Effective Date: November 1, 2025
"Controller" means the customer (you) who determines the purposes and means of processing Personal Data.
"Processor" means TheraLyze.ai, which processes Personal Data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person contained in adverse event reports.
"Processing" means any operation performed on Personal Data, including collection, storage, analysis, and transmission.
TheraLyze.ai acts as a Data Processor under GDPR Article 28. The Controller determines:
Processing of adverse event reports for pharmacovigilance case management, medical coding, narrative generation, and E2B XML file creation for regulatory submission.
Primary Region: EU-West-1 (Ireland)
Backup Region: EU-Central-1 (Frankfurt)
All processing occurs within the European Union.
All personnel with access to Personal Data are bound by confidentiality obligations and receive GDPR training.
Data is retained according to Controller instructions. Sandbox data can be deleted by users at any time. Production data follows regulatory retention requirements (typically 10 years for pharmacovigilance).
TheraLyze.ai uses the following sub-processors:
Controller will be notified 30 days before adding new sub-processors.
The Controller has the right to:
TheraLyze.ai will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) within 72 hours of notification.
In the event of a Personal Data breach, TheraLyze.ai will:
All data remains within the European Union. No transfers to third countries occur unless explicitly requested by Controller and protected by Standard Contractual Clauses (SCCs).
Upon termination or Controller request, TheraLyze.ai will:
Controller may audit TheraLyze.ai's compliance once annually upon 30 days' notice. ISO 27001 and SOC 2 audit reports are available upon request.
Each party is liable for damages caused by breach of GDPR obligations. TheraLyze.ai maintains cyber liability insurance of €5 million.
Data Protection Officer: dpo@theralyze.ai
Security Team: security@theralyze.ai
General Inquiries: support@theralyze.ai
This DPA is governed by the laws of Ireland and GDPR. Disputes will be resolved in Irish courts.