1. Parties and Definitions
PARTIES TO THIS AGREEMENT:
Data Controller: The individual or entity ("Customer," "you") who uses Gene Matrix's genetic testing services and determines the purposes and means of processing personal data.
Data Processor: Gene Matrix LLC ("Gene Matrix," "we," "us"), a company organized under the laws of Delaware, with principal offices at 123 Genomics Way, San Francisco, CA 94105, which processes personal data on behalf of the Data Controller.
DEFINITIONS:
Personal Data: Any information relating to an identified or identifiable natural person, including but not limited to genetic data, health information, contact details, and identification information.
Processing: Any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, erasure, or destruction.
Data Subject: The individual to whom personal data relates.
Sub-processor: Any third party engaged by Gene Matrix to process personal data on behalf of the Data Controller.
Data Protection Laws: All applicable laws and regulations relating to data protection and privacy, including but not limited to GDPR, HIPAA, CCPA, and other relevant legislation.
Supervisory Authority: The relevant data protection authority with jurisdiction over data processing activities.
2. Scope and Purpose
SCOPE OF AGREEMENT:
This Data Processing Agreement ("DPA") applies to all processing of personal data by Gene Matrix on behalf of the Data Controller in connection with the provision of genetic testing services.
PURPOSE OF PROCESSING:
Gene Matrix processes personal data solely for the following purposes:
- Providing genetic testing services as requested by the Data Controller
- Analyzing biological samples and generating test results
- Delivering test results to the Data Controller
- Providing customer support and service communications
- Maintaining and improving service quality
- Complying with legal and regulatory obligations
- Protecting the security and integrity of our systems
NATURE OF PROCESSING:
Processing activities include:
- Collection of personal and health information
- Receipt and processing of biological samples
- Genetic sequencing and analysis
- Storage of genetic data and test results
- Transmission of results to authorized recipients
- Retention and archival of data as required by law
- Secure deletion or anonymization upon request
CATEGORIES OF DATA SUBJECTS:
- Individuals who order genetic testing services
- Minors for whom testing is ordered by parents/guardians
- Healthcare providers acting on behalf of patients
- Research participants (with explicit consent)
TYPES OF PERSONAL DATA:
- Identification data: Name, date of birth, contact information
- Health data: Medical history, family health history, symptoms
- Genetic data: DNA sequences, genetic variants, test results
- Payment data: Billing information, transaction records
- Technical data: IP addresses, device information, usage data
3. Data Processor Obligations
GENE MATRIX'S OBLIGATIONS AS DATA PROCESSOR:
Lawful Processing:
Gene Matrix shall:
- Process personal data only on documented instructions from the Data Controller
- Not process personal data for any purpose other than as instructed
- Immediately inform the Data Controller if instructions violate data protection laws
- Comply with all applicable data protection laws and regulations
Confidentiality:
Gene Matrix shall:
- Ensure that all personnel with access to personal data are bound by confidentiality obligations
- Limit access to personal data to personnel who need it to perform their duties
- Implement appropriate confidentiality agreements with all staff and contractors
- Maintain confidentiality even after termination of this agreement
Security Measures:
Gene Matrix shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest (AES-256)
- Multi-factor authentication for system access
- Regular security assessments and penetration testing
- Intrusion detection and prevention systems
- Secure backup and disaster recovery procedures
- Physical security controls for facilities and equipment
- Regular security training for all personnel
- Incident response and breach notification procedures
Sub-processing:
Gene Matrix shall:
- Obtain prior written authorization from the Data Controller before engaging sub-processors
- Ensure sub-processors are bound by data protection obligations equivalent to this DPA
- Remain fully liable for the performance of sub-processors
- Maintain a current list of authorized sub-processors
- Notify the Data Controller of any intended changes to sub-processors
Data Subject Rights:
Gene Matrix shall:
- Assist the Data Controller in responding to data subject requests
- Provide necessary information to enable compliance with data subject rights
- Implement technical measures to facilitate data subject rights (access, rectification, erasure, portability)
- Respond to data subject requests within required timeframes
Data Protection Impact Assessments:
Gene Matrix shall:
- Assist the Data Controller in conducting data protection impact assessments
