Data processing agreement

The DPA, and where it has got to

If you put personal data about your own people into Ligara, the law makes you the controller and us your processor, and that relationship has to be governed by a contract. This page says what that contract will commit us to and how to get the current position in writing before it is signed.

No DPA is in force yet, and there is nothing to download from this page. We have deliberately not published a template. A processing agreement is the document your own compliance team will read most closely, and an unreviewed one assembled from a generator would fail that reading while looking reassuring. It is being drafted with advice.

01 · Roles

Who is the controller of what

Getting this the wrong way round is the most common mistake in vendor assessments, so it is worth being explicit.

Controller and processor roles for each category of data
Data You are We are Governed by
Personal data you upload about your staff, students or collaborators Controller Processor, acting on your instructions The DPA — in preparation
Your scientific data: compounds, structures, assay results Owner Custodian only. Generally not personal data at all, so data protection law is the wrong frame — confidentiality and IP are the right one Terms of service
Your own account details, and how you use the product Data subject Controller Privacy notice
An enquiry you send through this website Data subject Controller Privacy notice
02 · Contents

What the agreement has to contain

UK GDPR Article 28 sets most of this, so there is little discretion about the list. Publishing it now means you can check the draft against it when it arrives.

  • Subject matter, duration, nature and purpose of the processing, and the categories of data subject.
  • Processing only on your documented instructions, and a commitment to tell you if an instruction appears unlawful.
  • Confidentiality obligations on everyone with access.
  • Security measures under Article 32, described concretely rather than as “industry standard”.
  • Sub-processor terms: the current list, advance notice of additions, a right to object, and the same obligations flowed down.
  • Assistance with data-subject requests reaching us that belong to you.
  • Breach notification without undue delay, with what we will tell you and how fast.
  • Assistance with your DPIAs and with regulator engagement.
  • Deletion or return at the end, and what happens to backups.
  • Audit and information rights, proportionate to a company of our size — we will not promise on-site audits we cannot support.
  • International transfer terms, since some processing happens outside the UK.

The sub-processor list the DPA will annex is already published and current: see subprocessors, which names each vendor, what it does, and where it processes — including the steps that leave the UK.

03 · In the meantime

If you need something now

Plenty of evaluations cannot wait for a document to come back from counsel. Three things we can do today:

  • Answer your vendor assessment. Send the questionnaire and we will complete it, including the questions where the answer is “not yet”.
  • Give you the technical position in writing, signed, on letterhead, covering how isolation works, where data sits and what is not built yet. Much of it is already public on the security page.
  • Sign your DPA instead of ours. If your institution has a standard processor agreement, that is often faster for everyone. Send it over.

Ask us and say which of the three you need.

Last reviewed 17 September 2026. No agreement in force. TODO(legal): replace this page with the executed DPA, or with a downloadable counter-signable version, once counsel has settled it. Decide whether it is published openly or released on request.