Myelin · Privacy
Privacy notice
Version 1.0 · 25 July 2026
Who we are
Myelin (“we”) provides a transit and quality-review platform for R&D data exchanged between pharmaceutical companies and their external partners. For questions about this notice or your personal data, contact hello@myelinbridge.com.
Visiting this website
The public pages of this site use no advertising trackers and no analytics cookies. Our hosting provider (Vercel) processes standard technical request logs (IP address, user agent, requested page) to serve and secure the site — legal basis: legitimate interest in operating a secure service (Art. 6(1)(f) GDPR).
Using the Myelin platform
If you hold a platform account (as a sponsor or partner user), we process your account data — name, email address, organization and role — to operate the service: authentication, access control, review workflows, notifications, and the audit trail your organization relies on for traceability. Legal basis: performance of the contract with your organization (Art. 6(1)(b)) and legitimate interest in service security (Art. 6(1)(f)). Functional session cookies are used for sign-in; there are no third-party tracking cookies.
Research data transferred through Myelin is processed on behalf of and under the instructions of the sponsoring organization, which acts as data controller. Myelin acts as processor under a data processing agreement, stages research data in the EU only for transit and review, and purges staged copies automatically after verified delivery. Requests concerning research data should be directed to the sponsoring organization; we assist that organization in fulfilling them.
Where data lives, and who processes it
All primary data — database, temporary file staging, application compute, file transfer, backups — is processed in the European Union (Ireland, Dublin, Belgium). Our subprocessors are: Supabase (database, authentication, temporary storage — EU), Vercel (application hosting — EU compute), Google Cloud (file transfer and backups — EU), and Resend(transactional email — US). Notification emails carry only your name, email address and business metadata — never research file names or content; this is the only flow leaving the EU, safeguarded by the provider’s data processing agreement and EU-approved transfer mechanisms.
Retention
Account data is retained while your organization uses the service and removed on instruction thereafter. Staged research files are purged automatically after verified delivery plus a short grace window. The audit trail is retained as the sponsoring organization’s tamper-evident compliance record, under terms agreed with that organization. Backups roll over on a 30-day cycle.
Your rights
Under the GDPR you may request access to, rectification or erasure of your personal data, restriction of or objection to its processing, and portability. Write to hello@myelinbridge.com — we respond within one month. Where Myelin processes data as a processor, we will route your request to the controlling organization and assist it. You may also lodge a complaint with your local supervisory authority.
Changes to this notice
We update this notice when our processing changes — for example, a new subprocessor — and adjust the version and date above. Material changes are notified to platform users.