3.1 No attempting to identify patients or participants. You must not attempt to identify any patient or trial participant to whom Content relates where the Content did not originate from you or your organization. This prohibition applies whether or not the attempt succeeds, whether or not any transformation has been applied, and irrespective of any belief that the Content is anonymous.
Terms of Service
Effective date: 3 September 2026
These Terms of Service govern access to and use of the Collective Minds platform and CM's services. They are
entered into between Collective Minds Radiology AB ("CM"), a company registered in Sweden under number
559120-7187, and the Customer identified in the applicable Service Order. Certain provisions also apply directly to
Authorized Users and Session Viewers as expressly stated in these Terms.
The General Terms apply to everyone, including Customers, Authorized Users, and Session Viewers. Additional
Policies apply according to your role and the service or use concerned. More than one Additional Policy may apply
at the same time. The table that follows tells you which ones apply to you.
General Terms: Apply to everyone who uses the Platform (1-24).
Additional policies: Apply according to your role based on the information provided on item 25
For each Customer, the General Terms and applicable Additional Policies form part of the same agreement.
Opening or closing a section changes only what is shown on screen. Every provision applies according to its terms
whether or not you open it.
General Terms
These apply to everyone who uses the Platform, according to their terms.
1. Parties and how to read these Terms
1.1 These Terms are entered into between Collective Minds Radiology AB, company number 559120-7187, registered at Svärdvägen 5, 182 33 Danderyd, Sweden, and the Customer. In these Terms, CM, we and us mean Collective Minds Radiology AB. You means the Customer or, where the context requires, an Authorized User or Session Viewer.
1.2 The CM Group. Collective Minds Radiology AB belongs to a group of companies. Collective Minds Radiology AB is the CM entity that contracts with you under these Terms and is responsible to you for performance. CM may perform parts of the services through CM Group companies and remains responsible for that performance as provided in these Terms. Where a CM Group company processes personal data on the Customer's behalf, it does so as a subprocessor and is identified in the Subprocessor List.
1.3 Customer Affiliates. A Customer Affiliate may place a Service Order under these Terms, in which case that Affiliate is the Customer for that Service Order and is separately responsible for it. A Customer may permit its Affiliates' personnel to be Authorized Users, and the Customer remains responsible for them under clause 4.4.
1.4 How obligations are stated. Obligations are stated in ordinary language. Where an obligation depends on a technical standard, legal provision or specific data element, additional detail may follow in a passage marked Note. An introductory paragraph at the beginning of a section or of an Additional Policy is part of these Terms and binds the parties to the same extent as a numbered clause in that section or policy.
Note. A passage marked Note is an operative part of these Terms and binds the parties to the same extent as the clause it follows. A Note supplements, and must be read together with, the clause it follows. "Must" and "will" state obligations; "may" states a right.
1.5 Scope. These Terms govern access to and use of the Platform and the public CM website, which may be subject to separate terms of use. CM makes the Platform available only in territories in which it has determined it may lawfully do so. The description of a service does not constitute a representation that it is available in every territory.
1.6 Relationship with the Privacy Policy/Notice. These Terms allocate rights and obligations between the parties. Beyond matters described in these Terms of Service, the Privacy Policy/Privacy Notice describes how CM processes personal data for its own purposes in more detail; it is addressed to individuals, is not a contract, and is not incorporated into these Terms. Processing carried out by CM on the Customer's behalf is governed by the Data Processing Agreement, which prevails over these Terms on matters concerning personal data. Where CM acts as a business associate, the Business Associate Agreement prevails on matters concerning Protected Health Information (PHI).
1.7 Ownership. The Platform is CM's. Ownership of Content and Results is governed by clause 13. CM claims no ownership of, license over, or interest in either beyond the limited operating right in clause 13.6 needed to provide the services. Restrictions on export under clause 8 concern identifiability and permitted egress and do not determine ownership.
1.8 Acceptance. The Customer accepts these Terms by signing or otherwise accepting a Service Order or by completing a subscription. An Authorized User accepts the obligations in these Terms that expressly apply to Authorized Users by confirmation of these Terms before access to the Platform and by using the Platform. A Session Viewer accepts the obligations applicable to Session Viewers on the screen presented before Teaching Content opens and by using the Platform. An Authorized User or Session Viewer does not necessarily become the Customer or assume the Customer's obligation to pay Fees. Where the Customer has a signed master agreement with CM, the MSA and the Service Order will take precedence over any specific conditions agreed upon.
1.9 Eligibility and permitted use. The Platform is a professional medical imaging platform made available solely for healthcare, clinical trial, research, education and related professional purposes supported by CM's services. Access is limited to Customers, Authorized Users, and Session Viewers who are authorized to use the Platform for such purposes. The Platform is not made available to the general public and must not be accessed or used for personal use, general browsing, curiosity, exploration, competitive intelligence, unauthorized testing or any other purpose not permitted by these Terms or the applicable Service Order. Nothing in these Terms grants any person a right to access or use the Platform without authorization from CM or the applicable Customer.
1.10 Filtering. The Platform interface and this document may allow you to display only the provisions relevant to your role. Filtering affects display only. These Terms constitute one agreement and every provision applies according to its terms.
2. What capitalized words mean
Capitalized terms have the meanings below. Other words carry their ordinary meaning.
| Term | Meaning |
| Acceptable Use Policy | The contract document setting out detailed conduct rules for use of the Platform. |
| Additional Policy | A policy identified in the applicability table above that supplements the General Terms for a particular Customer, role, service or use. |
| Affiliate | An entity that controls, is controlled by, or is under common control with a party. |
| Authorized User | An individual to whom the Customer grants access to the Platform. |
| Business Associate Agreement | The agreement required by 45 CFR 164.504(e) where CM handles Protected Health Information on behalf of a Covered Entity or another business associate. |
| Clinical Trial | A clinical trial or clinical investigation recorded as such in the applicable Service Order and governed by the Clinical Trials Policy. |
| CM Group | Collective Minds Radiology AB and its Affiliates. |
| CM-Connect | The CM ingestion gateway described in clause 5, installed within the Customer's network and designed principally for DICOM Content. It may support other file types where the relevant functionality and configuration are enabled. |
| CM Security Commitments | The technical and organizational security measures and other security obligations expressly undertaken by CM under these Terms, the Data Processing Agreement, the applicable Service Order, or any other contract document expressly agreed between CM and the Customer. |
| Content | Health Data and any other data, document, annotation, response or file uploaded to or created within the Platform by or for the Customer or an Authorized User. |
| Cookie Policy | CM's published policy describing cookies and similar technologies used on CM's websites. It is addressed to individuals and is not a contract document. |
| Covered Entity | A health plan, health care clearinghouse or health care provider within the meaning of 45 CFR 160.103. |
| Customer | The entity or individual that enters into the applicable Service Order or subscription and is responsible for the Fees and its Authorized Users. |
| Data Processing Agreement | The agreement governing CM's processing of personal data on behalf of a controller or processor. |
| Data Specification | The published specification with which Content must comply, comprising a baseline standard and an enhanced standard for releases for a teaching session (Release State 4 terms). |
| De-identified | Treated so that the information is not individually identifiable under 45 CFR 164.514(b), by the Safe Harbor method or Expert Determination. Validly De-identified information is outside HIPAA. It does not follow that the information is anonymous under the GDPR. |
| Documentation | The user, technical, API and operating documentation made available by CM for the Platform. |
| Fees | The amounts payable under the applicable Service Order or subscription. |
| GDPR | The General Data Protection Regulation, Regulation (EU) 2016/679, as amended or replaced. |
| General Terms | The provisions of these Terms under the heading General Terms, which apply according to their terms to Customers, Authorized Users and Session Viewers. |
| Health Data | Data relating to health held on the Platform, including DICOM imaging from radiology, cardiology, nuclear medicine and digital pathology; whole slide images in vendor formats; laboratory results; reports and other free text; structured study data; waveforms and signals; and data derived from any of these. Health Data is data concerning health within the meaning of Article 4(15) GDPR and, where HIPAA applies to it, may constitute Protected Health Information. |
| HIPAA | The Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164, as amended. |
| Intended Purpose and Component Notice | The contract document stating the intended purpose of the Platform and identifying the Viewer, its manufacturer and the version made available. |
| Lead Party | The organization named in a Service Order as speaking for a Project involving more than one organization. |
| Limited Data Set | Protected Health Information from which the identifiers listed in 45 CFR 164.514(e)(2) have been removed. A Limited Data Set remains Protected Health Information under HIPAA. Its status under the GDPR must be assessed separately and it is Pseudonymized within the meaning of Article 4(5) GDPR only where the requirements of that provision are satisfied. |
| Non-Conforming Content | Content that does not comply with the applicable Data Specification, including Content containing direct identifiable identifiers, text rendered as image data, a visible slide label, or identifying information in a free-text field or burned-in pixels. |
| Platform | The CM software-as-a-service platform and the services provided through it. |
| Privacy Notice | CM's published notice describing how CM processes personal data for its own purposes. It is addressed to individuals and is not a contract document. |
| Project | The workspace for a single body of work, including a Clinical Trial, research study, development activity, collaboration or course. |
| Project record | An operational record of Project configuration, participants, Release States, permitted purposes and other Project facts authorized by the applicable Service Order. A Project record does not amend Fees, liability, warranties, term or other commercial terms unless the applicable Service Order expressly authorizes it. |
| Protected Health Information | Individually identifiable health information within the meaning of 45 CFR 160.103, held or transmitted by a Covered Entity or its business associate. |
| Pseudonymized | Processed so that the data can no longer be attributed to a specific person without additional information kept separately, within the meaning of Article 4(5) GDPR. Pseudonymized data remain personal data where the GDPR applies. Pseudonymization under the GDPR does not by itself constitute De-identification under 45 CFR 164.514(b) or take information outside HIPAA. |
| Release State | One of the states in clause 7 determining who may access an item of Content. |
| Results | Datasets, annotations, segmentations, measurements, statistics, figures and trained models produced from Content in a Customer's Project. |
| Service Level Agreement | CM's published service level agreement for the Platform, addressing availability, support coverage, severity levels, response and resolution targets, service metrics and the responsibilities of each party in relation to support. |
| Service Order | The order form, subscription record or other ordering document accepted by the parties that records the services ordered, Project details, plan, limits, Fees, term, hosting region, retention and any professional services. |
| Session Viewer | A person who accesses Teaching Content under a release for a teaching session (Release State 4 terms) with or without holding an account, under the specific teaching session. |
| Subprocessor List | The list published by CM identifying the subprocessors engaged in providing the Platform. |
| Teaching Content | Content made available for teaching under releases for a teaching session (Release State 4). |
| Viewer | The third-party medical image viewing component described in clause 9. |
2.1 "Including" means "including without limitation." A reference to legislation or a standard is to that instrument as amended or replaced. Headings do not affect interpretation.
3. Prohibited conduct
The prohibitions and reporting obligations below apply, according to their terms, to every Customer, Authorized User, and Session Viewer.
