Privacy Policy

Last Updated: July 30, 2026

Positive Ignition, Inc. and its subsidiaries and affiliates (collectively, “Positive Ignition,” the “Company,” “we,” or “us”) operate the TrialTime clinical trial training and qualification records platform (the “Platform”). We prioritize the protection of Personal Information entrusted to us. Accordingly, we provide this notice to inform you of our information practices, the kinds of information we collect when you interact with us, how we may use and disclose Personal Information, and the choices and rights you may have to manage the Personal Information we process about you (this “Privacy Policy”).

This Privacy Policy applies to the Personal Information we process through our business operations, our website at trialtime.com, and the TrialTime Platform, including all future websites or applications operated by or on behalf of Positive Ignition that link to this Privacy Policy (collectively, the “Services”). As used in this Privacy Policy, “Personal Information” has the meaning given to it under the law where you live, but typically refers to information that can be used to identify you as an individual. Activities we take with respect to your Personal Information are referred to as “processing.”

Important note about training and qualification records. TrialTime is a business-to-business platform used by clinical trial sponsors, contract research organizations (CROs), research sites, and other organizations to manage clinical trial training programs and to collect, verify, and maintain the qualification records of investigators, site staff, and other trial personnel. When we process Personal Information (including training records, credentials, licenses, CVs, and certifications) on behalf of, or in partnership with, our customers, that processing is subject to: (1) the terms of our agreements with those customers, (2) any consents or authorizations obtained by our customers from the individuals to whom the information relates, and (3) all applicable regulatory and data protection requirements — not the terms of this Privacy Policy. In those cases we act as a service provider or data processor, and the customer is responsible as the controller of that information. If you have questions about how your training or qualification records are used, please contact the sponsor, CRO, or research site that manages your records. If you are a Positive Ignition worker, contractor, or job applicant, the way we process your Personal Information is described in a separate Worker and Applicant Privacy Notice, not this Privacy Policy.

Information We Collect and How We Collect It

There are several ways we may obtain information about you. We collect information that you elect to provide to us when using our Services and when you otherwise interact with us, information we collect automatically when you use our Services, and information we receive from third parties. The categories of Personal Information we may collect, and our privacy practices, depend on the nature of your relationship with us and the requirements of applicable law. We endeavor to collect only information relevant to our business needs.

  1. Information you submit. We collect information whenever you provide it to us directly — for example, when you submit information through our “Contact Us” or demo-request pages, seek to partner with us, register for or log in to a Platform account, complete or record training, upload or maintain your qualification records, attend an event, or sign up for a newsletter or publication. Depending on how you use the Services, such information may include:
    • Contact and profile information, such as your name, employer or affiliated institution and position, business email address, business address, telephone number, and username.
    • Professional qualification information (typically entered by you or on your behalf through the Platform), such as your curriculum vitae, professional and medical licenses, board certifications, Good Clinical Practice (GCP) and protocol-specific training records, training completion dates and scores, financial disclosure information required for study participation, and electronic signatures used to attest to training or records.
    • Account credentials, such as passwords and authentication information.
  2. Cookies we set. We use a small number of cookies. Most are strictly necessary to operate the Platform; we also use two analytics cookies, described at (3) below. We do not use cookies for advertising, profiling, session replay, or tracking you across other websites, and apart from the analytics provider named below we do not permit third parties to set cookies through our Services.
    1. Session cookies (lms_refresh, lms_admin_refresh, lms_ghost_refresh). These keep you signed in and keep separate sessions separate — a learner session, an administrator session, and a support session viewed on your behalf are held independently so that starting one never ends another. They contain a session reference only, are marked HttpOnly so page scripts cannot read them, and are sent only over HTTPS.
    2. Training-content cookies (CloudFront-Policy, CloudFront-Signature, CloudFront-Key-Pair-Id). These are short-lived authorisations, issued when you open a course, that allow your browser to load that course’s videos, slides and documents from our content delivery network. They carry no identifier for you and expire shortly after the course is opened. Without them the course you requested cannot be displayed.
    3. Analytics cookies (_ga, _ga_<id>), set by Google Analytics. These tell us how the Platform is used — which screens are opened, and whether a visit is from someone who has used it before — so that we can see which parts of the training experience work and which do not. They store a randomly generated identifier for the browser. They last 425 days, and the usage data behind them is deleted after 14 months.
      What we deliberately do not send. We do not send Google any identifier of yours — not your name, not your email address, and not your user account. Analytics reporting is built from the address of the screen you opened, reduced to its general shape rather than its specific contents, and from the protocol and sponsor a screen relates to. Web addresses containing one-time links, such as a password reset or an invitation, are stripped before anything is sent, and page titles are replaced, so that neither a one-time link nor a person’s name reaches Google. We have also turned off Google’s advertising and cross-site features for this Platform.
      These are not strictly necessary, and you can refuse them. The Platform works fully without them. To refuse them, enable the “Do Not Track” or equivalent privacy setting in your browser, use your browser’s controls to block or delete cookies for this site, or install Google’s official opt-out browser add-on. You can also write to privacy@trialtime.com and we will exclude you.
    The cookies at (1) and (2) are required to deliver a service you have asked for, so they are set without asking for consent, as permitted for strictly necessary cookies; declining them would simply mean the Platform could not be used. The analytics cookies at (3) are not strictly necessary. The Platform is currently offered only to users in the United States, and we do not at present operate a consent banner; we tell you about these cookies here and give you the means to refuse them above. If you are in the European Economic Area or the United Kingdom, contact privacy@trialtime.com before using the Platform and we will exclude you from analytics.
  3. Information we collect automatically from devices and online activities. We may collect information about the devices you use to access our Services, including hardware model, operating system version, internet protocol (IP) address, user settings, browser or device information, approximate location derived from IP address, and internet service provider. We may also collect information about your activity on our Services — such as the pages you view, links you click, access dates and times, and how you otherwise interact with the Services.
  4. Information we collect from customers and other third parties. Where permitted by law, we may obtain Personal Information about you from our customers (for example, when a sponsor, CRO, or research site provisions your Platform account or uploads records about you), from third-party services and organizations, or from publicly available sources used to verify professional credentials.

