Legal

Privacy Policy Statement

This explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

Version 1.0 · Published September 2026

1. About this statement

JUMO Partners Limited (“JUMO”, “we”, “our”) is a healthcare market research and advisory firm. We work with pharmaceutical, medical device and healthcare organisations across Europe and Asia, and our work involves speaking with healthcare professionals and with professionals in the industry.

This statement applies to visitors to this website, to our business contacts, to people who take part in our research and advisory engagements, and to the associates and suppliers who work with us.

We have written it to meet Hong Kong’s Personal Data (Privacy) Ordinance, and, where they apply to a particular activity, China’s Personal Information Protection Law and the EU General Data Protection Regulation. Where those regimes differ, we apply the stricter standard rather than the more convenient one.

2. Who is responsible for your data

The data controller is JUMO Partners Limited, a company incorporated in Hong Kong, registered at Office 4, 10/F, Kwan Chart Tower, No. 6 Tonnochy Road, Wanchai, Hong Kong, Business Registration Number 69905908.

Our subsidiary 聚謀(上海)健康管理咨询有限公司 (JUMO (Shanghai) Health Management Consulting Co., Ltd.), Unified Social Credit Code 91310115MA1HAJK082, registered at 上海市浦东新区三林路344号, Pudong New Area, Shanghai, carries out research activities in mainland China. Where it collects personal information from individuals in mainland China, it does so as part of JUMO and under this statement. Its office address for correspondence is Room 442, Building A, No. 208 Wending Road, Xuhui District, Shanghai 200030.

JUMO is not a healthcare provider. We do not offer diagnosis, treatment or counselling, and this website is not a route for medical questions.

For any question about this statement, or to exercise your rights, contact us at privacy@jumopartners.com.

3. Our two lines of work — and why the difference matters to you

We do two different things, and what happens to your information depends on which one you are taking part in. We will always tell you which applies before you take part, never afterwards.

Market research. We interview healthcare professionals and industry professionals to understand clinical practice, unmet needs and attitudes to treatments. In this work, your identity is not disclosed to our client. Findings are reported in aggregated or anonymised form, and any quotation used is stripped of anything that could identify you. Our clients do not receive recordings or full transcripts. You will not be contacted commercially as a result of taking part.

Where a specific engagement carries a regulatory reporting duty — for example an obligation to report a side effect mentioned during an interview — we tell participants before they take part, never afterwards. JUMO does not hold marketing authorisations for any product; such a duty can reach us only through a client contract, and it applies to that engagement alone.

Expert identification and advisory. Separately, we help clients identify and engage specialists who may wish to advise them, speak at their events, or work with them in other ways. This work is not anonymous: with your explicit prior agreement, we share your name, title and institution with our client, who may then approach you directly.

These are kept apart deliberately. Information you give us in a market research interview is never used to introduce you to a client. If we think you might be interested in advisory work, we ask you separately, in a separate conversation, and you are free to say no without it affecting anything else.

4. What we collect, why we collect it, and our legal basis

4.1 Visitors to this website

What we collectWhyOur basis
Name, work email, company, area of interest, and the content of your messageTo answer your enquiry and follow up on itGDPR: our legitimate interest in responding to a business enquiry you initiated. PIPL: your consent, given when you submit the form.
A record that you submitted the form: the date and time, your IP address, and the version of this statement then in forceSo that we can show, if we are ever asked, what you were told and what you agreed toGDPR: our legal obligation to be able to demonstrate compliance. PIPL: necessity for the same purpose.
Pages viewed, referring site, device and browser type, and a shortened form of your IP addressTo understand how our site is usedOur legitimate interest in measuring our own audience. We use our own analytics software, running on our own server. No cookies are set, no analytics company receives anything, and your full IP address is never stored.
IP address, request logs, error recordsTo keep the site secure and availableGDPR: our legitimate interest in security. PIPL: necessity for providing the service you requested.

We ask that you do not include health information or other sensitive personal details in your message. This form is for business enquiries. It is not a route for medical questions, and it is not a route for reporting anything about a medicine or a device.

4.2 Business contacts

Where you are a client, prospective client, partner, supplier or journalist, we hold your name, role, organisation, professional contact details and a record of our dealings with you, so that we can manage the relationship and tell you about services relevant to your work. Our basis is our legitimate interest in running a business relationship (GDPR), and your consent or the necessity of performing a contract with you (PIPL).