3.2 No tracing, approaching or contacting individuals. You must not use Content as a means of locating, tracing, approaching or contacting any individual, and must not search for an individual in any other system on the basis of Content. Where you are the treating clinician, or the investigator at the site that enrolled a participant, this clause does not affect your existing relationship with that person.
3.3 No entering identifying information into any field. You must not enter identifying information into any field of the Platform, including a case or study title, folder or file name, clinical history or diagnosis field, annotation, slide text, question, response, variable label or code comment.
Note. This clause applies to any attribute or field editable through the Platform, including DICOM descriptive attributes such as Study Description and Series Description, comment and annotation attributes, Clinical Trial attributes in DICOM group 0012 where populated by the Customer, and label and macro images embedded in whole slide image files.
3.4 No uploading Content that has not been prepared. You must not upload Content that has not been prepared in accordance with clause 5. Where you are uncertain whether Content complies with the applicable Data Specification, you must not upload it.
3.5 No copying Content out of the Platform. You must not capture, photograph, screen-record, download, export, print or otherwise copy Content out of the Platform except as clause 8 expressly permits and subject to the conditions stated there.
3.6 No exporting Results that carry identifying information or another Customer's Content. Results are governed by clause 13.2 and may be taken out of the Platform subject to clause 8. You must not export Results that contain identifying information, incorporate another Customer's Content, or would permit an individual to be identified or singled out.
3.7 No sharing credentials or access links. You must not disclose or share your authentication credentials, any access link or access code with any person, including a colleague, student or collaborator on the same Project. You must notify CM on the same day if you believe credentials or an access link have been compromised.
3.8 No linking Content to other data to identify anyone. You must not link, combine or cross-reference Content with another dataset for the purpose of identifying an individual or in a manner that makes identification more likely. Linkage for a legitimate research purpose is governed by clause 5 of the Research Services Policy and the applicable Project documentation.
3.9 No training models on Content outside your own Project. You must not use Content to develop, train, fine-tune, validate or evaluate a machine learning model, or make Content available to any person for that purpose, unless the Content is within your own Project, you are entitled to use it for that purpose and clause 13 is satisfied. You must not use another Customer's Content, Content shared with you for a different purpose, or Teaching Content for those activities.
3.10 No harassment, discrimination or misrepresentation. You must not use the Platform or Content to harass, threaten, defame, humiliate, discriminate against or otherwise harm any person, including a patient, trial participant, colleague, other user or competitor, or to misrepresent a case, finding or result.
3.11 No use outside the permitted purpose. You must not use the Platform for any purpose other than the purposes permitted under clause 1.9, the applicable Service Order and any applicable Additional Policy. You must not use the Viewer outside the manufacturer's intended purpose or the limits in clause 9. Any clinical decision remains yours.
3.12 No security testing, scraping or reverse engineering. You must not conduct security testing without CM's prior written consent, attempt to access data you have not been granted, circumvent any access control or rate limit, scrape the Platform, or reverse engineer the Platform or any component within it. A vulnerability report made in good faith in accordance with clause 18.9 is not a breach of this clause.
3.13 Incidents must be reported immediately. You must notify CM immediately on becoming aware that identifying information is present in Content, that you have recognized an individual, that Content has been uploaded which should not have been, or that an access link or code has been disclosed beyond its intended recipients. A notification made in good faith under this clause is not itself a breach of these Terms and will not be treated as one.
3.14 Clauses 3.1, 3.2, 3.3, 3.5, 3.6 and 3.7 survive termination and continue to apply to Content to which you have had access.
3.15 Breach of clauses 3.1, 3.2, 3.3, 3.5, 3.6, 3.7 or 3.9 is a material breach for the purposes of clause 15.3.
4. Access, accounts and Customer responsibility
4.1 Accounts and access. Access to the Platform requires an account or other access method authorized by CM or the applicable Customer. Accounts may be provisioned by CM at the Customer's request, through an invitation or activation process, or by another account setup method made available by CM. For an individual subscription, an account may be provisioned on completion of the applicable subscription and verification process. Where single sign-on is enabled for a Customer, Authorized Users may authenticate through the Customer's identity provider. The availability of a registration page, login page, invitation link or other technical means of reaching the Platform does not by itself authorize access or use.
4.2 Customer administrator. The Customer must maintain at least one administrator, who is an Authorized User, able to act on its behalf in relation to user access, disposition of Content and matters reserved to the Customer under these Terms.
4.3 Authentication and single sign-on. Each Authorized User must use the authentication method made available for that account. Where single sign-on or another Customer-controlled identity provider is configured for the Customer, the Customer is responsible for the security and administration of that identity provider, including determining which of its users are entitled to authenticate through it and withdrawing that entitlement when appropriate. CM remains responsible for authentication and access controls operated by CM as part of the Platform in accordance with the CM Security Commitments.
4.4 Customer responsibility for Authorized Users. The Customer is responsible for the acts and omissions of its Authorized Users in relation to the Platform as if they were its own, including ensuring that each Authorized User is authorized to use the Platform, is aware of and complies with these Terms and the applicable Data Specification, withdrawing access promptly when an individual ceases to be entitled to it, and reporting incidents, as required under clause 3.13.
4.5 Multiple Customers. If an individual is an Authorized User of more than one Customer. Access, Content and audit records are maintained separately by Customer. Content held for one Customer is not available in another Customer's environment except through a permitted transfer under clause 7.5.
4.6 Deactivated Authorized Users. Where an Authorized User is deactivated, Content that person placed in a shared area remains available to the Customer. Content in that person's private area is dealt with under clause 15.6.
5. Ingestion: CM-Connect, web upload and preparation of Content
Content reaches the Platform through CM-Connect or web upload. The Service Order or the agreed Terms to which the route applies; however, if CM-Connect has not been explicitly agreed, web upload will be the available method.
Unless disabled by the Customer or otherwise configured, either route may apply CM's standard pseudonymization functionality. The availability or application of that technical functionality does not, by itself, mean that the Customer has procured a CM pseudonymization, de-identification, or anonymization service. CM pseudonymization, de-identification, or anonymization services need to be explicitly agreed upon and will generally entail costs to be borne by the Customer/User unless the costs are assumed by other means (e.g., an EU-funded consortium).
5.1 CM-Connect. CM-Connect is software installed by the Customer on a server within the Customer's network, on an operating system supported by CM. CM does not host it. It is designed principally for DICOM Content. It may support other file types where the relevant functionality and configuration are enabled. Separate channels may be configured, each with its own treatment rules and destination.
Note. For DICOM Content, channel rules may be expressed against the attribute confidentiality profiles in the DICOM Standard, PS3.15 Annex E, and the per-attribute actions in Table E.1-1. The configured channel records the base profile and applicable options. Private attributes may be enumerated by group and private creator and removed unless retained by recorded decision. Where pixel inspection or masking is configured, the Burned In Annotation attribute is not relied upon as conclusive evidence that no text is present.
5.2 Where CM-Connect pseudonymization functionality is enabled, the configured treatment is applied before transmission from the Customer's network to CM. CM-Connect establishes outbound connections and records the technical actions performed.
5.3 Replacement identifiers. Where CM-Connect replaces source identifiers, any mapping or additional information specifically enabling those replacement identifiers to be related to originating identifiers may be retained at the originating site and is not transmitted to CM. CM does not possess or access that additional information. This does not guarantee that no other identifying information remains in the Content and does not make the Content anonymous by default (requires specific configurations and other separate assessments to be agreed).
5.4 CM-Connect may apply the rules configured for a channel and record the treatment applied. The technical availability, configuration or application of those rules does not itself transfer responsibility for preparation of Content to CM. Responsibility is allocated under clauses 5.12 to 5.18.
5.5 File types. CM-Connect is designed principally for DICOM Content. Other file types may be accepted where relevant functionality is enabled. Acceptance of a file by CM-Connect or the Platform does not mean that the file type is supported for pseudonymization, that an applicable treatment has been successfully performed, or that the file is Pseudonymized, De-identified or anonymous. Unless expressly covered by the applicable Service Order, the Customer must verify non-DICOM and non-standard files separately.
5.6 Whole slide images. Where the Customer uploads whole slide images, embedded labels and macro images must be addressed in accordance with the applicable Data Specification and verified separately from metadata treatment. Removal of metadata does not by itself remove information rendered into those images.
5.7 The Customer is responsible for the server on which CM-Connect runs, including its security, patching, availability, backup and physical protection, and for the network configuration permitting it to operate. This general principle applies unless otherwise expressly agreed, in which case it will be subject to charges and additional agreements. The classes of data CM-Connect may query and retrieve are limited to those stated in the Service Order, and neither party may configure it to retrieve data outside that scope.
5.8 Web upload. Where Content is uploaded through the web interface, standard technical pseudonymization functionality may apply according to the applicable configuration. Web upload does not create the same technical and physical pre-transmission barrier as CM-Connect. Content uploaded through the web interface may reach CM infrastructure before or as that functionality is applied. The Customer must therefore satisfy its obligations under clauses 5.10 and 5.13 independently of the availability of that functionality.
5.9 CM-Connect is not available on an individual-user subscription. An individual subscriber uploads through the web interface unless expressly agreed otherwise, and normally this transforms an individual subscription into a customer that requires the signature of specific separate agreements, such as a master services agreement.
5.10 Upload warranty by the User. On each upload you warrant that, at that time: the Content complies with the applicable Data Specification; the Customer is authorized to upload and use the Content for the purpose for which it is being uploaded; the processing is lawfully authorized as required by clause 18.5; you have not entered identifying information into a field contrary to these Terms (specially clause 3); and you are not aware of a circumstance rendering the Content Non-Conforming Content.
5.11 CM records the identity of the person giving the warranty in clause 5.10, the time, the item concerned and the version of the text accepted.
Responsibility for preparation
5.12 Where CM is expressly engaged to prepare Content. Where the applicable Service Order expressly records that the Customer procures a CM pseudonymization or de-identification service in respect of a category of Content, whether through CM-Connect or another agreed method, CM is responsible for applying the treatment expressly described in that Service Order. That responsibility is limited to the agreed treatment and scope. The availability, configuration, or use of CM-Connect or web upload does not by itself constitute procurement of that service. Unless the Service Order expressly provides otherwise, CM does not represent that the resulting Content is pseudonymized, anonymous, validly De-identified under HIPAA, or outside applicable data protection law.
5.13 Where CM is not expressly engaged to prepare Content. Where the Service Order does not expressly record a CM pseudonymization, anonymization, or de-identification service, the Customer remains responsible for preparation, treatment, and verification of the Content. Any standard technical functionality available through CM-Connect or web upload is an additional technical control and does not transfer that responsibility to CM or constitute a warranty of its legal outcome. If that functionality is disabled or does not apply to the relevant file type, the Customer remains responsible for ensuring that the Content has been lawfully prepared before transmission.
5.14 Individual subscriptions. Unless the applicable Service Order expressly records a CM pseudonymization or de-identification service for an individual subscription, the clause above applies. The Individual Account Policy states the additional requirements applying to an individual subscription and the warranties on which CM relies.
