PPolySim OS

Data Processing Addendum

For teams, labs, and institutions. Last updated August 2026.

This Data Processing Addendum (“DPA”) supplements our Terms of Service for customers who need a data-processing agreement to use PolySim OS in compliance with applicable data-protection laws (including the GDPR and UK GDPR).

Roles. For personal data you submit through the service, you (the customer) are the data controller and PolySim OS acts as a data processor, processing personal data only on your documented instructions.

Scope of processing. We process account and usage data to provide, secure, and improve the service. Because simulations run locally, most model data never reaches our servers unless you save or share it.

Sub-processors. We use a limited set of vetted sub-processors — for identity/authentication, payments, email delivery, AI features, and hosting. We require each to maintain appropriate technical and organizational safeguards. A current list is available on request.

Security. We maintain encryption in transit, access controls, and data minimization as described on our Security page.

Data-subject rights & deletion. We assist you in responding to data-subject requests and will delete or return personal data on termination, subject to legal retention requirements.

International transfers. Where personal data is transferred across borders, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) as required.

Requesting a signed DPA. To execute a countersigned DPA for your organization, contact legal@polysimos.com.

This page is a summary provided for convenience and is not legal advice. Institutions should have their own counsel review the executed agreement.