Effective date: 1 July 2026
Last updated: 1 July 2026
1. Introduction
Kitsa Inc. ("Kitsa," "we," "our," or "us") is a health-technology company providing an AI platform for clinical research, including regulatory document authoring, clinical trial site selection, and patient pre-screening. We are located at 200 Connell Dr, Suite 1000, Berkeley Heights, NJ 07922, USA.
This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our website, our platform, and the products and services we provide (together, the "Services"). It also describes the choices and rights available to you.
This policy covers our public website and marketing activities, and it describes how we handle the data our sponsor, CRO, and clinical-site customers process through our platform. Where we handle personal or health information on behalf of a customer (for example, a clinical site or sponsor), that customer determines how the information is used, and their own privacy notices and agreements with us govern that processing. This is explained further in Section 4.
2. Products and Services Covered
This policy applies across the Kitsa platform, including:
- KScribe (Regulatory Document Authoring) — authors and validates clinical and regulatory documents across the trial lifecycle, drawing on customer-provided source material such as protocols, prior studies, sponsor libraries, and clinical data.
- KScout (Intelligent Site Selection) — scores and shortlists clinical research sites using signals such as site and investigator experience, past trial history, ICD-10-level disease prevalence, demographic data, geographic coverage, and site capabilities.
- KScreener (Patient Pre-screening) — applies a protocol's eligibility criteria to de-identified electronic health record (EHR) data at the clinical site to produce coordinator-ready worklists, with per-criterion reasoning and evidence.
Product-specific data handling is described where relevant below.
3. Our Roles: Controller, Processor, and Business Associate
Our responsibilities depend on the context in which we handle information:
- As a controller (or "business") — for information we collect directly for our own purposes, such as website visitor data, marketing contacts, and account administration, we determine how that information is used and are responsible for it under this policy.
- As a processor / service provider — when we handle customer data through the platform (for example, a sponsor's or site's protocol data, EDC archives, or clinical records), we act on that customer's documented instructions under our services agreement and, where applicable, a Data Processing Agreement (DPA).
- As a HIPAA Business Associate — where we handle Protected Health Information (PHI) on behalf of a covered entity or another business associate, we do so under a Business Associate Agreement (BAA) that governs our permitted uses and safeguards.
4. Information We Collect
4.1 Information You Provide Directly
When you contact us (for example, through our "Get in Touch" or demo-request forms) or otherwise communicate with us, we collect:
- Name
- Email address
- Company name
- Role / job title
- The contents of your message and any other details you choose to provide
If you hold an account on our platform, we also collect account credentials and authentication data, and we log account activity for security and audit purposes.
4.2 Customer and Clinical Data Processed Through the Platform
Our customers (sponsors, CROs, and clinical research sites) submit or connect data that we process on their behalf to deliver the Services. Depending on the product, this may include:
- KScribe: protocols, prior study documents, clinical study reports, SOPs, sponsor document libraries, and associated clinical data provided by the customer.
- KScout: protocol requirements and eligibility criteria, sponsor EDC archives (per engagement), and site- and investigator-level information. KScout also draws on external and epidemiological data sources, including public trial registries (e.g., ClinicalTrials.gov, EU CTR), scientific literature (e.g., PubMed), public payment records (e.g., CMS Open Payments), census/demographic data, and ICD-10-level disease-prevalence data.
- KScreener: EHR and site-level clinical data, including structured and unstructured signals (such as diagnoses, lab values, medication history, and prior treatment) used to assess protocol eligibility. How much of this is identifiable is set by the customer's configuration — see Section 4.3.
4.3 Health Information and PHI
Handling health information responsibly is central to how the platform is designed:
- KScreener can be run so that raw PHI stays at the clinical site. In that configuration KScreener runs within the site's environment and de-identification takes place in place: only a de-identified, tokenized worklist crosses the boundary, and tokens can be re-identified only by the site, within the site's own EHR session.
