Legal

Data Processing Addendum

Clinical Trial OS, Inc.Last updated

This DPA forms part of the agreement between you (the controller) and Clinical Trial OS, Inc. (the processor) and reflects GDPR Article 28 requirements for the processing of customer personal data, including any protected health information processed where a HIPAA BAA is separately executed.

Roles and scope#

For personal data contained in protocols and tenant content, you are the controller and we are the processor. We process such data only on your documented instructions, which include this DPA and your use of the service.

Subject matter and duration#

We process customer personal data for the purpose of providing the feasibility platform, for the duration of your subscription, plus any legally required audit-retention period.

Nature and purpose of processing#

Ingestion, structuring, retrieval, scoring, and storage of submitted clinical-trial materials to generate cited feasibility verdicts and maintain a tamper-evident audit trail. We do not use customer personal data to train machine-learning models.

Categories of data and data subjects#

Primarily trial-design and operational data, plus any personal data you choose to submit. Customers are instructed to de-identify protected health information; an inline PHI quarantine and DLP guard reduce the risk of inadvertent PHI entering the processing path.

Sub-processors#

You authorise us to engage the sub-processors below. We will give notice of intended changes so you can object on reasonable grounds.

  • Scaleway SAS — cloud hosting, compute, and managed Postgres storage (EU region — France).
  • phi-cloud — managed model-inference API used to run extraction and scoring (EU region).
  • Resend — transactional and notification email delivery.
  • Cloudflare — DNS, CDN, and edge network for the public site.

Model inference runs on open-weight models (Qwen / Gemma) hosted on our behalf by phi-cloud in the EU; protocols are not sent to any consumer or general-purpose model API (e.g. OpenAI, Anthropic, Google). The definitive, version-controlled sub-processor list is maintained by Clinical Trial OS, Inc. and available on request.

Security measures#

Encryption in transit and at rest, per-tenant isolation with a runtime guard, least-privilege access, key management, signed/immutable images, and a hash-chained audit trail aligned to 21 CFR Part 11 and EMA Annex 11.

International transfers#

Where processing involves transfers outside the EEA/UK, we rely on the EU Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism. EU customers may elect EU-region residency.

Assistance, breach notification, and audits#

We assist you with data-subject requests and DPIAs, notify you without undue delay of a personal-data breach affecting your data, and make available information necessary to demonstrate compliance, including audit support consistent with the GAMP-5 evidence bundle and Part 11 controls.

Return and deletion#

On termination, we make customer personal data available for export and then delete or anonymise it, except where retention is required by law.

Contact#

Data-protection enquiries: privacy@clinical-trial-os.com; security matters: security@clinical-trial-os.com.