Privacy Notice — PCRA Caribbean
DRAFT — requires review by qualified counsel in each participating jurisdiction before launch. Not yet in force.
Version: 0.1 (initial Caribbean draft) Drafted: August 4, 2026 Status: Draft — pending legal review. Placeholders in [brackets] must be completed before publication.
At a glance
PCRA Caribbean ("we", "us", "our") connects Caribbean healthcare and research sites with clinical trial sponsors. PCRA Caribbean is part of the PCRA Group — backed by PCRA UK — but runs separately on its own systems. This notice explains how we handle personal information on our website and portal.
Three things to know up front:
- We handle professional contact data only. The personal information we process is business-to-business contact data — the names, work emails, work phone numbers, and roles of staff at member sites and at sponsor organizations.
- We never hold patient data. Our portal is designed to hold organizational information about sites, professional contacts, and aggregate counts (for example, approximate patient panel sizes). It does not hold patient records, patient identities, or any individual health information — ever.
- We do not sell personal information, and we do not share it for advertising purposes.
1. Who we are
| Organization | PCRA Caribbean, operated by Primary Care Research Alliance Ltd ("PCRA UK") |
| Registered office | Middleton House, Yapton Road, Bognor Regis, West Sussex, PO22 6DU, United Kingdom |
| ICO registration | ZB864081 |
| Privacy contact | info@pcralliance.uk |
We are the organization responsible for the personal information described in this notice. Our service providers (hosting, database, and email vendors) act on our instructions under contract.
Because our network spans multiple Caribbean countries and territories, there is no single data-protection law that governs everything we do. We work to the applicable data-protection and health-research laws of each participating country and territory — for example Jamaica's Data Protection Act 2020, Barbados' Data Protection Act 2019, Trinidad & Tobago's Data Protection Act, the Dominican Republic's Law 172-13, and the GDPR where EU territories such as Guadeloupe, Martinique, Saint-Martin and French Guiana are involved.
2. What this notice covers
This notice applies to:
- Our public website and any contact or membership-inquiry forms on it.
- Our member portal, where site staff manage their site's profile and where sponsor contacts browse the network.
- Email correspondence with us.
It covers the personal information of:
- Site staff — physicians, nurses, practice and clinic managers, research coordinators, pharmacists, laboratory and diagnostics staff, and other professionals who represent a member site (hospitals, polyclinics, health centres, GP/family practices, private specialist clinics, physiotherapy clinics, diagnostics labs, dental clinics, pharmacies, and dedicated research units).
- Sponsor contacts — employees of pharmaceutical, biotech, medical device, and contract research organizations who engage with us.
- Website visitors and inquirers — anyone who visits our site or sends us a message.
What this notice does not cover — patient information
PCRA Caribbean does not collect, store, or process patient information. Clinical trials arranged through our network are conducted at the participating sites under each study's own protocol, consent process, and privacy documentation — those are between the site, the sponsor, and the participant, and are outside our systems.
If patient information is ever sent to us by mistake (for example, pasted into an email), our policy is to delete it promptly and confirm the deletion to the sender. Please do not send us any patient information.
3. What we collect
From site staff:
- Identity and contact: name, professional role or title, work email, work phone.
- Account information: login email, a securely hashed password (we never store passwords in plain text), and sign-in records.
- Site profile information you provide: your site's name, address, capabilities, equipment, research experience, team member names and roles, and aggregate figures such as approximate patient panel size. Aggregate figures are counts only — they identify no individual.
From sponsor contacts:
- Identity and contact: name, company, role or title, work email, work phone.
- Account information and sign-in records, as above.
- Inquiry details: the studies or capabilities you ask about.
From website visitors:
- Technical data: IP address, browser type, and pages visited, collected in standard server logs.
- Anything you enter in a contact or inquiry form.
Where we pre-populate a site's directory entry from information the site has already published on its own public website, we collect only public professional and business information, and only from public professional sources — see our Scraping Policy for the details and how to opt out.
4. How we use personal information
- Operating the network: matching sponsor study requirements with suitable member sites (feasibility matching).
- Running member and sponsor accounts on the portal, including sign-in security.
- Responding to inquiries and managing our business relationships.
- Sending operational communications about opportunities, membership, and the portal.
- Securing our systems, preventing abuse, and keeping audit records of account activity.
- Complying with applicable law.
We do not use personal information for automated decisions that produce legal or similarly significant effects about any individual.
5. No sale or sharing of personal information
- We do not sell personal information.
- We do not share personal information for advertising purposes.