5.15 Anonymization is a separate service. CM performs anonymization only where the applicable Service Order expressly records anonymization as a service and identifies its scope, method, assessment and agreed deliverables. Standard pseudonymization functionality and a pseudonymization service are not, by themselves, an anonymization service. Clause 12.9 applies except to the extent that an applicable Service Order expressly provides otherwise.
5.16 Identifying information received contrary to these Terms. Where Content transmitted to CM contains identifying information contrary to these Terms or the applicable Data Specification, that Content is Non-Conforming Content. Except to the extent the event results from CM's failure to perform a specific treatment expressly undertaken in the applicable Service Order, responsibility for the upload remains with the Customer, including where the Content was uploaded by an Authorized User.
5.17 CM's receipt, acceptance, storage or processing of Content, the application of standard technical functionality, the ability of CM-Connect or web upload to accept the file type, or the failure of an automated control to detect identifying information does not transfer responsibility for the upload to CM.
5.18 If CM becomes aware of, or reasonably suspects, that such Content has been received, CM will treat the matter as an information security and data protection incident and may take the investigation, containment, restriction, quarantine and remediation measures provided for in these Terms. Nothing in this clause limits an obligation imposed directly on CM under applicable law, the Data Processing Agreement or the Business Associate Agreement.
6. Ingestion controls
6.1 CM operates automated and non-automated ingestion controls. Those controls may inspect Content on and after ingestion for indications of Non-Conforming Content and may reject, flag or quarantine Content.
6.2 The Customer must not transmit to CM any key, code, mapping table or other additional information that would enable replacement identifiers to be linked to the corresponding source identifiers, unless the applicable Service Order expressly permits it. Where CM-Connect is used, clause 5 describes how that additional information is kept separate from the Content transmitted to CM. Where Content is uploaded through the web upload/interface, standard technical pseudonymization functionality may be applied, but the Content may reach CM infrastructure before or while that functionality is applied, and the functionality may be disabled, differently configured or unavailable for a particular file type.
6.3 The controls in this clause cannot detect every instance of Non-Conforming Content. Acceptance of Content by the Platform is not a confirmation that the Content complies with the Data Specification, is not a warranty, and is not evidence that a warranty was correctly given. Operation or failure of a control does not transfer the Customer's responsibility for preparation, treatment or verification except to the extent CM expressly undertook a specific treatment in the applicable Service Order.
6.4 On identifying Content that CM reasonably believes to be Non-Conforming Content, CM may immediately restrict access to it, place it in quarantine, suspend a Release State applying to it, invalidate an access link or code, and require the Customer to remediate or delete it. CM may reject Content before ingestion or isolate it where reasonably necessary to protect individuals, the Customer, other customers, the Platform or CM's compliance with applicable law. CM will not permanently delete Customer Content solely under this clause except on the Customer's documented instruction, where required by applicable law, or where expressly permitted by the Data Processing Agreement or Business Associate Agreement.
6.5 CM will notify the Customer promptly. Each party must provide the other with information within its control reasonably required to investigate, contain and remediate the incident and determine whether a notification obligation arises.
Note. The presence of identifying information or Non-Conforming Content does not by itself establish that a "personal data breach" within the meaning of the GDPR or a "breach" within the meaning of HIPAA has occurred. Where CM acts as processor, the Data Processing Agreement governs notification to the controller. Where CM acts as a business associate, the Business Associate Agreement governs applicable HIPAA notification. Nothing in this Note limits a mandatory obligation imposed by law.
7. Release States and Sharing
7.1 Every item of Content is in one of the Release States below. The Release State determines who may access the Content and the Data Specification with which it must comply.
| Release State | Permitted access | Conditions |
| 1. Private area | The uploading Authorized User only | Default on upload. Baseline Data Specification. |
| 2. Project | Authorized Users admitted to the Project, who may belong to more than one organization | Baseline Data Specification. The Lead Party controls admission. Normal state for Clinical Trials, studies and collaborations. |
| 3. Customer | All Authorized Users of the Customer | Baseline Data Specification. |
| 4. Teaching session | Persons holding the access link and code during the validity period | Enhanced Data Specification, the Education and Teaching Policy, and acceptance by each Session Viewer. |
| 5. Transfer to another Customer | The receiving Customer within its own Customer environment | Available only where the applicable Service Order permits it and subject to clause 7.5. |
| 6. Public | Not offered | The Platform provides no public Release State. |
7.2 A Release State may be changed or withdrawn at any time by the originating Authorized User or Customer administrator. Withdrawal removes prospective access only and does not undo access already exercised or alter records already created. It does not authorize continued access, use, or disclosure after access has been withdrawn except as otherwise permitted by these Terms, the applicable Service Order, or applicable law.
7.3 Content prepared only for the baseline Data Specification must not be placed in releases for a teaching session (Release State 4) and must first satisfy the enhanced Data Specification.
7.4 In a Project involving more than one organization, each participating organization remains responsible for its own Authorized Users and the Content it contributes.
7.5 A transfer to another Customer requires authorization by the originating Customer and acceptance by the receiving Customer, a stated purpose, and a record of the transfer identifying the Content, both Customers, the purpose, date, and authorizing persons. Replacement identifiers must not be carried across where doing so would preserve an unnecessary link between the two Customer environments.
8. Egress
8.1 Any assessment of identifiability or anonymity is contextual and is reached by reference to the environment in which information is held, the persons who may access it, and the means reasonably likely to be available to them. A copy removed from the Platform does not carry that conclusion with it.
8.2 Content. Export of a limited number of static images for a lecture or conference is permitted only where the applicable Service Order provides for it, up to the applicable limit, and only from material prepared to the enhanced Data Specification. Export in a consumer image format may discard file attributes while preserving information rendered into the image and therefore does not itself address text rendered into image data or a visible slide label. Export under this clause is an exception to clause 3.5. The other restrictions in these Terms continue to apply.
8.3 Results other than models and datasets. Tables, measurements, statistics and figures may be removed from the Platform, and CM does not restrict publication. They must not contain identifying information, incorporate another Customer's Content, or be presented in a manner that permits an individual to be identified or singled out. Small subgroups and extreme values may create such a risk even where no direct identifier is present. Any publication remains the responsibility of the party publishing or authoring it, and unless otherwise explicitly agreed, CM assumes no responsibility for publications made using data on CM’s Platform.
8.4 Derived datasets. A dataset constructed within a Project may be removed following an assessment, performed or accepted by CM, appropriate to the derived dataset and the environment into which it will be released, taking the assessment of the source Content into account. CM will not unreasonably withhold agreement. Agreement is not required where the applicable Service Order already expressly provides for delivery of that dataset. This clause manages identifiability and does not determine ownership.
8.5 Trained models. Export of model weights, or making a trained model available outside the Project, requires CM's prior written agreement and an assessment appropriate to the model and target environment. CM will not unreasonably withhold agreement. CM acquires no ownership interest in the model by reason of this clause.
Note. The assessment addresses relevant risks including memorization and membership inference. Both risks may increase where a model is trained on a small or distinctive cohort. CM's agreement or assessment under this clause is an egress and identifiability control. It does not establish that the Customer has a legal basis, authorization or other right to export or use the model.
8.6 Nothing in this clause permits screen capture, photography of a display or screen recording, which are prohibited in every Release State and for every category of Content and Results.
9. The Viewer
9.1 Except for the Viewer described in this clause, the Platform is not placed on the market by CM as a medical device. CM does not represent that the Platform as a whole holds a medical device approval, marking or certification. Medical images are displayed using the Viewer, which is a separate medical device component.
9.2 The Viewer and its manufacturer. The Viewer is MedDream. Current manufacturer documentation identifies MedDream UAB, K. Petrausko st. 26, LT-44156 Kaunas, Lithuania, as the manufacturer. CM is not the manufacturer and did not design the Viewer. The version of the Viewer made available through the Platform is identified by CM in the Platform or applicable Documentation.
9.3 Regulatory status. Current manufacturer documentation identifies MedDream as a Class IIb medical device under Regulation (EU) 2017/745, with notified body identification number 0197, and as FDA cleared under K222320. The regulatory certification and clearance relate to the Viewer and do not extend to the Platform as a whole or constitute a CM certification.
9.4 Intended purpose. The intended purpose of the Viewer is determined by its manufacturer. The Customer and Authorized Users must use the Viewer consistently with the manufacturer's applicable instructions for use. Use outside the manufacturer's intended purpose falls outside the manufacturer's conformity assessment.
9.5 Who may use it. The Customer is responsible for ensuring that use of the Viewer is limited to persons who satisfy the qualifications and user requirements stated in the manufacturer's documentation.
9.6 Mammography. Where the Viewer is used for mammography or another use subject to specific manufacturer conditions, the Customer and Authorized User must comply with those conditions. CM does not independently verify whether the Customer's source images, display or local environment satisfy them.
9.7 Mobile and other displays. The Customer and each Authorized User must comply with manufacturer requirements applicable to the display on which images are viewed. CM does not warrant that a device, browser, monitor or network controlled by the Customer satisfies those requirements.
9.8 No modification by CM. CM does not change the intended purpose of the Viewer or modify it in a manner intended to affect its compliance as placed on the market. Where a requested configuration would require CM to assume obligations of a manufacturer, CM may decline that configuration.
Note. Article 16 of Regulation (EU) 2017/745 provides circumstances in which a distributor, importer or other person may assume obligations incumbent on a manufacturer, including where it makes a device available under its own name or trademark subject to the applicable exception, changes the intended purpose, or modifies a device in a way that may affect compliance.
9.9 Version and manufacturer support. CM will use a Viewer version within the manufacturer's applicable supported lifecycle and will manage updates in accordance with CM's change-management processes. CM identifies the Viewer version currently made available through the Platform and will make that information available to the Customer on request.
9.10 Documentation on request. CM will identify the manufacturer and make applicable manufacturer documentation available to the Customer where reasonably required.
9.11 Incidents and field safety notices. The Customer and Authorized Users must notify CM without delay of a suspected malfunction, deterioration in performance or other safety issue concerning the Viewer. CM will transmit information to the manufacturer where appropriate and will communicate relevant field safety notices or corrective actions received from the manufacturer to affected Customers. Nothing in this clause replaces a reporting obligation imposed directly on a Customer or Authorized User by applicable law.
9.12 Teaching material. Teaching Content made available under releases for a teaching session (Release State 4) is for teaching only and must not be used for diagnosis, treatment or a clinical decision.
9.13 The rest of the Platform. Apart from the Viewer, no other part of the Platform is intended by CM to perform a diagnostic function or is placed on the market by CM as a medical device. An opinion, measurement or annotation recorded by an Authorized User is that person's own. CM does not review or endorse it.
10. Service levels, support and professional services
10.1 Availability, support coverage, severity levels, response and resolution targets, service metrics, and the responsibilities of CM and the Customer in relation to support are set out in the Service Level Agreement. The Service Level Agreement applies by default unless the applicable Service Order expressly provides otherwise.
