Data Processing Addendum
Last updated: 24 July 2026
1. Purpose and scope
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”, “Controller”) and the Operator of EUDAbridge (“Operator”, “Processor”). It applies whenever Customer’s use of the Service involves the processing of personal data for which Customer acts as controller under Regulation (EU) 2016/679 (“GDPR”) — for example, the name and contact details of a Person Responsible for Regulatory Compliance (PRRC), an authorised representative, or another individual referenced in uploaded device or actor data. It does not apply to Operator’s processing of Customer’s own account data (users, billing contacts), for which Operator acts as controller as described in the Privacy Policy.
2. Subject matter and duration
Subject matter: processing of personal data contained in the workbooks and files Customer uploads to the Service, and in the XML files generated from them. Duration: for as long as Customer maintains an active account, plus the retention period described in Section 8.
3. Nature and purpose of processing
Storage, validation, transformation and generation of EUDAMED-format XML files from Customer-supplied data, and related technical support.
4. Categories of data subjects
Individuals whose details may appear in Customer’s device or actor data, such as Persons Responsible for Regulatory Compliance (PRRC), authorised representatives, and other contacts named in manufacturer or device records.
5. Types of personal data
Name, business email address, business phone number, job title or role, and other business-contact fields present in EUDAMED actor or device records, as included by Customer in the data it uploads. Operator does not request special categories of data (Art. 9 GDPR) and Customer shall not submit such data through the Service.
6. Processor obligations
Operator shall:
- process personal data only on Customer’s documented instructions, including as necessary to provide the Service, unless required to do otherwise by EU or Member State law;
- ensure that personnel authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures under Art. 32 GDPR, including encryption in transit, access controls, and hosting within the EU;
- not engage a new sub-processor without providing prior notice to Customer, allowing Customer to object on reasonable grounds;
- assist Customer, insofar as reasonably possible, in responding to data subject requests and in complying with Art. 32–36 GDPR;
- notify Customer without undue delay after becoming aware of a personal data breach concerning Customer’s data;
- at Customer’s choice, delete or return all personal data at the end of the provision of services, subject to the retention period in Section 8;
- make available information reasonably necessary to demonstrate compliance with this DPA.
7. Sub-processors
Operator currently uses the following sub-processors:
- Render — application hosting and database — Frankfurt, Germany (EU).
- Brevo (Sendinblue SAS) — transactional email delivery — France (EU).
Operator will notify Customer of any change to this list at least thirty (30) days in advance, during which Customer may object on reasonable data-protection grounds.
8. Retention and deletion
Personal data covered by this DPA is retained for as long as Customer’s account is active and for thirty (30) days after termination, then deleted, consistent with Section 10 of the Terms of Service, except where longer retention is required by law.
9. International transfers
Operator does not transfer personal data outside the European Economic Area. If this changes, Operator will first implement a valid transfer mechanism (such as the EU Standard Contractual Clauses) before doing so.
10. Liability
Liability under this DPA is subject to the limitation of liability set out in Section 9 of the Terms of Service.
11. Precedence and signature
This DPA is incorporated into and forms part of the Terms of Service for all customers, without requiring a separate signature, to the extent it is relevant to Customer’s use of the Service. Organisations that require a countersigned copy for their own compliance records may request one through the in-app Support inbox.
See also the Terms of Service and the Privacy Policy.