Cytognosis Foundation Data Use Agreement
Agreement Date: [DATE]
Agreement ID: CYT-DUA-[YYYY]-[###]
Parties
Data Provider: Cytognosis Foundation
Address: San Francisco, California, United States
Contact:
Data Recipient: [RECIPIENT ORGANIZATION]
Address: [RECIPIENT ADDRESS]
Principal Investigator: [PI NAME AND TITLE]
Contact: [PI EMAIL AND PHONE]
Dataset Information
Dataset Name: [DATASET NAME]
Dataset Version: [VERSION NUMBER]
Dataset Description: [BRIEF DESCRIPTION]
Data Elements: [LIST OF DATA TYPES/ELEMENTS]
Number of Records: [APPROXIMATE COUNT]
Time Period: [DATA COLLECTION PERIOD]
Purpose and Scope
Research Purpose: [DETAILED DESCRIPTION OF RESEARCH PURPOSE]
Specific Aims:
1. [AIM 1]
2. [AIM 2]
3. [AIM 3]
Expected Outcomes: [DESCRIPTION OF EXPECTED RESEARCH OUTCOMES]
Public Health Benefit: [DESCRIPTION OF POTENTIAL PUBLIC HEALTH IMPACT]
Permitted Uses
The Data Recipient may use the Dataset for the following purposes:
ā
Permitted Activities
[ ] Statistical Analysis: Descriptive and inferential statistical analysis
[ ] Machine Learning: Development and training of AI/ML models
[ ] Visualization: Creation of charts, graphs, and data visualizations
[ ] Publication: Academic publication of research results
[ ] Presentation: Conference presentations and academic talks
[ ] Collaboration: Sharing results with approved collaborators
[ ] Education: Use in educational settings with restrictions
[ ] Validation: Validation of existing research findings
ā Prohibited Activities
[ ] Re-identification: Any attempt to identify individuals in the dataset
[ ] Redistribution: Sharing or redistributing the dataset to third parties
[ ] Commercial Use: Use for commercial product development or profit
[ ] Linking: Linking with other datasets to increase re-identification risk
[ ] Reverse Engineering: Attempting to reverse privacy-preserving techniques
[ ] Discrimination: Use for discriminatory or harmful purposes
[ ] Surveillance: Use for surveillance or monitoring of individuals
[ ] Marketing: Use for marketing or advertising purposes
Data Security and Privacy Requirements
Technical Safeguards
[ ] Encryption: All data must be encrypted at rest (AES-256 minimum)
[ ] Access Controls: Role-based access controls with multi-factor authentication
[ ] Network Security: Secure network connections (VPN, TLS 1.3)
[ ] Audit Logging: Comprehensive logging of all data access and usage
[ ] Backup Security: Encrypted backups with secure storage
[ ] Endpoint Protection: Anti-malware and endpoint detection on all devices
Organizational Safeguards
[ ] Training: All personnel must complete data security training
[ ] Access Management: Documented procedures for granting and revoking access
[ ] Incident Response: Established procedures for security incident response
[ ] Physical Security: Appropriate physical controls for data storage locations
[ ] Vendor Management: Due diligence for any third-party service providers
[ ] Clean Desk Policy: Secure handling of printed materials and devices
Privacy Protections
[ ] No Re-identification: Prohibition on any re-identification attempts
[ ] Aggregation Requirements: Minimum cell sizes for published results (nā„5)
[ ] Statistical Disclosure Control: Application of appropriate privacy techniques
[ ] Output Review: Review of all outputs before publication or sharing
[ ] Differential Privacy: Application of differential privacy where appropriate
[ ] Synthetic Data: Use of synthetic data generation where possible
Personnel and Access Management
Authorized Personnel
All personnel with access to the Dataset must be listed and approved:
| Name | Title | Role | Email | Training Date | Access Level |
|----------|---------|--------|---------|---------------|--------------|
| [NAME] | [TITLE] | [ROLE] | [EMAIL] | [DATE] | [LEVEL] |
| [NAME] | [TITLE] | [ROLE] | [EMAIL] | [DATE] | [LEVEL] |
Access Requirements
[ ] Background Checks: Appropriate background screening for all personnel
[ ] Confidentiality Agreements: Signed confidentiality agreements
[ ] Training Completion: Completion of required data security training
[ ] Institutional Affiliation: Verification of institutional affiliation
[ ] Supervisor Approval: Written approval from institutional supervisor
[ ] Regular Recertification: Annual recertification of access requirements
Data Handling Procedures
Data Receipt and Storage
[ ] Secure Transfer: Data received via secure, encrypted transfer method
[ ] Integrity Verification: Verification of data integrity upon receipt
[ ] Secure Storage: Storage on approved, secure systems only
[ ] Access Logging: Logging of all data access and usage activities
[ ] Backup Procedures: Implementation of secure backup procedures
[ ] Geographic Restrictions: Compliance with data residency requirements
Data Processing and Analysis
[ ] Approved Systems: Use of pre-approved computing systems only
[ ] Processing Documentation: Documentation of all processing activities
[ ] Quality Controls: Implementation of data quality assurance procedures
[ ] Version Control: Proper version control for analysis code and results
[ ] Reproducibility: Maintenance of reproducible analysis workflows
[ ] Error Handling: Appropriate procedures for handling data errors
Data Destruction and Return
[ ] Destruction Timeline: Secure destruction within [X] days of project completion
[ ] Destruction Method: Use of approved data destruction methods
[ ] Destruction Certification: Provision of destruction certificates
[ ] Derivative Data: Destruction of all derivative datasets and analyses
[ ] Backup Destruction: Destruction of all backup copies
[ ] Media Sanitization: Proper sanitization of storage media
Publication and Dissemination
Publication Requirements
[ ] Attribution: Proper attribution to Cytognosis Foundation in all publications
[ ] Pre-publication Review: Submission of manuscripts for review before publication
[ ] Embargo Periods: Compliance with any embargo periods
[ ] Open Access: Preference for open access publication when possible
[ ] Data Availability Statements: Appropriate data availability statements
[ ] Supplementary Materials: Sharing of analysis code and supplementary materials
Required Attribution
Standard Citation: [DATASET CITATION FORMAT]
Acknowledgment Text:
"This research was conducted using data provided by Cytognosis Foundation. The findings and conclusions in this report are those of the authors and do not necessarily represent the views of Cytognosis Foundation."
