Data Processing Addendum (DPA)
Effective date: 01-Mar-2026 Last updated: 01-Mar-2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Agreement") between Panacea Technology Pte. Ltd. ("Processor", "Panacea") and the Customer identified in the Agreement ("Controller", "Customer"). It applies where Panacea processes Personal Data on behalf of Customer in connection with the Service.
In case of conflict between the Agreement and this DPA regarding Personal Data, this DPA prevails.
1. Definitions
Terms used but not defined here (including "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor", "Personal Data Breach") have the meanings given in the EU/UK GDPR. "Applicable Data Protection Law" means the EU GDPR, UK GDPR, Singapore PDPA, CCPA/CPRA, and any other privacy or data protection laws applicable to Panacea's processing of Customer Personal Data.
2. Roles and scope
2.1 Customer is the Controller (or Processor acting on behalf of its own controller) of Customer Personal Data. Panacea is the Processor. 2.2 Panacea processes Customer Personal Data only to provide the Service under the Agreement and on Customer's documented instructions, including this DPA and Customer's configuration of the Service. 2.3 Panacea will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
3. Details of processing (Annex 1)
- Subject matter: Provision of the Service (pitch deck ingestion, extraction, enrichment, verification, analysis, sharing).
- Duration: Term of the Agreement plus any post-termination period for return or deletion of Customer Data.
- Nature and purpose: Hosting, structured-data extraction, enrichment against public sources, fact-checking, strategic analysis, collaboration and sharing.
- Categories of Data Subjects: Customer's authorized users; individuals named in pitch decks (founders, employees, advisors, customers).
- Categories of Personal Data: Identification and contact data (name, email), professional data (role, bio, employer), business contact data, content of uploaded documents, account and usage metadata.
- Sensitive data: None expected. Customer must not upload special-category data unless separately agreed.
4. Confidentiality
Panacea ensures that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.
5. Security measures (Annex 2)
Panacea implements technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and at rest at storage/database providers.
- Tenant isolation enforced at the application and database layers.
- Authentication via Auth0; role-based access control (owner / admin / analyst / viewer).
- Signed, short-lived tokens for unauthenticated share-links (HMAC; 15-minute TTL).
- Least-privilege access for personnel; audit logging.
- Routine backups and recovery procedures at infrastructure providers.
- Vulnerability management and dependency monitoring.
- Incident response process with defined roles and notification paths.
Measures may evolve; Panacea will not materially decrease the overall level of security during the term.
6. Sub-processors
6.1 Customer authorizes Panacea to engage Sub-processors to provide the Service. The current Sub-processors are listed in the Privacy Policy (PRIVACY.md, §6).
6.2 Panacea will impose data protection terms on each Sub-processor no less protective than this DPA and remains liable for their acts and omissions.
6.3 Panacea will provide notice of new or replacement Sub-processors (e.g., by updating the Privacy Policy and notifying account admins). Customer may object within 30 days on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer's exclusive remedy is to terminate the affected portion of the Service.
7. Data subject rights
Panacea will, to the extent legally permitted, promptly notify Customer of any request received directly from a Data Subject relating to Customer Personal Data, and will provide reasonable assistance (taking into account the nature of the processing) to enable Customer to respond.
8. Assistance to Controller
Panacea will provide reasonable assistance to Customer with: (a) data protection impact assessments and prior consultations; (b) security obligations; (c) breach notifications; and (d) responding to inquiries from supervisory authorities, in each case taking into account the nature of processing and information available to Panacea.
9. Personal Data Breach
Panacea will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to enable Customer to meet its own notification obligations.
10. International transfers
10.1 Where Panacea transfers Customer Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer will be governed by the EU Standard Contractual Clauses (2021/914) (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable), incorporated by reference, with the following selections: optional clauses applied where commercially reasonable; supervisory authority of the EU Member State of the data exporter; governing law of Ireland; courts of Ireland. 10.2 The UK International Data Transfer Addendum (IDTA) applies for UK transfers. 10.3 For Singapore-originating data, Panacea ensures recipients are bound to a standard of protection comparable to that required by PDPA s.26.
11. Return and deletion
On termination or expiration of the Agreement, Panacea will, at Customer's option, return or delete Customer Personal Data, except to the extent retention is required by law. Backups containing Customer Personal Data will be overwritten in the ordinary course.
12. Audits
12.1 Panacea will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including current certifications and audit summaries of its infrastructure providers where available. 12.2 Customer may, no more than once per 12 months and on at least 30 days' written notice, conduct an audit (itself or via an independent auditor bound to confidentiality) of Panacea's compliance with this DPA, during normal business hours and without disrupting the Service. Audit costs are borne by Customer unless material non-compliance is found.
13. CCPA addendum
Where Customer is a "business" and Panacea is a "service provider" under CCPA/CPRA, Panacea will: (a) process Personal Information only for the business purposes specified in the Agreement; (b) not sell or share Personal Information; (c) not retain, use, or disclose Personal Information outside the direct business relationship or for any "commercial purpose" other than providing the Service; and (d) notify Customer if it determines it can no longer meet these obligations.
14. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Agreement.
15. Order of precedence
In the event of any conflict, the order of precedence is: (1) the EU SCCs / UK IDTA, (2) this DPA, (3) the Privacy Policy, (4) the Agreement.
16. Signatures
This DPA is incorporated into and forms part of the Agreement and does not require a separate signature; acceptance of the Agreement constitutes acceptance of this DPA. A signed counterpart will be provided on request to Customer's authorized representative.
Panacea Technology Pte. Ltd. Email: [email protected] Registered address: #15-1282, 209A, Punggol Place, Singapore 821209
Email aliases on the aevumis.com domain are operated by Panacea Technology Pte. Ltd.