Data Processing Agreement
Last updated:
Scope & Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and Avicen ("Processor") for the provision of the Avicen medical record analysis and review platform (the "Service").
This DPA applies to all processing of personal data by the Processor on behalf of the Controller in connection with the Service, as required by the EU General Data Protection Regulation (GDPR) and any other applicable data protection laws.
Defined Terms
- Personal Data: Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
- Controller: The Customer, who determines the purposes and means of processing personal data.
- Processor: Avicen, who processes personal data on behalf of the Controller.
- Sub-Processor: A third party engaged by the Processor to carry out specific processing activities.
- Data Subject: The natural person to whom the personal data relates.
Details of Processing
The Processor shall process personal data in accordance with the Controller's documented instructions. The details of processing are as follows:
- Subject matter: Provision of the Avicen medical record analysis and review platform, including document ingestion, AI-powered analysis, and report generation.
- Duration: For the term of the service agreement between the Controller and the Processor.
- Nature of processing: Collection, storage, structuring, retrieval, analysis, and deletion of personal data.
- Purpose: To provide medical document analysis, evidence-grounded reporting, and record review tools to the Controller.
- Categories of data: Medical records, clinical documents, patient identifiers, health information, and user account data.
Obligations of the Controller
The Controller shall:
- Ensure that it has a valid legal basis for the processing of personal data and has obtained all necessary consents from data subjects
- Provide documented instructions to the Processor regarding the processing of personal data
- Promptly notify the Processor of any data subject requests or complaints relating to the processing
Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required by law
- Ensure that persons authorized to process personal data have committed to confidentiality
- Implement appropriate technical and organizational measures to ensure data security
- Assist the Controller in fulfilling its obligations regarding data subject rights, data protection impact assessments, and consultations with supervisory authorities
- Delete or return all personal data upon termination of the service agreement, at the Controller's choice
- Immediately inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data protection provisions
Sub-Processors
The Controller grants the Processor a general written authorisation to engage Sub-Processors for the performance of the Service. The Processor maintains an up-to-date list of Sub-Processors, made available upon request, and shall inform the Controller of any intended addition or replacement of a Sub-Processor at least 30 days in advance. The Controller may object to such a change within that period on reasonable, documented data protection grounds.
The Processor ensures that all Sub-Processors are bound by data protection obligations no less protective than those set out in this DPA.
Data Subject Rights
The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, and objection) by providing appropriate technical and organizational measures, taking into account the nature of the processing.
Technical & Organizational Measures
The Processor implements and maintains the following technical and organizational security measures:
- Encryption of data at rest (AES-256) and in transit (TLS 1.3)
- Multi-tenant data isolation with strict logical separation between customers
- Role-based access controls with multi-factor authentication for all personnel
- Regular security audits, penetration testing, and vulnerability assessments
- Incident response procedures with documented escalation paths
Medical Secrecy
The Processor's personnel are bound by strict confidentiality obligations. The processing carried out under this DPA is designed to be compatible with medical secrecy (in France, article L.1110-4 of the Public Health Code): the professional user remains the sole custodian of the medical file, the Processor acts exclusively on the Controller's documented instructions, and no third party is granted access to the data.
Data Breach Notification
In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach.
The notification shall include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to mitigate the effects.
International Data Transfers
Personal data is hosted with Exoscale (Akenes SA, Lausanne, Switzerland), a certified health data host (Hébergeur de Données de Santé, HDS) whose infrastructure is also HIPAA-compatible. Data of Swiss Controllers is hosted in Switzerland; data of French and EU Controllers is hosted in their country of operation or within the European Union, on Exoscale's EU zones. Switzerland benefits from a European Commission adequacy decision (Decision of 26 July 2000, maintained under the GDPR). If any transfer of personal data occurs outside the EEA and outside a country covered by an adequacy decision, the Processor shall ensure appropriate safeguards are in place.
Such safeguards may include Standard Contractual Clauses (SCCs), binding corporate rules, or other legally recognized transfer mechanisms.
Audit Rights
The Controller has the right to conduct audits (or appoint an independent auditor) to verify the Processor's compliance with this DPA. The Processor shall make available all information necessary to demonstrate compliance and shall allow and contribute to audits, subject to reasonable notice and scope.
Termination & Data Return
Upon termination or expiry of the service agreement, the Processor shall, at the Controller's election, return or securely delete all personal data within 30 days, unless applicable law requires continued storage.
The Processor shall provide written certification of data deletion upon the Controller's written request.
Contact
For questions about this DPA or data processing practices, please contact us at .