- Provide necessary information about processing activities
- Cooperate in consultations with supervisory authorities when required
Records and Documentation:
Gene Matrix shall:
- Maintain detailed records of all processing activities
- Document all security measures and procedures
- Provide documentation to the Data Controller upon request
- Maintain records for the duration required by law
4. Data Controller Obligations
DATA CONTROLLER'S OBLIGATIONS:
Lawful Basis:
The Data Controller shall:
- Ensure a lawful basis exists for all processing activities
- Obtain necessary consents from data subjects
- Provide required notices to data subjects
- Comply with all applicable data protection laws
Instructions:
The Data Controller shall:
- Provide clear, documented instructions for data processing
- Ensure instructions comply with applicable laws
- Update instructions as necessary
- Notify Gene Matrix of any changes to processing requirements
Data Accuracy:
The Data Controller shall:
- Ensure personal data provided is accurate and up-to-date
- Correct inaccurate data promptly
- Inform Gene Matrix of any data corrections needed
Data Subject Rights:
The Data Controller shall:
- Handle data subject requests in accordance with applicable laws
- Coordinate with Gene Matrix to fulfill data subject rights
- Respond to data subjects within required timeframes
Cooperation:
The Data Controller shall:
- Cooperate with Gene Matrix in ensuring compliance
- Provide necessary information for audits and assessments
- Respond promptly to Gene Matrix's compliance inquiries
- Notify Gene Matrix of any relevant regulatory changes
5. Sub-processors
AUTHORIZED SUB-PROCESSORS:
Gene Matrix currently engages the following categories of sub-processors:
Laboratory Services:
- CLIA-certified, CE-IVD Certified genetic testing laboratories
- Sample processing and analysis facilities
- Quality control and validation services
Technology Infrastructure:
- Cloud hosting providers (AWS, Google Cloud)
- Database management services
- Backup and disaster recovery services
- Content delivery networks
Payment Processing:
- PCI-DSS compliant payment processors
- Fraud detection and prevention services
Customer Support:
- Customer service platform providers
- Communication and email services
Security Services:
- Security monitoring and threat detection
- Penetration testing and vulnerability assessment
- Identity and access management
SUB-PROCESSOR REQUIREMENTS:
All sub-processors must:
- Sign data processing agreements with equivalent protections
- Implement appropriate security measures
- Comply with all applicable data protection laws
- Submit to audits and assessments
- Notify Gene Matrix of any security incidents
CHANGES TO SUB-PROCESSORS:
Gene Matrix shall:
- Notify the Data Controller at least 30 days before adding or replacing sub-processors
- Provide information about the sub-processor and processing activities
- Allow the Data Controller to object to the change
- Offer alternative solutions if the Data Controller objects
OBJECTION PROCESS:
If the Data Controller objects to a sub-processor:
- Objection must be based on reasonable grounds related to data protection
- Data Controller must notify Gene Matrix within 15 days
- Parties will work together to find an alternative solution
- If no solution is found, either party may terminate the affected services
CURRENT SUB-PROCESSOR LIST:
A current list of sub-processors is available at: www.genematrix.io/subprocessors
The Data Controller may request updates to this list at any time.
6. International Data Transfers
CROSS-BORDER DATA TRANSFERS:
Personal data may be transferred to and processed in countries outside the European Economic Area (EEA) and the Data Controller's jurisdiction.
TRANSFER MECHANISMS:
Gene Matrix ensures adequate protection for international transfers through:
Standard Contractual Clauses (SCCs):
- EU Commission-approved Standard Contractual Clauses
- UK International Data Transfer Agreement (where applicable)
- Swiss-US data transfer mechanisms (where applicable)
Adequacy Decisions:
- Transfers to countries with adequacy decisions from relevant authorities
- Compliance with adequacy requirements
Additional Safeguards:
- Supplementary measures beyond SCCs where required
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Contractual obligations on data recipients
TRANSFER IMPACT ASSESSMENT:
Gene Matrix has conducted transfer impact assessments to ensure:
- Laws in destination countries do not impair SCC protections
- Additional safeguards are implemented where necessary
- Data subjects' rights are protected
- Effective remedies are available
DATA LOCALIZATION:
Where required by law or requested by the Data Controller:
- Data can be stored in specific geographic regions
- Processing can be limited to approved jurisdictions
- Additional controls can be implemented
GOVERNMENT ACCESS:
In the event of government requests for data access:
