processing personal data:
RAN BIOLINKS CANADA LTD ensures that all processing of personal data is done on one of the following legal bases:
As a clinical research platform, MAESTRO may process special categories of personal data, including health data. We ensure that such processing is carried out in accordance with Article 9 of the GDPR, which requires additional conditions to be met, such as explicit consent or processing for medical diagnosis, the provision of health or social care, or scientific research purposes.
RAN BIOLINKS CANADA LTD respects and facilitates the rights of individuals under the GDPR, including:
RAN BIOLINKS CANADA LTD implements appropriate technical and organizational measures to ensure data protection by design and by default. This includes:
RAN BIOLINKS CANADA LTD conducts Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to the rights and freedoms of natural persons, particularly when using new technologies or when processing sensitive data on a large scale.
As a Canadian company, RAN BIOLINKS CANADA LTD benefits from Canada's adequacy status under GDPR for data transfers from the EU to Canada. Nevertheless, for transfers to other countries, we ensure that any transfer of personal data is subject to appropriate safeguards, such as:
RAN BIOLINKS CANADA LTD has procedures in place to detect, report, and investigate personal data breaches. In the event of a breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will also communicate the breach to the affected data subjects without undue delay.
RAN BIOLINKS CANADA LTD has appointed a Data Protection Officer (DPO) who is responsible for monitoring compliance with the GDPR and other data protection laws, providing advice on data protection matters, and cooperating with supervisory authorities. The DPO can be contacted at [email protected].
RAN BIOLINKS CANADA LTD provides regular training to its staff on data protection principles, procedures, and best practices. We ensure that all staff members are aware of their responsibilities under the GDPR, Canadian privacy laws, and other applicable data protection regulations.
RAN BIOLINKS CANADA LTD conducts due diligence on all third-party service providers who process personal data on our behalf to ensure they have appropriate technical and organizational measures in place to protect personal data. We enter into data processing agreements with these providers that comply with the requirements of the GDPR.
RAN BIOLINKS CANADA LTD maintains records of processing activities as required by Article 30 of the GDPR. These records include information about the purposes of processing, categories of data subjects and personal data, recipients of personal data, transfers to third countries or international organizations, time limits for erasure, and a general description of technical and organizational security measures.
RAN BIOLINKS CANADA LTD regularly monitors and reviews our compliance with the GDPR, Canadian privacy laws (including PIPEDA), and other applicable data protection laws. We update our policies, procedures, and practices as necessary to ensure ongoing compliance.
Given the nature of clinical research, RAN BIOLINKS CANADA LTD implements specific measures to protect the privacy and rights of clinical trial participants, including:
If you have any questions or concerns about our GDPR compliance or how we handle personal data, please contact our Data Protection Officer at [email protected] or write to us at:
RAN BIOLINKS CANADA LTD
10212 Yonge Street, 202, Richmond Hill, Ontario, Canada, L4C 3B6