DistillerSR GDPR Data Processing Addendum

Note to applicable Customers: Should your Organization require a signed copy of a DPA to be incorporated into the Agreement between DistillerSR Inc. and you, please inform your Account Executive.

Version 1.6 | July 9, 2026

This Data Processing Addendum (this “DPA”) governs the Vendor’s Processing of Uploaded Personal Data and Collected Personal Data (together “Customer Personal Data”) to the extent it relates to natural persons in the European Economic Area (“EEA”) in connection with Vendor’s provision of the Service(s) (defined below). Once fully executed, this DPA shall be incorporated into and made a part of either (i) the Proposal with DSR Subscription Terms, (ii) DistillerSR Terms of Service, or (iii) the Master Subscription Agreement (each, the “Contract”), by and between _______________________________________________________________ (“Customer“) and DistillerSR Inc. (“Vendor“). For the purposes of this DPA, the “Agreement” comprises the Contract together with this DPA and, to the extent applicable under the DSR Subscription Terms, DistillerSR Terms of Service, the Acceptable Use Policy, the Privacy Statement, and any Statements of Work, in each case as may be updated from time to time in accordance with their terms.

Except as expressly stated otherwise, in the event of a conflict between the terms of the Agreement and the terms of this DPA, the terms of this DPA will govern. This DPA applies to each subscription for Service(s) between Customer and Vendor pursuant to the Agreement, under which Vendor processes Uploaded Personal Data and/or Collected Personal Data as part of performing the applicable Service(s).

Definitions:

Collected Personal Data” means Personal Data collected by Vendor that is required for Customer and its Users to register for and access the Service(s) as well as contact, notification and other legitimate business purposes.
Controller” has the meaning given to it in the GDPR.
Controller-to-Controller Clauses” means Module One of the Standard Contractual Clauses for the transfer of personal data to third countries between controllers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Controller-to-Processor Clauses” means Module Two of the Standard Contractual Clauses between controllers and processors for Data Transfers, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Data Protection Laws” means applicable data protection or privacy laws and regulations of the relevant country in which the Service(s) are being performed, including, but not limited to and in each case to the extent applicable, the European Union General Data Protection Regulation 2016/679 (“GDPR”).
Processing” has the meaning given to it in the GDPR and “process”, “processes” and “processed” will be interpreted accordingly.
Processor” has the meaning given to it in the GDPR.
Prohibited Personal Data” has the meaning set out in section 6.2 of the Contract.
Security Incident” means an incident of Vendor’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
Service(s)” means any and all services and Software provided by Vendor to the Customer as described in one or more Proposals (including the Vendor’s Web-based applications, DistillerSR®, CuratorCR®, Smart Evidence Extraction, LitConnect, AI Classifier Manager, API Integrations, or any other services or applications that may be offered from time to time), including associated offline components. Each service applicable to the Customer may be described in an applicable proposal, order form, or invoice.
Standard Contractual Clauses” means the Controller-to-Controller Clauses and/or the Controller-to-Processor Clauses, as applicable.
Sub-processor” means any third party, including any Approved Sub-processor, engaged by Vendor to process Customer Personal Data on Vendor’s behalf in connection with the provision of the Service(s).
Third Country” means any country outside the EEA (as described in the GDPR).
“Uploaded Personal Data” means Personal Data uploaded by Customer, or its User, within the Service(s).
Users” means individuals, including you, who are authorized by Customer to use the Service(s), for whom subscriptions to the Service(s) have been purchased, and who have been supplied user identifications and passwords by Customer (or by Vendor at Customer’s request). Users may include employees, consultants, contractors and Customer Agents of Customer or its affiliates.
Unless otherwise indicated, all capitalized terms used but not defined in this DPA shall have the meanings given to them in Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”) or the Contract.

1. Data Processing.

1.1. Scope and Roles. This DPA applies when Customer Personal Data is processed by Vendor. In relation to Uploaded Personal Data, Vendor will act as Processor to Customer, who acts as Controller of Uploaded Personal Data. In relation to Collected Personal Data, Vendor acts as an independent Controller, and each party acts as a separate and independent Controller (and not as joint Controllers or in a Controller-Processor relationship) with respect to its own Processing of Collected Personal Data.