10.2 CM may suspend access for planned maintenance and, where necessary to protect the Platform or Content, for emergency maintenance. CM will use reasonable efforts to give advance notice of planned maintenance where practicable.
10.3 The Platform is not a system of record and must not be relied on as the sole authoritative repository of Content. The Customer is responsible for retaining any source or other authoritative record required for its purposes and obligations.
10.4 Professional services. Implementation, site onboarding, channel configuration, integration, migration and training are provided only where an applicable Service Order provides for them. A Service Order is subject to these Terms and varies them only where it expressly says so.
11. Security, processors and subprocessors and hosting
11.1 CM security commitments. CM will implement and maintain the technical and organizational security measures and other security obligations constituting the applicable CM Security Commitments.
11.2 11.2 Customer-side security and connectivity. The Customer is responsible for procuring and maintaining suitable internet and telecommunications connectivity for access to the Platform and for the security, configuration and operation of the systems, local networks and devices under its control that are used to access the Platform. The Customer is also responsible for any identity provider or single sign-on environment under its control, including the administration and withdrawal of user access through that environment, and for the infrastructure on which CM-Connect runs under clause 5.7.
11.3 CM engages subprocessors identified in the Subprocessor List. Notification of changes and the Customer's right to object are governed by the Data Processing Agreement.
11.4 Content is hosted in the region stated in the Service Order and, where none is stated, in a region within the European Union (Standard: Germany, Frankfurt).
11.5 Certifications and attestations held by CM's hosting provider relate to infrastructure operated by that provider and do not evidence CM's own certification. CM holds ISO/IEC 27001:2022 certification in respect of its information security management system.
11.6 CM does not represent that Content is beyond the reach of a lawful access request made to CM or a subprocessor by a public authority. On receipt of a request affecting Content, CM will, so far as lawfully permitted, notify the Customer, challenge a request that appears unlawful or excessive where appropriate, and disclose only what CM is legally required to disclose.
11.7 Audit. The Customer may verify CM's compliance with the applicable CM Security Commitments and its obligations under the Data Processing Agreement by written questionnaire and review of relevant reports and certifications. Except where a greater audit or verification right is required by the Data Processing Agreement, applicable law or a competent supervisory authority, or where additional verification is reasonably required following a material security or data protection incident, Customer-initiated verification may be exercised once in any twelve-month period on reasonable advance notice.
12. Warranties
12.1 CM undertakes that the services will be performed substantially in accordance with the applicable Service Order, these Terms, the applicable CM Security Commitments and Service Level Agreement, and with reasonable skill and care.
12.2 CM warrants that it holds and will maintain the licenses, consents and permissions necessary to perform its obligations under these Terms and the applicable Service Order and that it has the right to make the Platform available.
12.3 The undertaking in clause 12.1 does not apply to a non-conformity caused by use contrary to CM's instructions or Documentation, or by modification of the services by a person other than CM or a person authorized by CM.
12.4 Remedy for service non-conformity. Where the services do not conform to clause 12.1, CM will at its own expense use reasonable commercial efforts promptly to correct the non-conformity or provide an alternative means of achieving the intended performance. That correction or alternative is the Customer's remedy for the functional service non-conformity itself. It does not limit remedies arising from a separate breach of the CM Security Commitments, Data Processing Agreement, Business Associate Agreement or another independently applicable obligation.
12.5 Loss of Content. In the event of loss of or damage to Content, CM will use reasonable commercial efforts to restore affected Content from an available backup maintained by CM where restoration is technically possible. This clause does not limit liability arising from a separate breach of CM's obligations under the CM Security Commitments, Master Services Agreement, Service Orders, Data Processing Agreement, Business Associate Agreement or applicable law. CM remains responsible for subprocessors as provided in the Data Processing Agreement and these Terms.
12.6 The Customer, and not CM, is responsible for the results obtained from its use of the Platform and for conclusions it draws from that use. CM is not responsible for loss to the extent caused by inaccurate or incomplete information, instructions, configurations or scripts supplied by the Customer or action taken by CM on the Customer's documented instructions.
12.7 CM is not responsible for delay, unavailability, degradation or failure of the services to the extent caused by the Customer's systems, devices, local network or internet connectivity, or by telecommunications networks, internet service providers or other systems outside CM's reasonable control
12.8 Nothing in these Terms prevents CM from entering into similar agreements with other parties or independently developing, using, selling or licensing products or services similar to those provided under these Terms, provided that CM complies with clause 13 and its confidentiality and data protection obligations.
12.9 Warranties not given. Except to the extent expressly stated in an applicable Service Order, CM does not warrant that: Content is anonymous or has ceased to be personal data; data protection law no longer applies to Content; identification is impossible or the risk of identification is zero; a transformation removes every item from which an individual could be identified; the controls in clause 6 will detect every instance of Non-Conforming Content; an identifiability conclusion will remain valid over time or apply in another environment; a trained model contains no information derived from its training data; Content is De-identified under 45 CFR 164.514(b) or outside HIPAA; compliance with the GDPR constitutes compliance with HIPAA or vice versa; Content supplied by a user is accurate or clinically correct; use of the Platform will be uninterrupted or error-free; or the Platform is free from all vulnerabilities or malicious code.
12.10 Except as expressly stated in these Terms, the applicable Service Order, CM Security Commitments, Service Level Agreement, Data Processing Agreement or Business Associate Agreement, the Platform and Documentation are provided on an "as is" basis to the maximum extent permitted by law.
12.11 No statement made in a proposal, presentation, questionnaire response or other communication constitutes a warranty or representation unless expressly stated as such in these Terms, a Service Order, or another document signed or accepted by CM as containing that warranty or representation. This clause does not exclude liability for fraudulent misrepresentation.
12.12 Except as expressly stated in these Terms or an applicable Service Order, warranties, conditions and terms implied by law are excluded to the maximum extent permitted by applicable law.
13. Content, Ownership, Intellectual Property, Results and machine learning
13.1 Content. Ownership of Content remains with the person or organization entitled to it under the arrangements applicable to the relevant Project. Nothing in these Terms transfers ownership of Content to CM.
13.2 Results. Results belong to the Customer or such other person as the Customer's applicable arrangements provide. CM claims no ownership of or share in the exploitation of Results.
13.3 Export and portability. Export of Results is subject to clause 8. Export of Content is permitted only to the extent clause 8, the applicable Service Order and applicable data protection documentation allow. Return of Content on termination is governed by clause 15.4 and the Data Processing Agreement. Where CM provides an export, it will use a structured, commonly used and machine-readable format where reasonably available.
13.4 CM does not restrict publication of Results. Clause 8.3 governs what a publication must not contain. CM does not require sight of approval of or attribution in a publication unless expressly agreed for a specific service.
13.5 Consortiums. Where a Project is conducted by a consortium, ownership, access, publication and exploitation between participants are governed by the Consortium Agreement or equivalent applicable policy and any applicable consortium agreement. The Research Consortium Policy regulates this in more detail.
13.6 Operating right. The Customer grants CM a non-exclusive right to host, store, copy, transmit, render, index and otherwise process Content solely to the extent necessary to provide the services, comply with lawful instructions and perform CM's obligations. CM may exercise that right through CM Group companies and subprocessors engaged consistently with the Data Processing Agreement.
13.7 The right in clause 13.6 does not permit CM to publish Content, use Content for marketing, license Content for an independent purpose, or disclose Content to a person not entitled to receive it. This does not prevent disclosure to CM Group companies, subprocessors or other service providers solely to the extent necessary to provide the services and subject to applicable confidentiality and data protection obligations.
13.8 CM may use Content in marketing or promotional material only with written consent identifying the material and intended use. A general consent is not sufficient and may be withdrawn prospectively.
13.9 Machine learning by CM. CM will not use Content to develop, train, fine-tune, validate or evaluate a machine learning model for CM's own purposes, will not retain Content or a representation derived from Content in the parameters of a model for CM's own purposes, and will not sell, license or make Content available to another person for those purposes, except as clause 13.10 expressly permits.
13.10 Clause 13.9 does not prevent processing necessary to provide the services, operate security and ingestion controls, prevent abuse, or operate a model within a Customer's Project at the instruction of the Customer or other person entitled to instruct CM. Where such processing involves training or adaptation on Content, it must fall within the agreed Project purpose and applicable Service Order.
13.11 Machine learning by the Customer. The Customer may develop, train, fine-tune, validate and evaluate models on Content within its own Project where it is entitled to use that Content for that purpose. Clause 8.5 applies to a model leaving the Project.
13.12 Clause 13.9 is a material term for the purposes of clause 15.3.
13.13 CM owns the Platform and all rights in it other than rights in third-party components. The Customer receives no right in the Platform other than the right to use it under these Terms. CM may use feedback provided by the Customer without acquiring any right in Content or Results.
13.14 CM may generate and use aggregated statistics concerning use and performance of the Platform where those statistics contain no Content and do not identify a Customer, Authorized User, Session Viewer, patient or participant.
14. Fees
14.1 Fees, plan, billing period and limits are stated in the applicable Service Order. Limits apply in aggregate across the Customer unless the Service Order provides otherwise.
14.2 Where usage exceeds a contractual limit, and the Service Order provides an overage rate, the applicable overage charge may be invoiced at that rate.
14.3 Before invoicing an overage charge, CM will notify the Customer's administrator and give the Customer a reasonable opportunity to address the excess where the nature of the service permits it.
14.4 CM may introduce a new category of usage metric for a future renewal term on at least sixty days' notice before the end of the then-current term. The Customer may elect not to renew before the new metric takes effect.
14.5 Invoices are generally payable within thirty days of the invoice date unless the Service Order provides otherwise. CM may suspend access for an overdue invoice after giving reasonable written notice. Suspension does not relieve the Customer of the obligation to pay. Fees are exclusive of applicable taxes and duties.
15. Term, suspension and termination
15.1 The term is stated in the Service Order. Unless the Service Order provides otherwise, an institutional subscription has a term of twelve months and renews for successive twelve-month terms unless either party gives notice not to renew at least thirty days before the end of the then-current term.
15.2 CM may suspend access, in whole or in part, immediately where it reasonably believes that Non-Conforming Content has been uploaded, clause 3 has been breached, continued access presents a material risk to Content or the Platform, or continued access would cause either party to act unlawfully. CM will notify the Customer promptly where legally and operationally practicable and restore access when the ground for suspension has been resolved.
15.3 Either party may terminate for material breach not remedied within thirty days after written notice where the breach is capable of remedy. A breach identified in clause 3.15 may be treated as incapable of remedy where its nature justifies immediate termination.
15.4 Return and deletion. On termination, return or deletion of personal data is governed by the Data Processing Agreement and, where applicable, the Business Associate Agreement. CM will follow the Customer's documented instruction and any retention expressly agreed in the applicable Service Order, subject to applicable law. A return required under this clause or the Data Processing Agreement is not prohibited by clause 8.
Note. Article 28(3)(g) GDPR requires the processor, at the controller's choice, to delete or return personal data after the end of the provision of services unless applicable law requires storage. The Data Processing Agreement prevails on that matter.
