Privacy policy
What we collect, why we hold it, and what you can ask us to do with it.
Who we are
MedAchievers operates a research panel of verified healthcare professionals and carries out market research on behalf of pharmaceutical, medical device, diagnostics and consulting clients. For the purposes of India's Digital Personal Data Protection Act 2023 we are the Data Fiduciary for the personal data described here; under the UK and EU GDPR we act as Controller for our panel data and as Processor where a client supplies their own sample.
What we collect
From panel members: name, contact details, professional role, clinical specialty, professional registration number, country and state, year of birth, gender, and the records generated when we verify those details. From research buyers who contact us: name, work email, organisation and whatever you choose to put in your enquiry. From everyone: basic technical data such as IP address and browser type, collected by our hosting when a page is served.
Why we hold it
Panel data is held to confirm that a member is a practising healthcare professional, to match them to relevant studies, and to pay them. Enquiry data is held to answer you and, if we work together, to run the project. We rely on consent for panel membership and for research participation, and on legitimate interests for responding to business enquiries. Consent can be withdrawn at any time without affecting anything done before you withdrew it.
Verification records
Identity and credential checks generate documents and check results. These are held only as long as the check requires and are then deleted. They are never shared with clients and are never used for anything other than confirming that a member is who they say they are.
What clients receive
Survey responses reach our clients de-identified and, in most studies, aggregated. We do not sell contact details, and we do not pass a member's identity to a client without that member's specific, separate consent for that study.
Adverse events
Healthcare research carries a reporting obligation. If a member describes an adverse event or a product complaint during a study, we are required to pass the relevant details to the client's pharmacovigilance contact within an agreed window. This may include identifying information, and it is the one circumstance in which we will share it. Members are told this before they begin any study where it applies.
Sharing and location
We use third-party providers for hosting, survey delivery, identity verification and incentive payment. Each is bound by contract to process data only on our instructions. Where data is transferred outside its country of origin we rely on standard contractual clauses or an equivalent safeguard.
How long we keep it
Panel profiles are kept while membership is active and for a defined period afterwards so that we can honour tax, audit and anti-fraud obligations. Records of members removed for fraud are retained specifically to prevent re-registration. Enquiry correspondence is kept for as long as the commercial relationship needs it.
Your rights
You can ask us for a copy of what we hold, correct it, delete it, restrict how we use it, object to it, or withdraw consent. Under the DPDP Act you may also nominate someone to exercise these rights on your behalf. We respond within the statutory period. If you are not satisfied, you can complain to the Data Protection Board of India or, in the UK and EU, to your national supervisory authority.
Cookies
We use only what is needed to serve the site and understand basic traffic. We do not run advertising trackers and we do not sell any data collected here.
Contact
Write to us with any question about this policy, or to exercise any of the rights above.