This DPA is incorporated by reference into the Terms of Service / MSA between GeneData ("Processor") and Customer ("Controller"). It applies whenever GeneData processes personal data on behalf of Customer under GDPR, UK GDPR, or analogous laws.
1. Definitions
Capitalized terms not defined here have the meanings in GDPR Art. 4. "Personal Data" means any Customer Data that constitutes personal data under applicable law.
2. Roles
Customer is the Controller of Personal Data uploaded to the Service. GeneData is the Processor. GeneData processes Personal Data only on documented instructions from Customer (which include the Terms and these Service-Specific Instructions).
3. Scope of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the GeneData multi-tenant data-intelligence platform |
| Duration | The term of the agreement, plus the 30-day post-termination data-export window |
| Nature + purpose | Hosting, processing, transmitting, analyzing Customer Data as configured by Customer |
| Types of data | Whatever Customer uploads. May include names, emails, IDs, business records, telemetry. Customer represents NOT to upload special categories of data (GDPR Art. 9) without separate written agreement. |
| Categories of subjects | Customer's employees, contractors, customers, prospects, and other contacts |
4. Subprocessors
GeneData engages the subprocessors listed in subprocessors.md. Customer authorizes their use.
Notice of change: GeneData will notify Customer at least 30 days before adding or replacing a subprocessor that processes Personal Data. Customer may object on reasonable grounds; if the objection cannot be resolved, Customer may terminate the affected portion of the Service on 30 days' written notice.
GeneData remains responsible for subprocessor compliance.
5. Security
GeneData maintains technical and organizational measures appropriate to the risk, including:
| Control | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ on all customer-facing endpoints (Ingress + cert-manager) |
| Encryption at rest | AES-256-GCM envelope encryption for stored secrets; cloud-managed at-rest encryption for backups |
| Access control | Role-based (RBAC) + tenant isolation enforced at every service entry-point + NetworkPolicy isolation |
| Authentication | JWT with HS256, issuer/audience binding, 1h expiry, revocation via lib/jwt-revocation.ts |
| Vulnerability mgmt | Daily pnpm audit --audit-level critical; Trivy scan of all images in CI |
| Incident detection | SLO-based alerts via Prometheus; SIEM-style audit log with hash chain |
| Logical separation | Multi-tenant; tenant ID enforced from authenticated JWT (never client-supplied header) |
| Personnel | Background checks for engineers with prod access; access reviews quarterly |
| Backup + DR | Nightly logical pg_dump → S3; weekly automated restore drill |
6. Customer rights — assistance
GeneData assists Customer in fulfilling Data Subject requests within 30 days:
- Access: Customer can query their tenant's data via the Service API
- Rectification: Customer can edit data via the Service
- Erasure: GeneData provides a deletion endpoint that walks every table holding subject data and either deletes or anonymizes (audit log entries anonymized but retained for 7 years per legal requirement). Implementation:
apps/api/src/lib/dsar-deletion.ts - Portability: JSON export of tenant data on request
- Restriction: Customer can suspend processing via the in-app subscription pause
- Objection: Customer can disable optional AI features that send prompts to third-party LLMs
7. Breach notification
GeneData will notify Customer of a Personal Data Breach without undue delay and in any case within 72 hours of confirmation, with sufficient detail for Customer to meet its own notification obligations.
8. Cross-border transfers
Where Personal Data is transferred outside the EEA/UK to GeneData or its subprocessors, the transfer is governed by:
- EU Standard Contractual Clauses (Commission Decision 2021/914) module 2 (Controller-to-Processor), incorporated by reference
- For UK transfers: the UK International Data Transfer Addendum
- For US transfers: Data Privacy Framework certification (where applicable)
Enterprise customers may select EU-region hosting; the architecture supports per-region deployment.
9. Data Protection Impact Assessment (DPIA)
GeneData supplies, on request, the documentation Customer needs to complete its DPIA, including:
- A DPIA-ready data-flow diagram
- The subprocessor list
- Security control attestations (e.g. SOC 2 report when available)
- Records of processing activities (Art. 30)
10. Audits
Customer (or its independent third-party auditor) may audit GeneData's compliance with this DPA up to once per year, on 30 days' notice, during business hours. GeneData makes its SOC 2 Type II report available in lieu of on-site audit where acceptable. Cost of the audit is borne by Customer unless the audit reveals material non-compliance.
11. Termination
Within 30 days after termination, Customer must export Customer Data via the Service. After that period, GeneData deletes Customer Data, except:
- Backups retained per the retention schedule (see Privacy Policy §How long we keep it)
- Audit logs retained 7 years, anonymized
Customer may request a deletion certificate on request.
12. Order of precedence
If there's a conflict between this DPA and other terms, this DPA controls solely for processing of Personal Data.
SIGNATURES (when executed):
For Customer: ____________________ For GeneData: ____________________