1What This Document Is For
Institutional Review Boards and ethics committees ask the same questions of every study that collects data through a platform: where the data lives, who can see it, how participants consent, and what happens to the data afterwards. This page answers them for ExpiWell in citable form. The platform is trusted by IRBs in medical and clinical settings, and the team helps researchers through the review process — including the compliance verbiage an application needs. Reach us through the contact page or security@expiwell.com.
2A Compliance Statement You Can Cite
The paragraph below may be used directly in an IRB or ethics application:
ExpiWell takes data security and privacy seriously, adhering to rigorous standards to protect participant information. The software complies with both the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR), and the controls behind that compliance are monitored continuously and published in a public, real-time trust report. ExpiWell employs robust security measures, including data encryption, secure servers, and strict access controls, to safeguard against unauthorized access and data breaches. Data is anonymized and de-identified whenever possible to further protect participant privacy. All data is collected, stored, and processed in accordance with applicable legal and ethical standards, and participant rights are upheld throughout the research process. Through ExpiWell's Privacy Policy and Terms of Service, participants are informed about how their data will be used, and consent is obtained before data collection begins.
3How Participant Data Is Protected
Data is encrypted in transit with Transport Layer Security (TLS) and at rest with AES-256. Services run in the data centers of a major cloud infrastructure provider certified against ISO/IEC 27018, behind firewall systems and regular vulnerability scans, with the controls monitored continuously. The standing description — hosting, HIPAA safeguards, GDPR and data residency, access control — is the data security policy, and the real-time status of every monitored control is in the live trust report.
4Personally Identifiable Information
ExpiWell collects sensitive information and follows industry standards to protect it. Profile information that may be collected includes first name, last name, date of birth, ethnicity, gender, country, and state. That information exists to build a participant's ExpiWell profile and is not shared with researchers at any time. Submission data may also include sensitive information, but never profile information, and both are protected under the same data-protection practices.
5Passive Data and Device Permissions
ExpiWell currently collects only two forms of passive information:
- Location. If a researcher enables location collection, participants must first consent before GPS data (longitude, latitude, and time zone) is collected.
- Anonymous usage data, used to detect mobile issues and measure app performance.
The mobile apps request access to the phone's microphone, camera (photo and video), storage, and GPS. No device identifiers — and no other passive information that could link back to the user on the app side — are stored.
6Informed Consent
Participants are informed about how their data will be used through ExpiWell's privacy statement and Terms of Service, and consent is obtained before data collection begins. Where a study collects location data, collection is additionally gated on the participant's explicit consent, as described in clause 5.
7Data Control, Deletion and Retention
Researchers control their own participant data, and any of it can be deleted on request: select the item, confirm the request, and it is removed from ExpiWell's databases immediately. Daily backups retain deleted data for 8 days, after which it is removed from ExpiWell's servers automatically.
8Documents Available on Request
- The hosting provider's name and its current ISO/IEC 27018 certification
- The signed Business Associate Agreement (HIPAA)
- A formal GDPR statement of compliance
- The GDPR Article 28 data-processing contract, also downloadable from the GDPR policy
Request any of these from security@expiwell.com.