- Gene Matrix will notify the Data Controller unless legally prohibited
- Gene Matrix will challenge unlawful or overbroad requests
- Gene Matrix will provide minimum necessary information
- Gene Matrix will document all government access requests
TRANSPARENCY:
Gene Matrix maintains transparency regarding:
- Countries where data is processed
- Legal basis for each transfer
- Safeguards implemented
- Sub-processors involved in transfers
7. Security Measures
TECHNICAL SECURITY MEASURES:
Encryption:
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- End-to-end encryption for sensitive communications
- Encrypted backups with separate key management
- Hardware security modules (HSMs) for key storage
Access Controls:
- Multi-factor authentication (MFA) required for all access
- Role-based access control (RBAC)
- Principle of least privilege
- Regular access reviews and revocations
- Automatic session timeouts
- Biometric access controls for physical facilities
Network Security:
- Firewall protection and intrusion detection systems
- DDoS protection and rate limiting
- Network segmentation and isolation
- Virtual private networks (VPNs) for remote access
- Regular penetration testing
- 24/7 security monitoring and alerting
Application Security:
- Secure software development lifecycle (SDLC)
- Regular security code reviews
- Automated vulnerability scanning
- Web application firewall (WAF)
- Input validation and sanitization
- Secure API design and authentication
ORGANIZATIONAL SECURITY MEASURES:
Personnel Security:
- Background checks for all personnel
- Confidentiality and non-disclosure agreements
- Regular security awareness training
- Clear roles and responsibilities
- Separation of duties
- Disciplinary procedures for violations
Physical Security:
- Biometric access controls for facilities
- 24/7 video surveillance
- Secure sample storage and handling
- Controlled environment monitoring
- Visitor management and escort procedures
- Secure destruction of physical media
Incident Management:
- Incident response plan and team
- Regular incident response drills
- Forensic analysis capabilities
- Breach notification procedures
- Post-incident review and improvement
Business Continuity:
- Disaster recovery plan
- Regular backup procedures
- Redundant systems and failover
- Business continuity testing
- Emergency response procedures
SECURITY CERTIFICATIONS:
Gene Matrix maintains:
- ISO 27001 certification
- SOC 2 Type II compliance
- HIPAA compliance
- CLIA and CE-IVD certification
- Regular third-party security audits
8. Data Breach Notification
BREACH DETECTION AND RESPONSE:
Immediate Actions:
Upon discovering a personal data breach, Gene Matrix shall:
- Immediately contain and mitigate the breach
- Conduct preliminary assessment of scope and impact
- Preserve evidence for forensic analysis
- Activate incident response team
- Document all actions taken
NOTIFICATION TO DATA CONTROLLER:
Gene Matrix shall notify the Data Controller without undue delay and in any event within 24 hours of becoming aware of a breach.
Notification Contents:
The breach notification shall include:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate number of personal data records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Measures to mitigate possible adverse effects
- Contact point for further information
- Timeline of events
ONGOING UPDATES:
Gene Matrix shall:
- Provide regular updates as investigation progresses
- Share final incident report within 30 days
- Cooperate fully in breach response efforts
- Implement recommended remediation measures
ASSISTANCE TO DATA CONTROLLER:
Gene Matrix shall assist the Data Controller in:
- Assessing whether notification to supervisory authorities is required
- Preparing notifications to supervisory authorities
- Determining whether notification to data subjects is required
- Preparing communications to data subjects
- Responding to inquiries from authorities and data subjects
NOTIFICATION TIMELINES:
To Supervisory Authority (if required):
- GDPR: Within 72 hours of becoming aware
- Other jurisdictions: As required by applicable law
To Data Subjects (if required):
- Without undue delay if high risk to rights and freedoms
- In clear and plain language
- Including recommended protective measures
REMEDIATION:
Following a breach, Gene Matrix shall:
- Conduct thorough root cause analysis
- Implement corrective and preventive measures
- Update security controls as necessary
- Provide written report of improvements
- Conduct follow‑up security assessment
BREACH REGISTER:
Gene Matrix maintains a register of all data breaches, including:
- Facts relating to the breach
- Effects of the breach
- Remedial action taken
- Documentation for supervisory authority review
9. Audits and Compliance
AUDIT RIGHTS:
The Data Controller has the right to:
- Audit Gene Matrix's compliance with this DPA
- Request information about processing activities
- Review security measures and procedures
- Inspect facilities and systems (with reasonable notice)
