Skip to main content
Certara logo

Certara

GDPR evidence

certara.comLife sciences and biotechLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Certara and GDPR

CertReports found no public GDPR evidence for Certara as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, UK Extension Certification, SW-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
7 Apr 2022
Expires or valid through
16 Mar 2027
Scope
Our customers will typically act as data controllers for any Personal Information related to them or that they upload in our systems, products, and applications in connection with the provision of our Services. Certara will typically act as a data processor in accordance with applicable Service and/or data processing agreements. Further information, including specific obligations of the data controller and processor, can be found in our Service and/or data processing agreements. From Websites or Events: We may collect Personal Information that you choose to send to us or provide to us, for example, on our “Contact Certara” (or similar) online form or if you register for a Certara webinar. If you contact us through the Websites or via email, we will keep a record of our correspondence. We receive and store information about you, or your company provided directly to us, to satisfy customer contract obligations. The types of information we may collect directly from our customers and their users include names, usernames, email addresses, postal addresses, phone numbers, job titles, transactional information, as well as other contact or other information they choose to provide us or upload to our systems in connection with the Services. Other personal information we process may vary depending on the requirements specified in customer contracts. Certara advances modern drug development with modeling and simulation, regulatory science, and market access solutions and services. To provide these Services, Certara may receive source documents from our customers to create documentation and perform analysis associated with drug development and lifecycle support activities, including sales, marketing and submissions to regulatory bodies worldwide. Other personal information, including sensitive health and medical information may be collected when interacting with hospitals, medical providers, and other third parties to satisfy customer contract terms. We take appropriate steps to protect this information, including pseudonymization, encryption, and other industry standard security and privacy controls. We may share your information with third party vendors, contractors, and other service providers who we employ to perform tasks on our behalf, including a payment processing company, a website analytics company, a product feedback or help desk software provider, a CRM service provider, and an email service provider. We may also share your personal data with our parent companies, subsidiaries and/or affiliates for purposes consistent with this Privacy Notice. Personal Data may be transferred between Certara global Entities to ensure efficient and effective business operations and to enable the Certara Entities to provide customer, sales, marketing, human resource, finance, information technology, legal, quality assurance, software/product development, and other support services. Certara may process employee data of EU residents for the purpose of administering and carrying out employment or personnel relationships.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Certara, Inc.: Active: EU-US Certification, UK Extension Certification, SW-US Certification
Live pagesha256 b9d0471fc6
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
Synchrogenix receives data that reflects personal information for individuals who participate in clinical trials. While the data is not clearly identifiable, Synchrogenix has access to data collected at the individual level. Synchrogenix receives source documents from clients containing personal data to create documentation associated with drug development and lifecycle support activities, including submissions to regulatory bodies worldwide, as well as documents intended for public disclosure.In providing products/services that involve the transfer of personal data, Synchrogenix is acting as a data processor of client-controlled data, and after providing services to the client using the personal information, the information is destroyed, archived, or returned to the client per applicable SOPs and client agreements, not transferred onto any third parties.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Synchrogenix Information Strategies, LLC: Inactive
Live pagesha256 af933c4203
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
Certara may gather various types of information, including information that identifies or may identify you, as an individual (“Personal Information”), as explained in more detail below. From Websites or Events: We may collect any Personal Information that you choose to send to us or provide to us, for example, on our “Contact Certara” (or similar) online form or if you register for a Certara webinar. If you contact us through the Websites or via email, we will keep a record of our correspondence. We may also collect information about you from other publicly available sources, including third parties from whom we purchase personal data and combine this information with personal data provided by you. From the Services: We receive and store information you or your company provides directly to us to satisfy customer contract obligations. For example, when setting up new users for our Services, we collect Personal Information, such as name and e-mail address, to provide the individuals with the Services. The types of information we may collect directly from our customers and their users include names, usernames, email addresses, postal addresses, phone numbers, job titles, transactional information, as well as any other contact or other information they choose to provide us or upload to our systems in connection with the Services. Other personal information we process may vary depending on the requirements specified in customer contracts. Health and Medical Information: Together with our partners and clients, Certara advances modern drug development with modeling and simulation, regulatory science, and market access solutions and services. To provide these Services, Certara may receive source documents from customers to create documentation and perform analysis associated with drug development and lifecycle support activities, including sales, marketing and submissions to regulatory bodies worldwide. Other personal information, including sensitive health and medical information may be collected when interacting with hospitals, medical providers, and other third parties to satisfy customer contract terms. We take appropriate steps to protect this information, including pseudonymization, encryption, and via other industry standard security and privacy controls. Certara may share and disclose information (including Personal Information) in the following circumstances: Vendors, contractors, and other service providers We may share your information with third party vendors, contractors, and other service providers who we employ to perform tasks on our behalf. These companies include (for example) our corporate services providers (e.g., Oracle), website analytics companies (e.g., Google Analytics), product feedback or help desk software providers (e.g. ServiceNow), CRM service providers (e.g., Salesforce), email service providers (e.g., Microsoft) and others. If Certara receives your Personal Information and subsequently transfers that information to a third party agent or service provider for processing, Certara remains responsible for ensuring that such third party agent or service provider processes your Personal Information to the standard required by the applicable privacy laws, including the GDPR (see the section below headed “How are International Data Transfers processed?”). Certara Group Companies We may also share your personal data with our parent companies, subsidiaries and/or affiliates for purposes consistent with this Privacy Notice. Personal Data may be transferred between Certara Entities to ensure efficient and effective business operations and to enable the Certara Entities to provide customer, sales, marketing, human resource, finance, information technology, legal, quality assurance, software/product development, and other support services.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Certara Holding, Inc.: Inactive
Live pagesha256 84e720b300
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Certara GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Life sciences and biotech category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Life sciences and biotech vendor has GDPR evidence in the index yet.