Data processing agreement
This agreement governs MDCare's processing of personal data on behalf of a customer. It forms part of the subscription terms and is intended to satisfy Article 9 of the revised Swiss Federal Act on Data Protection and Article 28 of the General Data Protection Regulation.
1. Parties and roles
Controller: the customer identified in the subscription
(the clinic, hospital or practice).
Processor: AI-Fi Sarl.
The customer determines the purposes and means of the processing. MDCare processes personal data only on the customer's documented instructions, of which use of the service in accordance with its documentation forms part.
2. Subject matter, nature and purpose
Provision of a medical device maintenance management service: recording equipment, planning and recording maintenance, collecting measurements, storing evidential documents and producing the records required to demonstrate compliance with Swiss medical device regulation.
3. Duration
For the term of the subscription, and thereafter only for as long as needed to meet the deletion and return obligations in clause 10.
4. Categories of data subject
- The customer's staff who use the service: accounts, roles, and the actions they take
- Technicians and service partners named in maintenance records
- Contacts at the customer's suppliers
The service is not designed to process data concerning patients, and the customer undertakes not to enter patient data into it. Uploaded documents are the only route by which such data could arrive; the customer is responsible for what it uploads.
5. Categories of personal data
- Identity and contact data: name, email address, organisation, role
- Authentication data: password hash, session and token data
- Activity data: the audit trail of who recorded or changed what, and when
- Content data: device records, maintenance records, measurements and the documents uploaded as evidence, to the extent these name a person
- Billing data: billing contact and subscription status
No special categories of personal data within the meaning of Article 5(c) of the revised Swiss Act or Article 9 GDPR are intended to be processed.
6. Instructions
MDCare processes personal data only on the customer's documented instructions, including as to transfers abroad, unless required otherwise by Swiss or EU law. Where such a requirement applies, MDCare will inform the customer before processing unless the law forbids it. MDCare will tell the customer if, in its opinion, an instruction infringes applicable data protection law.
7. Confidentiality
Everyone MDCare authorises to process customer personal data is bound by an obligation of confidentiality that survives the end of their engagement, and has access only to what their role requires.
8. Security
MDCare implements the technical and organisational measures set out in Annex II, which is a summary of what is actually implemented — including the measures not yet in place. The customer confirms it has assessed those measures as appropriate to the risk of the processing it carries out.
9. Subprocessors
The customer gives general authorisation for MDCare to engage the subprocessors listed in Annex III. MDCare will give at least [30] days' notice before a new subprocessor begins processing customer personal data, by publishing the change on the subprocessor list and notifying the customer's billing contact. The customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the customer may terminate the affected part of the service [with a pro rata refund of prepaid fees].
Each subprocessor is bound by data protection obligations no less protective than those in this agreement, and MDCare remains fully liable to the customer for its subprocessors' performance.
10. Return and deletion
On termination, the customer may export its data for [30] days. After that, MDCare deletes it from live systems within [30] days, and from backups within [90] days as those backups age out on their ordinary retention cycle. Backups are not selectively edited; they expire. MDCare will confirm deletion in writing on request.
11. Assistance
Taking into account the nature of the processing, MDCare will assist the customer, at the customer's reasonable request:
- in responding to requests from data subjects to access, correct, delete or obtain their data;
- with data protection impact assessments and prior consultation;
- with the customer's own security obligations.
Where a data subject contacts MDCare directly about data held for a customer, MDCare will not respond substantively but will refer them to the customer and inform the customer promptly.
12. Data breaches
MDCare will notify the customer without undue delay, and in any event within [48] hours, of becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, that customer's personal data. The notification will describe what is known: the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken, and a contact point. Where the full picture is not yet available, MDCare will notify what it knows and follow up.
13. Audit
MDCare will make available the information necessary to demonstrate compliance with this agreement, and will allow and contribute to audits by the customer or a mandated auditor, [no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise, on thirty days' notice, during business hours, subject to confidentiality, and at the customer's cost]. MDCare may satisfy an audit request by providing documentation and answering questions in writing where that meets the customer's regulatory need.
14. Transfers abroad
Customer data is hosted in Germany (EU). Transfers to subprocessors outside Switzerland and the EEA are limited to those in Annex III and rely on the European Commission's standard contractual clauses with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, which are incorporated into this agreement by reference and prevail over it in the event of conflict.
15. Liability and governing law
[Liability under this agreement is subject to the limitations in the subscription terms.] This agreement is governed by Swiss law. The courts of [place] have exclusive jurisdiction, subject to any mandatory jurisdiction of a data subject's own courts.
Annex I — Details of the processing
As set out in clauses 2 to 5 above, which together form Annex I for the purposes of the standard contractual clauses. The customer is the data exporter and MDCare the data importer. The frequency of processing is continuous for the duration of the subscription.
Annex II — Technical and organisational measures
The full and current description is the security overview, which is incorporated here. In summary:
- Separation of customers. Every record belongs to one organisation. Isolation is enforced in the application, where a query without a tenant context fails rather than returning everything, and independently by database row-level security policies on every table holding customer data, applied to reads and to writes, with the application connecting as a non-superuser role so those policies bind it.
- Access control. Named accounts, three roles, passwords stored as salted PBKDF2-SHA256 hashes at 1,000,000 iterations, strength checks on new passwords, single-use time-limited invitation and reset tokens, and sessions on Secure, HttpOnly, SameSite cookies.
- Encryption. HTTPS everywhere with HSTS; uploaded documents stored privately and served only through signed links valid for five minutes; storage encrypted at rest by the hosting provider.
- Integrity. An append-only audit trail of creations, changes and deletions that the application refuses to modify or erase.
- Availability. Nightly database backups, compressed and retained, with implausibly small dumps rejected rather than stored, and restore procedures tested by executing them.
- Resilience and detection. Continuous liveness and readiness probing; error monitoring with personal data collection disabled.
- Development. An automated test suite that must pass before deployment, including tests that fail if a newly added table is not covered by tenant isolation.
- Measures not implemented. Stated in full under what we do not do yet: notably no multi-factor authentication, no sign-in rate limiting, no independent certification or penetration test, and no self-service export or erasure. The customer is asked to take these into account in its own risk assessment.
Annex III — Authorised subprocessors
| Subprocessor | Purpose | Location | Status |
|---|---|---|---|
| Hostinger International Ltd | Virtual server hosting: the application and the database | Germany (EU) | In use |
| Stripe Payments Europe Ltd | Subscription billing and payment processing | Ireland, with onward transfer to the United States | Not engaged |
| Delivery of service email: invitations, password resets, alerts | — | Not engaged | |
| Functional Software, Inc. (Sentry) | Error monitoring | United States | Not engaged |
| Object storage for uploaded maintenance reports and for off-site database backups | — | Not engaged |