CROss Alliance® is the commercial name of CROSS Research SA, a Contract Research Organization specialising in clinical research and development services for medicinal products, medical devices and food supplements.

This notice explains how CROSS Research SA (CROSS, we or us) processes personal data in connection with its website, communications, recruitment and business activities, including the use of approved artificial intelligence tools. Specific notices for study participants, volunteer registration and personnel supplement this notice and describe the processing relevant to those activities.

We process personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) and its implementing provisions, and Regulation (EU) 2016/679 (GDPR) where applicable. These frameworks have different scopes and requirements; GDPR provisions are not automatically equivalent to Swiss provisions.

You can browse the website without completing a form, but technical data, including IP addresses, may still be processed. Providing information voluntarily or continuing to use the website does not, in itself, constitute consent to all processing described in this notice.

We apply technical and organisational measures proportionate to the data and risks, including access restrictions, confidentiality obligations and appropriate security controls. No transmission or storage system can be guaranteed to be completely secure. Please contact us to arrange an appropriate channel before sending sensitive information.

1. Definitions

The following terms explain how this notice uses key data protection concepts.

  • Personal data

Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

  • Data subject

Data subject is any identified or identifiable natural person, whose personal data is processed by the controller responsible for the processing.

  • Processing

Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • Restriction of processing

Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.

  • Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

  • Pseudonymisation (or Coding)

Pseudonymisation (or Coding) is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.  Pseudonymised data remain personal data; pseudonymisation is not anonymisation.

  • Controller

Controller or controller responsible for the processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided by Union or Member State law.

  • Processor

Processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

  • Recipient

Recipient is a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

  • Third party

Third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

  • Consent

Consent of the data subject is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

2. Name and address of the Controller

CROSS Research SA is the controller for the website and its own recruitment and business administration. When acting on documented instructions for a sponsor or another controller, CROSS acts as a processor; the relevant study or activity notice identifies the applicable roles.

CROSS Research SA (company under the brand name CROss Alliance®)

Via F.A. Giorgioli 14

CH 6864, Arzo, Switzerland

Phone: +41 91.6300510

Fax:     +41.91.6300511

privacy@croalliance.com –  www.croalliance.com

3. Data Protection Officer

The Data Protection Officer of the controller is:

Lawyer Giuseppe Fadda

Via Corbetta Eugenio 1

22063 Cantù (CO), Italy

Phone: +39.031.3515460

privacy@croalliance.com

Any data subject may, at any time, contact our Data Protection Officer directly with all questions and suggestions concerning data protection.

4. Website access data

When you access the website, server logs may record your IP address, browser and operating system, pages requested, referring website, access date and time, and security-related events. These data may constitute personal data and are not treated as anonymous merely because they are technical logs.

We use these data to deliver and maintain the website, diagnose faults and prevent or investigate misuse and cyberattacks. Where the GDPR applies, the basis is our legitimate interest in operating a secure and reliable website (Article 6(1)(f)). Analytics and advertising are addressed separately below. Logs are retained for the period needed for these purposes; records relevant to a security incident may be retained for its investigation and any related legal claims.

5. Registration on our website

Where registration is available, we process the identification and contact details requested in the form, account information and relevant access records to provide and secure the requested service. Required and optional fields are identified at collection.

Where the GDPR applies, processing necessary for a contract with you or steps requested by you before a contract is based on Article 6(1)(b); account security is based on Article 6(1)(f). Other purposes and any required consent are explained in the relevant form. You may request correction or closure of your account, subject to applicable retention requirements. Access by service providers is described under Disclosure to recipients.

6. Subscription to our newsletters

We process your email address and subscription preferences to send the newsletter you request. Where the GDPR applies, this processing is based on consent (Article 6(1)(a)). We use an email confirmation procedure to verify subscriptions and retain proportionate evidence of consent, including the relevant date, time and, where necessary, IP address.

