LEGAL

Data Processing Agreement

Template v1.1 · Last updated 2026-07-30

This is the template Data Processing Agreement Onkydra offers to Team subscribers under GDPR Article 28. Buyers who require a signed DPA before onboarding can email hello@onkydra.com to receive a countersigned copy on Onkydra letterhead. The template will be reviewed by qualified Irish counsel before any first signature is executed.

1. Parties and scope

This Data Processing Agreement (the "DPA") is entered into between the Customer identified on the relevant order form or subscription (the "Controller") and Onkydra (the "Processor") and supplements the Onkydra terms of service. It governs the processing of personal data by the Processor on behalf of the Controller in the course of providing the Onkydra service (the "Service").

The DPA is a controller-to-processor arrangement within the meaning of Article 28 of Regulation (EU) 2016/679 (the "GDPR"). Where the Controller is subject to the UK GDPR or the Swiss Federal Act on Data Protection, this DPA applies mutatis mutandis to processing under those laws.

2. Definitions

Terms not defined in this DPA have the meaning given to them in the GDPR. "Personal data", "processing", "data subject", "controller", "processor", "sub-processor", and "supervisory authority" are used with the meaning of Articles 4 and 28.

3. Processor's obligations (Article 28(3))

The Processor will:

  1. Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or international organisation, unless required to do so by Union or Member State law; in such a case, the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  2. Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Take all measures required pursuant to Article 32 of the GDPR, as described in Annex II below.
  4. Respect the conditions in paragraphs 2 and 4 of Article 28 for engaging another processor.
  5. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
  6. Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor.
  7. At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
  8. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

4. Sub-processors (Article 28(2), 28(4))

The Controller provides general written authorisation for the Processor to engage sub-processors, subject to the conditions set out in Article 28(2) and 28(4). The current list of sub-processors, their processing region, and the transfer mechanism for each, is published at onkydra.com/subprocessors.

The Processor will notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least thirty (30) days before that change takes effect. The Controller may object to any such change within that period; if the objection is reasonable and cannot be resolved between the parties, the Controller may terminate the affected part of the Service with a pro-rated refund of any pre-paid fees.

Where the Processor engages a sub-processor for carrying out specific processing activities on behalf of the Controller, the same data protection obligations as set out in this DPA are imposed on that sub-processor by way of a written contract.

5. International transfers

Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a third country not covered by a European Commission adequacy decision, the parties enter into the Standard Contractual Clauses published in Commission Implementing Decision (EU) 2021/914, executed as a schedule to this DPA in the Module appropriate to the parties' roles. Where the Processor engages a sub-processor outside such a country, the equivalent transfer mechanism is applied under the sub-processor agreement.

6. Data subject rights and controller assistance

The Processor will notify the Controller without undue delay of any request received directly from a data subject to exercise their rights under Chapter III of the GDPR, and will not respond to such a request itself. The Processor will assist the Controller with appropriate technical and organisational measures, insofar as possible, to enable the Controller to respond to the request within the time limits set by the GDPR.

7. Personal data breach (Article 33)

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach. The notification will include, to the extent known at the time, the categories and approximate number of data subjects and personal data records concerned, the likely consequences, and the measures taken or proposed to address the breach.

8. Audit rights

The Processor will make available to the Controller, on reasonable notice and subject to reasonable confidentiality obligations, the information necessary to demonstrate compliance with this DPA. The Controller's audit rights are exercised at most once per calendar year, unless a personal data breach or a supervisory authority instruction requires more frequent inspection.

9. Return or deletion (Article 28(3)(g))

On termination of the Service, the Processor will, within thirty (30) days and at the Controller's choice, delete all personal data or return it in a structured, commonly used, machine-readable format. Backups are overwritten within a further sixty (60) days in accordance with the Processor's retention policy. Personal data required to be retained by applicable law, including for tax and audit purposes, is retained only for the duration and purpose required by that law and is thereafter deleted.

10. Liability and precedence

The parties' liability under this DPA is subject to the limitations set out in the underlying subscription agreement. In the event of a conflict between this DPA and the subscription agreement in relation to the processing of personal data, this DPA prevails.

