1. Who we are

Metamorphic AI ApS (“Metamorphic”, “we”, “us”) is the data controller for the personal data described in this policy, except where we act as a processor (see section 3).

Legal entity: Metamorphic AI ApS, CVR [company registration number], [registered address], Denmark.

Privacy contact: privacy@metamorphic-ai.com

Data Protection Officer: we have appointed an external Data Protection Officer, provided through Probo. You can reach the DPO at privacy@probo.com.

2. What this policy covers

This policy explains how we handle personal data for which Metamorphic is the controller: the data of visitors to our website and people who contact us, and of the customer personnel who use our platform.

It does not cover the clinical study content that our customers upload to the platform. For that content we act as a processor on our customers' instructions, as explained in section 3.

3. Our two roles

As a processor (clinical study content): Our platform drafts Clinical Study Reports from source materials provided by our customers, who are pharmaceutical sponsors and contract research organizations. Where those materials contain personal data, including health data, the customer is the controller and we process the data only on their documented instructions under Article 28 GDPR. The customer's own privacy notice governs that data, and the customer determines the Article 9 condition for any health data. We do not use this content to train AI models, and every AI-generated section is reviewed by an authorized user before use. If you are a clinical trial participant or are named in trial materials, please direct any request to the sponsor or CRO running the study; we will assist them as required.

As a controller: For the processing described in section 4, Metamorphic determines the purposes and means and is the controller.

4.1 Platform account users

Customer personnel who are given accounts to use the platform.

Data: name, business email, job title, role assignments, hashed authentication credentials, multi-factor enrolment, IP address, and login and session activity.

Purpose: creating and securing accounts, authenticating users, and applying role-based access.

Legal basis: our legitimate interest in secure, accountable access to the platform (Article 6(1)(f)).

Retention: account data is deleted or anonymized within one year of account deactivation or contract termination; authentication and session logs are kept for 30 days.

Your employer decides which of its personnel are given access.

4.2 Support

People who contact us for support.

Data: name, business email, the content of the request, and anything included in it.

Purpose: receiving, triaging, and resolving support requests and keeping a record of them.

Legal basis: our legitimate interest in handling support requests (Article 6(1)(f)).

Retention: two years after the relationship ends.

4.3 Website visitors and enquiries

People who visit our website or contact us through it.

Data: the contact details and message you send us, and limited technical data needed to serve the site.

Purpose: responding to your enquiry and operating the website.

Legal basis: our legitimate interest in responding to you and running our site (Article 6(1)(f)), or taking steps at your request before entering a contract (Article 6(1)(b)).

Retention: for as long as needed to handle your enquiry and any relationship that follows.

4.4 Platform telemetry and operational logs

Data: user identifiers, IP address, device and browser metadata, usage events, and diagnostic and performance logs.

Purpose: operating, securing, monitoring, and troubleshooting the platform and investigating security incidents.

Legal basis: our legitimate interest in a secure and reliable service (Article 6(1)(f)), supported by a documented Legitimate Interests Assessment.

Retention: 30 days for centralized application and access logs; security-relevant logs may be kept longer for an active investigation.

4.5 Billing and customer administration

The people at our customers who handle contracting, invoicing and payment.

Data: name, business email, telephone number, role, and the invoices and payment records associated with them.

Purpose: managing the contractual relationship, issuing invoices, taking payment, and keeping accounting records.

Legal basis: our legitimate interest in administering the customer relationship (Article 6(1)(f)); legal obligation for accounting records (Article 6(1)(c)).

Retention: accounting records are kept for five years from the end of the financial year they relate to, as required by the Danish Bookkeeping Act; other billing-contact data is deleted within one year of the contract ending.

4.6 Employees

Personal data about our own staff is handled separately as part of our employment relationship and is not covered by this policy.

6. Who we share data with

We use a small set of service providers (processors) to run our platform and business. They act on our instructions under written agreements:

Amazon Web Services (Frankfurt, EU) - cloud hosting and inference.

MongoDB Atlas (Frankfurt, EU) - database.

Stripe (US) - payment processing and invoicing.

Microsoft 365 (EU Data Boundary) - email and document collaboration.

Twingate - secured access to our production systems.

Probo (EU) - our compliance platform and external Data Protection Officer.

We also use standard business tools for source control, project management, secrets management, and our domain. A current list of processors is available on request. We do not sell personal data.

7. International transfers

We host and process personal data in the European Union (AWS Frankfurt). Where data reaches a country outside the EEA, we rely on a valid safeguard:

Microsoft 365 operates under Microsoft's EU Data Boundary, and Microsoft is certified under the EU-US Data Privacy Framework.

Our own billing is handled through Stripe (United States) under its Data Privacy Framework certification and Standard Contractual Clauses.

8. Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. Where we rely on consent, you can withdraw it at any time.

To exercise a right, contact us at privacy@metamorphic-ai.com. We respond within one month, which we may extend by two further months for complex requests, and we will tell you if we do. We may ask you to verify your identity. If your request concerns clinical study content, we act as a processor and will forward it to the relevant customer-controller.

If you have a concern, you can lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your local supervisory authority.

9. Cookies

Our website uses only the cookies and similar technologies necessary to operate it. We will ask for your consent before setting any non-essential or analytics cookies.

10. Automated decision-making

Our platform uses AI to draft document content, but it does not make automated decisions that produce legal or similarly significant effects on individuals, and it does not profile individuals. All AI-generated content is reviewed by a person before use.

11. Children

Our services are intended for business use and are not directed to children. We do not knowingly collect personal data from children under 16.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the “last updated” date above.

13. Contact

Controller: Metamorphic AI ApS, [registered address], Denmark.

Privacy contact: privacy@metamorphic-ai.com

Data Protection Officer (external, via Probo): privacy@probo.com

Supervisory authority: Datatilsynet, www.datatilsynet.dk