15.5 Where Content has been removed from the Platform under a permission that requires its return or destruction, the Customer must comply with that requirement on termination.
15.6 Where an Authorized User is deactivated, the Customer administrator may direct that Content in that person's private area be transferred to another Authorized User, transferred to the Customer administrator or deleted. CM will not treat deactivation of the individual as authority to delete Customer Content unless the Customer so instructs.
15.7 Clauses 3.14, 5.17 to 5.19, 6.4, 6.5, 8, 12, 13, 16, 17, 20, 22 and 23, and any provision which by its nature is intended to survive, survive termination.
16. Liability and indemnities
16.1 Subject to clause 16.2, neither party is liable for loss of profit, revenue, anticipated saving, business or goodwill, or for indirect or consequential loss.
16.2 Customer liabilities not excluded. Clause 16.1 does not limit or exclude the Customer's liability for death or personal injury caused by its negligence or the negligence of its Authorized Users, fraud or fraudulent misrepresentation, gross negligence or willful misconduct, the Customer's obligation to pay Fees, or any liability of the Customer that cannot lawfully be limited or excluded. The Customer remains responsible for its Authorized Users as provided in clause 4.4. Nothing in these Terms excludes or limits any liability of the parties that cannot lawfully be excluded or limited.
16.3 Customer indemnity. To the extent permitted by law, the Customer will indemnify CM against a third-party claim, lawfully recoverable regulatory fine, loss, cost or expense to the extent arising from: Non-Conforming Content uploaded by the Customer or its Authorized Users; breach of clause 3 by the Customer or its Authorized Users; absence of the legal authority required for Content uploaded or instructions given; or a third-party claim that Content supplied by the Customer infringes that person's rights. The indemnity does not apply to the extent the claim, fine, loss, cost or expense was caused or contributed to by CM's breach of these Terms, the Data Processing Agreement, Business Associate Agreement or applicable law. The Customer will also reimburse reasonable and documented incident-response costs actually incurred by CM to the extent caused by a matter for which the Customer is responsible under this clause.
16.4 CM intellectual property indemnity. CM will indemnify the Customer against a third-party claim that the Platform, as provided by CM and used in accordance with these Terms, infringes that third party's intellectual property rights. This does not apply to a claim arising from Content or Results, a modification not made or authorized by CM, or use outside these Terms. CM may, at its option, obtain the right for continued use, modify or replace the affected element with a substantially equivalent non-infringing element, or terminate the affected service and refund prepaid Fees attributable to the unused terminated period.
16.5 Time limit for contractual claims. A party asserting a contractual claim must notify the other in writing, identifying the event and grounds in reasonable detail, within six months after it became or reasonably should have become aware of the event, and commence proceedings within one year after that date. For a third-party indemnity claim, the notification period starts when the indemnified party receives or becomes aware of that claim. This clause does not apply to liability within clause 16.2 or where mandatory law provides otherwise.
16.6 Indemnity procedure. An indemnity is conditional on the indemnified party notifying the other promptly, not admitting liability or settling without consent, and providing reasonable cooperation. Control of a defense by the indemnifying party applies only to the extent legally permissible and must not prevent the indemnified party from complying with an obligation to a court, regulator, supervisory authority or other competent authority. Each party must take reasonable steps to mitigate loss.
17. Enforcement
17.1 Where CM reasonably believes these Terms have been breached, it may take one or more proportionate steps, in any order and without first exhausting another remedy.
| Step | Trigger |
| Requirement to remediate by a stated date | A breach capable of remedy |
| Restriction of an individual account | Breach by an identified individual |
| Immediate suspension | A ground in clause 15.2 |
| Invalidation of access links or codes | Non-Conforming Content has been released or access credentials have been compromised |
| Prevention of an export | An export contrary to clause 8 |
| Termination for cause | A ground in clause 15.3 |
| Recovery of costs | A matter within clause 16.3 |
| Notification to the Customer | A breach by an Authorized User |
| Report to a professional or supervisory body | Conduct that reasonably appears to constitute a serious breach of professional obligations or applicable law. Regarding Privacy and Data Protection, when acting as Processor, no communication is directly made to the supervisory body unless expressly agreed and/or required by law. |
| Injunctive relief | A threatened or continuing breach of a provision identified in clause 3.15 |
17.2 Before making a report to a professional or supervisory body, CM will consider whether a less intrusive step would adequately address the matter, record its reasons, and inform the individual concerned unless doing so would prejudice an investigation, contravene law or place data at further risk.
17.3 Records. CM records information reasonably necessary to establish relevant activity on the Platform, including who uploaded Content and when, the version of contractual text accepted where recorded, the outcome of applicable controls, Release State changes, exports and access events. CM may rely on those records in support of enforcement or compliance activity.
17.4 The Customer must cooperate with a reasonable investigation by CM into a suspected breach affecting patient or participant data and provide information within its control reasonably required for that investigation. This does not require disclosure of additional identifying information to CM unless lawfully necessary.
17.5 Nothing in this clause limits obligations imposed directly by applicable law, the Data Processing Agreement, Business Associate Agreement, or a competent supervisory or regulatory authority.
18. Compliance with laws
18.1 Each party will comply with laws applicable to it in connection with these Terms.
18.2 Export control and sanctions. Each party will comply with applicable export-control and sanctions laws. The Customer must not knowingly permit access to the Platform where doing so would breach those laws.
18.3 Anti-bribery. Each party will comply with applicable anti-bribery and anti-corruption laws and will not offer or accept an improper payment or advantage in connection with these Terms.
18.4 Approvals and regulatory responsibilities. The Customer must ensure that the authorizations, permits, approvals and ethics opinions required for its use of the Platform are in place and that it is authorized to instruct CM in reliance on them. Where the Customer acts as processor on behalf of another controller, this does not transfer to the Customer a responsibility that applicable law assigns to the controller, sponsor or another party. CM is responsible for regulatory requirements applicable to CM in providing the Platform and for the matters expressly allocated to CM under clause 9.
Legal basis and permitted use
18.5 Lawful processing. The Customer must ensure that processing it initiates or instructs on the Platform is lawfully authorized for each Project and purpose. Where the Customer acts as controller, it is responsible for determining, documenting and being able to demonstrate the applicable Article 6 GDPR basis and, for Health Data, the applicable Article 9 GDPR condition. Where the Customer acts as processor on behalf of another controller, the Customer must be authorized to instruct CM and must ensure that its instructions are consistent with its obligations to that controller. Where HIPAA applies, the Customer is responsible for ensuring that the relevant use or disclosure is permitted under HIPAA or supported by any authorization required by HIPAA. CM does not select or verify the Customer's legal basis merely by accepting Content.
18.6 Illustrative common legal frameworks. The table below is provided solely for general orientation and is not exhaustive. It does not determine, establish or confirm the legal basis, Article 9 condition, HIPAA permission, authorization, waiver or other legal requirement applicable to any particular Project or use of the Platform. The Customer and, where different, the relevant controller remain responsible under clause 18.5 for determining and documenting the applicable legal basis and other legal requirements. CM does not select, determine or verify those requirements merely because a use case is described below.
| Use of the Platform | GDPR | HIPAA where applicable |
| Clinical Trial | The applicable Article 6 basis and Article 9 condition depend on the controller's role, the purpose of the processing and applicable Union and Member State law. Depending on the circumstances, Article 6(1)(c), (e) or (f), and Article 9(2)(i) or (j), may be relevant where their respective requirements are met. Informed consent to participate in a Clinical Trial is distinct from the GDPR legal basis for processing personal data and does not by itself establish that basis. | Depending on the circumstances, a HIPAA authorization, a waiver or alteration of authorization under 45 CFR 164.512(i), or the use or disclosure of a Limited Data Set under 45 CFR 164.514(e) with an appropriate data use agreement may be relevant. |
| Consultation or second opinion | The controller must determine the applicable Article 6 basis. Article 9(2)(h), read together with Article 9(3), may be relevant where the processing is necessary for medical diagnosis, the provision of healthcare or another purpose falling within that provision and its requirements are met. | Disclosure of Protected Health Information to another healthcare provider for treatment may be permitted under 45 CFR 164.506(c)(2), subject to the applicable requirements of HIPAA. |
| Research outside a Clinical Trial | The controller must determine the applicable Article 6 basis and Article 9 condition. Article 9(2)(j) may be relevant where the processing is necessary for scientific research in accordance with applicable Union or Member State law and the safeguards required by Article 89(1) are satisfied. Other bases or conditions may apply depending on the circumstances. | Depending on the circumstances, a HIPAA authorization, a waiver or alteration under 45 CFR 164.512(i), or the use or disclosure of a Limited Data Set under 45 CFR 164.514(e) with an appropriate data use agreement may be relevant. |
| Teaching and professional education | The applicable Article 6 basis and Article 9 condition must be determined specifically for the teaching use. Article 9(2)(a) may be relevant where valid explicit consent has been obtained. In limited circumstances, Article 9(2)(h), read together with Article 9(3), may be relevant where the teaching activity forms part of healthcare provision or another activity falling within that provision and all applicable requirements are met. A legal basis or Article 9 condition applicable to research does not by itself authorize a teaching use. | Certain supervised healthcare training activities may qualify as healthcare operations under 45 CFR 164.501 and may be permitted under 45 CFR 164.506. Other teaching uses may require an authorization or another applicable HIPAA permission. |
18.7 GDPR and HIPAA are not interchangeable. Valid De-identification under 45 CFR 164.514(b) takes information outside HIPAA but does not by itself establish that information is anonymous under the GDPR. A Limited Data Set remains Protected Health Information under HIPAA, and its status under the GDPR must be assessed independently. Pseudonymized data remain personal data where the GDPR applies. Compliance with one regime does not establish compliance with the other.
18.8 Where CM is a business associate. Where the Customer is a Covered Entity, or a business associate acting on behalf of one, and CM processes Protected Health Information on its behalf, the parties must have a Business Associate Agreement in place before that Protected Health Information is uploaded. The Business Associate Agreement governs matters required by HIPAA and prevails on those matters.
18.9 Vulnerability reporting. A vulnerability affecting the Platform should be reported to CM with sufficient detail to allow investigation. A reporter must not access, alter, copy or disclose data belonging to another person and must not disclose the vulnerability publicly before CM has had a reasonable opportunity to address it. CM will not pursue a person who reports a vulnerability in good faith within those limits.
19. Evaluation features, components and APIs
19.1 Evaluation features. A feature identified as beta, preview, pilot or evaluation is provided on an evaluation basis, may be modified or withdrawn, and is excluded from the functional undertaking in clause 12.1 and from the Service Level Agreement unless otherwise stated. Health Data may be used with an evaluation feature only where the Service Order expressly permits it. Where Health Data is permitted, the CM Security Commitments, Data Processing Agreement and Business Associate Agreement continue to apply according to their terms.
