Privacy policy

How we handle personal information.

Effective date: 18 September 2026 · Last reviewed: 18 September 2026

FieldTruth.ai is a service of GRG Health. The data controller is Growman Research and Consulting Private Limited (“GRG,” “we”), registered office: 1102/1103/1104, C Wing, Teerth Technospace, Bengaluru–Mumbai Highway, Baner, Pune, Maharashtra 411045, India, with offices in the USA (1209 Orange Street, Wilmington, Delaware 19801), Singapore, the Philippines, and Gurugram, India.

This policy covers three groups: visitors to fieldtruth.ai, client representatives who contact or contract with us, and — at a summary level — contributing healthcare professionals, whose participation is governed in full by their own consent instruments and community terms.

1

What we collect, and why

Website visitors. We collect what you submit through our contact form (name, work email, company, role, type of organisation, what you are asking for, message, and the page, campaign link and referring site that brought you to the form) and limited technical data (IP address, browser type, pages visited) through privacy-respecting analytics. We use this to respond to your enquiry, operate and secure the site, and understand how it is used. Lawful bases: our legitimate interest in operating a business website and responding to enquiries; consent, where required, for any non-essential cookies.

Client representatives. When your organisation evaluates or licenses data from us, we process business contact details, correspondence, and contract and billing information — to negotiate and perform agreements, provide access to evaluation environments, meet legal obligations, and maintain the audit trail our documentation promises. Lawful bases: performance of a contract, legal obligation, and legitimate interest.

Contributing healthcare professionals. Professionals who take part in FieldTruth work do so through our community platform under explicit, layered consent captured before any participation — covering recording, processing and transcription, licensing to clients, and use as AI training data, each as a separate affirmation. Their identities are verified through our multi-layer process and held by us. Their identities are never disclosed to clients. Their participation, compensation, withdrawal rights, and data rights are governed by the contributor consent instruments and the community terms at kyrios.online. Withdrawal of consent applies to future collection and future licensing; material already licensed remains governed by the licence under which it was provided.

2

What we never do

  • We do not sell personal information — anyone’s, ever.
  • We do not disclose a contributor’s identity, contact details, or verification records to any client. Clients receive professional attributes only: specialty, country, experience band.
  • Licensed datasets are de-identified to a versioned redaction key before delivery: personal names, institutions, locations, and identifying details are removed or replaced with typed placeholders. Licensed datasets are not personal data by design; where any residual identification risk is found, the file is withheld.
  • Patient-identifiable information is never licensed. Where commissioned collection includes doctor–patient encounter recordings, both clinician and patient provide explicit consent before recording; files are de-identified to a versioned redaction key before delivery, and patient identity remains in our custody. We do not collect patient medical records; case datasets are physician-abstracted.
  • Data from research commissioned by our clients is never licensed, resold, or used to train AI models. That separation is warranted in writing to research clients and is structural to how FieldTruth operates.
3

Security

We are certified to ISO/IEC 27001:2022 (information security management) and ISO 20252:2019 (market, opinion and social research). Evaluation materials are provided through controlled environments — named users, streamed media, downloads disabled, expiring access. Access to personal information is restricted to personnel who need it, under confidentiality obligations, with audit logging.

4

International transfers

We operate from India, the Philippines, Singapore, and the United States. Where personal data of individuals in the EEA, UK, or other regulated jurisdictions is transferred internationally, we rely on appropriate safeguards, including standard contractual clauses and equivalent mechanisms, alongside our ISO-certified controls.

5

Retention

We keep personal information only as long as needed for the purposes above: enquiry data for 24 months after last contact; contract and audit-trail records for the duration of the relationship plus the period required by law and by our documented provenance commitments; contributor consent records for as long as licensed material remains in circulation plus statutory limitation periods — because our provenance certificates promise an audit trail for the life of every licence.

6

Your rights

Depending on your jurisdiction (including under the EU/UK GDPR, India’s Digital Personal Data Protection Act 2023, and applicable US state laws), you may have rights to access, correct, delete, restrict, or port your personal information, to object to processing, and to withdraw consent. To exercise any of them, write to compliance@grgonline.com. We respond within the timelines the applicable law requires. You may also complain to your supervisory authority. Our grievance officer for the purposes of Indian law is Akshat Bhatnagar, Chief Legal & Compliance Officer, reachable at the same address.

7

Cookies

The site uses strictly necessary cookies and, where enabled, privacy-respecting analytics. We do not use advertising trackers. Where law requires consent for any cookie, we ask first.

8

Third parties and links

The site links to related GRG properties, including kyrios.online (our professional community, with its own terms and privacy notice) and grgonline.com. Service providers who process data for us (hosting, form handling, analytics) act under contract, on our instructions, with confidentiality and security obligations.

9

Children

Our services and site are directed at professionals and organisations, not at children, and we do not knowingly collect children’s data.

10

Changes and contact

We will post updates to this policy here with a revised effective date; material changes affecting contributors are communicated through the community platform. Questions: compliance@grgonline.com · Growman Research and Consulting Private Limited, Pune, India.