- How much identifiable information reaches the platform is the customer's decision, not ours. Where a customer configures its site data to be processed on the platform, that includes identifiable patient information — for example a patient's name, date of birth, contact details held by the site, and the clinical record behind an eligibility decision. The My Volunteers application and KScreener's volunteer screens exist to show exactly that information to the site's own staff, because a coordinator has to be able to recognise the person they are screening. We process it on the customer's instructions, scoped to the customer's organization, and make it available only to the users that organization has authorized and to the applications it holds.
- Where we do handle PHI on behalf of a covered entity, we do so as a Business Associate under a BAA and in accordance with HIPAA.
4.4 Information We Collect Automatically
When you use our website, we and our service providers may automatically collect usage information such as your IP address, device and browser type, pages viewed, referring pages, and interactions with the site. Some of this information is collected through cookies and similar technologies (see Section 11).
5. How We Use Information
We use information for the following purposes:
- To provide and operate the Services, including authoring regulatory documents (KScribe), scoring and shortlisting sites (KScout), and screening for eligibility (KScreener).
- To respond to inquiries and communicate with you, including replying to form submissions and providing requested information about our Services.
- To administer accounts and provide support.
- To secure and maintain the Services, including troubleshooting, security monitoring, and service reliability.
- To meet legal, regulatory, and contractual obligations, including clinical-research recordkeeping and audit requirements (for example, 21 CFR Part 11 controls where applicable).
We use customer and clinical data only as needed to deliver the Services and as instructed by the relevant customer under our agreements.
6. AI Models and Your Data
We never use customer data to train AI models. This applies to all products and all customers, without exception. Customer content is processed only to generate that customer's own results and is never used to train, fine-tune, or improve any model for the benefit of Kitsa or any other customer.
- This applies across KScribe, KScout, and KScreener. There is no cross-customer learning: one customer's protocols, documents, sponsor libraries, EDC archives, or clinical data are never used to train models that serve anyone else.
- KScribe runs in an isolated, single-tenant environment; a customer's content is used solely to produce that customer's documents.
- KScreener's reasoning operates on whatever the customer's configuration makes available to it, with reasoning traces and model versions logged for auditability. Where the customer de-identifies at the site, the underlying PHI does not leave the site.
Foundation model processing via Amazon Bedrock. All large language model requests are processed through Amazon Bedrock, a HIPAA-eligible service. Under the AWS Bedrock model, prompts, context, and outputs are not used to train the underlying foundation models and are not shared with the third-party model providers. This means the content we process on your behalf is not exposed to any public or shared model for training purposes. This arrangement can be independently verified against AWS's published Bedrock data-handling terms.
7. How We Share Information
We share information only as described below:
- With service providers / sub-processors who help us operate the Services (for example, cloud hosting such as Amazon Web Services). These providers are bound by contractual obligations to protect the information and to use it only to provide services to us.
- With customers and their authorized parties. Outputs generated through the platform (such as document drafts, site shortlists, or eligibility worklists) are made available to the customer that engaged us and the users they authorize.
- With clinical sites, sponsors, and CROs as necessary to deliver the contracted Services and consistent with the applicable agreement, DPA, and/or BAA.
- For legal and safety reasons, where we believe disclosure is required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of Kitsa, our customers, or others.
- In a business transfer, such as a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and continued protection of the information.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
8. Profiles and Public Visibility
Registered users and organizations on the Kitsa platform have a user profile and an organization profile. By default, profile information is visible only within the platform, to the extent needed to provide the Services.
You control whether your profile is public. A user (or, for an organization profile, an authorized administrator) may choose to make a profile — or specific sections of it — public. This choice is yours to make and to change at any time.
When a profile is set to public:
- The public information on that profile becomes viewable by anyone, including people who are not registered Kitsa users and visitors who are not signed in.
- The public profile may be indexed by search engines (such as Google and Bing) and may appear in their results.
- Public information may be viewed, copied, cached, aggregated, or re-shared by third parties, including through automated scraping. Once information has been made public, we cannot control how others may copy or store it.
You choose which sections and fields appear on a public profile. Treat anything you place on a public profile as information you are comfortable making publicly available, and do not include sensitive information in public profile fields if you do not want it publicly visible.
