Overview of Regulatory Agreements
This document provides a comprehensive map of the contractual architecture, service commitments, and regulatory agreements governing the use of the myDRE platform. This centralized framework supports compliance verification under ISO 27001:2023 (A.05.19 - Information Security in Supplier Relationships, A.05.20 - Addressing Information Security within Supplier Agreements) and NIS 2 (Supply Chain Security).
To facilitate cross-institutional compliance and seamless multi-tenant collaboration, anDREa utilizes standardized enterprise agreements across all client organizations (Tenants).
1. Core Master Agreements & Privacy Documentation
All active master templates, baseline schedules, and corporate privacy frameworks are managed under a secure compliance repository available to auditors inside the Overview Agreements directory.
Core Contractual Pillars
- myDRE Master Service Agreement (The Agreement): The foundational contract establishing the legal, commercial, and operational relationship between anDREa B.V. and the Tenant organization.
- Standard Data Processing Agreement (DPA): Executed utilizing the validated Data Processing Agreement (specimen) specimen. This framework defines the strict data protection boundaries and safeguards required under the GDPR.
- Data Access Clarification Blueprint: The formal technical substantiation documenting anDREa's zero-knowledge infrastructure posture, verifying our role exclusively as a Data Processor for all managed myDRE cloud services.
- ARBIT 2022: Alignment with the standard Dutch government IT procurement terms (Algemene Rijksvoorwaarden voor het inkopen von IT), where contractually mandated by public sector or academic institutions.
Service Commitments & End-User Terms
- anDREa Service Level Agreement (SLA): Defines platform availability targets, incident response windows, support tier paths, and maintenance schedules (Service Level Agreement).
- myDRE Pricing Schedule: Contains the transparent, itemized commercial matrices for baseline platform orchestration and support tracking (myDRE Pricing).
- End User License Agreement (EULA): The mandatory terms of use that every researcher must accept upon logging into
mydre.org, defining account security duties and code restrictions (EULA (End User License Agreement)). - Onboarding Roadmap (Client - Next Steps in Detail): The formal technical specification guiding an institution from initial structural validation to full multi-tenant workspace implementation (Onboarding Journey).
2. Advanced Addenda & Technical Specifications
For environments leveraging custom infrastructure variations or automated identity management systems, the primary agreements are extended via specialized technical addenda:
- Outside SLA Request Protocols: The formal governance design documents required to evaluate, approve, and deploy non-standard cloud architectures, network ingress pathways, or custom marketplace integrations (Outside SLA requests).
- SCIM Integration Framework (Instructions, SIA & TD): The technical specifications, Security Impact Assessments (SIA), and Technical Designs (TD) governing automated System for Cross-domain Identity Management lifecycle synchronization between the Tenant's native directory and the myDRE environment (SCIM).
3. Institutional Reference Packages
For comprehensive compliance reviews, institutional procurement boards, Data Protection Officers (DPOs), and Chief Information Security Officers (CISOs) should reference these introductory components:
- anDREa FAQ Ledger: Contextual operational clarifications for general support queries and day-to-day platform behaviors.
- anDREa & myDRE Information Package: The unified pre-onboarding technical package outlining core platform mechanics, security parameters, and architectural compliance boundaries.