19.2 Third-party and open-source components. The Platform incorporates third-party and open-source components. License terms applicable to a component apply to the extent legally required. They do not reduce CM's obligations under the Data Processing Agreement, Business Associate Agreement, CM Security Commitments, or confidentiality provisions unless expressly agreed with the Customer to the extent legally permissible. Clause 9 governs the Viewer.
19.3 Interfaces. Where CM makes an application programming interface available, it must be used in accordance with its Documentation and applicable rate limits. CM may modify an interface on reasonable notice and will provide a reasonable transition period for a materially non-backward-compatible change where practicable.
19.4 Non-production environments. A sandbox, test or training environment must not contain Health Data relating to an identifiable individual unless the applicable Service Order expressly permits it. Where Health Data is expressly permitted, applicable security, data protection and Business Associate Agreement obligations continue to apply.
20. Confidentiality and publicity
20.1 Each party will keep confidential the other's non-public information disclosed in connection with these Terms, use it only for purposes connected with these Terms, and disclose it only to Affiliates, personnel, contractors, subprocessors, professional advisers and service providers who need it for those purposes and are subject to appropriate confidentiality obligations. This does not apply to information that becomes public without breach, was lawfully known without an obligation of confidence, is independently developed, or must be disclosed by law or a competent authority. Where lawfully permitted, the disclosing party will give appropriate notice of a compelled disclosure.
20.2 Confidentiality obligations concerning Content are additional to, and do not replace, clause 3 or the Data Processing Agreement. A contractual permission to disclose is not itself a GDPR legal basis.
20.3 Publicity. Neither party may use the other's name, logo or trademarks in publicity without prior written consent. Consent to identify the Customer as a customer may be given in a Service Order and may be withdrawn prospectively on reasonable notice. No consent to publicity extends to Content.
21. Changes to these Terms
21.1 CM may amend these Terms. Where an amendment is material and adverse to the Customer, CM will give at least sixty days' notice and, for an institutional subscription, the amendment will take effect at the start of the next renewal term. An amendment required by law or reasonably necessary to address a security or safety risk may take effect on shorter notice where the circumstances require.
21.2 CM will notify the Customer's administrator and publish the amended Terms with a revision or effective date. Superseded versions are available on request.
21.3 Where a material and adverse amendment is not required by law or an urgent security or safety risk, the Customer may elect not to renew before it takes effect.
21.4 Data Specification changes. A more demanding Data Specification applies prospectively to Content uploaded after its effective date unless the applicable Service Order expressly provides that existing Content must be reprocessed.
22. General
22.1 Assignment. The Customer may not assign or transfer these Terms without CM's written consent, not to be unreasonably withheld in connection with a legitimate corporate reorganization. CM may assign or transfer its rights and obligations to a CM Group company or in connection with a merger, reorganization or sale of the relevant business or assets, provided the assignee assumes CM's applicable obligations.
22.2 Force majeure. Neither party is liable for failure to perform caused by an event beyond its reasonable control, provided it takes reasonable steps to mitigate and resume performance. This does not apply to an obligation to pay amounts already due.
22.3 Notices. Contractual notices must be in writing. Notices to CM may be sent to its registered address and the address published for legal notices. Notices to the Customer may be sent to the administrator contact recorded for the Customer.
22.4 If a provision is invalid or unenforceable, it will be read down to the minimum extent necessary where legally possible and the remaining provisions continue in force. Failure or delay in enforcing a provision is not a waiver.
22.5 Entire agreement. These Terms together with the contract documents identified in clause 24 constitute the agreement between the parties on their subject matter and supersede prior understandings on that subject matter. This does not exclude liability for fraudulent misrepresentation.
22.6 Authorized Users and Session Viewers. An Authorized User or Session Viewer does not acquire the Customer's commercial rights under these Terms and is not responsible for Customer Fees or other commercial obligations. CM may enforce directly against an Authorized User or Session Viewer the provisions of these Terms and the applicable Additional Policy that expressly impose obligations on that person and that the person has accepted in accordance with clause 1.8.
22.7 The parties are independent contractors. Nothing in these Terms creates a partnership, employment relationship or general agency between them. An individual's authority to act for a controller under the Individual Account Policy is governed by that policy and does not make CM an agent of that controller.
22.8 These Terms are issued in English, and the English version governs unless mandatory law requires otherwise.
23. Governing law and disputes
23.1 These Terms and any dispute or claim arising out of or in connection with them are governed by Swedish law, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods.
23.2 Organizational Customers. For a Customer that is an organization rather than an individual, any dispute, controversy or claim arising out of or in connection with these Terms, or the breach, termination or invalidity thereof, shall be finally settled by arbitration in accordance with the Arbitration Rules of the SCC Arbitration Institute. The seat of arbitration shall be Stockholm, Sweden. The language of the arbitration shall be English. Either party may seek interim or injunctive relief from a competent court.
23.3 Individuals. For an individual subscriber, Authorized User or Session Viewer, the courts of Sweden have jurisdiction, with Stockholm District Court as the court of first instance, except to the extent mandatory law provides otherwise. Where such person acts as a consumer, nothing in these Terms deprives that person of mandatory protections or jurisdictional rights applicable in their country of habitual residence.
23.4 Nothing in this clause prevents a person from making a complaint to or cooperating with a competent supervisory or regulatory authority.
24. Contract documents
24.1 The Data Processing Agreement and, where applicable, the Business Associate Agreement prevail over every other contract document on matters concerning processing of personal data or Protected Health Information, respectively.
24.2 Summary of contractual obligations and documents:
| Document | Subject matter |
| Service Order | Services, Project purpose, controller and sponsor identification, approvals, Lead Party, plan, limits, Fees, term, hosting region, retention and expressly agreed variations |
| Project record | Operational Project configuration, participants, Release States, permitted purposes and Project facts authorized by the Service Order. A Project record does not amend Fees, liability, warranties, term or other commercial terms unless the Service Order expressly authorizes it. |
| Consortium agreement, where one exists | Ownership of and access to Content and Results, publication and exploitation as between consortium participants. CM is bound by a consortium agreement only to the extent CM expressly agrees to a provision or the applicable Service Order or Project record requires CM to implement an authorized configuration. |
| Signed master agreement, where one exists | The general negotiated commercial relationship and negotiated variations |
| Terms of Service | General Terms applicable to all matters within their scope. |
| Data Specification and CM-Connect rule specification | Content requirements and agreed technical treatment or configuration |
| Service Level Agreement and Acceptable Use Policy | Service levels, support and detailed conduct rules within their respective subject matter |
| Intended Purpose/Use | Intended purpose and information concerning the Platform and Viewer |
24.3 The Privacy Policy/Notice and Cookie Policy are addressed to individuals and are not contract documents. The terms of use of the public CM website govern that website only.
25. Additional policies
These policies apply in addition to the General Terms, depending on your role.
| If this describes you | Then you are also covered by |
| A hospital, clinic, university, academic medical center or other research institution holds the account | Hospitals, Clinics and Universities Policy |
| A biotech or pharmaceutical company, a contract research organization, or a medical device or software company holds the account | Biotech, Pharma, CRO and MedTech Policy |
| You hold an account in your own name rather than through an organization | Individual Account Policy |
| You use the Platform for a clinical trial | Clinical Trials Policy |
| You use the Platform for research that is not a clinical trial | Research Services Policy |
| You use the Platform for teaching, courses, conferences or examination | Education and Teaching Policy |
| Two or more organizations run a Project together in a research consortium | Research Consortium Policy |
| Your organization gave you access and you do not hold the account | Authorized User Terms |
| You are shown material in a teaching session and have no account | Session Viewer Terms |
More than one may apply to you at the same time. The applicable policy is set out below.
Hospitals, Clinics and Universities Policy
This policy applies to you if: A hospital, clinic, university, academic medical center or other research institution holds the account. The General Terms apply as well.
This policy applies to a hospital, clinic, university, academic medical center or other research institution that holds a subscription.
1 Your status. Unless the applicable Service Order expressly provides otherwise, an institution that uploads Health Data acts as the controller of that data within the meaning of Article 4(7) GDPR. CM processes that data on your behalf as processor and follows your documented instructions in accordance with the Data Processing Agreement. Where HIPAA applies and the institution is a healthcare provider, it is ordinarily a Covered Entity, and where Content includes Protected Health Information the Business Associate Agreement required under clause 18.8 of the General Terms applies.
2 The roles you may occupy. An institution may use the Platform in more than one capacity at the same time. You may act as a treating provider seeking or giving a consultation, as a trial site under the Clinical Trials Policy, as a Customer for research services under the Research Services Policy, as a teaching institution under the Education and Teaching Policy, or as a participant in a consortium under the Research Consortium Policy. The applicable Service Order identifies the relevant capacity for each Project where necessary.
3 Consultation and second opinion. Unless agreed otherwise explicitly in a Service Order, the Platform is not designed to be used to obtain or give a clinical opinion on a patient of yours; you remain responsible for the care of that patient, and for the record you keep of it. CM does not provide a clinical service, does not perform a clinical review of Content, and does not act as the system of record or hold the source patient record. Clause 18.6 of the General Terms describes the GDPR legal framework ordinarily relevant to this use. Where HIPAA applies, disclosure to another healthcare provider for treatment may be permitted under 45 CFR 164.506(c)(2).
4 Your people. You are responsible for your Authorized Users as clause 4.4 of the General Terms provides, including personnel of an Affiliate to whom you grant access. The Authorized User Terms state the obligations that apply directly to those individuals.
5 Hiring research services. An institution may engage CM to provide research services on the same basis as a sponsor, CRO or MedTech company. The Research Services Policy applies where relevant.
6 Academic use and publication. CM does not restrict publication and requires no sight of, approval of or attribution in a publication except where expressly agreed for a specific service. Clause 8.3 of the General Terms governs what a publication must not contain.
Biotech, Pharma, CRO and MedTech Policy
This policy applies to you if: A biotech or pharmaceutical company, contract research organization, or medical device or software company holds the account. The General Terms apply as well.
1 Your status. Where you are the sponsor of a Clinical Trial, you are ordinarily the controller of the trial data and CM processes that data on your behalf as processor in accordance with the Data Processing Agreement. Where you act as a CRO on a sponsor's documented instructions, the Service Order must identify the controller to the extent feasible or possible, and identify the party entitled to instruct CM. Where you act as processor on behalf of the controller, CM acts as your subprocessor in accordance with the Data Processing Agreement.
2 Lead Party. Where more than one organization participates in a Project, the Service Order may name a Lead Party through which operational instructions and notifications pass. Naming a Lead Party does not transfer controllership and does not make CM responsible for allocating legal responsibility among participants.
3 Trials and research. The Clinical Trials Policy applies to a Clinical Trial. The Research Services Policy applies to research that is not a Clinical Trial, including retrospective studies, algorithm validation and feasibility assessments.
4 Device and model development. Where the Project concerns development or validation of a medical device, software as a medical device or machine learning model, clause 13.11 of the General Terms governs use of Content within the Project and clause 8.5 governs export of model weights. CM acquires no ownership interest in the device, software or model merely by providing the Platform or services. Clause 9 governs the Viewer.