1.1.1. Uploaded Personal Data; Customer Responsibility. Customer acknowledges and agrees that Vendor does not generally access Uploaded Personal Data uploaded to the Service(s) without express consent prior to such access, and as such Vendor is not aware of the categories of data uploaded to the Service(s) by Customer. Customer agrees that it shall be solely responsible for the protection of such Uploaded Personal Data. Other than Vendor’s obligations set out under this DPA and the Agreement, Vendor shall have no additional or other obligations to secure Uploaded Personal Data received by Vendor from Customer or uploaded by Customer to the Service(s) without the knowledge or consent of Vendor.

1.1.2. Prohibited Personal Data. Pursuant to the Contract, Customer acknowledges and agrees that the uploading of any Prohibited Personal Data is strictly prohibited. Customer shall ensure that Customer and Users do not transmit or transfer any Prohibited Personal Data. Any uploading of such Prohibited Personal Data to Service(s) shall be deemed a violation of the Agreement and this DPA, and shall be considered a material breach in accordance with section 11.1 of the Contract. For clarity, the only Personal Data that Customer and its Users are permitted to upload to the Service(s) is Personal Data that has been published and is uploaded in the normal course of using the Service(s) (such as authors’ names and business contact information appearing in published medical journals/articles), which does not constitute Prohibited Personal Data; references in this DPA to Uploaded Personal Data shall be construed accordingly.

1.2. Inaccurate or Outdated Customer Personal Data. Taking into account the nature of the Processing, Customer agrees that it is unlikely that Vendor would become aware that Customer Personal Data transferred under the Standard Contractual Clauses is inaccurate or outdated. Nonetheless, if Vendor becomes aware that Customer Personal Data transferred under the Standard Contractual Clauses is inaccurate or outdated, it will inform Customer without undue delay. Vendor will make commercially reasonable efforts to cooperate with Customer to erase or rectify inaccurate or outdated Customer Personal Data transferred under the Standard Contractual Clauses.

1.3. Details of Data Processing.

1.3.1. Subject matter. The subject matter of the data Processing under this DPA is Uploaded Personal Data and/or Collected Personal Data, as applicable.

1.3.2. Duration. Vendor will process Customer Personal Data until termination of the Agreement, and thereafter only as necessary to return or delete it under section 12 and to meet its retention obligations under applicable law. During that period, the duration of Processing of Uploaded Personal Data is determined by Customer, and Collected Personal Data is retained in accordance with Vendor’s Privacy Statement.

1.3.3. Purpose. The purpose of the data Processing under this DPA is the provision of the Service(s) subscribed for by Customer in the Agreement from time to time.

1.3.4. Nature of the Processing. Intake, store, archive, delete, process in accordance with Customer designed workflow and perform such other services relating to Customer Personal Data as described in the Agreement and initiated by Customer’s express instructions from time to time.

1.3.5. Type of Customer Personal Data Processed. Uploaded Personal Data uploaded to the Service(s) under the Agreement and Collected Personal Data of Customer collected pursuant to Vendor’s Privacy Statement.

1.3.6. Categories of Data Subjects. The data subjects may include employees, suppliers, Users, authors and business contacts appearing in published literature (such as author names and business contact information in published medical journals/articles), or other individuals whose information Customer or its Users have obtained lawfully.

1.4. Compliance with Laws. Each party will comply with all Data Protection Laws, rules and regulations applicable to it and binding on it in the performance of this DPA, including the GDPR.

1.5. AI Processing of Customer Personal Data. To the extent Vendor processes Customer Personal Data using AI or AI Technologies (each as defined in the Contract) in connection with the Service(s), such Processing is governed by this DPA and shall be carried out only on Customer’s documented instructions as set out in Section 2. Vendor will not use Customer Personal Data to train, fine-tune, or otherwise permanently modify the weights of any AI model or underlying algorithm without Customer’s prior written consent; this does not restrict inference-time Processing (such as retrieval-augmented generation, in-context learning, caching, or session-level or short-term memory) that does not result in permanent modification of model weights. Vendor may anonymize, de-identify, or aggregate Customer Personal Data using industry-standard techniques in accordance with Data Protection Laws, will implement appropriate technical safeguards designed to prevent re-identification of individuals or Customer, and will inform Customer of its general anonymization methodology upon Customer’s written request.

