Legal | Data Protection
Data Processing Addendum
Last updated: July 7, 2026 | See also the GDPR overview and subprocessor list
1. What this addendum is
This Data Processing Addendum (DPA) applies when BCINexus processes personal data on your behalf — typically when you or your institution upload research data containing personal data to BCINexus cloud features. It supplements the Terms of Service and reflects the requirements of the GDPR, UK GDPR, and similar data protection laws.
In this relationship you (or your institution) are the controller, and BCINexus is the processor. For account and billing data about you as a user, BCINexus acts as a controller — that processing is described in the Privacy Policy, not this DPA.
Enterprise customers can request a signed, countersigned DPA (including Standard Contractual Clauses where needed) via [email protected].
2. Scope of processing
Subject matter: hosting, storage, sharing, review, and collaboration features you choose to use.
Duration: the life of your account plus the retention periods in the Privacy Policy.
Nature and purpose: providing, maintaining, securing, and improving the Services at your instruction.
Categories of data: whatever you upload — which is why your data should not include identifiable participant data unless you hold the required consent and ethics approvals.
Data subjects: research participants, team members, and other individuals whose data you lawfully upload.
BCINexus processes uploaded data only on your documented instructions (given through the product's features and settings) unless the law requires otherwise — in which case we will inform you before processing, where legally permitted.
3. Your responsibilities as controller
You warrant that you have a lawful basis, required consents, and required ethics approvals (IRB/IEC or equivalent) for all personal data you upload, and that your instructions to us comply with applicable law.
De-identify or pseudonymize participant data before upload wherever your protocol allows it. BCINexus is built for research data, not for raw identity records.
4. Our commitments as processor
- Confidentiality: personnel with access to your data are bound by confidentiality obligations
- Security: technical and organizational measures as described in the Privacy Policy, including encryption in transit, access controls, and hashed credentials
- Subprocessors: engaged only under written terms no less protective than this DPA; the current list is published at /subprocessors, and we will provide a mechanism to be notified of changes
- Assistance: reasonable help with data subject requests, security assessments, and data protection impact assessments, considering the nature of the processing
- Breach notification: we will notify you without undue delay after becoming aware of a personal data breach affecting your data
- Deletion or return: on termination of the Services, we will delete or return personal data at your choice, subject to the retention limits in the Privacy Policy
- Audit: we will make available information reasonably necessary to demonstrate compliance with this DPA
5. International transfers
Where personal data is transferred to a country without an adequacy decision, transfers rely on appropriate safeguards such as Standard Contractual Clauses. Enterprise customers requiring executed SCCs, transfer impact assessments, or specific hosting regions should contact [email protected] — regional hosting commitments require a signed agreement.
6. Precedence and contact
If this DPA conflicts with the Terms of Service, this DPA prevails for personal data processing. A signed enterprise DPA prevails over this page.
Responsible party: BCINexus. Formal legal entity name, registered address, DPO, EU representative, and UK representative details require business/legal approval before publication.
Questions: [email protected] | Privacy requests: [email protected]