Candidate for legal review

Data Processing Agreement

Version 1.0 · Effective: 14 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement under which Helena Bioinformatics EOOD provides the Service to the customer identified in an order, registration record or other written agreement (“Controller”). Helena is the “Processor”.

This DPA applies only where Helena processes personal data on behalf of the Controller. It must be accepted or signed by a person authorized to bind the Controller. It does not apply merely because a person creates an Individual or Distributor profile.

1. Definitions and interpretation

“Controller Data” means personal data processed by Helena on behalf of the Controller under the Service. “Data Protection Law” means the GDPR, applicable Bulgarian data-protection law and other binding law applicable to the processing. “Subprocessor”, “personal data breach”, “processing”, “controller”, “processor” and “data subject” have the meanings in Data Protection Law.

If this DPA conflicts with the main service agreement on data-protection matters, this DPA prevails. An order may specify additional safeguards but may not reduce mandatory protections.

2. Details and duration of processing

The subject matter, nature, purpose, data categories, data subjects and processing operations are described in Annex 1. Processing continues for the term of the Service and any limited return, deletion, backup-expiry or legal-retention period.

The Controller instructs Helena to process Controller Data as necessary to provide, secure, support and maintain the contracted Service; follow documented product configuration and support requests; and comply with this DPA and applicable law.

3. Controller obligations

The Controller determines the purposes and means of processing and is responsible for lawful instructions, transparency, Article 6 and Article 9 legal bases, data-subject rights, data accuracy and minimization. It must ensure that persons submitting data are authorized and that direct identifiers are not uploaded unless expressly agreed.

The Controller must not instruct Helena to process data unlawfully or outside the agreed Service. It must maintain reasonable account security, assign appropriate roles and notify Helena of relevant restrictions, requests and incidents without undue delay.

4. Processor obligations and instructions

Helena will process Controller Data only on documented instructions, including for international transfers, unless Union or Member State law requires processing. In that case Helena will inform the Controller before processing unless the law prohibits notice on important public-interest grounds.

Helena will immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Law and may suspend the affected processing until the instruction is amended or confirmed. Helena will ensure authorized personnel are bound by confidentiality and access data only as necessary.

5. Security of processing

Helena will implement and maintain appropriate technical and organizational measures taking account of the state of the art, implementation cost, scope, context and risk, including the risk presented by genetic and health data. Current measures are described in Annex 2.

Helena may update measures as technology and risk evolve, provided the overall level of protection is not materially reduced. The Controller acknowledges that security is a shared responsibility and will use available configuration and access controls appropriately.

6. Subprocessors

The Controller gives general written authorization for the subprocessors listed in Annex 3. Helena will impose data-protection obligations providing substantially equivalent protection and remains responsible for their performance to the extent required by Article 28 GDPR.

Helena will give at least 30 days’ prior notice of an intended addition or replacement that will process Controller Data. The Controller may object on reasonable documented data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate only the affected Service without penalty for the unused affected period.

A provider used only for public websites, ordinary business administration or payment processing is not a subprocessor under this DPA unless it receives Controller Data.

7. International transfers

Helena will host private genomic processing in the EEA unless the order expressly states otherwise. Helena will not transfer Controller Data outside the EEA without documented Controller authorization and a lawful Chapter V GDPR mechanism.

Where required, the parties incorporate the applicable European Commission Standard Contractual Clauses and supplementary measures. Helena will provide information reasonably required for the Controller’s transfer assessment.

8. Data-subject requests

Taking account of the nature of processing, Helena will provide reasonable technical and organizational assistance for the Controller to respond to requests under Chapter III GDPR. Helena will not respond substantively on the Controller’s behalf unless instructed or legally required.

If Helena receives a request relating to Controller Data, it will forward it to the Controller without undue delay where the requester and Controller can reasonably be identified.

9. Compliance assistance

Taking account of the nature of processing and information available, Helena will assist the Controller with Articles 32–36 GDPR, including security, breach assessment, data-protection impact assessments and prior consultation. Extraordinary assistance outside normal Service operation may be charged at an agreed reasonable rate unless caused by Helena’s breach.

10. Personal-data breaches

Helena will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Data and, where practicable, within 24 hours. The notice will provide available information about the nature, likely consequences, affected categories and approximate numbers, contact point and mitigation. Information may be supplied in phases.

Notification is not an admission of fault. The Controller is responsible for notifications to supervisory authorities and data subjects, and Helena will reasonably assist.