2. Customer Instructions.

2.1. Processing on Documented Instructions. Notwithstanding anything in the Agreement to the contrary, Vendor will only process Customer Personal Data on documented instructions from Customer, including transfers of Customer Personal Data to a third country or an international organization, unless required to do so by applicable law to which Vendor is subject. For avoidance of doubt, Customer’s documented instructions include the Agreement and this DPA.

2.2. Out-of-Scope Processing. Vendor may process data provided by Customer to Vendor outside the scope of this DPA or Agreement if accompanied by documented instructions from Customer directing Vendor to do so. Customer shall be responsible for any additional fees incurred by Vendor in carrying out such documented instructions on behalf of Customer.

2.3. Conflicting or Unlawful Instructions. Vendor will promptly inform Customer if following Customer’s documented instructions would result in a violation of applicable data protection law or where Vendor must disclose Customer Personal Data in response to a legal obligation (unless the legal obligation prohibits Vendor from making such disclosure).

3. Confidentiality. Vendor will restrict access to Customer Personal Data to those authorized persons who need the Customer Personal Data in connection with the provision of the Service(s) provided by Vendor. Vendor will ensure such authorized persons are obligated to maintain the confidentiality of any Customer Personal Data.

4. Security of Data Processing. The parties will implement and maintain appropriate technical and organizational measures designed to ensure the confidentiality, reliability, and integrity of the Customer Personal Data they each process and/or control, and any systems, facilities, or software that are used, accessed, or supported in connection with the Agreement, taking into account industry standards, implementation costs, the nature, scope, context, and Processing purposes, as well as the risk of varying likelihood, and severity, for the rights and freedoms of the data subjects. Such measures shall include encryption of Customer Personal Data in transit and at rest.

5. Sub-processing.

5.1. Approved Sub-processors. Customer hereby authorizes Vendor to use the Sub-processors set forth in Vendor’s list of Approved Sub-processors (“Approved Sub-processors”). If Vendor intends to change, modify, or replace an Approved Sub-processor providing Service(s) under the Agreement, Vendor shall provide Customer with at least fifteen (15) days’ advance notice of such change via email notification, provided that Customer has instructed Vendor to include Customer on its email notification list for updates to the Approved Sub-processors by following the instructions at the following link, or has otherwise indicated to Vendor that it should be included on the notification list. Customer will have an opportunity to review the implications of Vendor engaging such Sub-processor. Customer may object to the use of such Sub-processor in accordance with section 5.2 below, provided that any such objection is limited to objections based on documented legal non-compliance by the proposed Sub-processor. If Customer’s objection cannot be resolved and Customer reasonably demonstrates a material legal compliance risk, Customer’s sole remedy shall be to terminate the affected Service(s) upon thirty (30) days’ written notice. If Customer does not object to the proposed Sub-processor in accordance with section 5.2 below, such Sub-processor will be considered an Approved Sub-processor under the Agreement and this DPA without need for further amendment.

5.2. Objection to New Sub-processors. Customer may object to Vendor’s use of a new Sub-processor by notifying Vendor in writing within ten (10) business days of receiving notice under this Section 5, provided that any such objection is limited to objections based on documented legal non-compliance by the proposed Sub-processor. In the event of such objection by Customer, Vendor will take commercially reasonable steps to address the objections raised by Customer and provide Customer with a reasonable written explanation of the steps taken to address such objection. If Customer’s objection cannot be resolved and Customer reasonably demonstrates a material legal compliance risk, Customer’s sole remedy shall be to terminate the affected Service(s) upon thirty (30) days’ written notice. During such efforts, Vendor will still be required to provide the Service(s) in a manner that is consistent with the Agreement, this DPA and its contractual obligations thereunder.

5.3. Sub-processor Obligations. Where Vendor engages a Sub-processor for carrying out specific Processing activities on behalf of Customer, Vendor shall ensure that equivalent data protection obligations as described in this DPA are followed by such Sub-processor by way of a contract or other legal act under European Union (“EU”) or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the Processing will meet the requirements of the EU data protection law.

5.4. Vendor Liability for Sub-`processors. Where its Sub-processor fails to fulfil its data protection obligations, Vendor, as Processor of Uploaded Personal Data, will remain fully liable to Customer for the performance of that Sub-processor’s obligations.