4.3 Market research participants

Where you take part in an interview, discussion or survey, we may hold:

  • your name, professional title, specialty, institution and country;
  • your professional contact details;
  • your eligibility answers to our screening questions;
  • an audio recording of the conversation, and the transcript made from it;
  • a record of your consent, including when you gave it and to what.

We use this to conduct the research, to produce findings for our client, and to arrange your honorarium. Our basis is your consent, which you give before the conversation begins and can withdraw at any time.

We record audio only — never video. The recording is deleted once the transcript has been checked, and from that point we work only from the transcript. Our client receives neither.

4.4 Experts in our identification and advisory work

Where we are helping a client identify specialists who may wish to advise them, we hold your name, title, institution, area of expertise, publicly available professional information, and our notes on your relevance.

If we approach you about an opportunity, we will tell you which client is asking, wherever our agreement with them allows it. We share your details with that client only if you agree to it first. Our basis is your consent for that sharing; before you are approached, our basis is our legitimate interest in professional expert identification (GDPR), and, in mainland China, your consent.

4.5 Associates, freelancers and suppliers

We hold identity, contact, contractual and payment information for the people and firms who work with us, in order to engage them, pay them, give them the access their work requires, and meet our tax and record-keeping obligations. Our basis is the performance of our contract with you and our legal obligations.

4.6 The people we interview are professionals

We interview healthcare professionals and industry professionals, in their professional capacity — their clinical practice, their commercial judgment, their reading of a market. That is ordinary personal data. A physician’s opinion about a treatment is a professional judgment, not a disclosure about their own health.

We do not conduct patient or consumer research. We do not recruit patients, we do not interview individuals about their own health, condition or treatment, and we do not collect health information about the people we speak with.

Where we work with a patient organisation, we do so as a professional body, and we treat the people who represent it as professional contacts. If a representative begins to describe their own health experience, we do not record it and it does not form part of our analysis.

Because of this, our research does not involve sensitive personal information under the Personal Information Protection Law, or special categories of personal data under the GDPR.

4.7 Where your information comes from, when it does not come from you

Some of the professional information we hold was not given to us by you directly. We identify professionals through publicly available sources such as hospital and institutional websites, conference programmes and published scientific literature; through professional events and trade fairs; through colleagues who suggest relevant contacts; and through large professional networks and industry groups in which we take part.

We add a professional to our contact records only once they have agreed to be contacted about research. Where we hold information about you that did not come from you, we will tell you at our first contact what we hold and where we obtained it, and you may ask us to correct or delete it at any time.

4.8 Children

Our work is with professionals and adults. We do not knowingly collect information about anyone under 18, and this website is not directed at children.

4.9 Automated decisions

We do not make decisions about you by automated means, and we do not profile you for advertising purposes.

5. Who we share your information with

We do not sell personal data, and we do not share it for anyone else’s marketing.

Our clients. In market research, our clients receive findings only. They do not receive recordings, full transcripts, or anything identifying you. In our expert identification work, clients receive your name, title and institution — but only after you have agreed to it.

Our service providers. These companies process data on our instructions, under written contracts that require them to protect it and to use it for nothing else:

ProviderWhat they doWhere
MicrosoftEmail, file storage, and transcription of interview recordingsMicrosoft 365 infrastructure
ICDSoft LLC (Bulgaria)Hosting of this website, and of the messages you send us through itHong Kong data centre
MikeCRM — 上海易客多软件科技有限公司Business contact records maintained by our team. Messages you send through this website do not pass through it.Mainland China
Recruitment and fieldwork partnersIdentifying and scheduling research participantsVaries by project
Honorarium payment agenciesPaying participants for their timeVaries by market
Professional advisersLegal, accounting, audit and company secretarial servicesHong Kong, mainland China, Europe

Our associates. Experienced researchers who work with us on specific projects, under written confidentiality and data-protection obligations, within our secured cloud environment.

Where the law requires it. We may disclose personal data where we are legally obliged to, or to establish or defend legal claims.

6. Where your information goes

JUMO operates between Hong Kong, mainland China and Europe, so personal data may be handled in any of them.

This website, and the messages you send through it, are hosted in Hong Kong, where JUMO Partners Limited is established. Our other systems are in the Microsoft 365 environment we use worldwide.

