Privacy Policy
Last Updated: August 26, 2026
This Privacy Policy describes how Company (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when individuals visit tamarin.health, communicate with us, or interact with us in a business or professional capacity.
1. Scope
This Privacy Policy applies to personal information collected through tamarin.health and related public-facing websites, forms, communications, and business-development activities (collectively, the “Site”).
This Privacy Policy does not replace or modify any professional services agreement, network access agreement, API license, query addendum, data use agreement, business associate agreement, confidentiality agreement, clinical-trial agreement, statement of work, or other written agreement governing a specific research project, commercial relationship, or service.
If a separate written agreement governs particular information, data, research activity, or service, that agreement controls to the extent of any conflict.
This Privacy Policy is not a HIPAA Notice of Privacy Practices.
2. About the Site
Company operates a healthcare research network designed to support approved computation against source-connected healthcare data.
Potential uses include custom analysis, model validation, real-world evidence, clinical-trial feasibility, site discovery, patient identification, recruitment support, and related research activities.
Company is not a healthcare provider and does not provide medical diagnosis, treatment, or medical advice through the Site.
3. Information We Collect
We may collect the following categories of information.
Contact and professional information. This may include your name, business email address, telephone number, employer or organization, job title, professional role, and similar business contact information.
Research and project information. If you contact us regarding a potential research project, we may collect information about your research question, desired population, variables, data requirements, protocol, model, analytical objectives, therapeutic area, clinical-trial needs, timing, funding, or organizational capabilities.
Communications. We collect information that you provide when you communicate with us, participate in meetings, complete forms, request information, or otherwise correspond with Company.
Commercial and contractual information. For customers, research partners, and other counterparties, we may collect information relating to business relationships, contracts, invoicing, payments, research engagements, project administration, and support.
Website and technical information. When you visit the Site, Company and its service providers may automatically collect information such as your IP address, browser type, device information, operating system, referring page, pages visited, date and time of access, and similar usage information.
Cookies and similar technologies. Company may use cookies, local storage, pixels, and similar technologies for website functionality, security, analytics, performance, and other purposes described in this Privacy Policy.
Information from other sources. We may receive professional contact or business information from referrals, healthcare organizations, researchers, sponsors, CROs, conference organizers, publicly available sources, and other business partners.
4. Do Not Submit Patient-Level Health Information Through Public Website Forms
The public Site and general contact forms are not intended for submission of patient records, protected health information, medical record numbers, direct patient identifiers, or other patient-level clinical information.
If a proposed project requires regulated or sensitive health information, Company and the applicable parties will establish an appropriate contractual, technical, and secure workflow before such information is used.
Submission of information through a public website form does not independently authorize Company or any other party to use patient-level health information for research.
5. Research and Clinical Data
Healthcare organizations may participate in approved research using data maintained within source-connected or protected computing environments.
Depending on a particular research project, applicable data may include aggregate information, de-identified information, a limited data set, protected health information, or other regulated information.
The healthcare organization’s rights and responsibilities, Company’s role, researchers’ permitted uses, permitted outputs, applicable security controls, retention requirements, publication restrictions, and required approvals are governed by applicable law and the relevant written agreements.
Company’s services are designed so that Company personnel are not intended to access participating healthcare organizations’ underlying patient-level data in unencrypted or human-readable form. The specific technical architecture and contractual requirements applicable to a project may vary, and the applicable written agreement controls.
Where a business associate agreement, data use agreement, data processing agreement, Institutional Review Board or ethics approval, consent, authorization, waiver, or other project-specific requirement is necessary, the applicable parties must satisfy that requirement before the relevant activity occurs.
6. How We Use Information
Company may use personal information to:
- operate, maintain, secure, and improve the Site;
- respond to inquiries and communicate with you;
- evaluate potential research projects and business relationships;
- identify potentially relevant healthcare organizations, researchers, sponsors, CROs, or other research partners;
- administer research engagements and commercial relationships;
- coordinate meetings, onboarding, support, and project activities;
- provide requested information and services;
- maintain records and administer contracts;
- protect the security and integrity of Company systems and services;
- detect or prevent fraud, misuse, unauthorized access, or unlawful activity;
- comply with legal, regulatory, contractual, research, and institutional requirements;
- enforce Company’s agreements and legal rights;
- send business or marketing communications where permitted by law; and
- analyze Site usage and improve Company’s communications, products, and services.
You may opt out of non-transactional marketing emails at any time by using the unsubscribe mechanism included in the communication or by contacting us.
7. How We Disclose Information
Company may disclose personal information in the following circumstances.
Service providers. We may disclose information to service providers that support website hosting, analytics, communications, information technology, security, document management, billing, professional services, and other business functions.