How We Use Information We Collect

We will only use your Personal Information for lawful purposes. We may use it to provide our Services, for administrative purposes, and to market our business and Services, as described below.

We will only use your Personal Information for the purpose for which we collected it, unless we reasonably consider that we need to use it for another compatible reason as permitted by applicable law. If we need to use your Personal Information for a purpose not specified in this Privacy Policy, we will notify you where required, explain the legal basis that allows us to do so, or seek your consent, as required.

  1. Provide our Services. We primarily use Personal Information to deliver, maintain, and improve the Platform and our other Services, to support your relationship with us, to create and administer accounts, to record and verify training and qualification records, and to protect Positive Ignition and our users and partners.
  2. Administrative purposes. We may use Personal Information to, among other things: measure interest in our Services and content; comply with regulatory requirements applicable to clinical research (such as requirements relating to investigator and site-staff training and qualification); manage our agreements and your relationship with us; verify and maintain data integrity and quality; process transactions; and detect and prevent malicious, deceptive, fraudulent, or illegal activity.
  3. Marketing. We may use Personal Information to market our business and Services as permitted by applicable law — for example, to send communications about the Platform, features, and events to individuals we have identified as prospective or existing customers.
  4. Regulatory and compliance purposes. We may use the information we collect to support quality control, verify identity, enable registration for events, respond to questions and requests, comply with law and regulatory requirements, support audits by our customers and their sponsors, detect and respond to security incidents, identify and repair errors, and conduct internal research for technological development — as well as for purposes disclosed at the time information is provided or otherwise with consent.
  5. De-identified and aggregated information. We may use Personal Information to create de-identified or aggregated information, which is not subject to this Privacy Policy and which we may use for any lawful purpose.
  6. Other purposes. We may use your Personal Information for other purposes with your consent, as requested by you, or as required or permitted by applicable law.

How We Disclose Personal Information

We may disclose your Personal Information to third parties for a variety of business purposes, including to provide our Services, to protect us or others, or in the event of a major business transaction, as described below. We do not allow the third-party service providers that process Personal Information on our behalf to use it for their own marketing or other purposes, and we only permit them to process it under written contracts for specified purposes and in accordance with our instructions.

