Data Processing Agreement
Version 1.1 · Effective 2026-07-05
# Data Processing Agreement (DPA)
**Living SR&MA Platform**
**Version**: 1.1
> **How this Agreement applies.** This Data Processing Agreement ("Agreement") is incorporated into and forms part of the Platform's [Terms of Service](/legal/tos) (see its Section 4.6). It applies **automatically, without signature**, whenever the Controller (as defined below) uses the Platform in a way that involves the Processor processing Personal Data on the Controller's behalf. Institutions that require a countersigned copy may execute the signature version in the Appendix; the incorporated version and an executed copy have the same content and effect.
---
## Parties
**Data Controller** ("Controller"):
The user who accepts the Terms of Service, or the institution or other organization on whose behalf that user acts, in each case acting as the controller of Personal Data contained in project content processed through the Platform (as described in the [Privacy Policy](/legal/privacy), Section 2.1).
**Data Processor** ("Processor"):
Yuki Furukawa
Operating as: Living SR&MA Platform
Location: Japan
---
## 1. Background and Purpose
1.1. The Controller uses the Processor's cloud-based systematic review platform ("Platform") to manage and conduct systematic reviews and meta-analyses.
1.2. In the course of providing the Platform, the Processor processes personal data on behalf of the Controller as described in this Agreement.
1.3. This Agreement is entered into to ensure compliance with:
- **GDPR** (Regulation (EU) 2016/679) — where applicable
- **UK GDPR** and the Data Protection Act 2018 (United Kingdom) — where applicable
- **APPI** (Act on the Protection of Personal Information, Japan) — where applicable
- Other applicable data protection laws
---
## 2. Definitions
- **Personal Data**: Any information relating to an identified or identifiable natural person, as defined by GDPR Article 4(1) and APPI Article 2(1).
- **Processing**: Any operation performed on Personal Data, as defined by GDPR Article 4(2).
- **Sub-processor**: Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
---
## 3. Scope of Processing
### 3.1 Categories of Data Subjects
- Researchers and reviewers (Controller's team members)
### 3.2 Categories of Personal Data
| Category | Examples |
|----------|----------|
| Account data | Name, email address, profile picture (via Google OAuth) |
| Activity data | Screening decisions, extraction data, timestamps, IP addresses |
| Project data | Reference metadata, screening decisions, extraction records, knowledge-base content, comments, annotations |
| Team collaboration data | Project membership, collaborator names, collaborator email addresses, invitation status |
### 3.3 Nature and Purpose of Processing
The Processor processes Personal Data solely for the purpose of providing the Platform services, including:
- User authentication and access control
- Storing and displaying research project data
- Facilitating collaboration between team members
- Generating system logs for security and debugging
### 3.4 Duration of Processing
Processing continues for the duration of the Controller's use of the Platform. Upon termination, Section 10 applies.
### 3.5 Platform Storage Model
Personal Data controlled by the Processor for the hosted Platform is primarily stored in Supabase PostgreSQL in Tokyo (`ap-northeast-1`, Japan). The FastAPI application runs on Fly.io in Tokyo (`nrt`) and processes Personal Data in transit only. Logical backups of the production database are stored in Cloudflare R2 under the default jurisdiction (global edge, region `auto`) on a rolling 30-day retention cycle. Backup objects are created with `pg_dump -Fc` and protected by Cloudflare server-side encryption at rest.
PDFs and other user research files are stored in the Controller's own Supabase project when BYOK storage is configured. The Platform does not store PDFs in Operator-controlled storage.
---
## 4. Processor Obligations
The Processor shall:
(a) Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law; in that case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest;
(b) Ensure that persons authorized to process Personal Data have committed themselves to confidentiality;
(c) Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- HTTPS encryption for all data in transit
- Database encryption at rest
- Role-based access control
- Rate limiting and abuse prevention
- Regular security reviews
(d) Not engage another processor (sub-processor) without prior written authorization from the Controller (see Section 6);
(e) Assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection);
(f) Assist the Controller in ensuring compliance with obligations regarding data protection impact assessments and prior consultation with supervisory authorities, where applicable;
(g) At the choice of the Controller, delete or return all Personal Data upon termination of the service, and delete existing copies unless storage is required by applicable law;
(h) Make available to the Controller all information necessary to demonstrate compliance with this Agreement and allow for audits and inspections (see Section 8);
(i) Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes the GDPR, the UK GDPR, or other applicable data protection provisions.
