Data Processing Agreement

Last updated: 22.09.2026

This Data Processing Agreement ("Agreement") forms part of the agreement between:

1. Controller: The customer organization that owns or controls the data ("Controller")

2. Processor: Solu Healthcare Oy, Kalevankatu 31 A 13, FI-00100 Helsinki ("Processor")

Version 3, last updated 22.09.2026

This Agreement governs the processing of data by the Processor on behalf of the Controller, in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1. Definitions

Capitalized terms not otherwise defined shall have the meaning ascribed in the GDPR.

  • Customer Data / Company Personal Data: Microbial genomic data, related analytical results, and any personal data contained therein uploaded to the Solu Platform by the Controller or its authorized users.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Data Subject: An identified or identifiable natural person whose Personal Data is included in Customer Data.
  • Sub-processor / Contracted Processor: Any third party engaged by the Processor to process Customer Data on its behalf.
  • Data Protection Laws: GDPR and any other applicable data protection or privacy laws.
  • Standard Contractual Clauses (SCCs): The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Article 46(2)(c) GDPR.

2. Subject Matter and Purpose of Processing

2.1 The Processor shall process Customer Data solely for the purpose of providing the Solu Platform services to the Controller.

2.2 Processing includes any automated analysis, classification, and result generation performed by the Solu Platform to provide the agreed services.

2.3 The Processor may access Customer Data as necessary for operational support, customer support, troubleshooting, or security purposes, always in accordance with the Controller's instructions.

2.4 The Processor shall not process Customer Data for any other purpose, including marketing or research, unless the Controller gives a written instruction to that effect. The Controller's acceptance of the Solu Platform Terms and Conditions constitutes such an instruction in respect of the anonymised data rights set out in those Terms.

2.5 The details of the processing required by Article 28(3) GDPR are set out in Annex II.

2.6 The Processor shall not attempt to re-identify any natural person from Customer Data, nor combine Customer Data with other information for the purpose of enabling such identification, except where expressly instructed in writing by the Controller. The Processor shall impose an equivalent obligation on its personnel and Sub-processors.

2.7 The Parties acknowledge that Customer Data may incidentally contain data falling within Article 9(1) GDPR, including genetic or health data. The Processor applies the measures set out in Annex III to all Customer Data irrespective of classification.

3. Duration

This Agreement shall remain in effect for the duration of the Controller's use of the Solu Platform and any subsequent period required to comply with applicable laws. Upon termination, the Processor will return or delete Customer Data in accordance with Section 12.

4. Roles and Responsibilities

Controller responsibilities:

  • Determines the purpose and means of processing Customer Data.
  • Ensures that Customer Data is collected and shared in compliance with applicable laws.
  • Maintains a designated contact for notices under this Agreement.
  • Shall not include direct identifiers of natural persons (including names, national identification numbers, patient record numbers, or contact details) in sample identifiers, file names, or metadata fields uploaded to the Solu Platform, and shall apply pseudonymisation before upload.

Processor responsibilities:

  • Processes Customer Data only according to the Controller's documented and lawful instructions or via automated workflows.
  • Implements appropriate technical and organizational measures to protect Customer Data, as set out in Annex III.
  • Assists the Controller in responding to Data Subject requests, as far as technically possible and permitted by law.
  • Maintains confidentiality of Customer Data and ensures personnel are subject to confidentiality obligations.
  • Retains responsibility for configuring and maintaining automated workflows.
  • If the Processor becomes aware that Customer Data contains direct identifiers of natural persons, it shall notify the Controller without undue delay and shall await the Controller's instructions.

5. Instructions

5.1 The Controller acknowledges that Customer Data will be processed according to the automated workflows of the Solu Platform. Such processing is deemed to be in accordance with the Controller's instructions for the purpose of this Agreement.

5.2 Any additional processing not instructed in writing is prohibited.

5.3 The Processor shall immediately inform the Controller if, in its opinion, an instruction given by the Controller infringes the GDPR or other applicable Data Protection Laws. The Processor may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.

6. Technical and Organizational Measures

6.1 The Processor shall implement and maintain the technical and organizational measures set out in Annex III, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.

6.2 The Processor may update these measures from time to time, provided that the level of protection is not reduced.

6.3 The Processor maintains ISO 27001 certification covering the Solu Platform. A current copy of the certificate is available to the Controller on request.

7. Sub-processors

7.1 The Controller grants the Processor general authorization to engage Sub-processors for the processing of Customer Data, subject to this Section 7.

7.2 The Processor maintains an up-to-date list of Sub-processors at https://www.solugenomics.com/sub-processors. The Sub-processors engaged as at the Effective Date are set out in Annex I.

7.3 The Processor shall notify the Controller at least thirty (30) days before engaging a new Sub-processor or replacing an existing one. Notice is given by email to the Controller's designated contact and by updating the list referred to in Section 7.2. Where a change to the Sub-processor list originates with an upstream provider and the Processor receives less than thirty (30) days' notice of that change, the Processor shall notify the Controller as soon as reasonably practicable after receiving such notice, and in any event before the new Sub-processor begins processing Customer Data.

