Privacy Policy
This policy explains what data ClinicalMetric collects, why, and how you can control it. We are based in Greece and operate under the EU General Data Protection Regulation (GDPR).
1. Data Controller
The data controller responsible for your personal data is:
Kerasountos 94, Aigaleo 12242, Greece
GEMI: 181077901000
Email: legal@clinicalmetric.com
2. What Data We Collect
a) Email address — if you subscribe to our free weekly clinical trial alerts. Collected via Google Forms and stored in a private Google Sheet accessible only to ClinicalMetric. Used solely to send the weekly digest. You can unsubscribe at any time (see Section 6).
b) Usage data via Google Analytics 4 — pages visited, session duration, device type, country. Collected only after cookie consent. Pseudonymised. Used to understand which content is useful. We do not identify individuals.
c) Advertising data via Google AdSense — if you accept cookies, Google may serve personalised ads. Google acts as an independent data controller. See Google's Privacy Policy.
d) Contact form data — name and email when you contact us. Used only to respond. Not retained beyond 12 months.
3. Legal Basis for Processing
| Processing Activity | Legal Basis (GDPR Art. 6) |
|---|---|
| Email newsletter subscription | Consent (Art. 6(1)(a)) |
| Google Analytics (with cookie consent) | Consent (Art. 6(1)(a)) |
| Google AdSense (with cookie consent) | Consent (Art. 6(1)(a)) |
| Contact form response | Legitimate Interest (Art. 6(1)(f)) |
| Server logs (security, error monitoring) | Legitimate Interest (Art. 6(1)(f)) |
4. Cookies
We show a cookie consent banner on your first visit. Until you accept, Analytics and AdSense cookies are blocked.
| Cookie | Purpose | Duration |
|---|---|---|
| cm_cookie_consent | Stores your cookie consent choice | localStorage (persistent) |
| _ga, _ga_* | Google Analytics — distinguish users | 2 years |
| Google AdSense | Personalised advertising (if accepted) | Varies (Google-controlled) |
To withdraw cookie consent: clear your browser localStorage and cookies, refresh the page — the banner reappears. Opt out of personalised ads at Google Ads Settings.
5. Third Parties & Data Sharing
We do not sell your personal data. We share data only with:
- Google LLC — Analytics and AdSense. Data may be transferred outside the EU under Standard Contractual Clauses.
- Brevo (Sendinblue) — Contact form delivery only. Your email is not added to marketing lists via Brevo.
- Cloudflare — Infrastructure. Processes request metadata (IP, headers) for security and performance.
- Sponsor / Advertiser partners — ClinicalMetric offers sponsored article placements. If you click a sponsored link, the destination site may set its own cookies. We receive no personal data from these clicks.
6. Email Alerts — Subscription & Unsubscribe
When you subscribe to weekly trial alerts, your email is stored in a private Google Sheet. We use it only to send the weekly digest.
To unsubscribe: reply to any alert email with "unsubscribe" in the subject, or email legal@clinicalmetric.com. We process removals within 5 business days. There is no automated unsubscribe link — removals are manual.
7. Data Retention
- Email newsletter subscribers: until you unsubscribe or request deletion
- Contact form messages: up to 12 months after last correspondence
- Google Analytics data: 14 months (configured in GA4 settings)
- Server access logs: up to 30 days (Cloudflare default)
8. Your Rights Under GDPR
As an EU resident, you have the right to:
- Access — request a copy of the personal data we hold about you
- Erasure — request deletion ("right to be forgotten")
- Rectification — ask us to correct inaccurate data
- Restriction — ask us to limit processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interest
- Withdraw consent — at any time, without affecting prior processing
Email legal@clinicalmetric.com. Response within 30 days. You may also lodge a complaint with the Hellenic Data Protection Authority at dpa.gr.
9. Children's Privacy
ClinicalMetric is not directed at children under 16. We do not knowingly collect data from minors. Contact legal@clinicalmetric.com if you believe a child has submitted data and we will delete it immediately.
10. Changes to This Policy
Material changes will be reflected in an updated "Last Updated" date. We encourage periodic review of this page.
Contact & Data Requests
For any privacy question, data access request, or unsubscribe request:
legal@clinicalmetric.com
Response: up to 5 business days for unsubscribes, up to 30 days for GDPR rights requests.