- Engage third‑party auditors
AUDIT PROCEDURES:
Frequency:
- Annual audits as standard
- Additional audits upon reasonable request
- Immediate audits in case of suspected breach
Notice:
- Minimum 30 days' notice for routine audits
- Shorter notice for cause‑based audits
- Immediate access in emergency situations
Scope:
- Review of technical and organizational measures
- Examination of security controls
- Assessment of sub‑processor compliance
- Review of incident response procedures
- Verification of data handling practices
AUDIT REPORTS:
Gene Matrix shall:
- Provide existing audit reports and certifications
- Share SOC 2 Type II reports
- Provide ISO 27001 certificates
- Share penetration testing results (redacted as necessary)
- Provide compliance documentation
COOPERATION:
During audits, Gene Matrix shall:
- Provide reasonable access to facilities and systems
- Make personnel available for interviews
- Provide requested documentation
- Respond to findings and recommendations
- Implement agreed‑upon improvements
CONFIDENTIALITY:
Auditors must:
- Sign confidentiality agreements
- Limit access to necessary information only
- Protect Gene Matrix's confidential information
- Use information solely for audit purposes
COSTS:
- Routine annual audits: No charge to Data Controller
- Additional audits: Reasonable costs may apply
- Audits for cause: Gene Matrix bears costs if non‑compliance found
REMEDIATION:
If audits identify non‑compliance:
- Gene Matrix shall provide remediation plan within 15 days
- Implement corrections within agreed timeframe
- Provide evidence of remediation
- Submit to follow‑up verification
10. Data Return and Deletion
UPON TERMINATION OR EXPIRY:
At the end of the provision of services, Gene Matrix shall, at the Data Controller's choice:
Option 1: Return of Data
Gene Matrix shall:
- Return all personal data to the Data Controller
- Provide data in commonly used, machine‑readable format
- Include all copies and backups
- Provide data within 30 days of request
- Certify completion of data return
Option 2: Deletion of Data
Gene Matrix shall:
- Securely delete all personal data
- Delete all copies and backups
- Use secure deletion methods (overwriting, degaussing, physical destruction)
- Provide certification of deletion
- Complete deletion within 60 days
EXCEPTIONS:
Gene Matrix may retain personal data to the extent:
- Required by applicable law or regulation
- Necessary for legal claims or defense
- Required for regulatory compliance (e.g., CLIA retention requirements)
- Stored in backup systems (to be deleted in normal course)
RETENTION REQUIREMENTS:
Certain data must be retained for legal compliance:
- Test results: Minimum 10 years (CLIA requirement)
- Quality control records: 2 years
- Audit logs: 7 years
- Consent records: Duration of processing + 7 years
DELETION METHODS:
Electronic Data:
- Cryptographic erasure (destruction of encryption keys)
- Secure overwriting (DoD 5220.22‑M standard)
- Physical destruction of storage media
Physical Samples:
- Incineration or chemical destruction
- Documented chain of custody
- Certificate of destruction
VERIFICATION:
Gene Matrix shall provide:
- Written certification of deletion/return
- Details of data categories processed
- Confirmation of sub‑processor compliance
- Audit trail of deletion activities
DATA CONTROLLER RESPONSIBILITIES:
The Data Controller shall:
- Specify preference for return or deletion
- Provide instructions within reasonable timeframe
- Acknowledge receipt of returned data
- Confirm satisfaction with deletion certification
11. Liability and Indemnification
LIABILITY FOR DATA PROTECTION VIOLATIONS:
Joint and Several Liability:
Under GDPR and similar laws:
- Both parties may be held liable for data protection violations
- Data subjects may seek compensation from either party
- Parties are jointly and severally liable for damages
ALLOCATION OF LIABILITY:
Gene Matrix is liable for:
- Violations of data processor obligations under this DPA
- Unauthorized processing or disclosure of personal data
- Failure to implement adequate security measures
- Non‑compliance with Data Controller's lawful instructions
- Breaches caused by sub‑processors
Data Controller is liable for:
- Violations of data controller obligations
- Unlawful processing instructions
- Failure to obtain necessary consents
- Non‑compliance with data subject rights
- Violations of data protection laws in their capacity as controller
INDEMNIFICATION:
Gene Matrix shall indemnify the Data Controller for:
- Claims arising from Gene Matrix's breach of this DPA
- Fines or penalties imposed due to Gene Matrix's non‑compliance
- Costs of responding to breaches caused by Gene Matrix
- Legal fees and expenses related to Gene Matrix's violations
Data Controller shall indemnify Gene Matrix for:
- Claims arising from Data Controller's unlawful instructions
- Fines or penalties due to Data Controller's non‑compliance
- Claims related to Data Controller's failure to obtain consents
