This Appendix describes the processing of Personal Data carried out by the Processor on behalf of the Controller under the DPA.
1. Subject Matter and Purposes of the Processing
The Processor provides a software-as-a-service (SaaS) solution (the “Services”) designed to support the Controller's clinical, administrative and/or social care workflows, including AI-based documentation and clinical decision-support functionality. The Services are further defined in the Customer Agreement. The Services may also include the retrieval of Personal Data from the Controller's Customer Systems.
The Processor processes Personal Data on behalf of the Controller solely for the purpose of providing the Services under the Customer Agreement and in accordance with the Controller's documented Instructions. This description applies to the Services in their entirety, irrespective of which modules or functionality the Controller chooses to activate or use from time to time.
The permitted purpose also includes configuring, adapting and personalizing the Services for the Controller, its authorized Users and the Controller's tenant, including user preferences, workflow settings, templates, language settings, specialty or role-based configurations and Controller-specific output formatting, and carrying out quality assurance and clinician/safety evaluations necessary for the safe, correct and reliable provision of the Services to that Controller, solely as part of providing, maintaining, supporting and securing the Services.
The Controller determines the purposes and means of the processing and is solely responsible for the lawful basis under Articles 6 and 9 GDPR.
2. Data Subjects Categories
The following are sub-categories of the “Data Subjects” (as defined in the DPA) whose Personal Data is processed under this Appendix are the following:
(a) “User” means the Controller's social or healthcare professional, and other personnel who are authorised by the Controller to access and use the Services.
(b) “Participant” means an individual accessing healthcare, social care or related services from the Controller, where such services are documented or supported through the Services.
(c) “Supporting Participant” means an individual, other than the Participant, who is identified or referenced in connection with a Participant through the Services, including but not limited to a legal guardian (for example, where the Participant is a minor), a personal assistant, a family member or next of kin, a caregiver, a social worker or other social care representative, an interpreter or translator, a referring clinician, or another individual identified or referenced in connection with a Participant through the Services.
3. Categories of Personal Data
The table below sets out the categories of Personal Data processed by the Processor on behalf of the Controller, together with which category or categories of Data Subject each applies to:
Category of Personal Data | Description | Applicable Data Subject category |
|---|---|---|
Identification and contact data | Data that identifies or allows contact with a Data Subject, such as name, contact details, and, where mentioned or entered a unique identifier such as national identity number or session ID. | Users and Participants, only to the extent such data is mentioned or entered in connection with the Services or retrieved from the Controller’s Customer Systems. |
Account and usage data | Data generated through access to and use of the Services, such as user identifiers, login credentials, IP address, and activity or log data. | Users only. Participants and Supporting Participants do not hold accounts with the Services. |
Health-related data | Data concerning health and related sensitive circumstances that may be discussed or recorded during a consultation, or retrieved from the Controller's Customer Systems in advance of or otherwise outside a consultation, such as medical history, symptoms, diagnoses, treatment, medication, test results, and lifestyle or social circumstances (for example, tobacco or alcohol habits, family situation). | Participants. |
Recording and documentation data | Audio recordings, transcripts, clinical notes, generated documents, and suggested codes produced within the Services, which may incorporate any of the categories described above as well as any other Personal Data recorded, generated or referenced through provision of the Services. | Mainly Users and Participants. Supporting Participants only to the extent captured in a recording or resulting documentation. |
Communication data | Data relating to invitations and notifications, such as name (e.g., of an inviting administrator or other sender/recipient), email address, clinic name, and delivery or interaction metadata. | Users only, in connection with account invitations and notifications. |
Support data | Data relating to support requests submitted in connection with the Services, such as the requester's name and contact details, the content of the support request, and related correspondence and interaction metadata. | Users only, in connection with support requests submitted to the Processor regarding the Services. |
Personalization and configuration data | User preferences, templates, language settings, workflow settings, specialty or role-based configurations, Controller-specific output formatting, user-made edits, corrections and feedback to generated documents or other outputs (to the extent used to configure or personalize the Services), personalization artifacts, embeddings, vector databases and related metadata, only to the extent generated or maintained for the Controller's tenant and authorized Users as part of providing the Services. | Users and, only if the artifact contains or reveals their information, Participants and Supporting Participants. Such data remains Personal Data and, where applicable, Input Data unless irreversibly anonymized. |
4. Duration of Processing
Personal Data relating to Users is processed and stored by the Processor for the duration of the Customer Agreement and thereafter returned and/or deleted in accordance with the DPA, unless the parties agree otherwise in writing.
Personal Data relating to Participants and Supporting Participants is stored by the Processor for 30 days from the date of its creation, after which it is processed with the purpose of ensuring that directly identifying data, such as names, addresses and national identity numbers, does not remain in the record, unless the parties agree otherwise in writing. This operational retention period applies during the term of the Customer Agreement and is without prejudice to the DPA, which separately governs the return and/or deletion of Personal Data upon termination of the DPA. Personalization and configuration data is retained only for as long as necessary to provide the Services to the Controller and its authorized Users, or for the shorter period specified in the Customer Agreement, module-specific instructions or retention schedule.