Oncera — Privacy & Related Policies
Effective date: November 17, 2025
Entity: Oncera (legal name and mailing address to be supplied)
Contact: privacy@oncera.com
Oncera is a U.S.–based, clinician‑facing platform that helps oncology professionals discover sites, people, and trials. This website is not a patient intake portal and does not accept Protected Health Information (PHI).
1) Privacy Policy
1.1 Scope & Who We Are
This Privacy Policy explains how Oncera ("we," "us," "our") collects, uses, discloses, and protects information about clinician users (e.g., MDs, PIs) and other visitors to our website and services (the "Services"). Oncera does not solicit, receive, or store PHI and is not acting as a HIPAA covered entity or business associate for the Services described here. If we later offer patient‑facing features, we will update this Policy and add all required notices and controls. (For general HIPAA scope and definitions, see HHS guidance.)
1.2 Notice at Collection (California)
At or before the point of collection, we provide a concise notice describing categories of personal information collected, purposes, retention, and whether information is "sold" or "shared," with a link to this Policy. This implements California's Notice at Collection requirements.
Short‑form example (used on sign‑up pages):
We collect your name, professional affiliation, specialty, email, phone, and practice location to create and display your clinician profile, enable trial‑network discovery, and communicate with you. We also collect technical data (e.g., IP address, device/browser) for security and analytics. We do not sell or share your personal information for cross‑context behavioral advertising. If you enable precise device location, you may limit our use of it or disable it at any time. See the full Privacy Policy for categories, uses, retention, and your rights. We honor Global Privacy Control signals.
1.3 What We Collect
- Identifiers & Contact: name, professional email, professional phone.
- Professional Information: specialty, role (e.g., MD, PI), site/institution affiliations, NPI (if you add it).
- Location Information:
- Practice/Site location you provide (we may derive coordinates for mapping).
- Device‑derived precise geolocation (optional) if you grant OS/browser permission. Under the CPRA, "precise geolocation" means device‑derived data used to locate a consumer within a radius of 1,850 feet (≈ 564 meters).
- Technical & Usage Data: IP address, device/browser type, pages viewed, referrer, timestamps; cookie/SDK identifiers for session management, security, and analytics.
- Communications & Preferences: messages you send, notification settings, marketing preferences (if any).
1.4 Sources
- Directly from you (account creation, profile edits, forms).
- Public/professional sources you choose to link (e.g., institutional pages, NPI if you add it).
- Automatic collection from your device and our infrastructure/service providers (logs, metrics).
1.5 Why We Use Your Information (Purposes)
- Directory & Profile: create/display professional profiles (specialty, site, practice map pin) for discovery and collaboration.
- Communications: account and transactional notifications; optional network announcements.
- Security & Integrity: fraud prevention, debugging, monitoring.
- Analytics & Performance: measuring usage to improve Services (non‑profiling).
We do not use personal information for cross‑context behavioral advertising. If this changes, we will update this Policy and provide the required opt‑outs.
1.6 "Sell" / "Share" Status; Global Privacy Control
Oncera does not sell or share personal information (including any sharing for cross‑context behavioral advertising). If that changes, we will (i) add a "Do Not Sell or Share My Personal Information" link and (ii) honor Global Privacy Control (GPC) signals as valid opt‑outs.
1.7 Disclosures to Service Providers / Contractors (stack transparency)
We engage reputable vendors under contracts that restrict their use of personal information to services performed for Oncera. Core components of our stack include:
- Auth0 (Identity & Security): customer authentication, MFA, attack protection, session security. (Auth0)
- Supabase (Database/Backend): Postgres database and platform services; see Supabase security & compliance pages. (Supabase)
- Netlify (Hosting/CDN): site hosting, build/deploy platform, global CDN; see Netlify security/trust resources. (Netlify)
- GitHub (Repository/CI): source‑code hosting, CI workflows, and security tooling for our codebase. (GitHub)
These vendors may access data only to perform contracted services for us and are prohibited from secondary uses.
1.8 Your Privacy Rights
Depending on your jurisdiction (including California), you may have rights to know/access, delete, correct, and obtain a portable copy of your data; to opt out of sale/share; and to limit the use and disclosure of Sensitive Personal Information (e.g., device‑level precise geolocation). We provide at least two request channels (a web form and privacy@oncera.com), verify requests, and respond within the timelines set by law. We honor GPC signals for applicable opt‑outs. Note: California's prior B2B exemption expired January 1, 2023, so professional contact data (MDs, PIs) can be in scope.