  1. Consent. We will disclose Personal Information to parties outside of Positive Ignition when we have your consent to do so.
  2. Disclosures to provide our Services.
    1. Our customers. Where you access the Platform through a sponsor, CRO, research site, or other organization, we make your training and qualification records available to that organization and to the sponsors and study teams it authorizes, consistent with our agreement with that customer.
    2. Service providers. We may disclose Personal Information to third-party service providers that help us deliver the Services, including providers of IT support, cloud hosting, payment processing, and customer support.
    3. Business partners. We may disclose Personal Information to business partners to advance business initiatives or to jointly administer projects.
    4. Affiliates. We may provide Personal Information to our affiliates to process it on our behalf, based on our instructions and consistent with this Privacy Policy and appropriate confidentiality and security measures.
  3. Disclosures to protect us or others. We may access, preserve, and disclose information we hold about you if we, in good faith, believe doing so is required or appropriate to: comply with law enforcement requests and legal process, such as a court order or subpoena; protect your, our, or others’ rights, property, or safety; enforce our policies or contracts; collect amounts owed to us; or assist with an investigation of suspected or actual illegal activity.
  4. Business transactions. We reserve the right to disclose or transfer information we hold about you in connection with a proposed or actual reorganization, sale, merger, joint venture, assignment, financing, or other acquisition or disposal of all or part of our business or assets (including in connection with any bankruptcy or similar proceeding). Where such an event occurs, we will endeavor to require the recipient to use Personal Information in a manner consistent with this Privacy Policy and applicable law.

Your Privacy Choices

The choices you have about how we use your Personal Information depend on your circumstances, your relationship with us, and applicable law.

  1. Email communications. If you receive an unwanted marketing email from us, you can use the unsubscribe link at the bottom of the email to opt out of future marketing emails. You will continue to receive transaction- and account-related communications regarding the Services you use, as well as certain non-promotional communications (such as updates to our terms or this Privacy Policy), which you cannot opt out of.
  2. “Do Not Track” / “Global Privacy Control.” Some browsers offer a “Do Not Track” (“DNT”) setting or transmit a “Global Privacy Control” (“GPC”) signal (see https://globalprivacycontrol.org/). We do not respond to DNT signals. Where our Services detect a GPC signal and applicable law requires, we will treat it as a request to opt out of the sale or sharing of Personal Information for targeted advertising.
  3. Cookies and similar technologies. You may stop or restrict cookies using the controls in your browser or device. Because every cookie we set is strictly necessary to operate the Platform (see “Cookies we set” above), blocking them will prevent you from signing in or from viewing course content — there are no optional cookies to turn off, and so no cookie preference centre to offer. Browser settings must be applied separately in each browser and on each device.

Your Privacy Rights

In accordance with applicable law, you may have the right to:

  1. Access your Personal Information, including confirmation of whether we process it, a copy of it, and, in some cases, a portable electronic copy.
  2. Request correction of your Personal Information where it is inaccurate or incomplete. Where your records are managed by a customer (for example, a research site), we may refer you to that customer to make the correction.
  3. Request deletion of your Personal Information, subject to exceptions prescribed by law and to any retention obligations owed to our customers or required for clinical research recordkeeping.
  4. Object to processing of your Personal Information in certain circumstances, such as processing based on our legitimate interests for direct marketing.
  5. Opt out of “sale” or “sharing.” We do not “sell” Personal Information, and we do not “share” it for cross-context behavioural advertising as those terms are used in applicable state privacy laws. We conduct no advertising and use no advertising or analytics technologies in the Platform. If that ever changes, we will update this Policy and offer an opt-out before the change takes effect.
  6. Withdraw consent where our processing is based on your consent. Withdrawal takes effect only for future processing and does not affect processing carried out before withdrawal.
  7. Appeal our decision or response to your privacy rights request, where applicable, using the same method you used to submit your original request.
  8. Lodge a complaint with the data protection authority or other regulator responsible for enforcing data protection laws in your jurisdiction.

To make a privacy rights request, please use the contact information at the end of this Privacy Policy. If your request concerns training or qualification records managed by a sponsor, CRO, or research site, please direct your request to that organization, as we process those records on its behalf. We will process requests in accordance with applicable law and will not discriminate or retaliate against you for exercising your rights. To protect your privacy, we will take steps to verify your identity before fulfilling a request. Depending on your jurisdiction, you may designate an authorized agent to make a request on your behalf, and we may require proof of that authorization.