5 Protected Health Information. Where HIPAA applies and CM processes Protected Health Information on your behalf, clause 18.8 of the General Terms applies and a Business Associate Agreement must be in place before that Content is uploaded.
6 Inspection. Clause 8 of the Clinical Trials Policy applies to an inspection or audit by a competent authority relating to a Clinical Trial. You must give CM reasonable notice of a scheduled inspection involving the Platform where legally and practically possible, and CM will provide information and access reasonably required within the scope of its responsibilities.
Individual Account Policy
This policy applies to you if: You hold an account in your own name rather than through an organization. The General Terms apply as well.
1 Status. An individual subscriber contracts either as controller of the Health Data concerned or as a person duly authorized to act for and bind the controller in relation to the subscription and Content uploaded under it. CM is entitled to rely on the status stated by the individual when subscribing unless and until CM is notified that it has changed.
2 What is required. On subscribing, the individual must state which of the following applies. By doing so, the individual represents and warrants that the status stated is accurate and that, where the individual acts for a controller, the individual has authority to bind that controller in relation to the subscription, Data Processing Agreement, upload and use of Content, and instructions given to CM concerning that Content. CM records the status stated and relies on it in providing the Platform.
| Status stated | What is required |
| Controller | Entry into the Data Processing Agreement as controller and the warranties in clause 7. |
| Authorized to act for the controller | Authority to act for and bind the controller in relation to the subscription, Data Processing Agreement, Content uploaded and instructions given to CM, together with the warranties in clause 7. |
3 Two routes. An individual subscription may be entered into through a signed contractual process or through completion of an online subscription. Both routes are subject to these Terms.
4 Route 1, signed agreement. The individual signs the applicable agreement, Service Order and Data Processing Agreement either in their own capacity as controller or, where acting for another controller, with authority to bind that controller. CM may verify identity and professional status under clause 9.
5 Route 2, completion of a subscription. The individual accepts these Terms and the Data Processing Agreement on completing the subscription. Where the individual acts for a controller, that acceptance is made on the controller's behalf in reliance on the authority represented and warranted under clauses 2 and 7. The status statement and warranties establish the capacity in which the individual acts and the basis on which CM accepts the Content.
6 Relationship between the routes. Where a signed master agreement applies, clause 24 of the General Terms governs precedence. Neither route alters the allocation of responsibility for Content preparation in clause 5 of the General Terms. CM does not provide a separately commissioned pseudonymization or de-identification service on an individual subscription unless expressly agreed, although standard technical functionality may apply through web upload.
7 Warranties on an individual subscription. On subscribing, and again on each upload, the individual warrants each of the following. CM relies on these warranties in providing the Platform and accepting Content.
- ●Status. The status stated under clause 2 is accurate and remains accurate.
- ●Authorization to use the Content. The controller has authorized the upload and use of the Content for the purpose for which it is uploaded, and that authorization has not been withdrawn.
- ●Authority to contract and instruct. Where the individual is not the controller, the individual is duly authorized to bind the controller to these Terms and the Data Processing Agreement and to give CM instructions concerning the Content.
- ●Rights. The individual holds all rights necessary to upload the Content and permit the access allowed by the selected Release State.
- ●Independent treatment. The individual has applied and verified the treatment required for the Content before upload, in accordance with the applicable Data Specification or a documented procedure of the controller, and holds a record of what was applied. Any standard technical functionality applied through web upload does not transfer responsibility for preparation or verification to CM.
- ●No identifying information. The individual has not entered identifying information into a field contrary to clause 3 of the General Terms.
Note. Pseudonymization under Article 4(5) GDPR leaves data as personal data. Anonymous information is assessed under the identifiability standard reflected in Recital 26 GDPR, and pseudonymization does not by itself constitute anonymization. Where HIPAA applies, De-identification under 45 CFR 164.514(b) is a separate legal concept. Compliance with one regime does not establish compliance with the other. The warranties in clause 7 concern the individual's status, authority and treatment applied to the Content. They are not warranties that the Content is anonymous or outside applicable data protection law.
8 Consequence of a false warranty. A warranty in clause 7 that is untrue when given is a material breach for the purposes of clause 15.3 of the General Terms. CM may exercise applicable remedies under clause 17, including suspension or termination, and may recover amounts for which the individual is responsible under clause 16.3. CM may notify the controller, institution, professional body or supervisory authority where reasonably appropriate and legally permitted.
9 Identity and professional status. On subscribing, the individual must provide their full legal name, the institution, practice or clinic through which they act where applicable, a professional or business email address, and professional registration or license number where one exists. CM may verify that information, require evidence of it, and suspend or refuse access where information reasonably required to establish eligibility is not provided or cannot be verified. The individual must notify CM of a material change to that information or to the status or authority stated under clause 2.
10 Limits on individual subscriptions. CM-Connect is not available under the individual subscription level, and if exceptionally granted, will change the account status (no longer an individual subscription). Content volume and other limits are stated in the applicable subscription or Service Order. Transfer to another Customer is not available for an individual user without explicit permission. CM may require migration to an institutional subscription where use exceeds the limits of the individual service or where the nature of the use is no longer appropriate for an individual subscription.
11 Individual subscriptions. Individual subscriptions are billed according to the applicable subscription or Service Order. Cancellation takes effect in accordance with the applicable billing arrangement. Fees already paid are not refundable except where required by mandatory law. Where the subscriber is a consumer, mandatory consumer rights are unaffected. On termination or a valid deletion instruction, Content is handled in accordance with clause 15 of the General Terms, the Data Processing Agreement and applicable law.
Clinical Trials Policy
This policy applies to you if: The Platform is used for a Clinical Trial. The General Terms apply as well.
1 Where a Project is a Clinical Trial, participants will normally have given informed consent to participate and will have been informed as required about collection and processing of their data. These Terms do not treat that situation as equivalent to research conducted solely on records originally created for care.
Note. Informed consent to participate is required under the applicable clinical trials framework, including Articles 28 and 29 of Regulation (EU) 536/2014 in the European Union. Informed consent to participate in a Clinical Trial does not by itself constitute the legal basis for processing personal data under the GDPR. The controller must determine and document the applicable Article 6 GDPR basis and Article 9 GDPR condition, taking account of applicable Member State law. CM does not determine or verify that legal basis.
2 The Customer must record in the Service Order that a Project is a Clinical Trial. CM is not required to determine that a Project is a Clinical Trial in the absence of that record.
3 For each Clinical Trial the Customer confirms the identity of the sponsor and controller, to the extent possible and/or permitted, the protocol under which the work is conducted, that required approvals and ethics opinions are in place, that use of the Platform falls within the applicable authorization, the permitted uses of the data, and the persons who may be admitted to the Project.
4 CM does not assess the sufficiency of an authorization, legal basis or ethics opinion. Where CM considers that an instruction would cause CM to breach applicable law or its obligations as processor, CM may inform the Customer and decline or suspend the affected instruction as permitted by the Data Processing Agreement and applicable law.
5 Withdrawal by a participant. The Customer must notify CM through the appropriate controller, sponsor or Lead Party of a participant's withdrawal and the action CM is instructed to take. Withdrawal does not by itself determine what must happen to data already collected. That determination is for the controller under the applicable clinical trial, data protection and other legal framework. CM will act on documented instructions within the scope of its obligations.
6 Where CM generates identifiers under the applicable configuration, those identifiers may be designed to remain consistent within the applicable Clinical Trial and not across unrelated Clinical Trials or separately assessed releases. Consistency across separate Projects requires an agreed purpose and assessment of the effect on identifiability.
Note. Where DICOM Clinical Trial attributes in group 0012 carry sponsor, protocol, site, subject or time-point information, values must use the trial's appropriate coding. A trial subject identifier may constitute a pseudonym. A medical record number is not a pseudonym for this purpose and must not be placed in those attributes contrary to the applicable Data Specification.
7 CM maintains audit-trail, attribution and record-integrity controls for Clinical Trial Projects and will make available validation or qualification information maintained by CM where reasonably required for the Customer's qualification of the Platform.
8 CM will provide information and access reasonably required for an inspection or audit by a competent authority to the extent relating to CM's services and responsibilities, and will notify the Customer of an approach made directly to CM concerning the Customer's Clinical Trial so far as CM is lawfully permitted.
9 Retention requirements for a Clinical Trial are stated in the applicable Service Order or controller instructions. Any agreed retention beyond termination and applicable Fees must be addressed in the contractual arrangements for the Project.
10 On completion or termination, CM will provide agreed handover materials in the format stated in the Service Order, including applicable records of transformations and access where that deliverable has been agreed.
Research Services Policy
This policy applies to you if: The Platform is used for research that is not a Clinical Trial. The General Terms apply as well.
This policy applies whether the Customer is an institution, pharmaceutical or biotechnology company, CRO or MedTech company. The Clinical Trials Policy applies instead where the Project is a Clinical Trial.
1 This policy applies to research that is not a Clinical Trial. CM applies the same core requirements regardless of the scientific category of the Project.
2 For each Project, the Customer confirms the identity of the controller, the approval or authorization under which the work is conducted where applicable, that use of the Platform falls within that authorization, the permitted uses of the data, and the persons who may be admitted to the Project.
3 The relevant controller is responsible for determining the legal conditions applicable to the research use, including whether information was collected for the research purpose or is being further processed from another context. CM does not assume either position.
Note. Where personal data collected for one purpose is processed for another, the controller is responsible for establishing that the further processing is permitted and for applicable safeguards for scientific research, including Article 89(1) GDPR where relevant and any applicable Member State provisions. Article 89(1) GDPR is a safeguards provision and is not itself a legal basis. National requirements may include ethics or other approvals outside data protection law.
4 Where more than one organization participates in a Project, clause 7.4 of the General Terms applies. Where participating organizations are joint controllers, their Article 26 GDPR arrangement must be in place where required. CM does not supply that arrangement merely by acting as processor.
Note. Article 26 GDPR requires joint controllers to determine their respective responsibilities in an arrangement, the essence of which must be made available to data subjects. The Data Processing Agreement is a controller-to-processor instrument and does not serve that purpose.
5 Linkage of datasets is permitted where it forms part of the recorded Project purpose, falls within applicable authority and approvals, and is otherwise permitted by these Terms. Clause 3.8 of the General Terms continues to apply.
6 Clause 6 of the Clinical Trials Policy applies where CM generates identifiers for a research Project. Retention requirements for the Project are stated in the applicable Service Order or controller instructions and may reflect reproducibility, funder or recordkeeping requirements.
Research services provided by CM
7 Engaging CM for research services. CM may be engaged to provide research services in support of a Project, including imaging data management, reading and adjudication workflow, dataset curation, quality control of submitted imaging, and reporting. The applicable Service Order records the scope, deliverables, roles, timetable and Fees.