You may unsubscribe using the link in a newsletter or by contacting privacy@croalliance.com. Withdrawal does not affect the lawfulness of earlier processing. A minimal suppression record may be kept to respect your choice, and evidence of consent may be retained where necessary for compliance or legal claims. Providers supporting delivery may process data on our behalf.

7. Newsletter tracking

Where enabled, newsletter tracking records email openings and link selections through pixels or similar technologies to assess communication effectiveness. This is distinct from delivering the newsletter and may involve personal data.

Individual-level tracking is activated only after separate consent. Refusal does not prevent receipt of the newsletter. You may withdraw this consent through the available preference controls or by contacting us; unsubscribing also stops future newsletter tracking. Previously collected data are deleted or anonymised when no longer needed, subject to any applicable legal retention requirement.

8. Information about trials for healthy volunteers

People interested in our clinical trials may register to receive information by the channels they select, such as email, WhatsApp and other messaging applications or telephone. We process contact details, communication preferences and relevant registration records for this purpose, on the basis of consent where required. You may stop these communications by contacting volreg@croalliance.com.

Registration for information is not consent to participate in a trial. Any collection of health or other sensitive data for volunteer assessment or recruitment is covered by a specific notice and the applicable legal conditions, including explicit consent where required. Clinical studies have their own participant information and consent procedures. Service providers may support these activities under appropriate safeguards; this does not authorise unrelated disclosure or use.

9. Contact possibility via the website

When you contact us through a website form, we process the contact details, message and attachments you provide to respond and manage your request. Where the GDPR applies, the basis is Article 6(1)(b) for pre-contractual steps requested by you or a contract with you, or Article 6(1)(f) for other professional enquiries. Please do not include unnecessary health data or identity documents. Approved IT and AI providers may support processing as described below.

10. Email and professional communications

We process professional contact details, correspondence and relevant attachments to manage relationships with clients, investigators, suppliers, collaborators and other contacts, provide services and maintain related records. Data may be supplied by you, your employer or organisation, a sponsor, a study site or another authorised business contact. Public professional sources may also be used where relevant and lawful.

Where the GDPR applies, the basis is Article 6(1)(b) for contracts with the individual concerned, Article 6(1)(f) for managing business relationships and professional contacts, and Article 6(1)(c) for applicable legal obligations. A contract with your organisation is not, by itself, a contract with you. Processing may involve approved IT and AI services, subject to the safeguards below.

11. Job applications

We process contact details, CVs, qualifications, experience and other information relevant to the role to assess applications and organise recruitment. Access is limited to authorised personnel and providers who need the information. Under Swiss law, employment-related processing must also comply with Article 328b of the Code of Obligations. Where the GDPR applies, the basis is Article 6(1)(b) for pre-contractual steps, together with applicable legal obligations and, where necessary, legitimate interests in defending legal claims.

If you are recruited, relevant information becomes part of your personnel file under the employee notice. If no employment contract is concluded, application documents are retained for five years from notification of rejection or, if later, the last written contact between the parties concerning the application, in accordance with CROSS’s retention policy. At the end of this period, the documents are deleted, unless specific information must lawfully be retained for longer, for example in connection with an ongoing legal dispute. This retention period does not authorise unrelated reuse: consideration for future vacancies requires appropriate information and a lawful justification, including separate consent where required. Your rights under applicable data protection law remain unaffected.

12. Cookies

Cookies and similar technologies can store information on your device or access information already stored there. Strictly necessary technologies support functions such as security or services you request. Analytics, marketing and profiling technologies have different purposes and are not automatically necessary for the website to operate.

Non-essential tracking is activated only after your consent. You can refuse or withdraw consent as easily as you give it, without losing access to essential website functions. Browser controls provide an additional way to delete or block cookies, but do not replace the site’s consent controls.

The cookie information must identify the technologies actually used, their providers, purposes, duration and relevant recipients or transfers.