7.4 The Controller may object to a proposed Sub-processor within thirty (30) days of notice, on reasonable grounds relating to data protection. The Parties shall work in good faith to resolve the objection, including by considering alternative arrangements. If no resolution is reached within a further thirty (30) days, the Controller may terminate the affected services without penalty, with a pro-rata refund of any prepaid fees covering the terminated period.

7.5 The Processor shall impose on each Sub-processor data protection obligations no less protective than those set out in this Agreement, by way of a written contract.

7.6 The Processor remains fully liable to the Controller for the performance of each Sub-processor's data protection obligations.

7.7 In the event of any inconsistency between Annex I and the list maintained under Section 7.2, the list maintained under Section 7.2 shall prevail as the current list of Sub-processors, provided that changes have been notified in accordance with Section 7.3.

8. Data Subject Rights

8.1 The Processor shall assist the Controller in responding to Data Subject requests (access, rectification, erasure, restriction, data portability, objection), taking into account the nature of the processing and the information available to the Processor.

8.2 The Processor shall promptly notify the Controller if it receives a request from a Data Subject relating to Customer Data, and shall not respond to that request itself except on documented instructions from the Controller or as required by law.

9. Personal Data Breach Notification

9.1 The Processor shall notify the Controller without undue delay, and in any event within twenty-four (24) hours, after becoming aware of a Personal Data Breach affecting Customer Data.

9.2 Notification shall include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not available at once, it may be provided in phases without further undue delay.

9.3 Notification shall be sent by email to the Controller's designated contact. The Processor's contact point for breach matters is security@solugenomics.com.

9.4 The Processor shall cooperate with the Controller and take reasonable steps as directed to investigate, mitigate, and remediate the breach.

9.5 For the purposes of Section 9.1, the Processor becomes aware of a Personal Data Breach when a member of its security or engineering personnel has confirmed, following reasonable investigation, that a Personal Data Breach affecting Customer Data has occurred. Notification under Section 9.1 is not required for unsuccessful attempts or events that do not compromise the security of Customer Data.

10. Data Protection Impact Assessment and Prior Consultation

The Processor shall provide reasonable assistance to the Controller with any Data Protection Impact Assessments (DPIAs) or prior consultations with Supervisory Authorities, taking into account the nature of processing and the information available to the Processor.

11. International Data Transfers

11.1 Customer Data may be stored or processed outside the EU/EEA, including in the United States, subject to the safeguards in this Section. The processing location of each Sub-processor is set out in Annex I.

11.2 Where Customer Data is transferred to a third country, the Processor shall ensure that one of the following applies:

(a) the European Commission has adopted an adequacy decision covering the recipient, including certification under the EU-US Data Privacy Framework where applicable; or

(b) the transfer is governed by Standard Contractual Clauses; or

(c) another valid transfer mechanism under Chapter V GDPR applies.

11.3 If a transfer mechanism relied on under Section 11.2 ceases to provide a valid basis for transfer, the Processor shall without undue delay implement an alternative mechanism, or cease the affected transfer.

11.4 The Processor applies encryption in transit and at rest, strict access controls, and audit logging to all Customer Data regardless of processing location.

11.5 At the Controller's request, the Processor shall store and process Customer Data exclusively within the EEA. The Controller should contact support@solugenomics.com to arrange EU-only data residency.

12. Return or Deletion of Data

12.1 Upon termination of the Controller's account or the services, the Processor shall delete or return all Customer Data at the Controller's choice, unless retention is required by law.

12.2 Encrypted backups may be retained for recovery purposes for up to seven (7) days, after which they are deleted. Where Customer Data resides in infrastructure operated by a Sub-processor, final deletion from that Sub-processor's systems occurs in accordance with the Sub-processor's deletion procedures, and in any event within one hundred and eighty (180) days.

13. Liability

13.1 The Processor is liable only for breaches of this Agreement or the GDPR arising from its own negligence or willful misconduct, subject to Section 7.6.

13.2 Indirect or consequential damages are excluded to the extent permitted by law.

13.3 The Controller remains responsible for the lawful collection and sharing of Customer Data.

14. Confidentiality and Notices

14.1 Each Party shall maintain confidentiality of Customer Data and information received under this Agreement, except where disclosure is required by law.

14.2 Notices must be in writing and delivered by email. Notices to the Processor shall be sent to support@solugenomics.com. Notices to the Controller shall be sent to the email address associated with the Controller's account, or to such other address as the Controller notifies in writing. Either Party may change its notice address by written notice to the other.

15. Audit Rights

15.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR.

15.2 The Processor may satisfy a request under Section 15.1 by providing its current ISO 27001 certificate, the applicable statement of applicability, and summary reports of independent audits or penetration tests, subject to confidentiality.