1.9 Retention
We retain personal information only as long as needed for the purposes described, then delete or de‑identify it. California requires disclosure of retention periods or criteria by category. Our baseline schedule:
| Category | Default retention |
|---|---|
| Profile & professional data | While account is active + 12–24 months (audit/recordkeeping) |
| Communications (transactional) | 24 months |
| Server logs & security events | 90 days (unless escalated) |
| Backups | Rolling 35 days |
| Device‑derived precise location (if enabled) | Session‑only; not retained beyond feature delivery |
1.10 Security
We implement reasonable administrative, technical, and physical safeguards proportionate to the data and risks—encryption in transit, role‑based/least‑privilege access, MFA for administrative access, audit logging, backups, and incident response. We also rely on our vendors' published security programs (e.g., Supabase security; SOC 2 Type 2 program as described in Supabase's documentation).
1.11 International Users (if applicable)
If EU/UK clinicians use Oncera, we act as a controller for professional data and rely on appropriate lawful bases (often legitimate interests for a professional directory, or consent where required). Where data is transferred across borders, we use recognized transfer tools and provide EU/UK rights.
1.12 Children's Privacy
Oncera is directed to professionals and is not intended for children. We do not knowingly collect personal information from children under 13 (and do not knowingly sell/share data of consumers under 16).
1.13 Public Profiles & Your Choices
Clinician profiles (e.g., name, specialty, practice location, work email/phone) may be publicly viewable to enable networking and trial discovery. You may update or request removal of profile fields via Account Settings or by contacting privacy@oncera.com.
1.14 Links, Third‑Party Sites, and APIs
Our Services may link to external resources (e.g., ClinicalTrials.gov) or embed content/tools. Their privacy practices are governed by their policies.
1.15 Changes to this Policy
We will post updates here and adjust the Effective date. Material changes will be highlighted or communicated through the Service.
2) Cookie & Tracking Policy
2.1 What We Use
- Strictly necessary (authentication/session; security/anti‑fraud).
- Functional (remembering preferences).
- Analytics (aggregate measurement; not cross‑context advertising by default).
If we introduce advertising/retargeting technologies, we will seek consent where required, update this Policy, and provide Do Not Sell/Share choices; we also honor GPC signals for applicable opt‑outs.
2.2 Controls
Manage cookies via our on‑site Cookie Settings and your browser/OS settings. You may also send a GPC signal.
3) Accessibility Statement
We are committed to digital accessibility and aim to conform to WCAG 2.1 AA. If you encounter an accessibility barrier (e.g., with screen readers or keyboard navigation), contact accessibility@oncera.com and we will work to remediate promptly. (See DOJ's web accessibility guidance referencing WCAG 2.1 AA.)
4) Editorial & Content Policy
- Sources & Attribution: Trial information is primarily derived from official registries (e.g., ClinicalTrials.gov) and sponsor/organization postings; we attribute third‑party data where required and link to source entries.
- Informational Use Only: Content is for informational purposes only; it is not medical advice and does not endorse any drug, device, or protocol.
- Updates: We periodically refresh trial information and correct errors upon notice; listings can change at the source without our knowledge.
- Conflicts & Governance: Editorial decisions support accuracy, transparency, and neutrality; marketing claims about efficacy/safety are prohibited in editorial spaces.
5) Recruitment & Advertising Guidelines (if applicable)
If Oncera facilitates trial recruitment (beyond listing):
- Materials must conform to FDA and IRB requirements; no unsubstantiated claims of safety/efficacy.
- Copy and creative undergo internal review and, where required, IRB review before publication.
- We maintain archives of finalized recruitment materials and approvals.
6) Security Statement (Overview)
- Identity & Access: Auth0 for authentication, MFA, attack protection, and continuous session protections. (Auth0)
- Databasing & Backend: Supabase for PostgreSQL database and platform services; encryption in transit/at rest; documented RBAC; published security/compliance program (including SOC 2 as described by Supabase). (Supabase)
- Hosting & CDN: Netlify for site hosting, global CDN, and platform security measures; see Netlify's security and trust resources. (Netlify)
- Repository & CI/CD: GitHub for code hosting and workflows; enterprise‑grade platform and compliance resources (e.g., access to SOC reports) are available via GitHub's trust and security documentation. (GitHub)
Practices: role‑based access and least privilege, MFA for administrative accounts, branch protections and secret management in GitHub, environment‑variable controls in Netlify, database RLS in Supabase where applicable, encryption in transit, backups, monitoring, and incident response. (Always keep secrets out of source control and enforce secret‑scanning.)
7) How This Policy Relates to Your Terms & Disclaimer
This Privacy & Related Policies document supplements, and is incorporated by reference into, the site Terms & Conditions and Disclaimer. In case of conflict, the Terms control contractual matters; the Disclaimer controls clinical/medical reliance; this document controls privacy and related practices.