Data handling & privacy
EasyHTA is built around data minimization: the platform works from aggregate survival data, not from patient records. This page explains what the app accepts, where your data is processed and stored, how it is protected, how long it is kept, and the controls you have over it.
Our approach
Health-economic analysis does not need individual patient records, and EasyHTA is designed so that none enter the system. You work from aggregate survival data (time and survival-probability coordinates), whether digitized from a published Kaplan–Meier curve or derived from your own trial. That aggregate data can still be commercially confidential, which is exactly why the protections described below apply. Because the analysis never requires names, identifiers, or clinical records, the simplest way to protect your data is to never accept those in the first place. The sections below describe how that principle is enforced and how the rest of your work is handled.
What you can upload
Survival data is uploaded as a two-column table: time and survival. The app validates every upload against a strict allow-list and accepts those two columns only. Any additional column is rejected at upload rather than ignored, and a column that looks like a personal identifier, for example a name, email address, medical record number, date of birth, patient or subject ID, or similar, is named in the error so you know what to remove. A rejected file is never sent.
Where analysis runs
Reconstruction (recovering an individual-patient-data table from your survival curve) and parametric model fitting run on our servers, hosted in the European Union. These computations are stateless: the uploaded data is read into memory, processed to produce the response, and is not written to disk or to file storage. Your project is saved to your account as you work, so you can return to exactly where you left off, and saved projects stay private to you until you choose to share them (see What we store).
For accountability and abuse prevention, our servers record technical request logs (such as the endpoint called and the request size). These logs do not contain the contents of your uploads or results.
What we store
The platform saves your project to your account as you work, so you can return to exactly where you left off: your inputs, settings, reconstructed data, and results, together with the project name and version history. It also stores the information needed to run your account and workspaces, such as your workspace membership and role.
What we do not store:
- Your original upload as a file. The platform works from the parsed coordinates, not from a stored copy of your file.
- Payment card details. Billing is handled by a dedicated payment processor (see Billing).
- Personal or clinical identifiers, which the upload allow-list prevents from entering the system in the first place.
Where it is stored, and how it is protected
Saved data is stored in the European Union. It is encrypted at rest and encrypted in transit over HTTPS/TLS. Stored data is not cached on the content delivery network: requests that carry your analysis data are served with caching disabled, so your content is not retained at network edge locations.
Who can access your work
Access requires authentication, and your sessions are protected with standard web security controls.
Within a workspace, what each person can see and do is governed by their role, and projects are private to you until you choose to share them with the workspace. Roles and sharing are covered in detail in Workspaces & collaboration.
Retention and deletion
You can delete a project at any time. Deletion is honored automatically: removed records are scheduled for permanent expiry and are cleared without manual intervention. Short-lived items such as invitations and access grants expire automatically after a set period. Backups and point-in-time recovery exist to protect against accidental loss and operational failure.
Your data, exportable on demand
You can download the personal data held about you at any time, as a single file covering your account details, your workspace memberships, and the analyses you have created, both private and shared. Analyses are included as records of your work rather than the parsed coordinates or computed results themselves, and work created by other members of your workspaces is not included, since that is their data rather than yours. This supports your right of access and makes it straightforward to take your work elsewhere. To delete your account data, contact us at eemil@easyhta.com
Billing
Subscription billing is handled by a dedicated, PCI-compliant payment processor. We never see or store your card details; the platform retains only the processor’s account and subscription references needed to manage your subscription.
No third-party tracking of your content
EasyHTA does not run third-party product analytics or advertising trackers over your analysis content. The only logs we keep are technical, used to operate and secure the service, and they are retained for a short period and then deleted automatically. Cookies are limited to what the app needs to function, and consent is requested where required.
LinkedIn