Data Processing Addendum (Overview)
An overview of the Data Processing Addendum available to enterprise customers. The full executed DPA is provided on request.
Purpose of the DPA
The Data Processing Addendum (DPA) sets out the terms under which DermaGenome processes personal data on behalf of enterprise customers to comply with GDPR, UK GDPR, CCPA/CPRA, and equivalent laws. This page is an overview; the binding terms are in the executed DPA supplied during procurement.
Roles
The enterprise customer is the controller (or processor, where it acts for its own controller) of end-user personal data. DermaGenome acts as a processor or sub-processor, processing data only on documented instructions from the customer.
Categories of Data
The DPA covers account data, analysis inputs including images, derived intelligence outputs, and technical logs, to the extent these constitute personal data under applicable law.
Processing Purposes & Duration
Processing is limited to providing the contracted services for the agreement term plus any retention period required for security, legal compliance, or transition. Purpose limitation is enforced contractually and technically.
Sub-processors
DermaGenome engages sub-processors under written contracts with equivalent protections. The DPA includes a sub-processor notification mechanism and objection rights where applicable. A current list is provided to customers under NDA.
Security Measures
The DPA incorporates the security measures described in the Security Center and the executed agreement, including encryption, access control, audit logging, and incident response. Specific technical and organizational measures are appended to the executed DPA.
Data-Subject Rights & Assistance
DermaGenome assists the customer in responding to data-subject requests and regulatory inquiries, taking into account the nature of processing and the information available to us. Assistance timelines are defined in the DPA.
Personal Data Breach Notification
DermaGenome notifies the customer of a confirmed personal data breach without undue delay and provides information reasonably necessary for the customer to meet its own notification obligations. Notification timelines and channels are specified in the DPA.
Data Return & Deletion
After termination, DermaGenome returns or deletes customer personal data per the DPA and the agreement, retaining only what is required by law, with that data minimized and protected.
Audits & International Transfers
The DPA provides for audit rights consistent with the service and relies on Standard Contractual Clauses or equivalent safeguards for international transfers. The full executed DPA is available on request to enterprise customers.
