Data Processing Agreement
Last updated: July 23, 2026
Scope & Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and Avicen ("Processor") for the provision of the Avicen clinical intelligence platform (the "Service").
This DPA applies to all processing of personal data by the Processor on behalf of the Controller in connection with the Service, as required by the EU General Data Protection Regulation (GDPR) and any other applicable data protection laws.
Definitions
- Personal Data — Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
- Controller — The Customer, who determines the purposes and means of processing personal data.
- Processor — Avicen, who processes personal data on behalf of the Controller.
- Sub-Processor — A third party engaged by the Processor to carry out specific processing activities.
- Data Subject — The natural person to whom the personal data relates.
Details of Processing
The Processor shall process personal data in accordance with the Controller's documented instructions. The details of processing are as follows:
- Subject matter: Provision of the Avicen clinical intelligence platform, including document ingestion, AI-powered analysis, and report generation.
- Duration: For the term of the service agreement between the Controller and the Processor.
- Nature of processing: Collection, storage, structuring, retrieval, analysis, and deletion of personal data.
- Purpose: To provide clinical document analysis, evidence-grounded reporting, and decision-support tools to the Controller.
- Categories of data: Medical records, clinical documents, patient identifiers, health information, and user account data.
Obligations of the Controller
The Controller shall:
- Ensure that it has a valid legal basis for the processing of personal data and has obtained all necessary consents from data subjects
- Provide documented instructions to the Processor regarding the processing of personal data
- Promptly notify the Processor of any data subject requests or complaints relating to the processing
Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required by law
- Ensure that persons authorized to process personal data have committed to confidentiality
- Implement appropriate technical and organizational measures to ensure data security
- Assist the Controller in fulfilling its obligations regarding data subject rights, data protection impact assessments, and consultations with supervisory authorities
- Delete or return all personal data upon termination of the service agreement, at the Controller's choice
Sub-Processors
The Processor shall not engage any Sub-Processor without prior written authorization from the Controller. A list of approved Sub-Processors is maintained and made available upon request. The Processor will notify the Controller of any intended changes to Sub-Processors at least 30 days in advance.
The Processor ensures that all Sub-Processors are bound by data protection obligations no less protective than those set out in this DPA.
Data Subject Rights
The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, and objection) by providing appropriate technical and organizational measures, taking into account the nature of the processing.
Technical & Organizational Measures
The Processor implements and maintains the following technical and organizational security measures:
- Encryption of data at rest (AES-256) and in transit (TLS 1.3)
- Multi-tenant data isolation with strict logical separation between customers
- Role-based access controls with multi-factor authentication for all personnel
- Regular security audits, penetration testing, and vulnerability assessments
- Incident response procedures with documented escalation paths
Data Breach Notification
In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach.
The notification shall include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to mitigate the effects.
International Data Transfers
Personal data is primarily processed and stored in Switzerland, which benefits from an adequacy decision under the GDPR. If any transfer of personal data occurs outside of Switzerland or the EEA, the Processor shall ensure appropriate safeguards are in place.
Such safeguards may include Standard Contractual Clauses (SCCs), binding corporate rules, or other legally recognized transfer mechanisms.
Audit Rights
The Controller has the right to conduct audits (or appoint an independent auditor) to verify the Processor's compliance with this DPA. The Processor shall make available all information necessary to demonstrate compliance and shall allow and contribute to audits, subject to reasonable notice and scope.
Termination & Data Return
Upon termination or expiry of the service agreement, the Processor shall, at the Controller's election, return or securely delete all personal data within 30 days, unless applicable law requires continued storage.
The Processor shall provide written certification of data deletion upon the Controller's written request.
Contact
For questions about this DPA or data processing practices, please contact us at contact@avicen.io.