Annex I — Processing details

A. Subject-matter and nature of the processing

Provision of the Onkydra Service, an in-silico stratification workspace for rare-cancer drug development. Personal data is processed for account authentication, subscription management, product usage, transactional communications, and audit logging.

B. Duration

For the duration of the subscription plus the deletion and backup rotation windows described in Clause 9.

C. Purpose

Delivery, security, and continuous improvement of the Service; provision of customer support; compliance with the Processor's legal obligations.

D. Types of personal data

  • Account identifiers: name, work email, organisation, role.
  • Authentication metadata: Firebase Authentication UID, sign-in timestamps, IP addresses, user-agent strings.
  • Billing metadata (via Stripe): billing name and email, subscription state, invoice history. No primary account numbers are processed by the Processor.
  • Product-usage records: queries submitted, runs executed, artefacts generated, tool-chain audit log entries with agent name and timestamp.
  • Support communications: correspondence with the Processor via email or in-app messaging.

E. Special categories of personal data

The Service is not intended to receive or process Article 9 personal data. The Controller undertakes not to upload patient-identifiable data or other special categories of data to the Service.

F. Categories of data subjects

  • Authorised users of the Controller (individual researchers, biotech team members).
  • Billing contacts of the Controller.

G. Frequency of transfer

Continuous, on a per-request basis, for the duration of the subscription.

Annex II — Technical and organisational measures (Article 32)

The Processor implements the following measures. The exact set is subject to continuous improvement in response to the state of the art and the evolving threat landscape.

  • Encryption. Personal data is encrypted in transit with TLS 1.2 or later. At-rest encryption is provided by the underlying sub-processors: Google Cloud (AES-256) for the application database and object storage, and Stripe for billing data.
  • Authentication and access control.Access to the Controller's workspace is scoped by Firebase Authentication ID tokens verified on every request. Row-level security is enforced in the Postgres tenancy layer. Administrative access to production infrastructure is limited to named personnel with hardware-key 2FA.
  • Segregation.Personal data is logically separated from other customers' data by tenant identifier at every layer.
  • Audit logging. Agent runs, tool invocations, and access to personal data are logged with actor, timestamp, and outcome, and retained for the audit-log retention period set in the privacy policy.
  • Backups and business continuity.The application database is backed up daily with point-in-time recovery. The seven most recent daily backups are retained on a rolling basis, and the point-in-time recovery window is seven (7) days; the two windows run concurrently. Backups are encrypted and are stored in Google's EU multi-region, which is not the same region as the primary instance (europe-west2, London, United Kingdom).
  • Vulnerability management. The Processor monitors advisories for the third-party dependencies used by the application and applies fixes for critical advisories promptly once a fix is available. Automated secret scanning and dependency advisory checks now run in continuous integration on every push, with secret scanning covering full repository history rather than only the latest change. Critical advisories block; high advisories are reported, because several currently have no forward fix available from upstream. A written and rehearsed incident-response runbook is also not yet in place; until it is, the breach-notification obligation in section 7 above applies, and this Annex will be updated once the runbook is written and tested.
  • Personnel. Personnel with access to personal data are contractually bound to confidentiality and receive privacy training on onboarding and annually.
  • Sub-processor oversight.The current sub-processors, and the data-processing terms and transfer safeguards relied on for each, are published at onkydra.com/subprocessors. Each is engaged under the provider's published data-processing terms. The Processor does not represent that it holds a separately negotiated or counter-signed data-processing instrument with every sub-processor. The Processor will review a sub-processor's published security documentation and transfer mechanism before engaging it and again on any material change, and will record the change in that register.

Signing this DPA

To countersign this DPA, email hello@onkydra.com with the Controller's registered legal name, registered address, and the name and title of the authorised signatory. Onkydra will return a countersigned copy within five (5) business days. Requests for material amendments to the template are reviewed on a case-by-case basis.

This template is offered in good faith as a starting point and is subject to final review by qualified Irish counsel before any first signature is executed. It is not legal advice. See also our privacy policy and sub-processor register.