---
## 5. Controller Obligations
The Controller shall:
(a) Ensure that the processing of Personal Data is lawful and that appropriate legal bases exist;
(b) Inform the Processor of any data protection requirements specific to the Controller's jurisdiction or institution;
(c) Ensure that data subjects are informed about the processing of their Personal Data in accordance with applicable law;
(d) Not upload patient-level data or individually identifiable health information to the Platform. The Platform is designed for study-level research metadata only.
---
## 6. Sub-processors
### 6.1 Authorized Sub-processors
The Controller authorizes the use of the following sub-processors and acknowledges the related provider role split:
| Provider | Role / Purpose | Location | DPA Status / Safeguards |
|----------|----------------|----------|-------------------------|
| **Supabase Pte. Ltd** | Sub-processor for the Platform production PostgreSQL database (`users`, `projects`, `refs`, `decisions`, `extractions`, audit data, and Operator-side billing records) | Tokyo, Japan (`ap-northeast-1`), with provider access from Singapore / United States | Supabase DPA executed 2026-06-12; SCCs Modules 1-4 + UK Addendum + Swiss Addendum; Japan adequacy for EEA/UK-to-Japan data at rest |
| **Fly.io, Inc.** | Sub-processor for application runtime; no persistent personal-data store | Tokyo, Japan (`nrt`) | Fly.io DPA executed 2026-06-12; 2021 SCCs Module 2; DPF safeguards |
| **Cloudflare, Inc.** | Sub-processor for R2 database backups, operational-alert email routing, KV, and scheduled Workers | R2 default jurisdiction (global edge, region `auto`) | Cloudflare DPA incorporated into the Main Agreement; EU/UK/Swiss SCCs |
| **Sendinblue SAS** (Brevo) | Sub-processor for outgoing transactional email | France (European Union) | Brevo Data Processing Agreement incorporated as Appendix 3 of Brevo's Terms of Service, executed automatically on account creation; primary processing within the EU (France/Belgium), with onward access by Brevo group sub-processors outside the EEA covered by the EU-U.S. Data Privacy Framework and SCCs per Brevo's DPA |
| **Google LLC** | OAuth authentication and account profile retrieval; Google may act as an independent controller or processor as applicable to the OAuth processing context | Global / United States | DPF and SCC safeguards |
| **Paddle.com Market Ltd** | Merchant-of-Record billing and payment processing if paid plans are enabled; Paddle is controller/seller for buyer payment data, and the Processor receives shared buyer and subscription data as a separate controller | United Kingdom / global | Paddle DPA and Data Sharing Addendum to be accepted on account activation / production flip; production pending |
### 6.2 BYOK Services Selected by the Controller
When the Controller configures BYOK (Bring Your Own Key) features, the Controller independently selects and is responsible for:
- **Supabase instance** (user research data and PDF storage) — governed by the Controller's agreement with Supabase
The Controller's own Supabase project is not a Platform sub-processor. The Processor acts solely as a conduit for data transmission to BYOK services and assumes no responsibility for the processing performed by these Controller-selected providers.
### 6.3 Changes to Sub-processors
The Controller grants a general written authorization (GDPR Article 28(2)) for the sub-processors listed in Section 6.1. The Processor shall notify the Controller of any intended addition or replacement of a sub-processor at least **30 days** before the change takes effect, through an update to the public [Subprocessor Registry](/legal/subprocessors) and an email notification to active users, thereby giving the Controller the opportunity to object. If the Controller objects on reasonable data-protection grounds and the parties cannot resolve the objection in good faith, the Controller may terminate its use of the Platform and export and delete its data before the change takes effect. In urgent cases — for example, replacing a provider in response to a security incident — the notice period may be shortened to seven days, with the reason recorded in the Subprocessor Registry.
