TrialCurrent.
TrialCurrent

Data Processing Agreement

Effective as of the effective date of the applicable TrialCurrent services agreement

This Data Processing Agreement ("DPA") forms part of the agreement for TrialCurrent services between Greenlight Advisory LLC, a Wyoming limited liability company doing business as TrialCurrent ("TrialCurrent" or "Processor"), and the customer identified in that agreement ("Customer" or "Controller"). It applies when TrialCurrent processes personal data on Customer's behalf.

TrialCurrent is not designed for patient health information, ePHI, or special-category personal data. Customer will not submit that information to the service unless the parties first agree in writing to the required safeguards.

1. Subject matter and duration

This DPA governs TrialCurrent's processing of Customer Personal Data to provide the services described in the Agreement. It begins on the Agreement's effective date and continues until TrialCurrent no longer processes Customer Personal Data. Provisions that are intended by their nature to survive will remain in effect.

2. Definitions

3. Processing terms

4. Subprocessing

Customer authorizes the Subprocessors listed in Attachment 2. TrialCurrent will require each Subprocessor to protect Customer Personal Data under written terms appropriate to the services it provides. TrialCurrent will post its current Subprocessor list on its Security & Data Practices page and will notify affected Customer account administrators of a material addition or replacement. Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith to resolve the concern. If they cannot, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused terminated period. TrialCurrent remains responsible for its Subprocessors to the extent required by law.

5. International transfers

TrialCurrent is based in the United States and primarily processes Customer Personal Data in the United States. If applicable law requires a transfer mechanism for data originating in the EEA, United Kingdom, or Switzerland, the applicable 2021 EU Standard Contractual Clauses, UK Addendum, or Swiss modifications are incorporated to the extent required and control over conflicting terms in this DPA.

6. Confidentiality and security

People authorized to process Customer Personal Data are bound by confidentiality. TrialCurrent maintains technical and organizational measures appropriate to the nature of the service, including encryption in transit and infrastructure-level encryption at rest, server-side tenant access checks, role-based access, multi-factor authentication for administrative production accounts, restricted production access, scheduled database backups, and scoped time-limited links for external questionnaire participants. Current practices are described on TrialCurrent's Security & Data Practices page. If a lawful government request seeks Customer Personal Data, TrialCurrent will notify Customer unless prohibited and will disclose only what it is legally required to provide.

7. Security incidents

TrialCurrent will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. As information becomes available, the notice will describe the known nature and scope of the incident, affected data, mitigation measures, and a contact point. TrialCurrent will reasonably cooperate with Customer's legally required notifications. Notice is not an admission of fault or liability.

8. Audits

On written request no more than once per year (or as required by a regulator), TrialCurrent will demonstrate compliance with this DPA by completing Customer's reasonable security questionnaire and providing relevant documentation, including its current security practices and subprocessor terms. Where Data Protection Laws require more, Customer may conduct (directly or through an independent auditor bound to confidentiality) an audit on at least 30 days' notice, during business hours, no more than once per year, at Customer's expense and without disrupting the service. TrialCurrent will address material findings in good faith.

9. Return and deletion

On termination or expiration of the Agreement, TrialCurrent will make Customer Data available for export on request and will delete Customer Personal Data from active systems within 30 days, unless law requires retention or the parties agree otherwise in writing. Copies in standard backup rotation will remain protected under this DPA and will be deleted through the ordinary backup lifecycle. TrialCurrent will provide written confirmation of deletion upon reasonable request.

10. Liability

The liability terms of the Agreement apply to this DPA. Nothing in this DPA limits a data subject's rights or any liability that cannot be limited under Data Protection Laws.

11. General

This DPA is governed by the same law as the Agreement, except where applicable Data Protection Laws or incorporated transfer terms require otherwise. If any provision is unenforceable, the remainder remains in effect.

Privacy contact: John S. Sprankle, Founder, privacy@trialcurrent.com. Notices may also be sent to Greenlight Advisory LLC, 6515 Heather Way, West Palm Beach, FL 33406.

Attachment 1 — Details of processing

ItemDescription
Subject matterProvision of the TrialCurrent clinical research sales and operations platform
DurationThe Agreement term plus the deletion period in Section 9
Nature and purposeHosting, storage, display, security, support, scheduled backups, AI-assisted extraction and drafting for Customer's records, and transmission of Customer-approved outreach through Customer-connected services
Categories of personal dataProfessional business contact data, including names, titles, work email addresses, and work telephone numbers; Customer user account and service-log data; and professional references contained in Customer-uploaded notes and documents. Patient data, health information, ePHI, and special-category personal data are excluded.
Categories of data subjectsCustomer's employees and authorized users; business contacts at sponsors, CROs, research sites, and vendors; individuals referenced professionally in Customer's records
Processing locationsPrimarily the United States, subject to the infrastructure and processing locations of the listed Subprocessors

Attachment 2 — Subprocessors

SubprocessorPurposeLocation
Vercel Inc.Application hostingUnited States and other locations documented by Vercel
Supabase Inc.Database and file storageCustomer-selected U.S. hosting region
Anthropic PBCAI-assisted extraction and drafting; commercial API inputs and outputs are not used for model training by defaultUnited States

The Discover market-intelligence feed uses public-source business information and does not receive Customer workspace data. On that basis, it is not listed as a Subprocessor of Customer Personal Data.