On-Kare
    Log inDemo
    Legal Document

    Data Processing Agreement (DPA)

    Our commitment to transparent and compliant data processing for healthcare organizations worldwide.

    This Data Processing Agreement ("DPA") forms part of the service agreement between On-Kare SAS ("Processor") and the subscribing healthcare organization ("Controller"). It governs the processing of personal data, including protected health information (PHI), in connection with the On-Kare platform.

    On-Kare processes data in compliance with the EU General Data Protection Regulation (GDPR), the US Health Insurance Portability and Accountability Act (HIPAA), and applicable local healthcare data protection laws in over 50 countries.

    GDPR
    HIPAA
    SOC 2
    ISO 27001

    Agreement Articles

    Key provisions of the On-Kare Data Processing Agreement.

    Article 1 — Parties and Scope

    Defines the Controller (your organization) and the Processor (On-Kare SAS), and the scope of data processing under this agreement.

    • Controller: The healthcare organization subscribing to On-Kare services
    • Processor: On-Kare SAS, registered in France (SIRET provided upon request)
    • Scope: All personal data processed through the On-Kare platform

    Article 2 — Data Processing Details

    Specifies the types of personal data processed, categories of data subjects, and the purposes of processing.

    • Data types: Patient demographics, clinical records, appointment data, billing information
    • Data subjects: Patients, healthcare practitioners, administrative staff
    • Purpose: Healthcare service delivery, scheduling, billing, analytics, and compliance

    Article 3 — Controller and Processor Obligations

    Outlines the respective obligations of both parties regarding lawful data processing.

    • Processor acts only on documented instructions from the Controller
    • Confidentiality obligations for all personnel with access to personal data
    • Regular data protection impact assessments (DPIAs) conducted jointly

    Article 4 — Sub-processors

    Details the use of sub-processors and the Controller's right to object.

    • List of current sub-processors available upon request
    • Controller notified 30 days before any sub-processor change
    • Sub-processors bound by equivalent data protection obligations

    Article 5 — International Data Transfers

    Governs cross-border data transfers with appropriate safeguards.

    • EU Standard Contractual Clauses (SCCs) for transfers outside the EEA
    • Data residency options: EU, US, or region-specific hosting
    • Transfer Impact Assessment conducted for each destination country

    Article 6 — Security Measures

    Technical and organizational measures implemented to protect personal data.

    • AES-256 encryption at rest, TLS 1.3 in transit
    • Multi-factor authentication, role-based access controls
    • SOC 2 Type II audited infrastructure with 99.9% uptime SLA

    Article 7 — Data Breach Notification

    Procedures for detecting, reporting, and managing personal data breaches.

    • Controller notified within 72 hours of confirmed breach
    • Detailed incident report including scope, impact, and remediation steps
    • Dedicated incident response team available 24/7

    Article 8 — Data Subject Rights

    How On-Kare supports the Controller in fulfilling data subject rights requests.

    • Technical support for access, rectification, erasure, and portability requests
    • Automated data export in standard formats (JSON, CSV, FHIR)
    • Response assistance within 5 business days of Controller notification

    Article 9 — Duration and Termination

    Terms governing the duration of data processing and post-termination obligations.

    • DPA effective for the duration of the service agreement
    • Data returned or securely deleted within 30 days of termination
    • Certificate of destruction provided upon request

    Need a Signed DPA?

    Contact our compliance team to receive a signed copy of our Data Processing Agreement tailored to your organization.

    2,156 clinical and operational capabilities. One single platform.

    8 business domains, 25 specialties, 7 care settings and 343 AI-augmented capabilities — without stacking more software.

    See the coverage