Data Processing Agreement (DPA)
_Effective 15 July 2026 (v1.7)._
This Data Processing Agreement ("DPA") applies where ReadNTag, operated by Scinova Group LLP (UEN T23LL1363K) ("Processor", "we"), processes personal data on behalf of a customer ("Controller", "you"), for example where an institution, laboratory, or organization uses ReadNTag for its members. It supplements our Terms of Service and Privacy Policy. For consumer accounts (an individual using ReadNTag for their own purposes), we act as the controller and this DPA does not apply.
How to put this in place: organizations that require a signed DPA can contact dpo@readntag.com. We will execute this DPA (or a mutually agreed equivalent, including the applicable Standard Contractual Clauses) with an authorized signatory. This page is the standing template.
1. Roles and scope
You are the Controller and we are the Processor of the personal data you or your members submit to the Service ("Customer Personal Data"). We process Customer Personal Data only on your documented instructions, which the Terms, the Privacy Policy, and your configuration/use of the Service constitute, except where law requires otherwise (in which case we notify you unless prohibited).
2. Details of processing
- Subject matter: provision of the ReadNTag reference-management Service.
- Duration: for the term of your use of the Service, plus the retention periods in our Privacy Policy.
- Nature and purpose: hosting, storage, and processing of research references, documents, annotations, and account data to deliver the Service you configure.
- Types of personal data: account identifiers (name, email), authentication data, and the content and usage data described in the Privacy Policy. You must not upload special-category data unless separately agreed.
- Categories of data subjects: your authorized users (for example, an institution's researchers/staff).
3. Our obligations as Processor
We will: (a) process Customer Personal Data only on your documented instructions; (b) ensure persons authorized to process it are under confidentiality; (c) implement appropriate technical and organizational security measures (Section 6); (d) assist you, taking into account the nature of processing, with data subject requests and with your security, breach-notification, and impact-assessment obligations; (e) at your choice, delete or return Customer Personal Data at the end of the services and delete existing copies except where law requires retention; and (f) make available information reasonably necessary to demonstrate compliance and allow for audits as described in Section 8.
4. Sub-processors
You provide general authorization for us to engage the sub-processors listed on our Sub-processors page, each under a written contract with data-protection obligations no less protective than this DPA. We will update that page when sub-processors change and, where we have your contact on file, give notice of additions so you may object on reasonable data-protection grounds.
5. International transfers
Where processing involves a transfer of Customer Personal Data out of the EEA, UK, or Singapore to a country without an adequacy decision, the transfer is governed by an appropriate safeguard, including the relevant Standard Contractual Clauses (EU SCCs / UK IDTA) or the PDPA transfer-limitation safeguards, which are incorporated by reference and completed with the details in Sections 1 and 2.
6. Security
We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access controls, network isolation of the database, tenant separation, audit logging, and regular backups. A summary is available on request.
7. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to help you meet your own notification obligations.
8. Audit
On reasonable prior written notice, no more than once per year (unless required by a supervisory authority or after a breach), we will make available information necessary to demonstrate compliance with this DPA and contribute to audits, subject to confidentiality and to not compromising other customers' security.
9. Deletion and return
On termination, and on your written request, we will delete or return Customer Personal Data as described in Section 3(e) and in our Privacy Policy retention terms.
10. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If there is a conflict between this DPA and the Terms on the processing of Customer Personal Data, this DPA prevails.
ReadNTag · Scinova Group LLP (UEN T23LL1363K). Governing law: Singapore. To execute a DPA: dpo@readntag.com.