Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

Overview of Regulatory Agreements

This document provides a comprehensive map of the contractual architecture, service commitments, and regulatory agreements governing the use of the myDRE platform. This centralized framework supports compliance verification under ISO 27001:2023 (A.05.19 - Information Security in Supplier Relationships, A.05.20 - Addressing Information Security within Supplier Agreements) and NIS 2 (Supply Chain Security).

To facilitate cross-institutional compliance and seamless multi-tenant collaboration, anDREa utilizes standardized enterprise agreements across all client organizations (Tenants).


1. Core Master Agreements & Privacy Documentation​

All active master templates, baseline schedules, and corporate privacy frameworks are managed under a secure compliance repository available to auditors inside the Overview Agreements directory.

Core Contractual Pillars​

  • myDRE Master Service Agreement (The Agreement): The foundational contract establishing the legal, commercial, and operational relationship between anDREa B.V. and the Tenant organization.
  • Standard Data Processing Agreement (DPA): Executed utilizing the validated Data Processing Agreement (specimen) specimen. This framework defines the strict data protection boundaries and safeguards required under the GDPR.
  • Data Access Clarification Blueprint: The formal technical substantiation documenting anDREa's zero-knowledge infrastructure posture, verifying our role exclusively as a Data Processor for all managed myDRE cloud services.
  • ARBIT 2022: Alignment with the standard Dutch government IT procurement terms (Algemene Rijksvoorwaarden voor het inkopen von IT), where contractually mandated by public sector or academic institutions.

Service Commitments & End-User Terms​

  • anDREa Service Level Agreement (SLA): Defines platform availability targets, incident response windows, support tier paths, and maintenance schedules (Service Level Agreement).
  • myDRE Pricing Schedule: Contains the transparent, itemized commercial matrices for baseline platform orchestration and support tracking (myDRE Pricing).
  • End User License Agreement (EULA): The mandatory terms of use that every researcher must accept upon logging into mydre.org, defining account security duties and code restrictions (EULA (End User License Agreement)).
  • Onboarding Roadmap (Client - Next Steps in Detail): The formal technical specification guiding an institution from initial structural validation to full multi-tenant workspace implementation (Onboarding Journey).

2. Advanced Addenda & Technical Specifications​

For environments leveraging custom infrastructure variations or automated identity management systems, the primary agreements are extended via specialized technical addenda:

  • Outside SLA Request Protocols: The formal governance design documents required to evaluate, approve, and deploy non-standard cloud architectures, network ingress pathways, or custom marketplace integrations (Outside SLA requests).
  • SCIM Integration Framework (Instructions, SIA & TD): The technical specifications, Security Impact Assessments (SIA), and Technical Designs (TD) governing automated System for Cross-domain Identity Management lifecycle synchronization between the Tenant's native directory and the myDRE environment (SCIM).

3. Institutional Reference Packages​

For comprehensive compliance reviews, institutional procurement boards, Data Protection Officers (DPOs), and Chief Information Security Officers (CISOs) should reference these introductory components:

  • anDREa FAQ Ledger: Contextual operational clarifications for general support queries and day-to-day platform behaviors.
  • anDREa & myDRE Information Package: The unified pre-onboarding technical package outlining core platform mechanics, security parameters, and architectural compliance boundaries.