Data Processing Agreement

Last updated: June 2025

This Data Processing Agreement ("DPA") forms part of the agreement between CODX Systems ("Processor") and you ("Controller") when we process personal data on your behalf in connection with our services. This DPA is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data, including collection, storage, use, and deletion
  • Controller: The entity that determines the purposes and means of processing personal data
  • Processor: The entity that processes personal data on behalf of the Controller
  • Data Subject: The individual to whom the personal data relates

2. Scope & Purpose

This DPA applies to all personal data processed by the Processor on behalf of the Controller in connection with the services provided. The nature and purpose of processing is determined by the specific services engaged — including software development, cloud infrastructure management, data analytics, and technical support.

3. Processor Obligations

The Processor agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure that personnel authorised to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Not subcontract processing activities without prior written consent from the Controller
  • Assist the Controller in fulfilling its obligations regarding data subject rights
  • Notify the Controller without undue delay upon becoming aware of a personal data breach
  • Delete or return all personal data at the end of the services, as directed by the Controller

4. Data Subject Rights

The Processor shall assist the Controller in responding to data subject requests under applicable law, including:

  • Right of access to personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

5. Security Measures

The Processor maintains appropriate technical and organisational security measures, including:

  • Encryption of personal data at rest and in transit
  • Access controls based on the principle of least privilege
  • Regular security audits and vulnerability assessments
  • Secure development practices and code review
  • Incident response and disaster recovery procedures
  • Employee training on data protection and security

6. Subprocessors

The Processor may engage subprocessors (e.g., cloud hosting providers, analytics services) to assist in providing services. Current subprocessors include:

  • Vercel Inc. — Cloud hosting and deployment
  • Amazon Web Services (AWS) — Cloud infrastructure
  • Google Cloud Platform — Data storage and analytics

The Controller will be notified of any changes to subprocessors and may object within 14 days.

7. Data Transfers

Personal data may be transferred to and processed in countries where the Processor or its subprocessors maintain facilities. The Processor ensures that such transfers are governed by appropriate safeguards, including Standard Contractual Clauses (SCCs) adopted by the European Commission.

8. Duration & Termination

This DPA remains in effect as long as the Processor is processing personal data on behalf of the Controller. Upon termination of the underlying service agreement, the Processor shall delete or return all personal data within 30 days, unless retention is required by law.

9. Contact & Data Protection Officer

For questions or concerns regarding this DPA or data protection matters, please contact us. We will respond to any data protection inquiries within 48 hours.