QuestOmics

Data processing agreement

Processing your study data on your instructions

This agreement covers the personal data we process on your behalf under Article 28 of the GDPR. It sits alongside our Terms and Privacy Policy, and prevails over both for anything concerning that processing.

Version 2026-07-23-draft · July 2026

This is a draft

This text is published for review and is not yet offered for signature. If you need an executed data processing agreement, write to svalenzuela@questomics.app and we will send the current signature version along with your institution's preferred clauses where we can accommodate them.

1

Parties and roles

This agreement is between Sandro Valenzuela, a sole proprietorship (eenmanszaak) established in the Netherlands and registered with the Dutch Chamber of Commerce (the “Processor”), trading as QuestOmics, and the customer that has accepted it (the “Controller”).

The Controller determines the purposes and means of processing the study data it uploads. The Processor acts only on the Controller's documented instructions.

The Processor separately acts as an independent controller for your account details, your billing records, and the operational logs we keep to run the platform. That processing is governed by the Privacy Policy, not by this agreement.

2

Subject matter, duration, nature and purpose

The Processor processes personal data in order to provide the QuestOmics platform: storing uploaded sequencing files and sample metadata, running the bioinformatic analyses the Controller selects, generating results, figures, written interpretations and manuscript material, and making all of it available in the Controller's workspace.

Processing lasts for as long as the Controller holds an account, and ends in accordance with clause 9.

3

Personal data and data subjects

Categories of data subject:the human participants of the Controller's study, and the Controller's own authorised users.

Types of personal data: sequencing reads derived from human specimens, which may contain human genetic sequence before host read removal; sample identifiers assigned by the Controller; sample metadata such as group, condition and other study variables supplied by the Controller; and the analysis results derived from all of the above.

Special categories: data concerning health and genetic data within the meaning of Article 9 may be present. The Controller is responsible for establishing a valid Article 9 condition and for obtaining participant consent or another lawful basis before uploading. The Processor does not seek to identify any participant and processes such data only as set out in this agreement.

The Controller undertakes not to upload direct identifiers such as names, contact details or national identification numbers in sample metadata, and to use pseudonymous sample identifiers.

4

Instructions

The Processor processes personal data only on the Controller's documented instructions, which comprise this agreement, the Terms, and the actions the Controller takes in the platform, including which analyses it launches and with whom it shares a project.

The Processor does not use the Controller's uploaded data or results for its own purposes, does not pool them into external datasets, does not sell them, and does not use them to train its own or any third party's models.

If the Processor believes an instruction infringes data protection law, it will inform the Controller and may suspend that instruction.

5

Confidentiality

The Processor ensures that every person authorised to process the personal data is bound by an obligation of confidentiality, and grants access only where it is necessary to operate the platform or to provide support the Controller has requested.

6

Security

The Processor implements appropriate technical and organisational measures under Article 32. The measures in force are described on the security page, which forms Annex II to this agreement and covers encryption in transit and at rest, separation between accounts, isolated execution of analyses, access control, and deletion.

The Processor may update those measures as the platform evolves, provided the level of protection is not reduced.

7

Subprocessors

The Controller gives general authorisation for the Processor to engage the subprocessors listed on the subprocessors page, which forms Annex I to this agreement and currently names 10 third-party subprocessors.

The Processor imposes on each subprocessor data protection obligations no less protective than those in this agreement, and remains fully liable to the Controller for their performance.

The Processor will give notice before adding or replacing a subprocessor to Controllers who have asked to be notified. The Controller may object on reasonable data protection grounds, in which case the parties will discuss a resolution in good faith, and the Controller may terminate the affected service if none is found.

8

Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller in responding to requests from data subjects exercising their rights. The platform lets the Controller access, export and delete the data it has uploaded directly, which will normally be the fastest route.

The Processor assists the Controller in meeting its obligations under Articles 32 to 36, including data protection impact assessments and prior consultation, taking into account the information available to it.

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides the information the Controller reasonably needs to meet its own notification duties.

9

Deletion and return

The Controller may delete files, projects and results at any time in the platform. On termination of the account, the Processor erases the projects, files and analysis outputs associated with it, including the underlying stored objects.

The Processor retains only what Union or Member State law requires it to keep, such as the record of accepted policy versions with identifying details removed, and invoices required for tax purposes.

The Controller is responsible for exporting anything it wishes to keep before deleting its account.

10

Audits and information

The Processor makes available the information necessary to demonstrate compliance with Article 28, and will respond to reasonable written questions and security questionnaires from the Controller.

Where the Controller requires an audit or inspection, the parties will agree its scope, timing and cost in advance. Audits are limited to once in any twelve month period unless a supervisory authority requires otherwise or a breach has occurred.

11

International transfers

Uploaded sequencing files, analysis results and the application database are stored and processed within the European Economic Area.

Certain ancillary services operate outside the EEA, as identified on the subprocessors page. Those transfers are made under the European Commission's Standard Contractual Clauses together with the measures described on the security page.

12

Liability, term and governing law

This agreement takes effect when the Controller accepts it or begins using the platform, whichever is earlier, and continues for as long as the Processor processes personal data on the Controller's behalf.

Liability under this agreement is subject to the limitations set out in the Terms, except where such limitation is not permitted by applicable data protection law.

This agreement is governed by the law of the Netherlands, and the courts of the Netherlands have jurisdiction, without prejudice to any right a data subject has to bring proceedings elsewhere or to lodge a complaint with Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).

Annexes

Annex I, the list of authorised subprocessors, is the subprocessors page. Annex II, the technical and organisational measures, is the security page. Both are incorporated by reference and are versioned by their last-updated date.