Back to Home
Legal

Data Processing Agreement

Last updated: December 29, 2025 | GDPR Article 28 Compliant

This Data Processing Agreement ("DPA") establishes the terms under which Ekayana processes personal data on behalf of customers using our Bio-AI DIDs sequencer platform. This DPA is designed to meet the requirements of GDPR Article 28 and ensures appropriate safeguards for personal data processing.

Note: This DPA automatically applies to all customers processing personal data through Ekayana services. For enterprise customers requiring a signed DPA, please contact legal@ekayana.com.

1. Definitions & Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Ekayana ("Processor") and you ("Controller") for the processing of personal data.

Key Definitions:

  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data (collection, storage, retrieval, etc.)
  • Data Subject: The individual whose personal data is being processed
  • Sub-processor: Any third party engaged by Ekayana to process personal data

Scope of Processing:

This DPA applies to all personal data processed through the Ekayana platform, including:

  • Researcher identification data (names, emails, ORCID IDs)
  • Research participant data (as uploaded by Controller)
  • Usage and access logs
  • Authentication credentials

2. Data Protection Obligations

Processor Obligations (Ekayana):

  • Process personal data only on documented instructions from the Controller
  • Ensure persons authorized to process data are bound by confidentiality
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to data subject requests
  • Delete or return all personal data upon termination of services
  • Make available all information necessary to demonstrate compliance

Controller Obligations (You):

  • Ensure lawful basis for processing personal data
  • Provide clear instructions for data processing
  • Ensure data subjects are informed about processing
  • Maintain records of processing activities
  • Conduct Data Protection Impact Assessments where required
  • Notify Ekayana of any data subject requests or complaints

3. Sub-processors

Ekayana engages the following categories of sub-processors:

Infrastructure Providers:

Sub-processorPurposeLocation
IPFS NetworkDecentralized storageGlobal
FilecoinLong-term archivalGlobal
Cloud ProvidersAPI hostingEU/US

Service Providers:

Sub-processorPurposeLocation
BioAgents AIMetadata extractionEU
Authentication ServicesUser verificationEU

Sub-processor Management:

  • We maintain an up-to-date list of sub-processors
  • Controllers will be notified of any new sub-processors 30 days in advance
  • Controllers may object to new sub-processors within 14 days
  • All sub-processors are bound by equivalent data protection obligations

4. International Transfers

Transfer Mechanisms:

Personal data may be transferred outside the EEA using the following safeguards:

  • Standard Contractual Clauses (SCCs): EU Commission-approved clauses for transfers to third countries
  • Adequacy Decisions: Transfers to countries with adequate data protection (e.g., UK, Switzerland)
  • Binding Corporate Rules: For transfers within corporate groups

Decentralized Storage Considerations:

Due to the nature of IPFS and Filecoin:

  • Data is distributed across multiple nodes globally
  • Content addressing ensures data integrity regardless of location
  • Encryption is applied before distribution to protect data in transit and at rest

Transfer Impact Assessment:

We conduct Transfer Impact Assessments for all international transfers, considering:

  • Laws and practices of the destination country
  • Supplementary measures implemented
  • Effectiveness of safeguards

5. Data Retention & Deletion

Retention Periods:

Data CategoryRetention PeriodBasis
Account DataDuration of service + 30 daysContract performance
Research DataAs specified by ControllerController instructions
Access Logs12 monthsSecurity & compliance
Backup Data90 days after deletionBusiness continuity

Deletion Procedures:

Upon termination or Controller request:

  • Active data is marked for deletion within 24 hours
  • Data is removed from primary storage within 7 days
  • Backup copies are purged within 90 days
  • Confirmation of deletion is provided to Controller

IPFS Considerations:

  • Content on IPFS is unpinned from our nodes
  • We cannot guarantee removal from all IPFS nodes globally
  • For sensitive data, we recommend client-side encryption before upload

6. Security & Breach Notification

Technical Measures:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Content-addressed storage with cryptographic verification
  • UCAN-based capability authorization
  • Multi-factor authentication for administrative access
  • Regular security audits and penetration testing

Organizational Measures:

  • Staff training on data protection
  • Access controls based on least privilege principle
  • Incident response procedures
  • Business continuity planning

Breach Notification:

In the event of a personal data breach:

  • Ekayana will notify Controller within 24 hours of becoming aware
  • Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach
  • Controller is responsible for notifying supervisory authorities (within 72 hours) and data subjects as required

Request Signed DPA

Enterprise customers requiring a countersigned Data Processing Agreement can request one by contacting our legal team. We typically process DPA requests within 5 business days.