15.3 Where the information provided under Section 15.2 is not sufficient, the Controller may carry out an audit or inspection of the Processor's compliance with this Agreement, subject to the following:

(a) no more than once in any twelve (12) month period, except where a Personal Data Breach has occurred or a Supervisory Authority requires it;

(b) on at least thirty (30) days' written notice;

(c) during normal business hours, without unreasonable disruption to the Processor's operations;

(d) subject to the auditor entering into reasonable confidentiality undertakings; and

(e) at the Controller's cost, save where the audit reveals a material breach of this Agreement by the Processor.

15.4 Audits shall not extend to other customers' data, or to any information the disclosure of which would breach the Processor's confidentiality obligations to third parties.

16. Governing Law

16.1 This Agreement shall be governed by and construed in accordance with Finnish law.

16.2 Any disputes shall be subject to the jurisdiction of the Finnish courts.

Annex I: Sub-processors

This annex is a point-in-time record and is not updated during the term.

Sub-processors engaged as at the Effective Date. The current list is maintained at https://www.solugenomics.com/sub-processors.

I(a) Sub-processors of Customer Data

Sections 7.3 and 7.4 (notice and objection) apply to this part only.

Sub-processorEntityPurposeData processedProcessing locationTransfer mechanism
Google Cloud PlatformGoogle Ireland Limited / Google LLCCloud hosting, compute and storage for the Solu Platform backendCustomer Data, account data, usage and audit logsUnited States by default; EEA on requestEU-US Data Privacy Framework; Standard Contractual Clauses where the Framework does not apply

I(b) Other providers processing personal data in connection with the Services

Listed for transparency. Sections 7.3 and 7.4 do not apply.

ProviderEntityPurposeData processedProcessing locationTransfer mechanism
NetlifyNetlify, Inc.Hosting and content delivery for the Solu Platform web applicationIP addresses, request logs, session identifiers. No Customer Data is stored by this providerUnited StatesEU-US Data Privacy Framework; Standard Contractual Clauses where the Framework does not apply

Annex II: Details of Processing (Article 28(3) GDPR)

Subject matter of the processing

Provision of the Solu Platform, a cloud-based whole genome sequencing analysis and genomic surveillance service, to the Controller.

Duration of the processing

For the duration of the Controller's use of the Solu Platform, plus any retention period set out in Section 12.

Nature and purpose of the processing

Storage, automated bioinformatic analysis, classification, and result generation in respect of microbial genomic data uploaded by the Controller. Processing includes species identification, antimicrobial resistance detection, typing, cluster analysis, phylogenetics, and reporting. The Processor also processes data as necessary for operational support, customer support, troubleshooting, and security.

Types of personal data

The Processor does not require, and does not seek to derive, information enabling it to identify natural persons from microbial genomic data. Microbial genomic data may contain incidental host sequence data. The Processor does not analyse, extract, or otherwise process such data, and applies the same security measures to all Customer Data as set out in Annex III and Section 2.7. Personal data processed under this Agreement is limited to:

  • Any personal data the Controller chooses to include in sample identifiers, file names, or metadata fields
  • Account and authentication data of the Controller's authorized users (name, email address, organization)
  • Usage and audit log data associated with those users

Categories of data subjects

  • The Controller's authorized users of the Solu Platform
  • Where applicable and only to the extent the Controller includes identifying information, individuals from whom microbial samples were collected

Obligations and rights of the Controller

As set out in Section 4 of this Agreement and in the GDPR.

Annex III: Technical and Organizational Measures

The Processor maintains the following measures, which are certified under ISO 27001:

Encryption

  • Encryption of Customer Data at rest and in transit using industry standard algorithms

Access control

  • Role-based access control with least privilege
  • Multi-factor authentication for all personnel with access to production systems
  • Formal access provisioning and revocation procedures tied to employment status
  • Periodic access reviews

Logging and monitoring

  • Audit logging of access to and processing of Customer Data
  • Log retention in line with security and compliance requirements
  • Security monitoring and alerting on production infrastructure

Resilience and recovery

  • Encrypted backups retained for up to seven (7) days
  • Documented backup restoration procedures, tested periodically

Vulnerability and incident management

  • Vulnerability scanning and patch management
  • Documented incident response plan with defined roles and escalation paths
  • Periodic review and testing of security measures

Personnel

  • Confidentiality obligations for all personnel with access to Customer Data
  • Security awareness training
  • Background checks where permitted by applicable law

Supplier management

  • Written data protection agreements with all Sub-processors
  • Periodic review of Sub-processor security posture

Minimisation and de-identification

  • No storage of direct patient identifiers by design
  • Access to Customer Data restricted to personnel with an operational need, logged and reviewed

This Agreement is accepted by the Controller on acceptance of the Solu Platform Terms and Conditions or the Solu website Terms and Conditions, and forms part of those terms. A signed counterpart is available on request from support@solugenomics.com.