- Legal fees related to Data Controller's violations
LIMITATION OF LIABILITY:
Subject to applicable law:
- Liability for data protection violations is not capped
- Liability for other breaches is subject to Terms of Service limitations
- Neither party is liable for indirect or consequential damages (except as required by law)
- Force majeure events may excuse performance
INSURANCE:
Gene Matrix maintains:
- Cyber liability insurance
- Professional liability insurance
- General liability insurance
- Coverage amounts appropriate to risk
COOPERATION IN DEFENSE:
Parties shall:
- Notify each other promptly of claims
- Cooperate in defense of claims
- Not settle claims without other party's consent
- Share information necessary for defense
12. Term and Termination
TERM:
This DPA:
- Becomes effective upon first use of Gene Matrix services
- Remains in effect for the duration of the service agreement
- Survives termination for obligations that continue (e.g., data deletion, confidentiality)
TERMINATION:
This DPA may be terminated:
By Either Party:
- Upon termination of the underlying service agreement
- By mutual written agreement
- As required by law
By Data Controller:
- For material breach by Gene Matrix (with 30 days' cure period)
- If Gene Matrix engages unauthorized sub‑processors
- If Gene Matrix fails to comply with data protection laws
- Immediately for gross negligence or willful misconduct
By Gene Matrix:
- For material breach by Data Controller (with 30 days' cure period)
- If Data Controller provides unlawful processing instructions
- For non‑payment (subject to service agreement terms)
EFFECTS OF TERMINATION:
Upon termination:
- Gene Matrix shall cease all processing of personal data
- Data return or deletion procedures shall commence
- Sub‑processors shall be notified and instructed accordingly
- Final accounting and documentation shall be provided
- Confidentiality obligations continue indefinitely
SURVIVAL:
The following provisions survive termination:
- Confidentiality obligations
- Data return and deletion obligations
- Liability and indemnification
- Audit rights (for reasonable period)
- Dispute resolution procedures
TRANSITION ASSISTANCE:
Upon termination, Gene Matrix shall:
- Provide reasonable transition assistance
- Cooperate in data migration
- Provide necessary documentation
- Respond to reasonable inquiries
- Assist in continuity of services (if requested)
FINAL CERTIFICATION:
Within 60 days of termination, Gene Matrix shall provide:
- Certification of data deletion or return
- Final processing activity report
- Confirmation of sub‑processor compliance
- Final security incident report (if any)
13. General Provisions
GOVERNING LAW:
This DPA is governed by:
- The laws of the State of California, United States
- Applicable data protection laws (GDPR, HIPAA, CCPA, etc.)
- In case of conflict, data protection laws prevail
DISPUTE RESOLUTION:
Informal Resolution:
- Parties shall attempt to resolve disputes amicably
- Escalation to senior management
- Good faith negotiation period of 30 days
Mediation:
- If informal resolution fails, parties may agree to mediation
- Mediation conducted by mutually agreed mediator
- Costs shared equally
Arbitration:
- Disputes may be submitted to binding arbitration
- Arbitration conducted under AAA Commercial Rules
- Seat of arbitration: San Francisco, California
- Exception: Data protection authority complaints
Supervisory Authority:
- Data subjects may lodge complaints with supervisory authorities
- Parties shall cooperate with supervisory authority investigations
- Supervisory authority decisions are binding
AMENDMENTS:
This DPA may be amended:
- By mutual written agreement
- To comply with changes in data protection laws
- To reflect changes in processing activities
- With reasonable notice to Data Controller
SEVERABILITY:
- If any provision is invalid, it shall be modified to be valid
- If modification is not possible, the provision is severed
- Remaining provisions remain in full effect
ENTIRE AGREEMENT:
This DPA, together with:
- Terms of Service
- Privacy Policy
- Service Level Agreement
- Other referenced policies
Constitutes the entire agreement regarding data processing.
NOTICES:
All notices under this DPA shall be:
- In writing
- Sent to designated contacts
- Delivered by email or certified mail
- Deemed received upon delivery confirmation
LANGUAGE:
- This DPA is executed in English
- English version prevails in case of translation conflicts
COUNTERPARTS:
- This DPA may be executed in counterparts
- Electronic signatures are valid and binding
CONTACT INFORMATION:
For Data Protection Matters:
Gene Matrix LLC
Data Protection Officer
Email: dpo@genematrix.io
Phone: 1-800-GENE-MTX ext. 701
Address: 123 Genomics Way, San Francisco, CA 94105
For Legal Matters:
Gene Matrix LLC
Legal Department
Email: legal@genematrix.io
Phone: 1-800-GENE-MTX ext. 700
Questions about this agreement?
For questions about this Data Processing Agreement or our data processing practices, contact our privacy team.