CovaSyn

Data Processing Agreement (DPA)

If you are a business customer processing third-party personal data (e.g. customer records, patient data, study subject IDs) through the CovaSyn MCP platform, Article 28 GDPR requires us to enter into a Data Processing Agreement.

Request the DPA

Fill in the form and we will send the ready-to-sign DPA to the address given, within 24 hours.

Alternatively, a brief email to info@covasyn.com with company name, address, and the name of an authorized signatory works too.

What the agreement covers

  • Subject matter and duration of processing (term of your MCP subscription)
  • Nature, purpose, and categories of personal data processed
  • List of further sub-processors (Hetzner Online GmbH, Supabase (Datenbank und Authentifizierung), Stripe Payments Europe Ltd., Microsoft 365 (Exchange Online), Anthropic PBC, Cloudflare, Inc., Resend (Plus Five Five, Inc.), Twilio SendGrid, Trustpilot A/S, Google Ireland Ltd.), identical to the list in the privacy policy and on the trust page
  • Technical and organizational measures (TOMs)
  • Rights and obligations of both parties under Art. 28 GDPR
  • Third-country transfers and Standard Contractual Clauses (SCCs)

Questions about processing or TOMs go to info@covasyn.com.

Auftragsverarbeitungsvertrag (AVV) / Data Processing Agreement | CovaSyn