Privacy Policy
Last Updated: July 2026
1. Who we are
Metamorphic AI ApS (“Metamorphic”, “we”, “us”) is the data controller for the personal data described in this policy, except where we act as a processor (see section 3).
Legal entity: Metamorphic AI ApS, CVR [company registration number], [registered address], Denmark.
Privacy contact: privacy@metamorphic-ai.com
Data Protection Officer: we have appointed an external Data Protection Officer, provided through Probo. You can reach the DPO at privacy@probo.com.
2. What this policy covers
This policy explains how we handle personal data for which Metamorphic is the controller: the data of visitors to our website and people who contact us, and of the customer personnel who use our platform.
It does not cover the clinical study content that our customers upload to the platform. For that content we act as a processor on our customers' instructions, as explained in section 3.
3. Our two roles
As a processor (clinical study content): Our platform drafts Clinical Study Reports from source materials provided by our customers, who are pharmaceutical sponsors and contract research organizations. Where those materials contain personal data, including health data, the customer is the controller and we process the data only on their documented instructions under Article 28 GDPR. The customer's own privacy notice governs that data, and the customer determines the Article 9 condition for any health data. We do not use this content to train AI models, and every AI-generated section is reviewed by an authorized user before use. If you are a clinical trial participant or are named in trial materials, please direct any request to the sponsor or CRO running the study; we will assist them as required.
As a controller: For the processing described in section 4, Metamorphic determines the purposes and means and is the controller.
4.1 Platform account users
Customer personnel who are given accounts to use the platform.
Data: name, business email, job title, role assignments, hashed authentication credentials, multi-factor enrolment, IP address, and login and session activity.
Purpose: creating and securing accounts, authenticating users, and applying role-based access.
Legal basis: our legitimate interest in secure, accountable access to the platform (Article 6(1)(f)).
Retention: account data is deleted or anonymized within one year of account deactivation or contract termination; authentication and session logs are kept for 30 days.
Your employer decides which of its personnel are given access.
4.2 Support
People who contact us for support.
Data: name, business email, the content of the request, and anything included in it.
Purpose: receiving, triaging, and resolving support requests and keeping a record of them.
Legal basis: our legitimate interest in handling support requests (Article 6(1)(f)).
Retention: two years after the relationship ends.
4.3 Website visitors and enquiries
People who visit our website or contact us through it.
Data: the contact details and message you send us, and limited technical data needed to serve the site.
Purpose: responding to your enquiry and operating the website.
Legal basis: our legitimate interest in responding to you and running our site (Article 6(1)(f)), or taking steps at your request before entering a contract (Article 6(1)(b)).
Retention: for as long as needed to handle your enquiry and any relationship that follows.
4.4 Platform telemetry and operational logs
Data: user identifiers, IP address, device and browser metadata, usage events, and diagnostic and performance logs.
Purpose: operating, securing, monitoring, and troubleshooting the platform and investigating security incidents.
Legal basis: our legitimate interest in a secure and reliable service (Article 6(1)(f)), supported by a documented Legitimate Interests Assessment.
Retention: 30 days for centralized application and access logs; security-relevant logs may be kept longer for an active investigation.
4.5 Billing and customer administration
The people at our customers who handle contracting, invoicing and payment.
Data: name, business email, telephone number, role, and the invoices and payment records associated with them.
Purpose: managing the contractual relationship, issuing invoices, taking payment, and keeping accounting records.
Legal basis: our legitimate interest in administering the customer relationship (Article 6(1)(f)); legal obligation for accounting records (Article 6(1)(c)).
Retention: accounting records are kept for five years from the end of the financial year they relate to, as required by the Danish Bookkeeping Act; other billing-contact data is deleted within one year of the contract ending.
4.6 Employees
Personal data about our own staff is handled separately as part of our employment relationship and is not covered by this policy.
5. Legal bases and your right to object
We rely on performance of a contract (Article 6(1)(b)), our legitimate interests (Article 6(1)(f)), and, for tax and similar records, legal obligation (Article 6(1)(c)).
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (see section 8). We do not rely on consent for the processing in section 4; if we later introduce processing that needs consent, we will ask for it first.
7. International transfers
We host and process personal data in the European Union (AWS Frankfurt). Where data reaches a country outside the EEA, we rely on a valid safeguard:
Microsoft 365 operates under Microsoft's EU Data Boundary, and Microsoft is certified under the EU-US Data Privacy Framework.
Our own billing is handled through Stripe (United States) under its Data Privacy Framework certification and Standard Contractual Clauses.
8. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. Where we rely on consent, you can withdraw it at any time.
To exercise a right, contact us at privacy@metamorphic-ai.com. We respond within one month, which we may extend by two further months for complex requests, and we will tell you if we do. We may ask you to verify your identity. If your request concerns clinical study content, we act as a processor and will forward it to the relevant customer-controller.
If you have a concern, you can lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your local supervisory authority.
10. Automated decision-making
Our platform uses AI to draft document content, but it does not make automated decisions that produce legal or similarly significant effects on individuals, and it does not profile individuals. All AI-generated content is reviewed by a person before use.
11. Children
Our services are intended for business use and are not directed to children. We do not knowingly collect personal data from children under 16.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “last updated” date above.
13. Contact
Controller: Metamorphic AI ApS, [registered address], Denmark.
Privacy contact: privacy@metamorphic-ai.com
Data Protection Officer (external, via Probo): privacy@probo.com
Supervisory authority: Datatilsynet, www.datatilsynet.dk