8 How those services are performed. Research services are performed substantially in accordance with the applicable Service Order and with reasonable skill and care as clause 12.1 of the General Terms provides. Where the Customer is the controller, CM acts as processor. Where the Customer acts as processor on behalf of another controller, CM acts as subprocessor. In each case CM follows applicable documented instructions in accordance with the Data Processing Agreement. A different data protection role applies only where expressly agreed in the applicable Service Order and applicable data protection documentation. Performing research services does not of itself make CM an investigator or sponsor.
9 What the engagement does not include. Engaging CM for research services does not transfer to CM responsibility for determining or documenting the applicable GDPR legal basis, obtaining required approval or ethics opinion, or determining whether Content may lawfully be used for the Project. Those responsibilities remain with the controller or other party responsible under applicable law, and the Customer warrants that it is entitled to instruct CM in relation to the Content. CM does not author, review or approve a protocol, statistical analysis plan or publication unless the Service Order expressly provides otherwise.
10 Results of the engagement. Results produced through the research services are governed by clause 13 of the General Terms and the applicable Project arrangements. CM acquires no ownership interest in them merely by performing the services.
Education and Teaching Policy
This policy applies to you if: The Platform is used for teaching, training, courses, conferences, examination or continuing professional development. The General Terms apply as well.
1 Education is not research. Education and research are different uses and are governed separately. An approval, ethics opinion or legal basis obtained for research does not by itself extend to education, and a legal basis relied on for education does not by itself permit a research use. Where the same Content is used for both, each use must be independently authorized as required by clause 18.5.
2 The Customer confirms that it holds authority to make Content available for teaching and has satisfied applicable requirements, including any approval, notification or ethics requirement. CM does not assess the sufficiency of that authority merely by making the feature available.
3 Content placed by an Authorized User in a Customer shared area is placed on the Customer's behalf and remains under the Customer's control after that Authorized User ceases to have access.
4 Teaching Content may be made available to Session Viewers under releases for a teaching session (Release State 4 terms) subject to clause 5.
5 Making Teaching Content available under releases for a teaching session (Release State 4 terms) is subject to the following conditions: the material complies with the enhanced Data Specification; the access validity period is limited to the period configured for the relevant teaching activity; the applicable Session Viewer limit is observed; the access code is issued for a defined cohort and is not reused in a manner inconsistent with its intended purpose; access links and codes are not published publicly; and any other conditions recorded in the applicable Service Order are satisfied.
6 A Session Viewer must accept the applicable Session Viewer Terms before Teaching Content opens. CM records acceptance information sufficient to demonstrate the version accepted and access event. Access is not granted without acceptance.
7 Session Viewer conditions. A Session Viewer must agree that:
- ●the material contains medical images or other Health Data relating to real individuals, has been prepared so that the viewer should not be able to identify anyone, and must be treated as confidential;
- ●the viewer will not take screenshots, photographs, screen recordings or other copies, and will not download, save or share the material;
- ●the viewer will not attempt to identify an individual or use anything viewed to search for a person in another system;
- ●if the viewer recognizes an individual or believes identification is possible, the viewer will stop viewing and report the issue;
- ●the viewer will not disclose the access link or code;
- ●the material is for teaching and not for diagnosis, treatment or a clinical decision;
- ●responses submitted through the teaching functionality may be visible to the person conducting the teaching activity according to the applicable configuration; and
- ●access ends when the applicable validity period ends and may be ended earlier.
8 Preparation of Teaching Content. Content used for education must comply with the enhanced Data Specification before it is made available under releases for a teaching session (Release State 4 terms). Clause 5.6 of the General Terms applies to whole slide images and clause 3.3 applies to fields completed by a teacher or other Authorized User.
9 No research from Teaching Content. Teaching Content must not be used to answer a research question, construct a research dataset, or develop, train, fine-tune, validate or evaluate a machine learning model merely because it has been made available for teaching. Where the same Content is also used for research, the research use must be separately established under the Research Services Policy or Clinical Trials Policy.
10 Legal basis. The Customer is responsible under clause 18.5 of the General Terms for determining and documenting the Article 6 GDPR basis and, where Health Data are processed, the Article 9 GDPR condition applicable to the particular teaching use. The applicable basis depends on the circumstances and applicable Member State law. A basis available for research does not by itself authorize teaching. Where HIPAA applies, the Customer must separately determine whether the teaching use is a permitted use or disclosure under HIPAA or requires an authorization.
Research Consortium Policy
This policy applies to you if: Two or more organizations run a Project together. The General Terms apply as well.
This policy applies where a Project is conducted by two or more organizations acting together as a research consortium.
1 What a consortium is for these Terms. A consortium is a Project in which two or more organizations contribute Content or access Content contributed by another participant for a shared purpose recorded in the applicable Service Order or Project record. A consortium may relate to a Clinical Trial orresearch or , in which case the corresponding Additional Policy also applies.
2 The consortium agreement. Where participants have entered into a consortium agreement, that agreement governs ownership of and access to Content and Results, publication and exploitation between the participants to the extent provided in clause 24. CM is not a party to that agreement unless it expressly signs or otherwise agrees to be bound by a particular provision. CM is not required to interpret or police compliance with arrangements solely between participants.
3 Default position. In the absence of an applicable consortium agreement, each participant retains the rights it has in Content it contributes and Results it produces, subject to other applicable Project arrangements. Participation alone does not transfer those rights to another participant.
4 What CM gives effect to. CM gives effect to consortium arrangements to the extent the necessary operational configuration is recorded in the Service Order or authorized Project record, including participants, Lead Party, Release States, permitted access and applicable retention instructions. A consortium term that has not been translated into an instruction CM is entitled and able to implement is not automatically operative against CM.
5 Controllership between participants. Where participants determine purposes and means of processing together, they may be joint controllers and Article 26 GDPR requires them to determine their respective responsibilities in an arrangement, the essence of which must be made available to data subjects. That arrangement is between the relevant participants. The Data Processing Agreement with CM is a controller-to-processor or processor-to-subprocessor instrument and does not replace an Article 26 arrangement. CM does not become a joint controller merely by hosting or providing the Platform for the consortium Project.
Note. Where participants instead determine the purposes of their own processing independently, they may act as separate controllers and Article 26 GDPR may not apply between them. The participants are responsible for assessing and documenting their own relationship.
6 Contributing and accessing Content. A participant that contributes Content warrants that it is entitled to make that Content available for the recorded Project purpose. A participant accessing another participant's Content must use it only for the permitted purpose and subject to the restrictions in the General Terms and applicable Project arrangements.
7 Publication. Publication between participants is governed by the applicable consortium arrangements. Clause 8.3 of the General Terms continues to apply. CM does not restrict publication, require sight of a publication or require attribution unless expressly agreed for a specific service.
8 A participant leaving. Where a participant leaves a consortium, its Content and Results are dealt with under the consortium agreement and, so far as CM is concerned, under the applicable Service Order or Project record and clause 15 of the General Terms. Departure does not by itself withdraw access already granted to Content that participant contributed. The participants must provide any change of instruction or configuration required as a result of the departure.
9 Fees. The Service Order identifies the party or parties responsible for Fees. CM is not responsible for enforcing an internal allocation of Fees between consortium participants unless expressly agreed.
Authorized User Terms
This policy applies to you if: Your organization gave you access and you do not hold the Customer account. The General Terms apply as well.
These Terms state obligations that apply directly to an individual granted access by a Customer.
1 Who this applies to. You are an Authorized User if an organization that has an agreement with Collective Minds has granted you access to the Platform. You are not the Customer and are not responsible for paying for or configuring the service. These Authorized User Terms state the obligations that apply to you personally.
2 Your account. Your account is yours alone. You must not share credentials, an access link or access code with another person. You must tell Collective Minds promptly if you believe credentials or an access link have been compromised.
3 Identification. You must not attempt to identify a patient or trial participant from Content that did not originate from you or your organization. You must not use Content to locate, trace, approach or contact a person or search for that person in another system. If you are the treating clinician or investigator at the site that enrolled the participant, your existing relationship with that individual is unaffected.
4 What you type. You must not enter identifying information into a Platform field contrary to the General Terms or Data Specification.
5 What you upload. You must not upload Content that has not been prepared in accordance with the applicable Data Specification and clause 5 of the General Terms. If you are uncertain whether Content complies, do not upload it.
6 What you may take out. You must not capture, photograph, screen-record, download, export, print or otherwise copy Content out of the Platform except where the General Terms expressly permit it. Screen capture, photography of a display and screen recording are prohibited.
7 Linking and models. You must not link, combine or cross-reference Content with another dataset to identify a person or make identification more likely. You must not use Content for machine learning outside the Project and purpose for which the Content has been made available to you.
8 Conduct. You must not use the Platform or Content to harass, threaten, defame, humiliate, discriminate against or otherwise harm a person, or misrepresent a case, finding or result. You must not conduct unauthorized security testing, attempt to access data not granted to you, circumvent an access control or rate limit, scrape the Platform or reverse engineer it.
9 Clinical responsibility. Except for the Viewer described in clause 9 of the General Terms, the Platform is not placed on the market by Collective Minds as a medical device. Any clinical decision you make remains yours.
10 Reporting. You must tell Collective Minds immediately if you become aware that identifying information is present in Content contrary to these Terms, you have recognized a person where you should not have been able to do so, Content has been uploaded that should not have been, or an access link or code has reached an unintended recipient. A good-faith report is not itself a breach.
11 If you break these rules. Collective Minds may suspend or withdraw your access and notify the Customer through which you obtained access. Where appropriate and legally permitted, serious conduct concerning identification of a patient or trial participant may also be reported to a professional or supervisory body.
12 The full Terms. The General Terms and these Authorized User Terms apply according to their terms. Where they conflict, the General Terms prevail. The applicable Terms are available at collectiveminds.health/terms-of-service.
Session Viewer Terms
This policy applies to you if: You are shown material in a teaching session, conference or course and do not otherwise have an account on the Platform.
1 What you are being shown. The material contains medical images and other Health Data relating to real people. It has been prepared so that you should not be able to identify anyone and must be treated as confidential. Collective Minds does not represent that the material is anonymous or that it falls outside the GDPR or other applicable data protection law.
2 You may look, and nothing more. You may view the material for the teaching purpose for which access is provided. You must not take a screenshot, photograph, screen recording or other copy and must not download, save, forward or share it.
3 Do not try to identify anyone. You must not attempt to identify a person shown in the material or use anything you see to search for a person in another system.
4 If you recognize someone. If you recognize a person or believe you can identify one, stop viewing and tell the person conducting the session and Collective Minds. A good-faith report is not itself a breach.
5 Your access. Access is limited to the validity period established for the relevant teaching session or course and may be ended earlier by Collective Minds or the organization conducting it. Access links and codes are personal to you and must not be passed on.
6 If you break these rules. Collective Minds may invalidate the access link or code and notify the organization conducting the session. Where appropriate and legally permitted, serious conduct concerning identification of a patient or trial participant may be reported to a professional or supervisory body. Obligations concerning confidentiality, copying and identification continue after access ends.
7 The full Terms. The General Terms and these Session Viewer Terms apply according to their terms. Where they conflict, the General Terms prevail. The applicable Terms are available at collectiveminds.health/terms-of-service.