1. Roles and scope
The DPA applies to personal data in customer materials processed on customer instructions. The customer determines purposes and means; HÉDÉONIX acts as processor. HÉDÉONIX-controlled account, security, direct inquiry, contract, payment, and legal-obligation data remains under the Privacy Policy.
2. Processing details
- Purpose: product operations, collaboration, regulatory and quality documentation
- Data subjects: customer staff, researchers, and business contacts
- Fields: work identity, contact, organization, role, assignment, authorship, review, approval, and comments
- Duration: contract term plus agreed export and deletion period
- Excluded: patient or study-subject identifiers, health information, and source data without separate written authorization
3. Instructions and safeguards
HÉDÉONIX processes only documented instructions and contracted functions. Customers must hold authority, legal basis, and notices.
- Least privilege and MFA
- Tenant, storage, worker, and export isolation
- Transport and storage protection
- Access, change, and export logs
- Training, incident response, and recovery
4. Subprocessing and transfers
Subprocessors follow the published list and contractual safeguards. Material changes to a subprocessor or processing region receive notice and an objection process. The final schedule will state work, region, fields, and retention by provider.
5. Rights, audit, incidents, deletion
HÉDÉONIX supports rights requests, regulator inquiries, incident investigations, and reasonable security verification while protecting other customers. At termination, data is returned or deleted subject to legal retention, audit integrity, and backup expiry.