Vigente desde: 2026-09-20 · Versión: v1.1
Data Processing Addendum Overview
Resumen de roles de responsable/encargado y temas de un futuro acuerdo de tratamiento de datos.
Operador: Celiums Solutions, LLC
Purpose and status
This page is an operational overview, not an executed data processing addendum (DPA). A signed customer DPA, where appropriate, must identify the parties, roles, subject matter, duration, instructions and applicable law without relying on this overview alone.
Likely roles
Celiums Solutions, LLC is the sole operator of OncoRadar. For ordinary account administration and service security, it may act as an independent controller or business. When a customer organization submits personal data for processing under documented instructions, the final DPA may characterize Celiums Solutions, LLC as processor or service provider for that data. Role allocation depends on actual use and law.
Processing scope
The service processes account identity, memberships, workspace research content, developer metadata, security records and privacy requests to provide, secure and support OncoRadar. PHI, patient data and clinical records are prohibited, and no HIPAA business associate relationship is offered by these materials.
Core DPA topics
A final DPA should address documented instructions, confidentiality, security measures, subprocessor notice, assistance with rights and incidents, deletion or return, audits, international transfers, government requests, liability alignment and an annex describing data subjects, categories and duration.
- Subprocessor currently identified in code and deployment configuration: AWS, including Amazon Bedrock Mantle; contract and region details remain pending confirmation.
- Technology: Hyphae is open-source data-plane technology; Qwen and Gemma are model technologies and do not become OncoRadar operators.
- Deletion: active-record and organization-workspace handling requires an operational review; no request is complete merely because it was submitted, and backups are not erased instantly.
Security and audits
Current measures are summarized in the Security Notice and reusable security inventory. No certification, audit report, penetration-test cadence, transfer mechanism or customer audit procedure is promised unless expressly agreed after verification.
Open items
Formation state, addresses, governing law, transfer locations and mechanisms, numeric retention periods, incident notice timing, audit mechanics, signature authority and jurisdiction-specific annexes remain pending. Contact the legal address to discuss a reviewed DPA before production processing that requires one.