Research and business partners. When you ask Company to evaluate or facilitate a potential research opportunity, we may disclose appropriate business or project information to healthcare organizations, researchers, sponsors, CROs, consultants, or other parties as reasonably necessary to evaluate or support that opportunity.
Sensitive or regulated health information remains subject to applicable legal and contractual restrictions.
Professional advisers. We may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers.
Legal and compliance purposes. We may disclose information when required by law, legal process, court order, or governmental request, or when reasonably necessary to protect Company, its users, its business partners, or others.
Corporate transactions. We may disclose information in connection with an actual or proposed financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to applicable confidentiality and legal requirements.
Company does not obtain ownership of a healthcare organization’s underlying patient data merely because the healthcare organization participates in Company’s network.
Company does not sell participating healthcare organizations’ patient-level clinical data as a Company-owned data asset.
8. Cookies and Similar Technologies
The Site uses cookies and similar technologies.
Necessary cookies may be used to operate the Site securely and provide basic website functionality.
With your permission where required, Company may also use analytics and performance cookies to understand Site traffic, usage, and performance.
Third-party services or integrations used on the Site may also place cookies or similar technologies, subject to their own privacy practices and Company’s applicable consent settings.
Where available, you may use the Site’s cookie-preference controls to accept, decline, or manage non-essential cookies.
You may also control certain cookies through your browser settings. Blocking cookies may affect some Site functionality.
Company does not use public website analytics tools to access patient-level clinical data maintained by participating healthcare organizations.
9. Sale, Sharing, and Targeted Advertising
Company does not sell personal information for monetary consideration.
Certain disclosures involving online advertising, analytics, or similar technologies may be considered a “sale,” “sharing,” or “targeted advertising” under some privacy laws even if no money changes hands.
Where Company engages in an activity subject to such requirements, Company will provide the notices, consent mechanisms, or opt-out methods required by applicable law.
Where required by applicable law, Company will also process recognized opt-out preference signals.
10. Data Retention
Company retains personal information for as long as reasonably necessary for the purposes for which the information was collected, including to maintain business and research relationships, perform contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, maintain security, and preserve appropriate business records.
Research data and research outputs may be subject to separate retention requirements established by project-specific agreements, healthcare organization requirements, IRB or ethics requirements, sponsors, or applicable law.
11. Data Security
Company uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, loss, or disclosure.
No method of transmission or electronic storage can be guaranteed to be completely secure.
Research engagements involving regulated or sensitive data may be subject to additional safeguards established by the applicable written agreements and technical environment.
12. Your Privacy Rights
Depending on your residence and applicable law, you may have certain rights regarding personal information, which may include the right to:
- request access to personal information Company maintains about you;
- request correction of inaccurate personal information;
- request deletion of certain personal information;
- obtain a portable copy of certain information;
- opt out of certain sales, sharing, targeted advertising, or profiling;
- limit certain uses of sensitive personal information;
- withdraw consent where processing is based on consent; and
- appeal certain decisions relating to a privacy request.
Company may need to verify your identity before responding to a request.
Certain information may be exempt from a request where permitted or required by law.
Company will not unlawfully discriminate against an individual for exercising an applicable privacy right.
Privacy requests may be submitted to legal@tamarin.health.
13. HIPAA and Other Health Privacy Requirements
Whether HIPAA or another healthcare privacy law applies to a particular activity depends on the parties, information, purpose, and structure of the applicable project.
Where Company performs services that require a business associate agreement or other healthcare privacy agreement, that agreement governs Company’s permitted uses and disclosures.
Nothing in this Privacy Policy independently authorizes Company, a researcher, a healthcare organization, or another party to access, use, or disclose protected health information.
14. Consumer Health Data
Certain U.S. states provide additional protections for consumer health data that is not otherwise regulated by HIPAA or another applicable health privacy law.
Where such a law applies to Company’s activities, Company will provide additional notices, obtain consent, honor applicable consumer rights, and maintain any separate consumer health data privacy policy required by applicable law.
15. Children
The Site is intended for business and professional audiences and is not directed to children.
Company does not knowingly collect personal information through the public Site from children under 18.
If you believe a child has provided personal information through the Site, please contact Company.
16. Third-Party Sites and Services
The Site may contain links to websites, applications, or services operated by third parties.
Company does not control and is not responsible for the privacy practices, security, or content of third-party services.
17. International Visitors
Company is based in the United States.
If you access the Site from outside the United States, information you provide may be processed in the United States or other jurisdictions where Company or its service providers operate, subject to applicable law.
18. Changes to This Privacy Policy
Company may update this Privacy Policy from time to time.
When changes are made, Company will update the “Last Updated” date above.
A change to this Privacy Policy does not modify the terms of a separate signed agreement unless that agreement is amended in accordance with its terms.
19. Contact
Questions, concerns, and privacy requests may be directed to: