This Data Processing Agreement ("DPA") forms part of the agreement for TrialCurrent services between Greenlight Advisory LLC, a Wyoming limited liability company doing business as TrialCurrent ("TrialCurrent" or "Processor"), and the customer identified in that agreement ("Customer" or "Controller"). It applies when TrialCurrent processes personal data on Customer's behalf.
1. Subject matter and duration
This DPA governs TrialCurrent's processing of Customer Personal Data to provide the services described in the Agreement. It begins on the Agreement's effective date and continues until TrialCurrent no longer processes Customer Personal Data. Provisions that are intended by their nature to survive will remain in effect.
2. Definitions
- "Customer Personal Data" — personal data contained in Customer Data that TrialCurrent processes on Customer's behalf (see Attachment 1).
- "Data Protection Laws" — data protection and privacy laws applicable to a party's processing under this DPA, which may include U.S. state privacy laws (e.g., CCPA/CPRA) and, where applicable, the EU and UK GDPR.
- "Security Incident" — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Subprocessor" — a third party engaged by TrialCurrent to process Customer Personal Data (Attachment 2).
- Other terms ("processing," "controller," "processor," "data subject") carry the meanings in applicable Data Protection Laws.
3. Processing terms
- Instructions. TrialCurrent processes Customer Personal Data only on Customer's documented instructions — the Agreement, this DPA, and Customer's use of the service's features constitute those instructions — unless required otherwise by law, in which case TrialCurrent notifies Customer unless legally prohibited.
- Excluded data. TrialCurrent is not designed for patient health information, electronic protected health information, or special-category personal data. Customer will not submit that information to the service unless the parties first agree in writing to the required safeguards.
- Compliance and accuracy. Each party complies with its own obligations under Data Protection Laws. Customer is responsible for the accuracy and lawful basis of the Customer Personal Data it submits.
- No sale or sharing. TrialCurrent does not "sell" or "share" Customer Personal Data as those terms are defined in U.S. state privacy laws, and processes it only as a service provider/processor.
- AI processing. TrialCurrent may send limited Customer Personal Data to its commercial AI provider when a Customer user invokes an AI-assisted feature. The provider does not use API inputs or outputs to train its generative models unless TrialCurrent expressly opts in. TrialCurrent does not opt in on Customer's behalf.
- Data subject requests. TrialCurrent provides reasonable assistance (at Customer's reasonable expense for extraordinary efforts) with data subject requests, and forwards to Customer any request it receives directly concerning Customer Personal Data.
- Aggregated data. TrialCurrent may process aggregated, de-identified data that does not identify Customer or any person, to maintain and improve the service.
- Assistance. TrialCurrent reasonably assists Customer with data protection impact assessments and regulator consultations where required and relevant to the service.
4. Subprocessing
Customer authorizes the Subprocessors listed in Attachment 2. TrialCurrent will require each Subprocessor to protect Customer Personal Data under written terms appropriate to the services it provides. TrialCurrent will post its current Subprocessor list on its Security & Data Practices page and will notify affected Customer account administrators of a material addition or replacement. Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith to resolve the concern. If they cannot, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused terminated period. TrialCurrent remains responsible for its Subprocessors to the extent required by law.
5. International transfers
TrialCurrent is based in the United States and primarily processes Customer Personal Data in the United States. If applicable law requires a transfer mechanism for data originating in the EEA, United Kingdom, or Switzerland, the applicable 2021 EU Standard Contractual Clauses, UK Addendum, or Swiss modifications are incorporated to the extent required and control over conflicting terms in this DPA.
6. Confidentiality and security
People authorized to process Customer Personal Data are bound by confidentiality. TrialCurrent maintains technical and organizational measures appropriate to the nature of the service, including encryption in transit and infrastructure-level encryption at rest, server-side tenant access checks, role-based access, multi-factor authentication for administrative production accounts, restricted production access, scheduled database backups, and scoped time-limited links for external questionnaire participants. Current practices are described on TrialCurrent's Security & Data Practices page. If a lawful government request seeks Customer Personal Data, TrialCurrent will notify Customer unless prohibited and will disclose only what it is legally required to provide.
7. Security incidents
TrialCurrent will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. As information becomes available, the notice will describe the known nature and scope of the incident, affected data, mitigation measures, and a contact point. TrialCurrent will reasonably cooperate with Customer's legally required notifications. Notice is not an admission of fault or liability.
8. Audits
On written request no more than once per year (or as required by a regulator), TrialCurrent will demonstrate compliance with this DPA by completing Customer's reasonable security questionnaire and providing relevant documentation, including its current security practices and subprocessor terms. Where Data Protection Laws require more, Customer may conduct (directly or through an independent auditor bound to confidentiality) an audit on at least 30 days' notice, during business hours, no more than once per year, at Customer's expense and without disrupting the service. TrialCurrent will address material findings in good faith.
9. Return and deletion
On termination or expiration of the Agreement, TrialCurrent will make Customer Data available for export on request and will delete Customer Personal Data from active systems within 30 days, unless law requires retention or the parties agree otherwise in writing. Copies in standard backup rotation will remain protected under this DPA and will be deleted through the ordinary backup lifecycle. TrialCurrent will provide written confirmation of deletion upon reasonable request.
10. Liability
The liability terms of the Agreement apply to this DPA. Nothing in this DPA limits a data subject's rights or any liability that cannot be limited under Data Protection Laws.
11. General
This DPA is governed by the same law as the Agreement, except where applicable Data Protection Laws or incorporated transfer terms require otherwise. If any provision is unenforceable, the remainder remains in effect.
Privacy contact: John S. Sprankle, Founder, privacy@trialcurrent.com. Notices may also be sent to Greenlight Advisory LLC, 6515 Heather Way, West Palm Beach, FL 33406.
Attachment 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the TrialCurrent clinical research sales and operations platform |
| Duration | The Agreement term plus the deletion period in Section 9 |
| Nature and purpose | Hosting, storage, display, security, support, scheduled backups, AI-assisted extraction and drafting for Customer's records, and transmission of Customer-approved outreach through Customer-connected services |
| Categories of personal data | Professional business contact data, including names, titles, work email addresses, and work telephone numbers; Customer user account and service-log data; and professional references contained in Customer-uploaded notes and documents. Patient data, health information, ePHI, and special-category personal data are excluded. |
| Categories of data subjects | Customer's employees and authorized users; business contacts at sponsors, CROs, research sites, and vendors; individuals referenced professionally in Customer's records |
| Processing locations | Primarily the United States, subject to the infrastructure and processing locations of the listed Subprocessors |
Attachment 2 — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting | United States and other locations documented by Vercel |
| Supabase Inc. | Database and file storage | Customer-selected U.S. hosting region |
| Anthropic PBC | AI-assisted extraction and drafting; commercial API inputs and outputs are not used for model training by default | United States |
The Discover market-intelligence feed uses public-source business information and does not receive Customer workspace data. On that basis, it is not listed as a Subprocessor of Customer Personal Data.