Turning off public visibility. You can make your profile private again, or hide specific sections, at any time through your profile settings. When you do, our platform automatically removes the profile from the public version of the site and from our sitemap and applies a noindex directive, so that search engines stop indexing it. These steps are handled automatically in code. However, search engines and other third parties operate independently of Kitsa and may retain cached or previously copied versions for some time; that refresh process is outside our control, and you may contact the relevant search engine directly to request removal of outdated results.
Profiles are professional, not patient data. User and organization profiles relate to platform users and their organizations (such as researchers, coordinators, sites, sponsors, and CROs). Patient information and PHI are never part of a public profile and are never made publicly visible or indexable.
9. Data Security and Compliance
We maintain an information security program with administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. Our controls and independently audited certifications include:
- SOC 2 Type II — independently audited controls covering security, availability, and confidentiality.
- ISO/IEC 27001:2022 — a certified Information Security Management System (ISMS).
- HIPAA — PHI handled under Business Associate Agreements, with the safeguards required by the HIPAA Security and Privacy Rules.
- 21 CFR Part 11 — audit-ready controls for electronic records and signatures where applicable to clinical workflows.
Our safeguards include encryption of data in transit and at rest, role-based access controls, tenant isolation for customer environments, comprehensive audit logging of actions and model versions, and continuous monitoring. KScreener supports an architecture in which identifiable PHI remains within the site's environment; where a customer instead processes identifiable data on the platform, it is scoped to that customer's organization and reachable only by the users and applications that organization is authorized for.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We encourage you to protect your account credentials and to contact us promptly if you suspect any unauthorized activity.
10. Data Retention
We retain information for as long as needed to fulfill the purposes described in this policy, to provide the Services, and to comply with our legal, regulatory, and contractual obligations, including clinical-research recordkeeping requirements. Retention of customer and clinical data is governed by the applicable customer agreement, DPA, and/or BAA. When information is no longer required, we delete or de-identify it in accordance with our retention schedules.
11. International Data Transfers
We are based in the United States and may process information in the United States and other countries where we or our service providers (such as AWS) operate. Data protection laws in these countries may differ from those where you are located. Where we transfer personal information across borders, we implement safeguards required by applicable law, such as Standard Contractual Clauses. If you are located outside the United States, please review Section 13 for rights that may apply to you.
12. Cookies and Similar Technologies
Our website uses cookies and similar technologies to operate the site, remember preferences, and analyze usage. You can control cookies through your browser settings, and where required we provide a cookie banner or preference tool to manage non-essential cookies.
13. Your Privacy Rights
Depending on your location and the applicable law (such as the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and other U.S. state privacy laws), you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your personal information, subject to legal exceptions;
- Object to or restrict certain processing;
- Data portability — receive your information in a structured, commonly used, machine-readable format;
- Withdraw consent where processing is based on consent; and
- Not be discriminated against for exercising your rights.
To exercise these rights with respect to information we control, contact us at contact@kitsa.com. We will verify your request and respond within the timeframes required by law.
Health information (PHI): Because PHI in the platform is typically handled on behalf of a healthcare provider or other covered entity, requests to access, amend, or delete PHI should generally be directed to the relevant provider or site, who is responsible for that information. We will support our customers in responding to such requests as required by our BAA and applicable law.
Customer and clinical data: If we process your information on behalf of a customer (for example, as a processor or Business Associate), please direct your request to that customer. We will assist them as required by our agreements and applicable law.
14. Children's Privacy
Our website and Services are not directed to children, and we do not knowingly collect personal information directly from children through our website. Where clinical data processed on behalf of a customer relates to minors (for example, in pediatric research), that information is handled under the customer's authority and the applicable regulatory, consent, and BAA/DPA framework.
15. Third-Party Links
Our website may contain links to third-party websites and services that we do not control. We are not responsible for their privacy practices, and we encourage you to review the privacy policies of any third-party sites you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date, and where required by law we will provide additional notice. We encourage you to review this policy periodically.
17. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Kitsa Inc. 200 Connell Dr, Suite 1000 Berkeley Heights, NJ 07922, USA Email: contact@kitsa.com Phone: +1 (908) 280-2100

