Legal

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between PrimusReview ("Processor") and the customer ("Controller") and governs the processing of personal data by PrimusReview on behalf of the customer in connection with the PrimusReview service.

1. Definitions

In this DPA: "Controller" means the customer organisation that determines the purposes and means of processing personal data. "Processor" means PrimusReview, which processes personal data on behalf of the Controller. "Personal Data" means any information relating to an identified or identifiable natural person submitted to the PrimusReview platform. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion. "Sub-processor" means any third party engaged by PrimusReview to process personal data in connection with the service. "UK GDPR" means the UK General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.

2. Scope and purpose of processing

PrimusReview processes personal data submitted by the Controller for the following purposes: - Providing the AI-assisted compliance review service - Storing review history and associated annotations - Managing user accounts and authentication - Sending transactional emails related to the service - Providing customer support PrimusReview will not process personal data for any purpose other than those set out above without the prior written consent of the Controller.

3. Nature of personal data processed

The personal data processed may include: - Account data: names, email addresses, company names - Document content: text extracted from promotional materials submitted for review (which may incidentally contain references to named individuals, patient populations, or healthcare professionals) - Usage data: review history, material types, timestamps - Communication data: contact form submissions and support correspondence The Controller is responsible for ensuring that any personal data submitted to the platform is done so with appropriate lawful basis and, where the materials contain special category data (such as patient health information), that appropriate safeguards are in place.

4. Obligations of the Processor

PrimusReview shall: (a) Process personal data only on documented instructions from the Controller, including with regard to transfers to third countries (b) Ensure that authorised personnel are subject to appropriate confidentiality obligations (c) Implement appropriate technical and organisational security measures as described in our Security Overview at primusreview.com/security (d) Not engage sub-processors without prior written authorisation from the Controller, except as set out in this DPA (e) Assist the Controller in responding to data subject requests to exercise their rights under UK GDPR (f) Assist the Controller in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments, and prior consultation (g) At the Controller's choice, delete or return all personal data on termination of the service (h) Make available all information necessary to demonstrate compliance with this DPA (i) Notify the Controller without undue delay upon becoming aware of a personal data breach

5. Sub-processors

The Controller authorises PrimusReview to engage the following sub-processors: - Supabase Inc. — database and authentication (AWS eu-west-2, London) - Anthropic PBC — AI model processing (United States) - Vercel Inc. — application hosting and delivery (United States/EU) - Stripe Inc. — payment processing (United States) - Resend Inc. — transactional email (United States) - Google LLC — business email (Google Workspace) Full details of sub-processors, including their locations and processing activities, are available at primusreview.com/sub-processors. PrimusReview will notify the Controller of any intended changes to sub-processors with reasonable notice, giving the Controller the opportunity to object.

6. International data transfers

Some sub-processors are located outside the UK and EEA, including in the United States. PrimusReview ensures appropriate safeguards are in place for all international transfers, including: - Standard Contractual Clauses (SCCs) as approved by the UK ICO or European Commission - Adequacy decisions where applicable - Sub-processor compliance with UK GDPR transfer requirements Details of transfer mechanisms for each sub-processor are available on request.

7. Security measures

PrimusReview implements the following technical and organisational security measures: - TLS 1.2/1.3 encryption in transit for all connections - AES-256 encryption at rest for all database storage - Row-level security (RLS) ensuring logical data separation between customers - Password hashing via bcrypt - Rate limiting on all API endpoints - Content Security Policy and security headers - CAPTCHA on account creation - Error monitoring and uptime alerting - Regular dependency updates Full details are available at primusreview.com/security.

8. Data subject rights

PrimusReview will assist the Controller in responding to data subject requests. Users of the platform can exercise the following rights directly: - Access: users can view their data via the dashboard - Rectification: users can update their account information in settings - Erasure: users can delete their account and all associated data via the settings page - Portability: available on request to thompson.daniel@primusreview.com For requests that cannot be fulfilled directly by the data subject, PrimusReview will respond within one calendar month.

9. Breach notification

In the event of a personal data breach, PrimusReview will: (a) Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach (b) Provide sufficient information to allow the Controller to fulfil its own notification obligations to the ICO and affected data subjects (c) Cooperate with the Controller and take reasonable commercial steps to assist in the investigation and remediation of the breach Notifications should be sent to the Controller's designated data protection contact.

10. Term and termination

This DPA remains in effect for the duration of the service agreement between the Controller and PrimusReview. On termination of the service: - The Controller's account and all associated personal data will be deleted within 30 days - Billing records will be retained for 7 years as required by HMRC - The Controller may request confirmation of deletion in writing This DPA survives termination of the service agreement to the extent necessary to give effect to its terms.

11. Governing law

This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales. This DPA is intended to satisfy the requirements of Article 28 of the UK GDPR.

12. Requesting a signed DPA

Enterprise customers requiring a countersigned DPA for procurement purposes should contact us at thompson.daniel@primusreview.com. We will provide a signed copy within 5 business days.