Data processing agreement

Version 0.1 · 2026-09-25

This agreement governs MDCare's processing of personal data on behalf of a customer. It forms part of the subscription terms and is intended to satisfy Article 9 of the revised Swiss Federal Act on Data Protection and Article 28 of the General Data Protection Regulation.

Passages in [square brackets] are commercial or legal decisions that have not been made yet. They must be settled before this is offered for signature.

1. Parties and roles

Controller: the customer identified in the subscription (the clinic, hospital or practice).
Processor: AI-Fi Sarl.

The customer determines the purposes and means of the processing. MDCare processes personal data only on the customer's documented instructions, of which use of the service in accordance with its documentation forms part.

2. Subject matter, nature and purpose

Provision of a medical device maintenance management service: recording equipment, planning and recording maintenance, collecting measurements, storing evidential documents and producing the records required to demonstrate compliance with Swiss medical device regulation.

3. Duration

For the term of the subscription, and thereafter only for as long as needed to meet the deletion and return obligations in clause 10.

4. Categories of data subject

The service is not designed to process data concerning patients, and the customer undertakes not to enter patient data into it. Uploaded documents are the only route by which such data could arrive; the customer is responsible for what it uploads.

5. Categories of personal data

No special categories of personal data within the meaning of Article 5(c) of the revised Swiss Act or Article 9 GDPR are intended to be processed.

6. Instructions

MDCare processes personal data only on the customer's documented instructions, including as to transfers abroad, unless required otherwise by Swiss or EU law. Where such a requirement applies, MDCare will inform the customer before processing unless the law forbids it. MDCare will tell the customer if, in its opinion, an instruction infringes applicable data protection law.

7. Confidentiality

Everyone MDCare authorises to process customer personal data is bound by an obligation of confidentiality that survives the end of their engagement, and has access only to what their role requires.

8. Security

MDCare implements the technical and organisational measures set out in Annex II, which is a summary of what is actually implemented — including the measures not yet in place. The customer confirms it has assessed those measures as appropriate to the risk of the processing it carries out.

9. Subprocessors

The customer gives general authorisation for MDCare to engage the subprocessors listed in Annex III. MDCare will give at least [30] days' notice before a new subprocessor begins processing customer personal data, by publishing the change on the subprocessor list and notifying the customer's billing contact. The customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the customer may terminate the affected part of the service [with a pro rata refund of prepaid fees].

Each subprocessor is bound by data protection obligations no less protective than those in this agreement, and MDCare remains fully liable to the customer for its subprocessors' performance.

10. Return and deletion

On termination, the customer may export its data for [30] days. After that, MDCare deletes it from live systems within [30] days, and from backups within [90] days as those backups age out on their ordinary retention cycle. Backups are not selectively edited; they expire. MDCare will confirm deletion in writing on request.

11. Assistance

Taking into account the nature of the processing, MDCare will assist the customer, at the customer's reasonable request:

Where a data subject contacts MDCare directly about data held for a customer, MDCare will not respond substantively but will refer them to the customer and inform the customer promptly.

12. Data breaches

MDCare will notify the customer without undue delay, and in any event within [48] hours, of becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, that customer's personal data. The notification will describe what is known: the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken, and a contact point. Where the full picture is not yet available, MDCare will notify what it knows and follow up.

13. Audit

MDCare will make available the information necessary to demonstrate compliance with this agreement, and will allow and contribute to audits by the customer or a mandated auditor, [no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise, on thirty days' notice, during business hours, subject to confidentiality, and at the customer's cost]. MDCare may satisfy an audit request by providing documentation and answering questions in writing where that meets the customer's regulatory need.

14. Transfers abroad

Customer data is hosted in Germany (EU). Transfers to subprocessors outside Switzerland and the EEA are limited to those in Annex III and rely on the European Commission's standard contractual clauses with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, which are incorporated into this agreement by reference and prevail over it in the event of conflict.

15. Liability and governing law

[Liability under this agreement is subject to the limitations in the subscription terms.] This agreement is governed by Swiss law. The courts of [place] have exclusive jurisdiction, subject to any mandatory jurisdiction of a data subject's own courts.


Annex I — Details of the processing

As set out in clauses 2 to 5 above, which together form Annex I for the purposes of the standard contractual clauses. The customer is the data exporter and MDCare the data importer. The frequency of processing is continuous for the duration of the subscription.

Annex II — Technical and organisational measures

The full and current description is the security overview, which is incorporated here. In summary:

Annex III — Authorised subprocessors

Subprocessor Purpose Location Status
Hostinger International Ltd Virtual server hosting: the application and the database Germany (EU) In use
Stripe Payments Europe Ltd Subscription billing and payment processing Ireland, with onward transfer to the United States Not engaged
Delivery of service email: invitations, password resets, alerts — Not engaged
Functional Software, Inc. (Sentry) Error monitoring United States Not engaged
Object storage for uploaded maintenance reports and for off-site database backups — Not engaged

Maintained on the subprocessor list, which is the authoritative version.


AI-Fi Sarl.
Available in English only. French, German and Italian versions follow legal review, since a translated contract needs a lawyer per language.