Back to Legal Hub
Privacy & Data Protection
Version 3.0
Last Updated: January 15, 2025
Effective: January 1, 2025

Data Processing Agreement

DPA designed to align with GDPR Article 28, defining data-processing terms, security obligations, and sub-processor arrangements for enterprise clients. Not a third-party certification.

Executive Summary

Article 28
GDPR-aligned
48 Hours
Breach Notification Target
SOC 2-aligned
Infrastructure Practices
AES-256
Encryption Standard

Compliance & Certifications

GDPR
EU General Data Protection Regulation
CCPA
California Consumer Privacy Act
SOC 2
Service Organization Control Type II
ISO 27001
Information Security Management
HIPAA
Health Insurance Portability Act
SCCs
Standard Contractual Clauses

Data Classification Levels

Public
Low

Non-sensitive business information

Examples: Marketing materials, public APIs

Internal
Medium

Standard business data

Examples: Usage analytics, support logs

Confidential
High

Sensitive business information

Examples: Research data, client information

Restricted
Critical

Highly sensitive personal data

Examples: Medical records, genetic data

Technical & Organizational Measures (TOM)

Encryption

TLS 1.3 in transit, AES-256 at rest

All data encrypted with industry-leading algorithms

Access Control

MFA, RBAC, zero-trust architecture

Principle of least privilege enforced

Infrastructure

Hosted on SOC 2-audited providers

Geo-redundant infrastructure targets

Auditing

24/7 monitoring, quarterly penetration tests

Continuous compliance verification

Authentication

Biometric, hardware tokens, SSO

Multi-layered identity verification

Backup & Recovery

Encrypted backups, 15-minute RPO

4-hour RTO with automated failover

Data Subject Rights

Right of Access

Request a copy of personal data we process

Response: 30 days

Right to Rectification

Correct inaccurate or incomplete data

Response: 14 days

Right to Erasure

Request deletion of personal data

Response: 30 days

Right to Restrict

Limit how we process your data

Response: 72 hours

Right to Portability

Receive data in machine-readable format

Response: 30 days

Right to Object

Object to processing for specific purposes

Response: 72 hours

1. Definitions and Interpretation

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement between PlanckChron Inc. ("Processor") and Customer ("Controller"). This DPA is effective upon the date the Customer accepts the Terms of Service.

  • Personal Data: Any information relating to an identified or identifiable natural person ("Data Subject")
  • Processing: Any operation or set of operations performed on Personal Data
  • Data Subject: The individual to whom Personal Data relates
  • Sub-processor: Third party engaged by Processor to process Personal Data

2. Scope of Processing

This DPA applies to all Processing of Personal Data by PlanckChron on behalf of Customer in connection with the Services. The scope includes:

Data Categories Processed

  • • User account information and credentials
  • • Research data and experimental results
  • • Clinical trial participant information
  • • Analytics and usage telemetry

Processing Activities

  • • Collection, storage, and retrieval
  • • Analysis and aggregation
  • • Transfer and transmission
  • • Deletion and anonymization

3. Processor Obligations

PlanckChron, as the Processor, commits to the following binding obligations:

Process Personal Data only on documented instructions from Controller
Ensure personnel are bound by confidentiality obligations
Implement appropriate technical and organizational measures
Engage Sub-processors only with prior written consent
Assist Controller in responding to Data Subject requests
Notify Controller of breaches without undue delay (max 48 hours)
Delete or return Personal Data upon termination
Make available all information for compliance audits

4. Authorized Sub-Processors

Customer authorizes PlanckChron to engage the following Sub-processors. Changes will be notified 30 days in advance.

Sub-processorServiceLocationSafeguardsData Types
AWSCloud HostingUnited StatesSCCs, SOC 2, ISO 27001All customer data
SupabaseDatabase ServicesUnited StatesSCCs, SOC 2, GDPRApplication data
VercelApplication HostingUnited StatesSCCs, SOC 2Frontend assets
StripePayment ProcessingUnited StatesPCI-DSS, SCCsPayment information
CloudflareCDN & SecurityGlobalSOC 2, ISO 27001Traffic data
SendGridEmail DeliveryUnited StatesSOC 2, SCCsEmail addresses

Customer may object to Sub-processor changes within 15 business days of notification.

5. International Data Transfers

Personal Data may be transferred to and processed in the United States and other jurisdictions. Such transfers are protected by:

Standard Contractual Clauses (SCCs)

EU Commission-approved clauses for controller-to-processor transfers

Binding Corporate Rules

Internal policies ensuring consistent data protection across entities

Adequacy Decisions

Transfers to countries with adequate protection levels

Supplementary Measures

Additional technical safeguards including encryption and pseudonymization

6. Data Breach Notification

In the event of a Personal Data breach, PlanckChron will notify Customer without undue delay and no later than 48 hours after becoming aware of the breach.

Notification Will Include:

  • • Description of breach nature and scope
  • • Categories and volume of data affected
  • • Number of Data Subjects impacted
  • • Likely consequences and risk assessment

Remediation Actions:

  • • Immediate containment measures
  • • Ongoing mitigation steps
  • • Contact point for further information
  • • Support for regulatory notification

7. Audit Rights

Controller has the right to audit Processor's compliance with this DPA, subject to the following:

30 Days
Advance notice required
1x Annual
On-site audit frequency
Unlimited
Documentation requests

8. Term, Termination & Data Retention

This DPA remains in effect for the duration of the Service Agreement. Upon termination:

Data Return Options:

  • Export in standard formats (JSON, CSV, XML)
  • API access for 30 days post-termination

Data Deletion:

  • Secure deletion within 90 days
  • Certificate of destruction provided

Contact Information

For questions or concerns, please contact the appropriate department:

Privacy Team

DPA inquiries and data protection requests

Data Protection Officer

GDPR compliance and regulatory matters

Legal Affairs

Contract negotiations and enterprise DPAs

Corporate Headquarters

Planckchron Inc
11601 Wilshire Boulevard, Suite 500
Los Angeles, CA 90025
United States

Registered Office

Corporation Trust Company
1209 Orange Street
Wilmington, DE 19801