How Lasso Informatics collects, uses, discloses, and protects personal information through our website and research platform.
Lasso Informatics website and platform
Effective date: August 1, 2026
Last revised: August 1, 2026
This policy explains how Lasso Informatics Inc. and Lasso Informatics US Inc. (together, "Lasso," "we," "us," or "our") collect, use, disclose, and protect personal information through the Lasso website at www.lassoinformatics.com and the Lasso research platform (together, the "Services"). It applies to website visitors, prospective customers, registered platform users, and customer personnel who use the Services.
If your organization has a separate written agreement with Lasso, including a Business Associate Agreement, that agreement controls where it conflicts with this policy for the data it covers.
Lasso builds and operates software for research data management, serving research sponsors, research sites, and government research agencies across Canada and the United States.
Lasso collects two distinct categories of information, and this policy treats them differently.
Information Lasso controls directly. This includes information from website visitors and prospects, account administrator and user contact details, billing contacts, job applicants, and personnel of Lasso customers and vendors. Lasso decides how and why this information is used, and this policy governs it in full.
Protected health information customers submit to the platform. Lasso customers, typically research sponsors and sites, use the platform to manage research data. That data may include protected health information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). For this data, Lasso acts as a Business Associate, and the customer or its affiliated covered entity acts as the Business Associate Agreement (BAA) counterparty and, where applicable, the HIPAA covered entity. Lasso processes this data only as the BAA and the customer's instructions permit.
A research participant whose health information appears in the platform should direct privacy questions and HIPAA rights requests, such as access or amendment requests, to the sponsor or site that submitted the data. Lasso does not have a direct relationship with research participants and will support the covered entity in responding to a valid request under the terms of the applicable BAA.
Website
Platform accounts
Content customers submit to the platform
Communications
System and security logs
Lasso does not use customer-submitted research data, including PHI, for its own marketing or advertising, and does not sell personal information or PHI to third parties.
With a user's consent, Lasso may send text messages to a phone number provided through the website or the platform. Lasso sends these messages for account and security purposes, including but not limited to:
These are transactional messages tied to an account or a support interaction. Lasso does not use text messaging for marketing without separate, express consent. Message and data rates from the recipient's carrier may apply. Reply STOP to a Lasso text message to opt out of non-essential messages. Lasso does not share phone numbers collected for text messaging with third parties for their own marketing purposes.
Where Lasso processes PHI on behalf of a customer, Lasso operates as a Business Associate under HIPAA and the applicable BAA. Lasso maintains administrative, physical, and technical safeguards aligned to the HIPAA Security Rule and to NIST SP 800-53 control families, including:
Lasso notifies the affected customer of a breach of unsecured PHI in the timeframe the BAA and the HIPAA Breach Notification Rule require, so the customer can meet its own notification obligations to affected individuals and regulators. Lasso does not access, use, or disclose PHI beyond what the BAA and applicable law permit.
Lasso does not sell personal information or PHI, and does not share PHI with any party outside the uses this policy and the applicable BAA describe.
Lasso maintains a security program aligned to NIST SP 800-53 and designed to support HIPAA and SOC 2 requirements. Current attestations and certifications, once completed, are available at trust.lassoinformatics.com.
Lasso retains website and prospect contact data for as long as needed to respond to the inquiry and for a reasonable period after, consistent with applicable law. Lasso retains account and system security logs for at least 6 years, consistent with its internal data management policy and NIST SP 800-53 control AU-11. Lasso retains customer-submitted research data, including PHI, for the period the applicable customer agreement, BAA, and any governing federal or provincial records schedule require, and deletes or returns it at contract end according to that agreement.
Website visitors and prospects. You may ask Lasso to access, correct, or delete the personal information Lasso holds about you by contacting the Privacy Officer in Section 15.
Platform account users. Contact your organization's platform administrator to update or remove your account information. Lasso supports the administrator in fulfilling that request.
Individuals whose health information appears in customer research data. Direct a request to the sponsor or site that submitted your data. Lasso supports that organization's response under the terms of the applicable BAA.
Quebec and Canadian residents. You have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25, including the right to access and correct your personal information and the right to file a complaint with the Commission d'acces a l'information du Quebec.
Essential cookies support functions such as page navigation and form submission and cannot be turned off without affecting site function. Analytics cookies activate only with consent where applicable law requires it. You can manage cookie preferences through your browser settings or, where available.
Lasso stores platform data in the United States. Where Lasso transfers personal information across the Canada-US border for hosting, support, or processing, Lasso does so under contractual safeguards consistent with PIPEDA and applicable US law.
The Services are not directed to children, and Lasso does not knowingly collect personal information from anyone under 16. If Lasso learns that it has collected information from a child without the consent required by law, Lasso will delete it.
Direct questions about this policy, a privacy request, or a suspected security incident to:
Lasso may update this policy as its practices, the Services, or applicable law change. Lasso will post the revised policy on this page and update the revision date above. For a material change, Lasso will provide additional notice, such as an email to account administrators or a notice on the website, before the change takes effect.