generated: '2026-08-08' method: searched source: https://www.caidya.com/privacy-notices/ scope: >- Caidya publishes no public API, so there is no OpenAPI/securityScheme surface to derive API-level conformance from (no oauth2, no OIDC, no RFC 9457, no JSON:API, no FHIR). What Caidya does publish is a regulatory and data-protection posture, captured here. Every entry below is a claim Caidya makes on its own public pages, with the page recorded as evidence — API Evangelist has not audited or verified any of these programs. standards: - id: gdpr conforms: true evidence: Caidya Privacy Policy names EU GDPR as a governing regime for personal data processing source: https://www.caidya.com/privacy-notices/ - id: uk-gdpr conforms: true evidence: UK GDPR named alongside EU GDPR in the Caidya Privacy Policy source: https://www.caidya.com/privacy-notices/ - id: swiss-fadp conforms: true evidence: Swiss Federal Act on Data Protection (FADP) named in the Caidya Privacy Policy source: https://www.caidya.com/privacy-notices/ - id: ccpa-cpra conforms: true evidence: California Consumer Privacy Act (2018) and California Privacy Rights Act (2020) named, with data-subject rights process source: https://www.caidya.com/privacy-notices/ - id: china-pipl conforms: true evidence: China Personal Information Protection Law and China Cybersecurity Law named — relevant to Caidya's long-standing China operations source: https://www.caidya.com/privacy-notices/ - id: wa-mhmda conforms: true evidence: Washington My Health My Data Act addressed by a dedicated Consumer Health Information Privacy Notice (effective 2024-09-01) source: https://www.caidya.com/privacy-notices/ - id: eu-us-data-privacy-framework conforms: true evidence: Caidya states participation in the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US Data Privacy Framework source: https://www.caidya.com/privacy-notices/ - id: eu-standard-contractual-clauses conforms: true evidence: EU Standard Contractual Clauses and the UK International Data Transfer Agreement named as cross-border transfer mechanisms source: https://www.caidya.com/privacy-notices/ - id: computer-systems-validation conforms: true evidence: 'Caidya states it delivers a "compliant, computer systems validation (CSV)-aligned ecosystem with controlled change" across sponsor EDC/eCOA/IRT/CTMS/eTMF/safety systems' source: https://www.caidya.com/clinical/clinical-data-management/ # Checked and NOT found published anywhere on the public site as of 2026-08-08. # Recorded so a later round does not re-litigate the same misses. not_published: - id: soc2 conforms: null note: no SOC 2 report or trust center found; trust.caidya.com does not resolve, /trust and /security both 404 - id: iso-27001 conforms: null note: no ISO 27001 certification claim found on the public site - id: hipaa conforms: null note: HIPAA is not named in the published privacy notices - id: 21-cfr-part-11 conforms: null note: CSV alignment is claimed but 21 CFR Part 11 / EU Annex 11 are not named explicitly - id: cdisc-sdtm-adam conforms: null note: Caidya sponsors and attends CDISC China Interchange 2026 but publishes no CDISC conformance statement, Define-XML, or ODM artifact