ADDENDUM EFFECTIVE DATE: [DATE]

This Genomic Data Use Agreement Addendum ("Addendum") is entered into by and between:

Institution: [Full Legal Name of Institution], a [state/type of entity] with its principal place of business at [Address] ("Institution"), acting in connection with NIH-funded research under Award No. [NIH NOTICE OF AWARD NUMBER]; and

Service Provider: Polsia, Inc. (d/b/a Baseshift), a Delaware corporation with its principal place of business at [Address] ("Baseshift").

This Addendum supplements and is incorporated into the Master Services Agreement or Terms of Service in effect between the parties ("Base Agreement"). In the event of a conflict, this Addendum controls with respect to genomic data. Capitalized terms not defined herein have the meanings given in the Base Agreement.

Section 1 — Permitted Genomic Data Use Scope

1.1 Covered Data

This Addendum applies to all genomic data submitted by Institution to Baseshift, including but not limited to: Variant Call Format (VCF) files, Binary Alignment Map (BAM) files, CRAM files, and derived variant calls, annotations, and pathogenicity classifications generated by the Baseshift analysis pipeline (collectively, "Genomic Data").

1.2 Permitted Use by Baseshift

Baseshift may process Genomic Data solely to provide the analysis services described in the Base Agreement. Specifically, Baseshift is authorized to:

All AI annotation calls are routed through the Polsia AI proxy. No patient name, date of birth, medical record number, or other direct identifier is transmitted outside Institution's de-identified dataset.

1.3 Restriction to NIH Award Purpose

Institution warrants that its use of the Baseshift service is limited to the research purpose stated in the applicable NIH Notice of Award referenced above. Institution shall not use Baseshift to process genomic data outside the scope of that Award without prior written consent from Baseshift and, where required, an amendment to this Addendum.

1.4 Prohibition on Commercial Sublicensing

Institution may not sublicense, sell, transfer, or otherwise grant third parties access to Genomic Data or derived outputs through the Baseshift platform without Baseshift's prior written consent. This prohibition applies regardless of whether the Genomic Data has been de-identified.

1.5 Baseshift Internal Use Limitation

Baseshift shall not use Genomic Data for any purpose other than service operation (annotation pipeline, quality assurance, and technical support) to the minimum extent necessary. Baseshift shall not use Genomic Data to train generalized machine learning models, publish research, or develop products beyond those contracted with Institution, except with Institution's explicit written consent.

Section 2 — Data Minimization and Retention

2.1 Active Retention Period

Raw Genomic Data files (VCF, BAM, CRAM) uploaded to the Baseshift platform are retained on Baseshift infrastructure (Neon PostgreSQL and Cloudflare R2 object storage) only for the period required to complete analysis and deliver the clinical report, plus a post-delivery retention window of ninety (90) calendar days ("Retention Period"), unless a shorter period is agreed in writing.

2.2 Deletion Request

Institution must submit a written deletion request to sales@baseshift.io upon expiration of the Retention Period or upon conclusion of the research project covered by the NIH Award, whichever is earlier. Baseshift will acknowledge receipt within five (5) business days and confirm secure deletion within thirty (30) calendar days of the request.

2.3 Secure Deletion Warranty

Baseshift warrants that upon deletion: (a) raw files are permanently removed from Cloudflare R2 object storage; (b) database records referencing the file are purged; and (c) Baseshift will provide written confirmation of deletion including a description of the records destroyed. "Secure deletion" means overwrite or cryptographic erasure consistent with NIST SP 800-88 guidelines.

2.4 Derived Variant Data

Derived variant rows stored in the Baseshift variants table (annotation fields, pathogenicity classifications, ACMG verdicts) may be retained beyond the Retention Period only if Institution explicitly agrees to an extended schedule in writing. Absent such agreement, derived variant data is deleted concurrently with raw files.

2.5 No Secondary Copies

Baseshift personnel shall not retain copies of Genomic Data on local workstations, personal storage, or any system outside the designated Baseshift production infrastructure. Temporary processing buffers are purged immediately upon completion of each analysis job.