6. Vendor Assistance

6.1. Data Subject Requests. If a data subject makes a request to Vendor, Vendor will promptly forward such request to Customer once Vendor has identified that the request is from a data subject for whom Customer is responsible. Customer authorizes Vendor, on Customer’s behalf, to respond to any data subject who makes a request to Vendor, to confirm that Vendor has forwarded the request to Customer. With regards to Uploaded Personal Data, the parties agree that Vendor forwarding data subjects’ requests to Customer in accordance with this Section, represent the scope and extent of assistance required from Vendor. Taking into account the nature of the Processing, Vendor will assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III of the GDPR, consistent with Article 28(3)(e) of the GDPR. With respect to Collected Personal Data, Vendor acts as an independent Controller and shall be responsible for responding to data subject requests it receives in relation to the Collected Personal Data it processes; each party shall inform the other of any such request that relates to the other party’s Processing of Collected Personal Data.

6.2. Data Protection Impact Assessments and Prior Consultation. Taking into account the nature of the Processing and the information available to Vendor, Vendor will provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Articles 35 and 36 of the GDPR, in each case solely in relation to the Processing of Customer Personal Data by Vendor and at Customer’s expense.

7. Optional Security Features. Vendor offers optional security features in the Service(s) that Customer may implement for greater security, including multi-factor authentication and single sign-on authentication. User is responsible for maintaining adequate security and control of all User IDs, Passwords, hints, personal identification numbers (PINs), or any other codes used to access the Service(s).

8. Security Incident Notification. After becoming aware of a Security Incident affecting Customer Personal Data under the Agreement or this DPA, Vendor will notify Customer without undue delay and in any event within forty-eight (48) hours. Where Customer becomes aware of a Security Incident affecting Customer Personal Data processed under this DPA, Customer will notify Vendor without undue delay. Such notification will describe, to the extent then known and as further information becomes available: (a) the nature of the Security Incident; (b) the number and categories of data subjects and data records affected; (c) the name and contact details for the relevant contact person; and (d) any other information related to the Security Incident as required by law or applicable supervisory authority.

9. Audits. Upon request but only to the extent required by the GDPR, Vendor will make available to Customer all information necessary, and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, to demonstrate compliance with this DPA, Data Protection Laws, and any other regulatory compliance requirements. Such audits or inspections shall be limited to Vendor’s Processing of Customer Personal Data in its capacity as a Processor or Controller only, not any other aspect of Vendor’s business or information systems, unless otherwise agreed upon within the applicable Contract. If Customer requires Vendor to submit to audits or inspections that are necessary to demonstrate compliance, Customer will provide Vendor with written notice at least 60 days in advance of such audit or inspection. Such written notice will specify the things, people, places or documents to be made available. Such written notice, and anything produced in response to it (including any derivative work product such as notes of interviews), will be considered Vendor’s “Confidential Information” pursuant to the Contract. Customer will make every effort to cooperate with Vendor to schedule audits or inspections at times that are convenient to Vendor. Customer shall be solely responsible for all costs incurred in relation to audits or inspections, including the reasonable costs incurred by Vendor as a result of time spent assisting with the audit.

10. Transfers of Customer Personal Data.

10.1. Application of Standard Contractual Clauses. The Standard Contractual Clauses will only apply to Customer Personal Data that is transferred, either directly or via onward transfer, to any Third Country, (each a “Data Transfer”).

10.1.1. Applicable Modules. With regards to Uploaded Personal Data, the Controller-to-Processor Clauses apply, where the Customer is the Controller and Vendor is the Processor. In the case of Collected Personal Data, the Vendor is an independent Controller. To the extent Collected Personal Data originating in the EEA is transferred between the parties as independent Controllers to a Third Country, the Controller-to-Controller Clauses apply, with the party disclosing such Collected Personal Data acting as data exporter and the receiving party acting as data importer. Vendor also maintains relevant safeguards with its third-party service providers engaged to process such Collected Personal Data, such as Binding Corporate Rules and applicable Standard Contractual Clauses.