- We do not provide personal information to data brokers or advertising networks.
Within the ordinary operation of the network: a member site's published profile (including professional contact details the site chooses to publish) is visible to authorized sponsor users; and when a sponsor and a site agree to be introduced, we pass the relevant professional contacts between them. That is the purpose members and sponsors join for.
6. Who we share information with
- Service providers — the vendors that host our website, application, database, and email, acting under contract and only on our instructions.
- Member sites and sponsor users — as described in Section 5, in the ordinary operation of the network.
- Professional advisers — lawyers, accountants, and insurers, where necessary.
- Authorities — if required by law, subpoena, or court order.
Where data is hosted: [Hosting regions — to be confirmed.] Our hosting providers may be located outside the participating Caribbean countries and territories. Where the applicable law of your country or territory (including the GDPR for the EU territories) requires safeguards for cross-border transfers, we will put those safeguards in place and document them here before launch. [Cross-border transfer safeguards — to be completed with counsel.]
7. Cookies
We use only cookies that are strictly necessary to operate the site — for example, keeping you signed in to the portal and protecting against abuse. We do not currently set analytics or advertising cookies. If that changes, we will update this notice and provide any legally required choices before doing so.
You can clear or block cookies in your browser settings; blocking essential cookies will prevent you from staying signed in.
8. Security
We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the data we hold, including encryption in transit, hashed passwords, role-based access controls, and audit logging of account activity. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by the applicable law of your country or territory.
9. Retention
We keep personal information only as long as needed for the purposes above:
- Account and profile data: for the duration of the membership or sponsor relationship, plus a reasonable wind-down period.
- Inquiry records: for as long as needed to handle and follow up on the inquiry.
- Server logs: for a short operational window, then deleted or aggregated.
A detailed retention schedule will be finalized before launch. [Retention schedule — to be completed.]
10. Access, correction, and deletion requests
You can ask us at any time to:
- Access — tell you what personal information we hold about you and provide a copy.
- Correct — fix inaccurate or outdated information (portal users can edit most of their own information directly).
- Delete — remove your personal information, subject to legal and contractual record-keeping obligations.
- Removal from the directory — if information about you or your site was collected from public sources, you can ask us to remove it and to stop any further collection. See the Scraping Policy for the quickest routes.
How to make a request: email info@pcralliance.uk from the email address associated with your record. We will verify your identity, respond within the timeframe required by the law applicable in your country or territory (and in any event within 45 days), and never charge a fee for a reasonable request. If we deny a request in whole or part, we will explain why and how to appeal.
We will never discriminate against you — in pricing, service, or membership — for exercising any privacy right.
11. Your privacy rights across the Caribbean
There is no single Caribbean data-protection law. Your rights depend on the law of the country or territory where you are located. As a matter of policy, we honor access, correction, and deletion requests from anyone, anywhere in the network — but the notes below flag the main statutory regimes:
- Jamaica — the Data Protection Act 2020 gives you rights of access, correction, and erasure, and a right to complain to the Office of the Information Commissioner.
- Barbados — the Data Protection Act 2019 provides similar rights, overseen by the Data Protection Commissioner.
- Trinidad & Tobago — the Data Protection Act provides data-privacy protections overseen by the Office of the Information Commissioner (as its provisions are brought into force).
- Dominican Republic — Law 172-13 on the protection of personal data provides rights of access, rectification, and cancellation.
- EU territories (Guadeloupe, Martinique, Saint-Martin, French Guiana, and other territories where EU law applies) — the GDPR applies in full, including rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority (for the French territories, the CNIL).
- Other participating countries and territories — where local data-protection or privacy law gives you additional rights, we will honor those too.
To exercise any of these rights, email info@pcralliance.uk. If we decline a request, you have the right to appeal by replying to our response; we will answer your appeal within the period the applicable law requires.
Note: much of the information we handle is business-to-business professional contact data, which some laws treat differently from consumer data. We honor access, correction, and deletion requests regardless.
12. Children
Our website and portal are for professionals and are not directed to anyone under 18. We do not knowingly collect personal information from minors.
13. Changes to this notice
We may update this notice as our services or the law change. The version number and date at the top tell you which version you are reading. For material changes, we will notify account holders directly and post a notice on the portal.
A summary of changes is maintained at /privacy-policy/changes.
14. Contact us
| Privacy requests | info@pcralliance.uk |
| General inquiries | info@pcralliance.uk |
If you have any question about this notice or how we handle your information, please get in touch — we will answer in plain language.