From mainland China. Where our Shanghai subsidiary collects personal information in mainland China, that information may be transferred to Hong Kong and to our Microsoft 365 environment. When this happens we obtain your separate consent to the transfer, tell you who will receive the information and how to exercise your rights against them, carry out an impact assessment beforehand, and rely on a documented legal basis under the Personal Information Protection Law. Because we do not handle patient health information, these transfers do not involve sensitive personal information.

From Europe. Where you give us information directly — through this website, or by taking part in our research — you are providing it to JUMO Partners Limited in Hong Kong, and we tell you that clearly at the point of collection. Where personal data instead reaches us from a client or partner established in the European Economic Area, that transfer is made under Standard Contractual Clauses or another mechanism approved under the GDPR.

Hong Kong. Hong Kong law does not currently restrict transfers of personal data out of the territory, but we apply contractual safeguards to every such transfer as a matter of policy, in line with the Privacy Commissioner’s guidance.

7. How long we keep your information

InformationHow long we keep it
Website enquiries, and our correspondence with you about them24 months from our last contact with you
The record that you submitted a form: date, IP address, policy version24 months from our last contact with you
Website analyticsAggregated. No individual record is kept beyond 14 months
Website server logs90 days
Business contact recordsWhile the relationship is active, reviewed every 5 years
Screening answers and consent recordsFor as long as we hold the related research data, plus 3 years
Interview audio recordingsDeleted within 60 days of the transcript being approved
Interview transcripts, pseudonymised12 months after the project closes
Expert and professional contact recordsReviewed every 5 years; removed where there has been no contact
Payment and financial records7 years, as required by tax law
Associate and supplier contracts7 years after the engagement ends

When a retention period ends we delete the information or irreversibly anonymise it.

8. Your rights

Depending on where you are and which law applies, you may ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct anything inaccurate or incomplete;
  • delete your data, where we no longer have a good reason to keep it;
  • restrict or object to how we use it, including stopping marketing at any time;
  • receive your data in a portable form, or have it transferred to someone else;
  • withdraw your consent, where our use depends on it — this does not affect anything we did before you withdrew it;
  • ask us to explain how we handle your information.

Where a person has died, a close relative may exercise these rights in respect of their information, unless that person had arranged otherwise.

How to exercise them. Write to us at privacy@jumopartners.com. We may need to confirm your identity before we act, to make sure we do not disclose your information to someone else. We respond free of charge, and within the time the applicable law requires — within 40 days in Hong Kong, within one month under the GDPR, and promptly under the Personal Information Protection Law. If a request is unusually complex we will tell you, and explain why.

If you are unhappy with our response. Please tell us first — most issues are quicker to resolve directly. You also have the right to complain to a regulator: the Office of the Privacy Commissioner for Personal Data, Hong Kong; the Cyberspace Administration of China or your local cyberspace administration, if you are in mainland China; or your national data protection authority, if you are in the European Economic Area.

9. How we protect your information

We work in the cloud rather than on individual computers. Project material is created, stored and handled within our Microsoft 365 environment, which means our protection is anchored where the data actually lives.

In practice:

  • access to personal data is limited to the people who need it for a specific project, and is removed when the project ends;
  • all accounts require multi-factor authentication;
  • our company computers are encrypted;
  • everyone who works with us — employees and research associates alike — signs confidentiality and data-protection obligations, and works within our secured cloud environment rather than storing project material locally;
  • we train our people on data protection and keep the training current;
  • we have an incident management procedure, and we notify affected people and the relevant authorities where the law requires it.

No system is completely secure, and we do not claim otherwise. What we commit to is that we handle your information carefully, that we review these measures regularly, and that we tell you promptly if something goes wrong.

10. Cookies

This website does not use cookies for analytics, advertising or tracking. We do not use any third-party analytics or advertising service, and no outside company is told anything about your visit.

Our cookie declaration below lists anything this site does set. Because we set nothing that needs your permission, there is no cookie banner here to accept or decline — there is nothing to consent to.

NameWhat it doesSet byHow long it lastsCategory
NoneThis website sets no cookies for analytics, advertising or tracking, and loads nothing from any third party.———

11. Changes to this statement

We review this statement at least every two years, and whenever our practices change. The version and date at the top tell you which version you are reading. If we make a change that materially affects how we use your information, we will tell you directly where we can, and always by posting a notice on this website before the change takes effect.

12. How to contact us

JUMO Partners Limited
Office 4, 10/F, Kwan Chart Tower, No. 6 Tonnochy Road, Wanchai, Hong Kong
Business Registration Number 69905908
Email: privacy@jumopartners.com