10.1.2. Authorized Locations. Customer authorizes Vendor to store and/or process Customer Personal Data in the United States or any other country in which they or their Sub-processors maintain facilities or provide services. For greater certainty, Customer Personal Data is hosted by Amazon Web Services (AWS) and is stored and processed only in its US East-1 data centre or in Canada, and is not hosted within the EEA. Customer represents and warrants that Customer’s collection of any Customer Personal Data is conducted in accordance with Chapter 2, Article 6 of the GDPR. The parties appoint each other to perform any such transfer of Customer Personal Data to any such country and to store and process Customer Personal Data in connection with the provision of the Service(s) by Vendor. The parties will conduct all such activity in accordance with Chapter 2, Article 6 of the GDPR, the terms of the Agreement, and any applicable law.
10.2. Supplementary Measures and Transfer Impact Assessments. With respect to any Data Transfer, Vendor shall maintain commercially reasonable supplementary technical and organizational measures, including encryption of Customer Personal Data in transit and at rest, designed to protect the transferred Customer Personal Data. Upon Customer’s written request, Vendor shall provide the information reasonably necessary for Customer to complete a transfer impact assessment.

11. Termination of the DPA. This DPA will continue in force until terminated in accordance with the Agreement. Notwithstanding such termination, this DPA will continue to apply to any Processing of Customer Personal Data carried out by Vendor after termination until such Customer Personal Data has been returned or deleted in accordance with section 12, and any provisions of this DPA that by their nature should survive termination will survive.

12. Return or Deletion of Customer Personal Data. Customer shall have the ability to request Vendor to return or delete all Customer Personal Data processed in connection with the Service(s) at any time, including upon termination of the Agreement and for 60 days thereafter, subject to Vendor’s internal procedures, and Vendor’s obligations under any applicable laws requiring the preservation of such Customer Personal Data. Notwithstanding Customer’s right to request the return or deletion of Customer Personal Data under the GDPR, Customer represents and warrants that Customer is aware and acknowledges that Vendor is subject to Canadian and American laws requiring the retention of certain records and audit trails. Notwithstanding any provision to the contrary, nothing in this DPA shall be construed to require the deletion of any items of Customer Personal Data that are contained in electronic form on archive systems or other disaster recovery systems from which such items cannot reasonably be accessed or deleted.

13. Duties to Inform. Where Customer Personal Data becomes subject to confiscation during bankruptcy or insolvency proceedings, or similar measures by third parties while being processed by Vendor, Vendor will inform Customer without undue delay. Vendor will, without undue delay, notify all relevant parties in such action (for example, creditors, bankruptcy trustee) that any Customer Personal Data subjected to those proceedings is Customer’s property and area of responsibility and that Customer Personal Data is at Customer’s sole disposition.

14. Entire Agreement; Conflict. This DPA incorporates Module One and Module Two of the Standard Contractual Clauses by reference. Except as amended by this DPA, the Agreement will remain in full force and effect. Nothing in this document varies or modifies the Standard Contractual Clauses.

CUSTOMER NAME: [INSERT]

Per: ____________________________
Name:
Title:

DISTILLERSR INC.

Per: _______________________
Name:
Title:

SCHEDULE 1
TRANSFER MECHANISMS FOR EUROPEAN DATA TRANSFERS
1. Standard Contractual Clauses Operative Provisions And Additional Terms
1.1. Interpretation. For the purposes of the Controller-to-Processor Clauses, Customer is the data exporter and Vendor is the data importer. For the purposes of the Controller-to-Controller Clauses (Module One), which apply to any transfer of Collected Personal Data between the parties as independent Controllers to a Third Country as described in section 10.1.1, the party disclosing such Collected Personal Data is the data exporter and the receiving party is the data importer. The Controller-to-Controller Clauses are incorporated by reference and draw on the same information set out in Schedule 2 (Annexes I and II), as adapted to reflect the controller-to-controller relationship. For clarity, the provisions of this Schedule 1 addressing instructions (section 1.4), sub-processors (sections 1.6 and 1.7), and audits (section 1.8) apply only to the Controller-to-Processor Clauses (Module Two) and the Uploaded Personal Data leg, as those Clauses have no equivalent under Module One; the provisions addressing the docking clause (section 1.3), security of Processing (section 1.5), redress (section 1.9), supervision (section 1.10), government access requests (section 1.11), and governing law and forum (section 1.12) apply to both the Controller-to-Processor Clauses (Module Two) and the Controller-to-Controller Clauses (Module One).