Children’s Information

Our Services are directed to professionals involved in clinical research and are not directed to children under 16 (or other age as required by local law), and we do not knowingly collect Personal Information from children. If you believe a child has provided us with Personal Information, please contact us, and if we learn we have collected such information in violation of applicable law, we will promptly take steps to delete it unless we are legally obligated to retain it.

Retention

We retain the Personal Information we collect for as long as you use our Services, or as necessary to fulfill the purposes for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, enforce our agreements, and comply with applicable laws — including clinical research recordkeeping and audit requirements and the retention periods specified in our agreements with our customers. Where we process training and qualification records on behalf of a customer, retention is governed by our agreement with that customer.

Information Security

The security of Personal Information provided to us is important to us, and we take reasonable technical and organizational measures designed to protect it. However, no method of transmission over the internet or storage of information can be guaranteed to be 100% secure. While we strive to protect your Personal Information, we cannot ensure or warrant its security, and you provide it at your own risk. To the fullest extent permitted by applicable law, we do not accept liability for unauthorized disclosure.

Third-Party Sites and Services

This Privacy Policy does not apply to services offered by other companies or individuals, or to other sites linked from our Services. Our Services may contain links to third-party websites for your convenience. We do not control those websites or their privacy practices, which may differ from ours. We encourage you to review the privacy policy of any third-party website before submitting your Personal Information to it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time as we deem necessary in our discretion. If there are material changes, we will notify you as required by applicable law. We encourage you to review this Privacy Policy periodically. Any changes take effect after being posted or otherwise provided by us.

Contact Us

Positive Ignition, Inc.
Attn: Privacy
1732 Wabasso Way
Glendale, CA 91208
Email: privacy@trialtime.com
Phone: 310-623-7733

Notice at Collection and Supplemental Notice for Residents of Certain U.S. Jurisdictions

  1. United States. This Notice at Collection and Supplemental Notice is for residents of states that have adopted comprehensive privacy legislation now or in the future (“Applicable State Laws”).
  2. Personal Information we collect and disclose. As described in “Information We Collect and How We Collect It,” we collect Personal Information directly from you, automatically when you use our Services, and from our customers and other sources. Depending on how you use our Services, the categories of Personal Information we may have collected in the preceding 12 months, and the categories of third parties to which we disclose it for a business purpose, are described below.
Category of Personal Information CollectedCategories of Third Parties Disclosed to for a Business Purpose
Identifiers, such as name, business address, email, username, or other online identifierOur customers; service providers; business partners; data analytics providers
Professional or employment-related information, such as CV, employer, position, licenses, certifications, and training recordsOur customers; service providers
Internet or other electronic network activity, such as interactions with our website and PlatformService providers; data analytics providers
Sensory data, such as audio or visual information collected at eventsService providers; business partners
  1. Use of Personal Information. We may use or disclose Personal Information for the purposes described in “How We Use Information We Collect,” including to provide the Services, for administrative purposes (including security and fraud prevention), to process your requests with your consent, and to comply with law and enforce our rights and the rights of others.
  2. Sales / sharing of Personal Information. We do not disclose your Personal Information in exchange for money. Certain online analytics or advertising activities may be considered a “sale” or “share” under some state privacy laws. We do not have actual knowledge that we “sell” or “share” the Personal Information of consumers under 16 years of age.
  3. Submitting a privacy rights request. You can exercise the rights available to you under Applicable State Laws as described in the “Your Privacy Choices” and “Your Privacy Rights” sections above.

EU and EEA/EFTA

Where we process personal data subject to the EU/UK General Data Protection Regulation, the primary legal bases on which we rely are set out below.

Processing PurposeDataPrimary Legal Basis
Provide our ServicesIdentity, contact, account, and qualification information you or your organization submitPerformance of a contract; our legitimate interests; and your consent where required
Administrative, regulatory, and compliance purposesIdentity, contact, communications, and information collected automaticallyCompliance with a legal or regulatory obligation; our legitimate interests (to operate and secure our business and prevent fraud); and your consent where required
MarketingIdentity, contact, and website/Platform usage dataOur legitimate interests (to develop and grow our business); consent where required by law (e.g., non-essential cookies)

Where we process personal data on behalf of a customer as a processor, that customer is the controller and its instructions and privacy notices govern that processing.