Depending on the used browser, it is possible to disable cookies following the given instructions:

13. Google Analytics

Where enabled with your consent, Google Analytics is used to measure website use and the effectiveness of communications. Depending on configuration, this may involve device or browser identifiers, interaction data and other personal data. Aggregated reports do not, by themselves, make the underlying processing anonymous.

Google Analytics is treated as an analytics service, not automatically as a strictly necessary or functional cookie. The cookie information identifies the actual Google service and contracting entity, configuration, retention settings, consent controls and relevant international transfers. Refusing analytics does not prevent ordinary browsing.

14. Routine erasure and blocking of personal data

Personal data are deleted or effectively anonymised when no longer needed for their purpose and no applicable retention obligation or other lawful necessity remains. Where retention is required, access and use are restricted to the relevant purpose. Backup copies are removed through the applicable backup lifecycle, subject to legal preservation requirements. Retention criteria are described below.

15. Disclosure to recipients and international transfers

We do not sell personal data. Access is limited to authorised personnel and recipients who need the data for the relevant purposes. Depending on the activity, recipients include IT hosting, cloud, communications, security and approved AI providers; professional advisers and auditors; clients, sponsors and study sites where necessary and authorised; and competent authorities where legally required or permitted.

Providers acting on our behalf are subject to appropriate data-processing agreements, confidentiality obligations and security requirements. Where CROSS acts as a processor for a sponsor or another controller, any sub-processing is subject to the controller’s instructions and the required authorisation. Other recipients may act as independent controllers for their own lawful responsibilities.

International transfers may occur through hosting, support or remote access. Under Swiss law, we assess the destination country’s protection in accordance with the Federal Council’s adequacy determinations or use appropriate safeguards under Article 16 FADP, including recognised contractual clauses and supplementary measures where necessary; any exception must meet Article 17 FADP. Where the GDPR applies, we also comply with Chapter V, including the applicable European Commission adequacy decision or appropriate transfer safeguards. Swiss adequacy for transfers from the EEA does not authorise every onward transfer from Switzerland.

[INSERT THE VERIFIED DESTINATION COUNTRIES AND THE APPLICABLE TRANSFER MECHANISM FOR EACH RELEVANT SERVICE OR LINK TO A COMPLETE CURRENT LIST.] You can contact privacy@croalliance.com for further information and a copy of applicable safeguards, subject to necessary redactions.

16. Use of artificial intelligence

We may use approved corporate artificial intelligence (AI) services, including ChatGPT Business and others, to support authorised professional activities: drafting, translation, summarisation, consistency checks, quality control, information retrieval, and programming or analysis support. Depending on the task, inputs may include professional contact details, correspondence, CVs, documents and authorised coded study data. Outputs may also contain personal data and are subject to the same protection requirements.

AI is a processing tool, not an independent legal basis or permission to use data for unrelated purposes. Its use must remain necessary and compatible with the relevant purpose and legal conditions. Where CROSS processes data for a sponsor, the sponsor’s instructions, contractual restrictions and applicable authorisations also apply.

Only information reasonably necessary for the task may be entered by authorised personnel in approved corporate environments. Personal or unapproved AI accounts may not be used for restricted personal or confidential data. Relevant outputs are checked by competent personnel; professional accountability remains with the responsible person. Uses with potentially material impact require a documented, proportionate assessment, including a data protection impact assessment where legally required.

Coded or pseudonymised study data remain personal data. Their use requires appropriate safeguards, exclusion of direct participant identifiers and the re-identification key, and preservation of study blinding. Directly identifying participant data are not permitted by default; exceptional use requires demonstrated necessity, appropriate legal conditions, specific information to participants where required, consistency with the study arrangements and documented internal approval.

Approved internal knowledge bases may organise, index and retrieve authorised documents, including through numerical representations used for retrieval (embeddings). This does not in itself train or fine-tune the underlying model. Such bases remain subject to purpose, access and retention restrictions. Sponsor information may not be reused for unrelated activities or other clients merely because it has been included in a knowledge base.

For the routine AI assistance described here, services must be selected and configured so that input and output content is not used to train or improve the provider’s general-purpose models. This does not mean that data are never stored or accessed: authorised provider processing for service delivery, security, support or legal obligations may still occur under the applicable terms. Integrations and external applications require separate assessment. Any distinct model-training or fine-tuning project would require a separate assessment, appropriate information and any necessary authorisations before it begins.

Prompts, uploaded files, retrieval indexes, conversations and outputs are subject to retention and deletion controls. Final records follow the requirements of the underlying activity; intermediate AI material is retained only where necessary for that activity, traceability, security or legal obligations. The recipients and transfer safeguards described above also apply to AI services.

17. Rights of the data subject

You may exercise the rights available under the law applicable to the processing by contacting privacy@croalliance.com or our DPO. These include access and a copy of your data, correction, and, where the relevant conditions are met, deletion, restriction, portability and objection. Rights and exceptions are not identical under the GDPR and Swiss law.

We may request proportionate information to verify your identity. Requests are normally free of charge; any legally permitted fee or refusal will be explained. Under the GDPR, we respond without undue delay and within one month, with an extension of up to two further months where permitted; we inform you of the extension and reasons within the first month. Swiss access requests are normally answered within 30 days; any delay is explained with the expected response date.

  • Right of confirmation

You may ask whether we process personal data concerning you.

  • Right of access

You may request access to your data and information on the purposes, categories, sources, recipients, retention and applicable transfer safeguards, together with information about relevant automated decisions. A copy is provided subject to the rights and freedoms of others and applicable legal exceptions.

  • Right to rectification

You may request correction of inaccurate data and completion of incomplete data, taking account of the processing purpose.

  • Right to erasure (Right to be forgotten)

You may request deletion where, for example, data are no longer needed, consent is withdrawn and no other lawful ground applies, an applicable objection is upheld, or processing is unlawful. Deletion is not absolute: legal retention obligations, legal claims and applicable research exceptions may require continued retention. We explain any relevant limitation; we do not promise automatic or immediate deletion in every case.

  • Right of restriction of processing

Where the GDPR applies, you may request restriction in the circumstances set out in Article 18, including disputed accuracy, unlawful processing where you oppose deletion, data needed for your legal claims, or verification of an objection. Applicable Swiss protective remedies remain available.

  • Right to data portability

Where the applicable conditions are met, you may receive the personal data you provided in a structured, commonly used and machine-readable format and request transmission to another controller where technically feasible. Under the GDPR this applies to automated processing based on consent or a contract; Swiss portability is governed by Articles 28 and 29 FADP.

  • Right to object

Under the GDPR, you may object on grounds relating to your particular situation to processing based on Article 6(1)(e) or (f), including related profiling. We stop that processing unless compelling legitimate grounds override your interests, rights and freedoms, or processing is needed for legal claims.

You may object to direct marketing at any time, including related profiling, without giving reasons. We then stop processing for those purposes. Research is not a blanket exemption from rights: any restriction must meet a specific applicable legal provision and its safeguards. Article 89 GDPR does not, by itself, remove participants’ rights.

  • Automated individual decision-making, including profiling

The GDPR provides protection against solely automated decisions producing legal or similarly significant effects, subject to its limited exceptions and safeguards (Article 22). Swiss law provides information and human-review rights for automated individual decisions under Article 21 FADP, subject to its conditions and exceptions. Our actual approach is described under Automated decisions below.

  • Right to withdraw data protection consent

Where processing is based on consent, you may withdraw it at any time, as easily as it was given. Withdrawal does not affect earlier lawful processing or processing that must continue on a separate valid ground.

You may lodge a complaint with the competent EU/EEA supervisory authority where the GDPR applies, including in your habitual residence or place of work or where the alleged infringement occurred. For Swiss data protection concerns you may contact the Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch. Judicial remedies remain available. You do not have to contact CROSS before approaching an authority.

