Data Processing Agreement

Effective Date: July 1, 2026.

This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable order form or agreement referencing this DPA ("Customer", "Controller") and SCINR DATA SL, a company registered in Spain with registered tax ID B26938134 and address at Av. Manuel Fraga Iribarne 69, 3A, 28055 Madrid, Spain ("Scinr AI", "Processor"), together the "Parties".

This DPA forms part of, and is incorporated into, the Terms of Service and/or order form between the Parties governing Customer's use of the Newton platform (the "Agreement"). It applies whenever Scinr AI processes personal data on behalf of Customer in connection with the Service.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 (the "GDPR"). "Sub-processor" means any third party engaged by Scinr AI to process personal data on Customer's behalf in connection with the Service.

2. Subject matter, nature, and duration

2.1 Scinr AI processes personal data on Customer's behalf solely as necessary to provide the Newton platform, in accordance with Customer's documented instructions, as further described in Annex I.

2.2 Processing continues for the duration of the Agreement, and for any period thereafter during which Scinr AI holds Customer Data prior to deletion or return, as described in Section 10.

3. Customer's instructions

3.1 Scinr AI will process personal data only on documented instructions from Customer, including with regard to transfers of personal data to a third country, unless required to do otherwise by EU or Member State law, in which case Scinr AI will inform Customer of that legal requirement before processing, unless the law prohibits such notice.

3.2 The Agreement, including this DPA and Customer's configuration and use of the Service, constitutes Customer's documented instructions. Additional instructions outside the scope of the Agreement require separate written agreement, including with respect to fees.

3.3 Scinr AI will promptly notify Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Confidentiality

Scinr AI ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security of processing

Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, Scinr AI implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II.

6. Sub-processors

6.1 Customer authorizes Scinr AI to engage sub-processors to support the Service, as listed in Annex III.

6.2 Scinr AI will impose data protection obligations on each sub-processor that are substantially equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures.

6.3 Scinr AI will notify Customer of any intended addition or replacement of sub-processors with reasonable advance notice, giving Customer the opportunity to object on reasonable data protection grounds. If the Parties cannot resolve the objection, Customer may terminate the affected portion of the Service as its sole remedy.

6.4 Scinr AI remains liable to Customer for the performance of each sub-processor's obligations, to the extent required by applicable law.

7. International transfers

7.1 Where Scinr AI or a sub-processor transfers personal data outside the European Economic Area (EEA), it will ensure the transfer is subject to appropriate safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses (2021/914), an adequacy decision, or another valid transfer mechanism.

7.2 Where the Standard Contractual Clauses apply, they are incorporated into this DPA by reference, with Scinr AI as "data exporter" (acting as processor on behalf of Customer) and the relevant sub-processor as "data importer," and Customer authorizes Scinr AI to enter into and execute the Standard Contractual Clauses on Customer's behalf where necessary to give effect to this Section.

8. Assistance to Customer

8.1 Taking into account the nature of the processing, Scinr AI will assist Customer, insofar as reasonably possible, by appropriate technical and organizational measures, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under the GDPR.

8.2 Scinr AI will assist Customer in ensuring compliance with obligations relating to security of processing, personal data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the information available to Scinr AI.

9. Personal data breach notification

Scinr AI will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer's personal data, providing information reasonably available to Scinr AI to assist Customer in meeting its own notification obligations under the GDPR.

10. Deletion or return of data

Upon termination or expiry of the Agreement, and at Customer's election, Scinr AI will delete or return all personal data processed on Customer's behalf, and delete existing copies, unless applicable law requires continued storage. Customer may request export of Customer Data for a period of 30 days following termination, after which Scinr AI may proceed with deletion in accordance with its data retention practices.

11. Audits and inspections

11.1 Scinr AI will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality obligations, and no more than once per year absent a security incident or regulatory requirement.

11.2 Scinr AI may satisfy audit requests by providing a summary of relevant third-party audit reports or certifications, where available, in lieu of an on-site audit, where reasonably sufficient to demonstrate compliance.

12. Liability

Liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except where such limitation is not permitted under applicable data protection law.

13. Governing law

This DPA is governed by the laws of Spain, consistent with the governing law provisions of the Agreement.

14. Precedence

In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses (where applicable), the Standard Contractual Clauses prevail.

Annex I — Details of processing

Subject matter: Provision of the Newton agentic memory platform for life sciences supply chain and regulatory use cases.

Duration: For the term of the Agreement, plus any post-termination retention period described in Section 10.

Nature and purpose of processing: Ingestion, structuring, storage, retrieval, and AI-assisted analysis of documents and records submitted by Customer, including construction of a knowledge graph and generation of AI-assisted outputs (e.g., summaries, classifications, agent responses) based on that data.

Categories of data subjects (as applicable to Customer's use of the Service): Customer's employees, contractors, suppliers, and other individuals referenced in documents or records submitted to the Service.

Categories of personal data (as applicable to Customer's use of the Service): names, business contact details, professional roles, and other personal data contained within documents, records, or communications submitted by Customer (for example, personal data referenced within regulatory dossiers, quality records, or supply chain documentation). Scinr AI does not require special categories of personal data (Art. 9 GDPR) to provide the Service; Customer is responsible for not submitting such data unless expressly agreed in writing.

Frequency of processing: Continuous, for the duration of the Agreement.

Annex II — Technical and organizational measures

Scinr AI implements measures including:

  • encryption of personal data in transit and, where applicable, at rest;
  • access controls based on the principle of least privilege, with authentication required for all administrative and user access;
  • logical separation of Customer environments/data where applicable to the Service architecture;
  • logging and monitoring of access to production systems;
  • a documented incident response process for identifying, containing, and notifying personal data breaches;
  • confidentiality obligations for personnel and contractors with access to personal data;
  • secure software development practices and periodic review of key infrastructure configurations;
  • contractual security requirements imposed on sub-processors.

Specific technical details may be provided to Customer on request to support its own risk assessment.

Annex III — Sub-processors

  • Cloud hosting provider — AWS, Azure and Google Cloud Platform (EU / EEA)
  • Database / graph database provider — Neo4j Aura and MongoDB Atlas (EU / EEA)
  • LLM / AI model provider — Cloud AI-assisted processing and inference (EU / EEA)
  • Email / communications provider — MailerLite and Substack (EU / EEA / US)

Scinr AI will keep this list current and notify Customer of changes in accordance with Section 6.3. An up-to-date list is available on request to privacy@scinr.com.

SCINR DATA SL - Av. Manuel Fraga Iribarne 69, 3A, 28055 Madrid, privacy@scinr.com