Data Processing Agreement (DPA)
ARTICLE 1 – PARTIES
This Data Processing Agreement (DPA) is entered into between:
The Customer, a legal entity or professional that has subscribed to the Take-QAIR® platform services (the “Controller”);
MELTOD HEALTH, SAS with share capital of €1,000, registered office: 11 Rue du Donjon 76000 Rouen, registered with the Rouen Trade and Companies Register under no. 888 043 619, represented by Melvain TODEM (the “Processor”).
ARTICLE 2 – PURPOSE
This DPA sets out the conditions under which the Processor processes personal data on behalf of the Controller, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.
It forms a contractual annex to the General Terms of Sale and the Terms of Use.
ARTICLE 3 – DESCRIPTION OF THE PROCESSING
| Item | Description |
|---|---|
| Purpose | Provision of the Take-QAIR® platform: well-being and pathway follow-up, self-reported indicators, dashboards and support |
| Nature of operations | Collection, recording, hosting, consultation, analysis, restitution and deletion |
| Data subjects | Patients or users, healthcare professionals, authorized users of the Customer |
| Categories of data | Identity and contact details, login credentials, self-reported well-being indicators, pathway data, consents, connection logs and, where applicable, health data |
| Duration | Term of the contract, followed by the limited retention provided for in Article 13 |
ARTICLE 4 – OBLIGATIONS OF THE PROCESSOR
The Processor undertakes to:
Process data only on documented instructions from the Controller, and inform it without delay if an instruction appears to infringe the regulations;
Ensure the confidentiality of the data and make sure that persons authorized to process it are bound by confidentiality;
Implement the security measures set out in Article 6;
Keep a record of the categories of processing activities carried out on behalf of the Controller;
Assist the Controller with impact assessments and prior consultations;
Make available the information necessary to demonstrate compliance with its obligations.
ARTICLE 5 – OBLIGATIONS OF THE CONTROLLER
The Controller undertakes to:
Document its instructions in writing;
Have the necessary legal bases, inform data subjects and obtain their consent where required;
Manage its users’ accounts and enter only the data necessary for the purpose of the processing.
ARTICLE 6 – SECURITY
The Processor implements appropriate technical and organizational measures within the meaning of Article 32 GDPR, described in Annex 2. These measures may evolve without reducing the overall level of security.
ARTICLE 7 – HEALTH DATA AND HOSTING
Where the platform processes health data, it is hosted by a provider certified for Health Data Hosting (HDS): OVH SAS, within the European Union.
ARTICLE 8 – SUB-PROCESSORS
The Controller gives general authorization for the use of the sub-processors listed in Annex 1. The Processor informs it of any change with 30 days’ notice, during which the Controller may object on legitimate grounds.
The Processor imposes on its sub-processors the same obligations as those of this DPA and remains liable for their performance.
ARTICLE 9 – TRANSFERS OUTSIDE THE EUROPEAN UNION
No data is transferred to a country outside the European Union or the European Economic Area without instructions from the Controller and without the appropriate safeguards provided for by the GDPR.
ARTICLE 10 – RIGHTS OF DATA SUBJECTS
The Processor assists the Controller, through appropriate technical and organizational measures, in responding to requests to exercise data subjects’ rights. If it receives a request directly, it forwards it to the Controller within 5 working days without responding to it, unless instructed otherwise.
ARTICLE 11 – PERSONAL DATA BREACHES
The Processor notifies the Controller of any personal data breach as soon as possible and no later than 48 hours after becoming aware of it, specifying its nature, the categories and approximate number of data subjects and data concerned, its likely consequences and the measures taken.
ARTICLE 12 – AUDIT
The Controller may verify compliance with this DPA through an audit carried out by itself or by a third party bound by confidentiality, with 30 days’ notice and no more than once a year, except in the event of a proven incident. The costs of the audit are borne by the Controller.
ARTICLE 13 – FATE OF DATA AT THE END OF THE CONTRACT
At the end of the contract, the Processor returns the data to the Controller and then deletes it within 30 days, unless a legal retention obligation applies. Backup copies are deleted according to their rotation cycle, within a maximum of 90 days. A deletion certificate may be provided on request.
ARTICLE 14 – TERM, LIABILITY AND GOVERNING LAW
This DPA is entered into for the term of the contract. In the event of a conflict relating to the processing of personal data, it prevails over the other contractual documents. The parties’ liability is governed by the General Terms of Sale.
This DPA is governed by French law. Any dispute falls within the jurisdiction of the courts of the Processor’s registered office.
ANNEX 1 – AUTHORIZED SUB-PROCESSORS
| Sub-processor | Function | Location |
|---|---|---|
| OVH SAS | HDS hosting of the platform and data | European Union |
| OVH SAS | Email and sending of transactional emails | European Union |
ANNEX 2 – SECURITY MEASURES
Encryption of communications and data;
Secure access management, strong authentication and separation of profiles;
Access logging and monitoring;
Automated backups, business continuity plan and disaster recovery plan;
Regular security audits;
Confidentiality commitment and staff awareness training.