Data Processing Agreement (DPA)
Our commitment to transparent and compliant data processing for healthcare organizations worldwide.
This Data Processing Agreement ("DPA") forms part of the service agreement between On-Kare SAS ("Processor") and the subscribing healthcare organization ("Controller"). It governs the processing of personal data, including protected health information (PHI), in connection with the On-Kare platform.
On-Kare processes data in compliance with the EU General Data Protection Regulation (GDPR), the US Health Insurance Portability and Accountability Act (HIPAA), and applicable local healthcare data protection laws in over 50 countries.
Agreement Articles
Key provisions of the On-Kare Data Processing Agreement.
Article 1 — Parties and Scope
Defines the Controller (your organization) and the Processor (On-Kare SAS), and the scope of data processing under this agreement.
- Controller: The healthcare organization subscribing to On-Kare services
- Processor: On-Kare SAS, registered in France (SIRET provided upon request)
- Scope: All personal data processed through the On-Kare platform
Article 2 — Data Processing Details
Specifies the types of personal data processed, categories of data subjects, and the purposes of processing.
- Data types: Patient demographics, clinical records, appointment data, billing information
- Data subjects: Patients, healthcare practitioners, administrative staff
- Purpose: Healthcare service delivery, scheduling, billing, analytics, and compliance
Article 3 — Controller and Processor Obligations
Outlines the respective obligations of both parties regarding lawful data processing.
- Processor acts only on documented instructions from the Controller
- Confidentiality obligations for all personnel with access to personal data
- Regular data protection impact assessments (DPIAs) conducted jointly
Article 4 — Sub-processors
Details the use of sub-processors and the Controller's right to object.
- List of current sub-processors available upon request
- Controller notified 30 days before any sub-processor change
- Sub-processors bound by equivalent data protection obligations
Article 5 — International Data Transfers
Governs cross-border data transfers with appropriate safeguards.
- EU Standard Contractual Clauses (SCCs) for transfers outside the EEA
- Data residency options: EU, US, or region-specific hosting
- Transfer Impact Assessment conducted for each destination country
Article 6 — Security Measures
Technical and organizational measures implemented to protect personal data.
- AES-256 encryption at rest, TLS 1.3 in transit
- Multi-factor authentication, role-based access controls
- SOC 2 Type II audited infrastructure with 99.9% uptime SLA
Article 7 — Data Breach Notification
Procedures for detecting, reporting, and managing personal data breaches.
- Controller notified within 72 hours of confirmed breach
- Detailed incident report including scope, impact, and remediation steps
- Dedicated incident response team available 24/7
Article 8 — Data Subject Rights
How On-Kare supports the Controller in fulfilling data subject rights requests.
- Technical support for access, rectification, erasure, and portability requests
- Automated data export in standard formats (JSON, CSV, FHIR)
- Response assistance within 5 business days of Controller notification
Article 9 — Duration and Termination
Terms governing the duration of data processing and post-termination obligations.
- DPA effective for the duration of the service agreement
- Data returned or securely deleted within 30 days of termination
- Certificate of destruction provided upon request
Need a Signed DPA?
Contact our compliance team to receive a signed copy of our Data Processing Agreement tailored to your organization.
2,156 clinical and operational capabilities. One single platform.
8 business domains, 25 specialties, 7 care settings and 343 AI-augmented capabilities — without stacking more software.