Data Processing Agreement (DPA)
If you are a business customer processing third-party personal data (e.g. customer records, patient data, study subject IDs) through the CovaSyn MCP platform, Article 28 GDPR requires us to enter into a Data Processing Agreement.
Request the DPA
Fill in the form and we will send the ready-to-sign DPA to the address given, within 24 hours.
Alternatively, a brief email to info@covasyn.com with company name, address, and the name of an authorized signatory works too.
What the agreement covers
- Subject matter and duration of processing (term of your MCP subscription)
- Nature, purpose, and categories of personal data processed
- List of further sub-processors (Hetzner Online GmbH, Supabase (Datenbank und Authentifizierung), Stripe Payments Europe Ltd., Microsoft 365 (Exchange Online), Anthropic PBC, Cloudflare, Inc., Resend (Plus Five Five, Inc.), Twilio SendGrid, Trustpilot A/S, Google Ireland Ltd.), identical to the list in the privacy policy and on the trust page
- Technical and organizational measures (TOMs)
- Rights and obligations of both parties under Art. 28 GDPR
- Third-country transfers and Standard Contractual Clauses (SCCs)
Questions about processing or TOMs go to info@covasyn.com.
