Data Processing Agreement
Signed for any tenant with EU data subjects, with our subprocessor list and Standard Contractual Clauses attached.
Plain-language summary
Under GDPR, when one party (the controller) decides what to do with personal data and another (the processor) actually handles it, they sign a DPA. You're the controller; Oncominder is the processor. This DPA says: we'll only process personal data on your instructions, we'll keep it secure, we'll help you respond to data-subject requests, and we'll tell you fast if anything goes wrong. The Standard Contractual Clauses are attached for international transfers.
1. Definitions
Capitalized terms have the meanings given in the GDPR (Regulation (EU) 2016/679). "Customer Data" means personal data Customer uploads to the Service.
2. Roles
Customer is the Controller. Oncominder is the Processor. To the extent Customer's customers (e.g. patients, study participants) are data subjects, Customer remains the Controller of their data.
3. Scope and purpose
We process Customer Data only as documented in this DPA, the underlying Service Agreement, or as required by law. We will inform Customer if we believe an instruction violates the GDPR.
4. Security
We implement technical and organizational measures appropriate to the risk, including the controls described on our security page: AES-256 encryption at rest, TLS 1.3 in transit, role-based access, audit logging, and continuous monitoring.
5. Subprocessors
Customer authorizes the subprocessors listed in our trust center. We will give Customer at least 30 days' notice before adding or replacing a subprocessor; Customer may object on reasonable grounds.
6. Data subject rights
We will assist Customer in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within applicable timeframes.
7. Breach notification
We will notify Customer without undue delay, and in any event within 24 hours, after becoming aware of a Personal Data Breach affecting Customer Data, with the information required to meet GDPR Art. 33.
8. International transfers
Where Customer Data is transferred outside the EEA, we rely on the Standard Contractual Clauses (Module 2: Controller-to-Processor) approved by Commission Decision 2021/914, which are incorporated by reference into this DPA. For US transfers we additionally rely on the EU-US Data Privacy Framework where applicable.
9. Audits
Customer may audit our processing of Customer Data once per year, on reasonable notice, during business hours, subject to confidentiality. Our SOC 2 Type II report and ISO 27001 certificate satisfy most audit requirements without an on-site visit.
10. Return or deletion
On termination, we will return or delete Customer Data within 60 days, except as required by law to retain.
Annex I — Subject matter, duration, nature, and purpose
Hosting, processing, and securing personal data on behalf of Customer in connection with delivery of the Oncominder platform, for the duration of the Service Agreement.
Annex II — Technical and organizational measures
Provided in the trust center; controls are mapped to ISO 27001, NIST 800-53 Moderate, and the SOC 2 Trust Services Criteria.