This Data Processing Addendum forms part of the agreement between Vantis Strategies LLC, doing business as nuemed, and the customer. It applies where nuemed processes personal data on the customer's behalf.
1. Definitions and interpretation
In this Addendum, "applicable data-protection law" means privacy and data-protection law that applies to the processing covered by this Addendum. "Customer personal data" means personal data processed by nuemed on behalf of the customer. "Controller", "processor", "personal data", "personal-data breach", "processing" and "supervisory authority" have the meanings given by applicable data-protection law.
If this Addendum uses a term defined in the main agreement, that definition applies unless the context requires otherwise. References to law include amendments and replacement legislation.
2. Roles and instructions
The customer is the controller and nuemed is the processor, except where applicable law assigns a different role. nuemed will process personal data only to provide, secure and support the service, according to the agreement and the customer's documented lawful instructions.
The customer is responsible for the lawfulness, accuracy and scope of its instructions and for providing required information to patients and staff.
The agreement, the customer's configuration and authorised use of the service constitute documented instructions. Additional instructions must be agreed in writing and may be subject to reasonable fees where they require work outside the service.
If we reasonably believe an instruction breaches applicable data-protection law, we will inform the customer unless law prohibits notice and may pause the affected processing until the parties resolve the issue.
3. Processing details
- Subject matter: provision of clinic management software and related support.
- Duration: the subscription term plus the agreed export and deletion period.
- Nature: collection, organisation, hosting, retrieval, transmission, backup, support, export and deletion.
- Purpose: enabling the customer to administer its clinic, workforce, appointments, records, communications, payments and configured workflows.
- People: patients, prospective patients who book, clinic personnel, practitioners, contractors and customer contacts.
- Data: identity and contact data, appointment and account data, health and treatment information, forms, notes, photographs, prescriptions, communications, financial records, files, audit data and technical identifiers.
4. Customer obligations
The customer will comply with applicable data-protection law and ensure that it has a valid lawful basis and, where required, a condition for processing health or other sensitive information. The customer will provide all required notices, obtain any required permissions and ensure its instructions are fair, lawful and transparent.
The customer is responsible for data accuracy, minimisation, retention choices, responding to individuals, configuring user permissions and determining whether the service is appropriate for its jurisdiction and professional obligations.
The customer must not provide customer personal data subject to HIPAA or use the service in a way prohibited by the main agreement.
5. Confidentiality and personnel
nuemed will ensure that people authorised to process customer personal data are bound by confidentiality and receive access only where necessary for their duties.
We will provide relevant privacy and security instructions to authorised personnel and will revoke access when it is no longer required. Confidentiality obligations continue after access or engagement ends.
6. Security
nuemed will maintain measures appropriate to the risk, including access controls, tenant separation, transport protection, protected database storage, backups, permission controls, logging, incident procedures and controlled support access.
The customer must configure roles appropriately, keep credentials secure and notify nuemed promptly of suspected misuse.
Security measures may evolve as technology and risk change. We may replace a measure with another that provides an equivalent or greater level of protection. No contractual measure represents a guarantee that a security incident can never occur.
The customer acknowledges that security is a shared responsibility. It must protect its devices, networks, administrator accounts and exports and must not weaken or circumvent service controls.
7. Subprocessors
The customer gives general authorisation for nuemed to use subprocessors needed to provide the service. Current categories and providers appear on the Subprocessors page.
nuemed will require subprocessors to protect personal data under written terms appropriate to their role. We will give at least 30 days' notice before appointing a material new subprocessor where reasonably practicable.
A customer may raise a reasonable data-protection objection during that period. The parties will work in good faith on a practical solution. If none is available, either party may end the affected service.
nuemed remains responsible for a subprocessor's performance of the data-protection obligations subcontracted to it to the extent required by applicable law.
8. Individual rights
Taking account of the nature of processing, nuemed will provide reasonable assistance so the customer can respond to valid requests for access, correction, deletion, restriction, objection and portability.
If nuemed receives a request relating to customer-controlled data, we will normally direct the person to the customer unless law requires a different response.
The customer is responsible for determining whether a request is valid and for communicating with the individual. Assistance beyond standard service functionality may be charged at reasonable rates where permitted by law.
9. Personal-data breaches
nuemed will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data. We will provide reasonably available information needed for the customer's assessment and notification duties.
Notification does not constitute an admission of fault or liability.
Where reasonably available, notice will describe the nature of the incident, affected categories of information, likely consequences, measures taken or proposed, and a contact for follow-up. Information may be supplied in phases as an investigation continues.
The customer is responsible for notifying regulators, patients and other persons unless applicable law assigns that duty directly to nuemed.
10. Compliance assistance
Taking account of the service and information available to us, nuemed will provide reasonable assistance with security obligations, breach assessments, data-protection impact assessments and regulator consultations.
We will also provide reasonable information about the service needed for the customer to maintain its processing records and demonstrate compliance. The customer remains responsible for its own assessment and regulatory decisions.
11. Audit information
On reasonable written request, nuemed will provide information necessary to demonstrate compliance with this Addendum. Audits must protect other customers, security and confidential information and should normally occur no more than once annually unless a regulator or material incident requires otherwise.
The parties will first use current independent reports, certifications, policies and written responses where these reasonably satisfy the request. Any further audit must occur during normal business hours, on reasonable notice, under confidentiality and without disrupting the service.
The customer will bear its audit costs and reimburse reasonable costs incurred by nuemed, unless the audit identifies a material breach by nuemed.
12. International transfers
Where a restricted transfer requires contractual safeguards, the parties incorporate the applicable European Commission Standard Contractual Clauses, using the controller-to-processor module, and the applicable UK addendum or transfer agreement.
The customer authorises transfers needed to use the subprocessors disclosed by nuemed, subject to those safeguards.
For the European Commission Standard Contractual Clauses, Module Two applies where the customer is a controller and nuemed is a processor. The optional docking clause applies, subprocessor authorisation is general, the notification period is stated in this Addendum, and the competent supervisory authority and governing law will be determined by the exporter's establishment and applicable law. Annex information is supplied by the agreement, this Addendum and the Subprocessors page.
For transfers governed by United Kingdom data-protection law, the parties incorporate the then-current ICO International Data Transfer Addendum to the EU Standard Contractual Clauses. The parties will complete any transfer assessment and supplementary measures required of them by applicable law.
13. Return and deletion
After termination, the customer has 30 days to request an export. nuemed will aim to delete production data within 60 days and allow deleted data to expire from rotating backups within 90 days, unless law or the customer's documented instruction requires longer retention.
Until deletion is complete, this Addendum continues to apply. Data retained in backups will be isolated from ordinary use and deleted through the normal backup-expiry cycle. We may retain information where law requires it, but only for that legal purpose.
14. Government requests
Unless prohibited by law, we will notify the customer of a legally binding request for customer personal data. We will review the request, challenge it where there are reasonable grounds, and disclose only information legally required.
15. United States healthcare data
This Addendum is not a HIPAA business associate agreement. The customer must not use nuemed to process protected health information regulated by HIPAA.
16. Duration, conflict and liability
If this Addendum conflicts with the main agreement on personal-data processing, this Addendum controls. Liability under this Addendum is subject to the liability terms in the main agreement, except where applicable law requires otherwise.
This Addendum takes effect when the customer accepts the main agreement and remains in force for as long as nuemed processes customer personal data. The parties may sign a separate copy if reasonably required for regulatory records.