Data Processing Agreement
Last updated: December 29, 2025 | GDPR Article 28 Compliant
This Data Processing Agreement ("DPA") establishes the terms under which Ekayana processes personal data on behalf of customers using our Bio-AI DIDs sequencer platform. This DPA is designed to meet the requirements of GDPR Article 28 and ensures appropriate safeguards for personal data processing.
Note: This DPA automatically applies to all customers processing personal data through Ekayana services. For enterprise customers requiring a signed DPA, please contact legal@ekayana.com.
1. Definitions & Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Ekayana ("Processor") and you ("Controller") for the processing of personal data.
Key Definitions:
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data (collection, storage, retrieval, etc.)
- Data Subject: The individual whose personal data is being processed
- Sub-processor: Any third party engaged by Ekayana to process personal data
Scope of Processing:
This DPA applies to all personal data processed through the Ekayana platform, including:
- Researcher identification data (names, emails, ORCID IDs)
- Research participant data (as uploaded by Controller)
- Usage and access logs
- Authentication credentials
2. Data Protection Obligations
Processor Obligations (Ekayana):
- Process personal data only on documented instructions from the Controller
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests
- Delete or return all personal data upon termination of services
- Make available all information necessary to demonstrate compliance
Controller Obligations (You):
- Ensure lawful basis for processing personal data
- Provide clear instructions for data processing
- Ensure data subjects are informed about processing
- Maintain records of processing activities
- Conduct Data Protection Impact Assessments where required
- Notify Ekayana of any data subject requests or complaints
3. Sub-processors
Ekayana engages the following categories of sub-processors:
Infrastructure Providers:
| Sub-processor | Purpose | Location |
|---|---|---|
| IPFS Network | Decentralized storage | Global |
| Filecoin | Long-term archival | Global |
| Cloud Providers | API hosting | EU/US |
Service Providers:
| Sub-processor | Purpose | Location |
|---|---|---|
| BioAgents AI | Metadata extraction | EU |
| Authentication Services | User verification | EU |
Sub-processor Management:
- We maintain an up-to-date list of sub-processors
- Controllers will be notified of any new sub-processors 30 days in advance
- Controllers may object to new sub-processors within 14 days
- All sub-processors are bound by equivalent data protection obligations
4. International Transfers
Transfer Mechanisms:
Personal data may be transferred outside the EEA using the following safeguards:
- Standard Contractual Clauses (SCCs): EU Commission-approved clauses for transfers to third countries
- Adequacy Decisions: Transfers to countries with adequate data protection (e.g., UK, Switzerland)
- Binding Corporate Rules: For transfers within corporate groups
Decentralized Storage Considerations:
Due to the nature of IPFS and Filecoin:
- Data is distributed across multiple nodes globally
- Content addressing ensures data integrity regardless of location
- Encryption is applied before distribution to protect data in transit and at rest
Transfer Impact Assessment:
We conduct Transfer Impact Assessments for all international transfers, considering:
- Laws and practices of the destination country
- Supplementary measures implemented
- Effectiveness of safeguards
5. Data Retention & Deletion
Retention Periods:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account Data | Duration of service + 30 days | Contract performance |
| Research Data | As specified by Controller | Controller instructions |
| Access Logs | 12 months | Security & compliance |
| Backup Data | 90 days after deletion | Business continuity |
Deletion Procedures:
Upon termination or Controller request:
- Active data is marked for deletion within 24 hours
- Data is removed from primary storage within 7 days
- Backup copies are purged within 90 days
- Confirmation of deletion is provided to Controller
IPFS Considerations:
- Content on IPFS is unpinned from our nodes
- We cannot guarantee removal from all IPFS nodes globally
- For sensitive data, we recommend client-side encryption before upload
6. Security & Breach Notification
Technical Measures:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Content-addressed storage with cryptographic verification
- UCAN-based capability authorization
- Multi-factor authentication for administrative access
- Regular security audits and penetration testing
Organizational Measures:
- Staff training on data protection
- Access controls based on least privilege principle
- Incident response procedures
- Business continuity planning
Breach Notification:
In the event of a personal data breach:
- Ekayana will notify Controller within 24 hours of becoming aware
- Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach
- Controller is responsible for notifying supervisory authorities (within 72 hours) and data subjects as required
Request Signed DPA
Enterprise customers requiring a countersigned Data Processing Agreement can request one by contacting our legal team. We typically process DPA requests within 5 business days.