2.6 Data Minimization at Upload

Institution shall upload only the minimum Genomic Data necessary to accomplish the stated research purpose. Institution shall not include patient-identifying metadata (name, DOB, MRN, SSN, address) in VCF headers, BAM read group tags, or file names submitted to Baseshift.

Section 3 — Prohibited Re-identification

3.1 General Prohibition

Neither party shall attempt, directly or indirectly, to re-identify any individual from de-identified Genomic Data or derived outputs. This prohibition applies regardless of the method of re-identification, including but not limited to: statistical inference, database linkage, imputation, or any technique that could uniquely distinguish or characterize an individual research subject.

3.2 Linkage Attack Prohibition

The parties acknowledge that genomic variant data is quasi-identifiable. Baseshift expressly prohibits linkage attacks that combine variant data processed through the Baseshift platform with publicly available genomic databases (including but not limited to: dbSNP, ClinVar, gnomAD, 1000 Genomes, TCGA, or any genealogy database) in any manner designed or likely to identify the research subjects from whom Genomic Data was derived.

3.3 PHI Acknowledgment

The parties acknowledge that genomic data is quasi-identifiable and becomes Protected Health Information ("PHI") as defined under HIPAA (45 CFR §160.103) when linked to any direct or indirect identifier listed in 45 CFR §164.514(b)(2). Institution represents that it has applied appropriate de-identification measures before submitting Genomic Data to Baseshift. Where Genomic Data constitutes or may constitute PHI, the parties' separately executed Business Associate Agreement ("BAA") governs; this Addendum supplements but does not replace that BAA.

3.4 AI Annotation Calls — No PII Transmitted

Baseshift warrants that its AI annotation pipeline, which routes calls through the Polsia AI proxy, transmits only genomic variant coordinates, alleles, gene symbols, and computed annotation fields. No patient name, date of birth, geographic data smaller than state, or other HIPAA identifier is included in any payload sent to the AI annotation service. Baseshift maintains technical controls enforcing this restriction.

3.5 Third-Party Access

Baseshift shall not disclose Genomic Data to any third party except: (a) subprocessors operating under written data processing agreements with protections at least equivalent to this Addendum (current subprocessors: Neon database hosting, Cloudflare R2 storage, Polsia AI proxy); (b) as required by law, with prompt notice to Institution to the extent legally permitted. Baseshift maintains an up-to-date subprocessor list available upon request.

Section 4 — Breach Notification Timeline

4.1 Notification Obligation

Baseshift shall notify Institution in writing within seventy-two (72) hours of discovering a confirmed breach or reasonably suspected unauthorized access, acquisition, use, or disclosure of Genomic Data ("Security Incident"). This timeline is consistent with GDPR Article 33 and HIPAA §164.412 requirements.

4.2 Notification Content

The initial notification shall include, to the extent known at the time of notification:

Where full information is not available within 72 hours, Baseshift shall provide an initial notice with available information and supplement it as additional details become known, without undue delay.

4.3 Downstream Notification Responsibilities

Institution is solely responsible for:

Baseshift will reasonably cooperate with Institution's downstream notification obligations, including providing supplemental documentation and making personnel available for regulatory inquiries.

4.4 Incident Response Cooperation

Baseshift shall promptly take reasonable steps to contain the Security Incident, preserve evidence, and prevent further unauthorized access. Baseshift will provide Institution with reasonable access to relevant logs and records to support Institution's investigation and regulatory obligations. Each party shall bear its own costs of incident response unless the incident is attributable to the other party's breach of this Addendum.

Signature Block

Institution

Authorized Representative Signature
Printed Name
Title
Date

Baseshift (Polsia, Inc.)

Authorized Representative Signature
Printed Name
Title
Date
BAA Reference: Where a separate Business Associate Agreement is in effect between the parties, that BAA is effective as of [BAA EFFECTIVE DATE] and is incorporated herein by reference. This Addendum supplements the BAA with respect to genomic data handling obligations.