Back to home

Data Processing Agreement (DPA)

Draft under legal review · June 2026

Parties

Between the Therapist ("Controller") and [Operator] ("Processor"). Deemed accepted upon using sanemos-pro's clinical features.

1. Purpose and roles

The Processor processes, on behalf of and under the Controller's instructions, the personal data of the Controller's patients entered or managed on the platform, solely to provide the service described in the Terms.

2. Data and data-subject categories

Data subjects: the Controller's patients. Data: identification and contact, intake forms, session notes and goals, tasks, communications and, where applicable, video-call recordings. Includes sensitive mental-health data, subject to heightened protection.

3. Instructions

The Processor processes data only per the Controller's documented instructions and as needed to provide the service; it does not use the data for its own purposes. AI summaries are generated only at the Controller's request and are not used to train third-party models.

4. Confidentiality

The Processor ensures authorized personnel are bound by confidentiality.

5. Security measures

TLS encryption in transit; role-based access control (RLS); encryption of intake forms (AES-256-GCM). The Processor applies reasonable technical and organizational measures appropriate to the data's sensitivity.

6. Sub-processors

The Controller authorizes the sub-processors listed in the Privacy Policy (Supabase, Vercel, Flow, LiveKit, Resend, AI providers). The Processor will give reasonable advance notice of material changes, allowing reasoned objection.

7. Assistance to the Controller

The Processor reasonably assists the Controller in handling patient rights requests and security obligations. Patient consent is obtained by the Controller; on the platform, the patient accepts the link from the patient app (sanemos.ai).

8. Breach notification

The Processor will notify the Controller without undue delay (target: within 72 hours of becoming aware) of any security breach affecting their patients' data, with available information.

9. Return or deletion

On service termination, at the Controller's choice, the Processor returns or deletes patient data within 30 days, except where law requires retention.

10. Audit

The Processor makes available the reasonable information needed to demonstrate compliance with this DPA.

11. Term and governing law

Effective for the duration of the service relationship. Governed by Chilean law (19,628 and 21,719); jurisdiction: courts of Santiago.