18. Purpose and legal basis for the processing

The purposes and relevant GDPR legal bases are identified in the activity-specific sections above. Consent is one possible basis, not a general substitute for assessing lawfulness. Legitimate interests require necessity and a balancing of interests; they do not automatically apply because a person is a client.

Processing health data or other special categories under the GDPR requires both an Article 6 basis and an applicable Article 9 condition. Clinical research, safety reporting and employee processing are addressed in their specific notices and legal arrangements; consent to participate in a study is not automatically the GDPR legal basis for every study activity. In an emergency, vital interests fall under Article 6(1)(d), with Article 9(2)(c) applicable to special-category data only where its conditions are met.

For private-sector processing under Swiss law, we comply with the principles of lawfulness, good faith, proportionality, purpose limitation and accuracy under Article 6 FADP, and with data protection by design and by default and data security under Articles 7 and 8. Processing must respect personality rights under Articles 30 and 31; where justification is required, it may consist of consent, an overriding private or public interest, or a legal provision. Where consent is required, it must be informed and freely given, and explicit for sensitive personal data or high-risk profiling. This framework is distinct from the legal bases in Article 6 GDPR.

19. Legitimate interests

Our relevant interests are maintaining professional relationships, responding to enquiries, ensuring the quality and efficiency of authorised services, protecting systems and records, and establishing, exercising or defending legal claims. We assess necessity, reasonable expectations, impact on individuals and safeguards before relying on these interests. Using AI does not remove that assessment.

20. Retention periods

Retention depends on the category and purpose. Enquiries are kept for their handling and necessary follow-up; professional correspondence and contractual records for the relationship and applicable accounting, regulatory or claims periods; subscriptions until withdrawal or cessation of the service, with limited evidence and suppression records as described above. Application retention is addressed in its dedicated section.

Clinical study records follow the study-specific statutory and regulatory requirements and controller instructions, explained in the participant notice. AI use does not independently justify a longer period. We review necessity and limit access to retained records. More precise information about the period applicable to your data is available from privacy@croalliance.com.

21. Providing personal data

We identify required information and explain whether it is needed by law, for a contract or to provide a requested service. Without it, we may be unable to respond, provide the service or conclude the contract. Optional information and consent to unrelated activities are not made conditions for essential services.

Study participation is voluntary. The study-specific information explains which data are needed for participation and what withdrawal means, including any lawful continued retention. You are not required to contact an employee before receiving the information necessary to make your choice.

22. Automated decisions and updates to this notice

For the activities described in this notice, we do not use AI to make solely automated decisions producing legal or similarly significant effects on individuals. AI assistance is subject to meaningful human review. In particular, AI may not autonomously determine study eligibility, treatment or participant safety decisions. Any permitted analytics or marketing profiling is distinct from such decisions and is governed by the consent controls described above.

We may update this notice to reflect changes in processing. Material changes are brought to the attention of affected individuals through appropriate channels, with additional information and consent where required before the relevant new processing. Publication of a revised notice does not itself authorise a new purpose or override a specific notice, consent, sponsor instruction or contract.

23. Summary of changes

v.1.0 – June, 2018 – Initial release

v.2.0 – February, 2020 – Update: “CROSS Metrics” has been removed after a merger by incorporation of CROSS Metrics SA in CROSS Research SA

v.3.0 – May, 2020 – Update: Section 12 “Cookies” have been amended

v.4.0 – May, 2022 – Update: In section 12 “Cookies”, links to external websites have been updated

v.5.0 – October, 2023  – Updated references to new Swiss Federal Act on Data Protection

v.6.0 – April, 2026 – Update: Replacement of the reference to Internet Explorer with Microsoft Edge

v.7.0 – September, 2026 –  AI-assisted processing and internal knowledge bases; clarification of roles, legal grounds, recipients, transfers, cookies, retention and individual rights.