1.2. Reference to the Standard Contractual Clauses. The relevant provisions contained in the Standard Contractual Clauses are incorporated by reference and are an integral part of this DPA. The information required for the purpose of the Appendix to the Standard Contractual Clauses is set out in Schedule 2.

1.3. Docking Clause. The optional docking clause under Clause 7 shall not apply under either the Controller-to-Processor Clauses (Module Two) or the Controller-to-Controller Clauses (Module One).

1.4. Instructions. This section 1.4 applies only to the Controller-to-Processor Clauses (Module Two) and to Uploaded Personal Data. This DPA and the Agreement are Customer’s complete instructions at the time of execution of the DPA for the Processing of Uploaded Personal Data. Any additional instructions must be consistent with the terms of this DPA and the Agreement. For the purposes of Clause 8.1(a), the instructions by Customer to process Uploaded Personal Data are set out in section 2 of this DPA and include onward transfers to third parties located outside Europe for the purpose of providing the Service(s). For the avoidance of doubt, Collected Personal Data is not processed on Customer’s instructions; each party processes Collected Personal Data as an independent Controller in accordance with the Controller-to-Controller Clauses (Module One).

1.5. Security of Processing. For the purposes of Clause 8.6(a) as it applies to the Controller-to-Processor Clauses (Module Two), and Clause 8.5 as it applies to the Controller-to-Controller Clauses (Module One), the parties agree that the technical and organizational measures implemented and maintained by Vendor provide a level of security appropriate to the risk with respect to the Personal Data each party processes. Customer is solely responsible for independently determining whether the technical and organizational measures implemented by Vendor meet Customer’s requirements.

1.6. General Authorization to use Sub-processors. With regards to Module Two only, option 2 under Clause 9 shall apply, and pursuant to Clause 9(a), Vendor has Customer’s general authorization to engage Sub-processors in accordance with section 5 of this DPA.

1.7. Notification of New Sub-processors and Customer’s Objection Rights. Customer acknowledges that, pursuant to Clause 9(a), Vendor may engage new Sub-processors, as described in sections 5.1 to 5.3 of this DPA. Vendor shall follow the notification and objection procedure as set out in sections 5.1 and 5.2 of the DPA.

1.8. Audits under the Standard Contractual Clauses. The parties agree that the audits described in Clause 8.9 shall be carried out in accordance with section 9 of this DPA.

1.9. Redress. Pursuant to Clause 11, Customer may contact Vendor at privacy@distillersr.com, or as otherwise provided in Vendor’s Privacy Statement. With respect to the Controller-to-Processor Clauses (Module Two) and Uploaded Personal Data, Vendor shall inform Customer if it receives a complaint or request from a data subject with respect to such Customer Personal Data, in accordance with section 6 of this DPA. With respect to the Controller-to-Controller Clauses (Module One) and Collected Personal Data, each party, as an independent Controller, shall handle complaints and requests it receives from data subjects in relation to the Collected Personal Data it processes, and shall inform the other party of any complaint or request that relates to the other party’s Processing. The optional provision in Clause 11 (independent dispute resolution body) shall not apply under either Module.

1.10. Supervision. For the purpose of Clause 13, the competent supervisory authority shall be determined in accordance with Clause 13, namely: (i) where the data exporter is established in an EEA member state, the supervisory authority of that member state; (ii) where the data exporter is not established in the EEA but has appointed an EU representative pursuant to Article 27(1) of the GDPR, the supervisory authority of the member state in which that representative is established; or (iii) failing the foregoing, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located.

1.11. Notification of Government Access Request. In accordance with Clause 15(1), which applies under both the Controller-to-Processor Clauses (Module Two) and the Controller-to-Controller Clauses (Module One), the data importer shall notify the data exporter of any government access request relating to the transferred Customer Personal Data. Where Vendor is the data importer, Vendor shall notify Customer accordingly.

1.12. Governing Law and Choice of Forum. For the purposes of Clause 17 (Governing law) and Clause 18 (Choice of forum and jurisdiction) of the Standard Contractual Clauses, under both the Controller-to-Processor Clauses (Module Two) and the Controller-to-Controller Clauses (Module One), the Standard Contractual Clauses shall be governed by the law of the Republic of Ireland, and any dispute arising from the Standard Contractual Clauses shall be resolved by the courts of the Republic of Ireland.