Prohibited Statements
[ ] No Endorsement: Cannot claim Cytognosis Foundation endorsement
[ ] No Warranty: Cannot make warranty claims about the data
[ ] No Liability: Cannot hold Cytognosis Foundation liable for research outcomes
[ ] No Commercial Claims: Cannot make commercial claims based on the data
Compliance and Monitoring
Reporting Requirements
[ ] Annual Reports: Annual progress reports on research activities
[ ] Publication Notifications: Notification of all publications using the data
[ ] Incident Reports: Immediate reporting of any security incidents
[ ] Access Reports: Regular reports on personnel with data access
[ ] Usage Statistics: Periodic reports on data usage and analysis activities
[ ] Compliance Attestations: Annual compliance attestations
Audit Rights
[ ] Audit Access: Cytognosis Foundation right to audit compliance
[ ] Documentation Review: Right to review all relevant documentation
[ ] System Inspection: Right to inspect data storage and processing systems
[ ] Personnel Interviews: Right to interview personnel with data access
[ ] Corrective Actions: Right to require corrective actions for violations
[ ] Access Suspension: Right to suspend access for non-compliance
Legal and Regulatory Compliance
Applicable Laws and Regulations
[ ] HIPAA: Strict adherence to the Health Insurance Portability and Accountability Act.
[ ] GDPR: Compliance with General Data Protection Regulation (if data subjects reside in the EU).
[ ] IRB Approval: Current and valid Institutional Review Board approval or formal exemption is mandatory prior to data release.
[ ] Open Science Mandate: Acknowledgment that Cytognosis Foundation operates under an open-science, non-profit mandate; data cannot be siloed for exclusive commercial exploitation.
Liability and Indemnification
[ ] Indemnification: Recipient fully indemnifies Cytognosis Foundation, its officers, and employees against any claims arising from the Recipient's misuse, unauthorized disclosure, or negligent handling of the Dataset.
[ ] Limitation of Liability: Cytognosis Foundation provides the Dataset "AS IS" without warranties of any kind (express or implied, including merchantability or fitness for a particular purpose). In no event shall Cytognosis Foundation be liable for any indirect, consequential, or punitive damages.
[ ] Breach Costs: Recipient bears full financial and legal responsibility for all costs related to a data breach originating from their systems, including notification costs, credit monitoring, and regulatory fines.
Term and Termination
Agreement Term
Start Date: [START DATE]
End Date: [END DATE]
Renewal Options: Subject to annual review of a submitted progress report and compliance attestation.
Termination Conditions
[ ] Material Breach: Immediate termination upon any material breach of this Agreement, notably unauthorized re-identification attempts or data transfer.
[ ] Convenience: Termination by Cytognosis Foundation with 30 days written notice.
[ ] Regulatory Directive: Immediate termination if required by changes in applicable law or regulatory authority directives.
Post-Termination Obligations
[ ] Data Destruction: Immediate, secure destruction of all original data, backup copies, and derivative datasets within 14 days of termination.
[ ] Destruction Certification: Submission of a formal, legally binding (and optionally notarized) Certificate of Data Destruction signed by the Recipient's Authorized Institutional Official and Chief Information Security Officer.
[ ] Survival: Confidentiality, indemnification, and liability limitations shall survive the termination of this Agreement in perpetuity.
Signatures and Approvals
Cytognosis Foundation
Name: Shahin Mohammadi
Title: Chief Data Officer
Signature: _________________________
Date: _____________
Name: [LEGAL REPRESENTATIVE]
Title: [TITLE]
Signature: _________________________
Date: _____________
Data Recipient Organization
Name: [PI NAME]
Title: [PI TITLE]
Signature: _________________________
Date: _____________
Name: [INSTITUTIONAL REPRESENTATIVE]
Title: [TITLE]
Signature: _________________________
Date: _____________
Appendices
Appendix A: Technical Specifications
Data format specifications
System requirements
Security configuration details
Transfer procedures
Appendix B: Data Dictionary
Variable definitions
Coding schemes
Data quality indicators
Known limitations
Appendix C: Contact Information
Technical support contacts
Legal contacts
Emergency contacts
Escalation procedures
Document Version: 1.0
Last Updated: September 2025
Template Owner: Legal and Compliance Team, Cytognosis Foundation
Classification: Template - Internal Use Only