SHEET L-03 · DATA PROCESSING AGREEMENT
Data Processing Agreement
How we process the personal data inside your review workspace, on your instructions, under Article 28 of the GDPR.
1. Parties and scope
This agreement is between the customer organisation ("controller") and David Reifs, of c/ Nyerros, 4, 08500 Vic, Barcelona, Spain ("processor"), and forms part of the Terms of Service. It applies to personal data that the controller or its users put into a workspace, and to nothing else: personal data we collect as controller in our own right is covered by the Privacy Policy instead.
Where this agreement and the Terms of Service disagree about the processing of personal data, this agreement wins.
2. Subject matter, duration, nature and purpose
| Subject matter | Provision of the Evidentium evidence synthesis platform |
|---|---|
| Duration | For as long as the account is open, plus the deletion period in clause 11 |
| Nature | Storage, retrieval, deduplication, automated screening against controller-defined criteria, generation of reporting figures, drafting assistance, export |
| Purpose | Enabling the controller to conduct and report evidence synthesis |
3. Categories of data and data subjects
See Annex I. In practice the personal data inside a review workspace is overwhelmingly bibliographic: author names and affiliations that are already published. The other category is the controller's own users.
4. Our obligations
- We process personal data only on the controller's documented instructions, which include using the platform's features as designed. If we believe an instruction breaks data protection law we will say so.
- We will not use the data for any purpose of our own. In particular we do not use workspace content to train models, ours or anyone else's, and we do not profile data subjects.
- Our personnel are bound by confidentiality and access production data only where a task requires it.
- We implement the measures in Annex II and will not materially weaken them during the agreement.
- We assist the controller with data subject requests, impact assessments and consultations with supervisory authorities, to the extent the controller cannot do it through the platform itself.
5. Your obligations
- You determine the purpose and means of your processing, and you warrant that you have a lawful basis for what you put into the workspace.
- You keep your users' access rights current, including removing people who leave.
- You are responsible for the lawfulness of any personal data you upload beyond bibliographic metadata, for example if a review includes participant-level data.
- You comply with the licence terms of any database whose records you retrieve using your own API keys.
6. Sub-processors
The controller gives general authorisation for the sub-processors listed in Annex III. We remain responsible for their performance and bind them to obligations no weaker than these.
We will give at least thirty days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find a solution, and if none is possible you may terminate the affected part of the service without penalty.
7. International transfers
The workspace region is chosen at account creation and fixed: European Union, United States, Australia. Records, backups and exports stay inside it.
Where a transfer of personal data outside the EEA or the United Kingdom does occur, it is made under the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with the technical measures in Annex II. On request we will provide the transfer impact assessment we rely on.
8. Personal data breaches
We will notify the controller without undue delay, and in any event within seventy-two hours of becoming aware of a personal data breach affecting their workspace. The notification will describe what happened, which categories and roughly how many records are affected, the likely consequences and what we are doing about it, and we will keep the controller updated as we learn more.
We will not notify a supervisory authority or data subjects on the controller's behalf unless they ask us to in writing.
9. Audits and information
On reasonable request, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information needed to demonstrate compliance with this agreement, and will submit to an audit conducted at the controller's cost, during business hours, under confidentiality, and in a way that does not compromise other customers' data.
10. Assistance with data subject rights
The platform lets the controller find, correct, export and delete records directly, which is usually the fastest route. Where a request cannot be satisfied that way, we will help within a reasonable period, and we will pass on any request that reaches us directly rather than answering it ourselves.
11. Deletion and return
On termination the controller may export everything through the platform. After how long workspace data survives account closure we delete the workspace and its backups, unless law requires us to keep something, in which case we keep only that and only for as long as required.
We will confirm deletion in writing on request.
12. Liability and precedence
The liability provisions of the Terms of Service apply to this agreement. Nothing here limits a data subject's rights or the powers of a supervisory authority.
Annex I. Processing details
| Categories of data subjects | Categories of personal data |
|---|---|
| Authors of published studies | Names, affiliations, ORCID identifiers and other bibliographic metadata as published |
| The controller's own users | Name, work email, workspace role, activity and decision records, sign-in metadata |
| Study participants, only if the controller uploads such data | Whatever the controller chooses to upload, which may include special category data and should be minimised |
Frequency: continuous for the duration of the agreement. Special category data is not required by the service and the platform is not designed for it.
Annex II. Technical and organisational measures
- Encryption of personal data in transit using TLS.
- Authenticated workspaces with per-project membership; single sign-on and audit logs available on institutional plans.
- Administrative access limited to named operators, over authenticated sessions that expire.
- Regional isolation: a workspace is created in one region and its records, backups and exports remain there.
- Minimised egress: figure rendering receives counts and labels only, so no title, abstract or author name reaches a third party.
- Workspace content is excluded from model training by contract and by configuration.
- Backups taken within the workspace region, restorable, and covered by the same access controls.
- Change management and reviewed deployments; logging of administrative actions.
This annex describes measures the platform implements today. Before signing it with a customer, confirm each line against your current infrastructure and add anything a certification you hold obliges you to state.
Annex III. Authorised sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| hosting provider and the region each account sits in | Hosting, storage and backup | Workspace region |
| model provider used when a customer does not bring their own key | Automated screening and drafting, where the controller has not connected its own model key | Per provider terms |
| email or CRM tool used to answer demo requests | Correspondence with the controller's administrative contacts | Per provider terms |
Bibliographic sources queried on the controller's behalf, such as PubMed, Europe PMC, OpenAlex, ClinicalTrials.gov, arXiv, DBLP, Scopus and Web of Science, receive the search query and return published metadata. They are not sub-processors of the controller's workspace content.