11. Audit and information rights

Helena will make available information reasonably necessary to demonstrate Article 28 compliance. The Controller should first use current security documentation, certifications and independent reports made available by Helena.

If that information is insufficient, the Controller may conduct one audit per year on at least 30 days’ notice, during normal business hours, through a qualified independent auditor bound by confidentiality. Additional audits are permitted after a material breach or where a supervisory authority requires them. Audits must avoid access to other customers’ data, disruption and security compromise.

12. Return and deletion

At the Controller’s choice, Helena will return or delete Controller Data after the Service ends, unless law requires retention. The Controller must communicate its choice before termination or within the period stated in the order; otherwise Helena may delete according to the documented retention schedule.

Deletion applies to active systems and derived analysis results in scope. Backup copies are isolated from ordinary use and expire through the backup lifecycle unless restoration is required for disaster recovery, in which case deletion restrictions are reapplied. Helena will provide reasonable deletion confirmation on request.

13. Government and third-party requests

Unless prohibited by law, Helena will notify the Controller of a binding request for Controller Data and will challenge requests it reasonably considers unlawful or disproportionate. Helena will disclose only the minimum legally required data.

14. Liability and term

This DPA begins when the main agreement becomes effective or an authorized representative accepts it and remains in force while Helena processes Controller Data. Liability is governed by the main agreement, subject to liabilities and data-subject rights that cannot be limited under Data Protection Law.

15. Governing law and changes

This DPA is governed by Bulgarian law and directly applicable European Union law. Competent courts in Sofia have jurisdiction unless mandatory law provides otherwise.

Helena may update this standard DPA to reflect law or Service changes. A material reduction of protection requires notice and, where required, renewed agreement. Each version is preserved by version, language, effective date and content digest.

Annex 1 — Processing details

Subject matter and purpose: provision of genomic and biomedical analysis, evidence retrieval, prioritization, reporting, collaboration, support, security and related contracted functions.

Operations: receipt, validation, storage, organization, parsing, annotation, comparison, classification support, querying, retrieval, generation, display, transmission to authorized users, backup, security logging, return and deletion.

Data subjects: patients and relatives whose data is submitted by the Controller; authorized users; and other persons included in Controller Data under documented instructions.

Data categories: pseudonymized sample identifiers; genetic variant and sequence-derived data; phenotype and health information; family relationships; clinical annotations; analysis parameters and results; reports; provenance; and access metadata. Direct identifiers are excluded unless specifically agreed.

Special categories: genetic and health data under Article 9 GDPR. Frequency: as initiated by authorized users or configured workflows. Duration: the Service term plus the return, deletion, backup-expiry and legally required periods.

Annex 2 — Technical and organizational measures

Governance and people: documented access responsibilities, confidentiality obligations, least privilege, administrator controls, security and privacy review, incident response and change management.

Identity and access: individual accounts, password hashing, role-based authorization, expiring sessions or tokens, privileged-access restrictions and auditable administrative actions. Multi-factor authentication is applied where configured and required by the applicable access policy.

Infrastructure and communications: EEA-based private processing infrastructure, network filtering and service isolation, encrypted transport using current secure protocols, managed secrets and restricted administrative access.

Data protection: pseudonymization requirements, minimization, separation between public and private AI paths, controlled storage, backup and recovery processes, retention configuration and deletion procedures. Encryption at rest is applied where supported and configured for the relevant storage layer; Helena does not represent that a single algorithm protects every medium.

Assurance and continuity: security logging, monitoring, vulnerability and dependency management, tested deployment and migration procedures, backup validation, incident escalation and periodic control review. Exact retention periods and recovery objectives are those documented for the contracted configuration.

Annex 3 — Authorized subprocessors

Hetzner Online GmbH, Germany / Finland infrastructure region — dedicated server, network and storage infrastructure for private Service processing in the EEA.

No public website, analytics, ordinary email, payment or public-AI provider is authorized by this Annex to receive private Controller Data. If a contracted feature requires another provider, Helena must add it through the notice and authorization process in Section 6 before that provider receives Controller Data.

16. Execution and contact

Electronic acceptance by the Controller’s authorized laboratory representative, tied to the exact version and digest in Helena’s legal registry, constitutes written execution where permitted by law. Helena records the accepting user, organization, time, source and document digest.

Data-protection notices under this DPA should be sent to privacy@helena.bio. Operational security incidents should also be sent to security@helena.bio.

Helena Bioinformatics EOOD · UIC 208673837

14 Tsar Ivan Asen II Street, floor 1, apartment 1, 1142 Sofia, Bulgaria

legal@helena.bio · privacy@helena.bio