---
## 7. Data Breach Notification
7.1. The Processor shall notify the Controller without undue delay (and in any event within **48 hours**) after becoming aware of a Personal Data breach.
7.2. The notification shall include:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
7.3. The Processor shall cooperate with the Controller in investigating and remediating the breach.
---
## 8. Audits and Inspections
8.1. The Processor shall make available to the Controller all information necessary to demonstrate compliance with this Agreement.
8.2. The Processor shall allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to:
- Reasonable advance notice (at least 30 days)
- Audits conducted during normal business hours
- Confidentiality obligations on the part of the auditor
- No more than one audit per calendar year (unless required due to a data breach)
---
## 9. International Data Transfers
9.1. Personal Data is primarily stored in Japan in Supabase PostgreSQL in Tokyo (`ap-northeast-1`). The application runtime is Fly.io Tokyo (`nrt`) and processes Personal Data in transit only.
9.2. Japan has received an adequacy decision from the European Commission (January 2019), permitting EEA-to-Japan transfers without additional safeguards for Personal Data stored or processed in Japan. Transfers from the United Kingdom to Japan may rely on the United Kingdom's adequacy regulations for Japan where applicable.
9.3. For provider access or processing outside Japan, including US-parent access by Supabase, Fly.io, Cloudflare, or Google, the Processor relies on the relevant provider's data processing terms, 2021 EU Standard Contractual Clauses, DPF safeguards where applicable, and transfer impact assessments where required.
9.4. For transfers subject to the UK GDPR, the Processor will use the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable.
9.5. Cloudflare R2 backup objects may be stored and processed through Cloudflare's default jurisdiction (global edge, region `auto`) and are protected by Cloudflare server-side encryption at rest. Production database backups are retained on a rolling 30-day cycle.
9.6. For BYOK services, the Controller is responsible for ensuring that any international data transfers through the Controller's selected Supabase project comply with applicable law.
---
## 10. Data Return and Deletion
10.1. Upon termination of the Controller's use of the Platform, the Processor shall:
- Provide the Controller with the ability to export all project data through the Platform's built-in export features
- Delete active Operator-controlled Personal Data within **30 days** of termination, unless longer retention is required by applicable law, audit obligations, legal claims, or the Data Retention Policy
10.2. Production database backups are retained in Cloudflare R2 on a rolling 30-day cycle. The Processor does not selectively erase individual records from existing backup snapshots and does not restore deleted or anonymized data from backups except where necessary for disaster recovery. If a disaster recovery restore occurs, completed deletion or anonymization requests are reapplied where technically feasible before normal service resumes.
10.3. The Processor shall provide written confirmation of deletion upon request.
---
## 11. Liability
11.1. Each party's liability under this Agreement is subject to the limitations set forth in the Platform's Terms of Service.
11.2. The Processor shall not be liable for any processing performed by BYOK services or providers selected by the Controller.
---
## 12. Term and Termination
12.1. This Agreement shall remain in effect for the duration of the Controller's use of the Platform.
12.2. This Agreement shall automatically terminate upon termination of the Controller's Platform account.
12.3. Sections 7, 8, 10, and 11 shall survive termination.
---
## 13. Governing Law
This Agreement shall be governed by and construed in accordance with the laws of **Japan**, without regard to conflict of law principles. Any disputes arising under this Agreement shall be submitted to the exclusive jurisdiction of the **Tokyo District Court**.
---
## Appendix: Optional Signature Execution
Execution of this Appendix is **not required** for this Agreement to apply — see "How this Agreement applies" at the top of this document. It is provided for institutions whose internal compliance processes require a countersigned copy.
**Data Controller**:
Name: ____________________________
Title: ____________________________
Institution: ____________________________
Date: ____________________________
Signature: ____________________________
**Data Processor**:
Name: Yuki Furukawa
Date: ____________________________
Signature: ____________________________
---