SCHEDULE 2
ANNEX I

A. LIST OF PARTIES
Data exporter(s):
Name: [CUSTOMER to insert]
Address: [CUSTOMER to insert]
Contact person’s name, position and contact details: [CUSTOMER to insert]
Data Protection Officer’s (if any) name, position, and contact details: [CUSTOMER to insert]
EU representative’s (if any) name, position, and contact details: [CUSTOMER to insert]

Activities relevant to the data transferred under these Clauses: Upload to the Service(s) Uploaded Personal Data, lawfully obtained by Customer and such other activities as required access the Service(s) from time to time.

Customer Signature and date:
______________________________________
Role (controller/processor): Controller of Uploaded Personal Data and independent Controller of Collected Personal Data

Data importer(s):
Name: DistillerSR Inc.
Address: 505 March Road, Suite 450, Ottawa, ON, Canada K2K 3A4
Contact person’s name, position and contact details: Naomi Morisawa De Koven
Data Protection Officer’s / EU representative’s (if any) name, position, and contact details: [Vendor to insert]

Activities relevant to the data transferred under these Clauses: Intake, store, archive, delete, process in accordance with Customer designed workflow and perform such other services relating to Customer Personal Data as described in the Agreement and initiated by Customer’s express instructions from time to time. With respect to Collected Personal Data, Vendor processes such data as an independent Controller for its own purposes, namely enabling Customer and Users to register for and access the Service(s), contact and notification, maintenance of Vendor’s audit trail as required for regulatory compliance, and other legitimate business purposes described in Vendor’s Privacy Statement.

Signature and date:
______________________________________

Role (controller/processor): Processor of Uploaded Personal Data and independent Controller of Collected Personal Data

Note on Controller-to-Controller transfers (Module One): The exporter/importer roles set out above reflect the Uploaded Personal Data leg under the Controller-to-Processor Clauses (Module Two). For transfers of Collected Personal Data between the parties as independent Controllers under the Controller-to-Controller Clauses (Module One), these roles may reverse depending on the direction of the transfer, such that the party disclosing the Collected Personal Data is the data exporter and the receiving party is the data importer, as described in section 1.1 of Schedule 1.

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred:
The data subjects may include employees, suppliers, Users, authors and business contacts appearing in published literature (such as author names and business contact information in published medical journals/articles), or other individuals whose information Customer or its Users have obtained lawfully.

Categories of personal data transferred:
Uploaded Personal Data uploaded to the Service(s) under the Agreement and Collected Personal Data of Customer collected pursuant to Vendor’s Privacy Statement.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:

n/a

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):
Continuous, depending on use of the Service(s) by Customer and Users.

Nature of the processing:
Intake, store, archive, delete, process in accordance with Customer designed workflow and perform such other services relating to Customer Personal Data as described in the Agreement and initiated by Customer’s express instructions from time to time.

Purpose(s) of the data transfer and further processing:
The purpose of the data processing under this DPA is the provision of the Service(s) subscribed for by Customer in the Agreement from time to time.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period:

Collected Personal Data will be deleted once it is no longer required to provide the Service(s) or for legitimate business interests.

Uploaded Personal Data must be deleted by Customer once it is no longer required by Customer. Vendor has implemented stringent least privilege access and controls, limiting its access to Uploaded Personal Data and unless specifically requested by Customer will not access Uploaded Personal Data.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:
Sub-processors process Customer Personal Data in accordance with section 5 of this DPA to provide the Service(s), pursuant to the Agreement. Sub-processors will process Customer Personal Data for the duration of the Agreement, subject to section 5.

The identities of Sub-processors are available at https://help.distillersr.com/hc/en-us/articles/37669776483597-DistillerSR-Approved-Third-Party-Service-Providers.

C. COMPETENT SUPERVISORY AUTHORITY
The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses, by reference to the establishment of the data exporter (or, as applicable, the location of its EU representative or of the relevant data subjects).

ANNEX II
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Vendor will maintain administrative, physical, and technical safeguards for the protection, confidentiality, security and integrity of Collected Personal Data and Uploaded Personal Data, as further described in Vendor’s SOC II Type II report, which is available upon request. Vendor will not materially decrease the overall security of the Service(s) during a subscription term.