Terms of Service (ToS)
This Terms of Service (ToS) is a legally binding framework establishing the mandatory behavioral and operational rules for accessing the myDRE Shared Tenant ecosystem. This document applies to all managed assets, including mydre.org, support.mydre.org, underlying API protocols, Virtual Machines (VMs), Azure Batch accounts, storage architectures, and cloud databases.
Conformed to ISO 27001:2023 A.05.10 and NIS 2 parameters, this policy undergoes strict evaluation and re-validation at least annually or immediately following key infrastructure adjustments.
1. Compliance Baseline & Platform Suitability
Statutory Framework Alignments
By accessing the platform, users agree to operate in complete accordance with applicable Dutch and European medical research, privacy, and clinical guidelines:
- The General Data Protection Regulation (GDPR / AVG).
- The Medical Research Involving Human Subjects Act (WMO - Wet Medisch Wetenschappelijk Onderzoek met Menschen).
- The Medical Treatment Agreement Act (WGBO - Wet Geneeskundige Behandelovereenkomst).
- The Federa Code of Conduct for Health Research (Code Goed Gedrag).
- Core Good Clinical Practice (GCP) baselines.
Platform Security Profile (CIA-AA Classification)
The myDRE environment is engineered and validated to host workloads conforming to the following security parameters:
| Security Vector | Baseline Classification | Operational Standard |
|---|---|---|
| Confidentiality | HIGH | Strict role-based isolation of sensitive, diagnostic, and PII datasets. |
| Integrity (of Data) | MEDIUM | Standard transactional checking; suitable for standard secondary health data studies. |
| Availability | MEDIUM | Guided by standard business continuity parameters and hosting SLAs. |
| Auditability / Traceability | MEDIUM | Incorruptible system-wide logging of administrative and access lifecycles. |
| Authenticity | HIGH | Enforced baseline multi-factor authentication (MFA) parameters. |
The Insider Boundary: myDRE is structurally engineered to prevent, capture, and isolate unauthorized access trails or horizontal tenant leaks. The platform is not designed to block or withstand malicious intent carried out by explicitly authorized users. Managing insider threats relies exclusively on institutional vetting and peer oversight.
2. Universal User Obligations
Every platform participant is bound by the following code of conduct:
- Credential Discipline: Users must maintain exclusive control of their platform identities. Sharing unique usernames, passwords, or Multi-Factor Authentication (MFA) parameters is strictly prohibited.
- Organizational Constraints: Beyond this global Terms of Service, user workloads must align with the parameters defined by their home institution. Users should familiarize themselves with the tenant policies.
- Anti-Circumvention Enforcement: Users must never attempt to bypass, weaken, or compromise the system's technical security perimeters. Prohibited actions include forcing entry into administrative interfaces, identity fraud, hacking, or executing unauthorized data movements between Workspaces utilizing external, unmanaged channels.
- Abuse and Penalties: Any form of systemic abuse targeting communication layers, portal engines, or support tools (
support.mydre.org) will trigger an immediate, permanent platform ban at anDREa's sole discretion. - Auditing Disclosures: All platform-wide interactions, compute state changes, and ingress/egress transactions are continuously logged. These logs are bound to the lifecycle of the parent Workspace and are utilized to monitor for indicators of systematic misuse.
- Software Licensing Compliance: Users may deploy proprietary code packages or bring their own licensed software onto myDRE virtual desktops. anDREa provides no guarantee of performance and limited support for custom utilities. Legal compliance with third-party software licensing agreements remains the exclusive liability of the research team.
- White-Hat Testing Limits: Security researchers or white-hat testers are strictly prohibited from scanning, probing, or testing the environment unless they have executed formal terms and received explicit, written authorization from the anDREa CTO.
3. Workspace Accountable Responsibilities
The Workspace Accountable serves as the primary legal and financial custodian for their allocated environment and holds the following explicit responsibilities:
- Financial Liability: The Accountable maintains ultimate ownership of all cloud resource consumption and associated infrastructure costs. Azure utilization fees are billed directly to the Tenant organization by their cloud reseller.
- Vetting Obligations: When extending invitations to join a Workspace, the Accountable has an explicit duty of care to verify that the target individual is the correct, intended person.
- Proxy Accountability: The Accountable accepts ultimate responsibility for all data contents and analytical activities occurring within their Workspace, acting as the proxy guarantor for external collaborators or clinicians invited under their mandate.
- Lifecycle Governance & Disposal: Workspaces remain active until deleted or transitioned into an archived state (which defaults to a 15-year retention period). The Accountable is responsible for planning proper decommissioning at the end of the research lifecycle, which includes arranging the necessary financial support for multi-year archival storage.
4. Administrative Support Protocol
To log an explicit compliance query, verify environmental boundary conditions, or file a technical incident report:
- Navigate to the secure myDRE Support Area.
- Authenticate your profile, select Add ticket, and route the inquiry to the myDRE department.
- Select the template matching your scenario, complete the required fields, and submit.