Data Processing Agreement
Last updated: 2 September 2026
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the agreement between Qmedify (“Processor”) and the customer identified in the applicable order or account (“Controller”) for the use of the Qmedify platform (the “Service”).
To the extent Qmedify processes personal data on the Controller’s behalf in connection with the Service, Qmedify acts as a processor and the Controller acts as a controller (or as a processor acting on behalf of its own controller). This DPA implements Article 28 of Regulation (EU) 2016/679 (“GDPR”).
2. Subject matter and details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Service to the Controller. |
| Duration | For the term of the agreement, plus the deletion period in section 9. |
| Nature and purpose | Hosting, storage, and processing of Controller data to operate the Service, including AI-assisted drafting, literature search, and document generation. |
| Types of personal data | Account data (name, email, role); any personal data the Controller or its users choose to enter into the workspace or upload (e.g. names of authors, reviewers, or individuals referenced in clinical or literature materials). |
| Categories of data subjects | The Controller’s personnel and authorised users; individuals referenced in content the Controller submits. |
| Special categories | Not intentionally processed. The Controller must not upload health or other special-category data relating to identifiable individuals unless separately agreed. |
3. Processor obligations
- Process personal data only on the Controller’s documented instructions, including this DPA and use of the Service, unless required otherwise by law (in which case Qmedify will inform the Controller where legally permitted).
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement and maintain the technical and organisational measures described in Annex 2.
- Assist the Controller, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations under Articles 32–36 GDPR.
- Make available information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, subject to section 7.
- Inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law.
4. Security
Qmedify implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2, and reviews them periodically. The Controller is responsible for its own use of the Service, including access management and the decision about what data to enter.
5. Sub-processors
The Controller provides general authorisation for Qmedify to engage sub-processors to provide the Service. Current sub-processors are listed in Annex 3. Qmedify imposes data protection obligations on each sub-processor that are no less protective than those in this DPA and remains liable for their performance. Qmedify will give the Controller reasonable prior notice of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data protection grounds.
6. International transfers
Controller data is hosted in the European Union (application hosting and database, authentication, and file storage in the Frankfurt region). Certain sub-processors identified in Annex 3 — namely the payment processor and the AI providers — process limited personal data in the United States. Where processing involves a transfer of personal data outside the EEA/UK to a country without an adequacy decision, such transfers are made under the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with any supplementary measures required. Annex 3 identifies the location of each sub-processor.
7. Audits
Qmedify will respond to reasonable written audit requests by providing its then-current security documentation and answers to a security questionnaire. Where that is not sufficient to satisfy a mandatory audit obligation, the Controller may conduct an audit no more than once per year, on at least 30 days’ notice, during business hours, without disrupting Qmedify’s operations, and subject to confidentiality. The Controller bears its own audit costs.
8. Personal data breach
Qmedify will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and will provide information reasonably available to it to assist the Controller in meeting its notification obligations.
9. Return and deletion
On termination of the Service, and on the Controller’s written request, Qmedify will delete or return the Controller’s personal data and delete existing copies within a reasonable period (target 30 days), unless retention is required by law. Controllers can also delete data within the Service at any time.
10. Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the agreement. If there is a conflict between this DPA and the agreement on data protection matters, this DPA prevails.
Annex 1 — Parties
Processor: Qmedify, operated by SIA Medicity, a limited liability company registered in Latvia under unified registration number 40203372881, with its registered office at Apuzes street 13–8, Riga, Latvia. Contact: info@qmedify.com.
Controller: the customer identified in the order or account.
Controller: the customer identified in the order or account.
Annex 2 — Technical and organisational measures
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Access control: authenticated accounts, least-privilege roles, and database row-level authorisation isolating each customer’s workspace.
- Application hosting and data storage with reputable cloud providers in the European Union (Frankfurt region).
- Logical separation (multi-tenancy) of each customer’s data, enforced at the application and database layers.
- Automated encrypted backups with point-in-time recovery and periodically tested restore procedures.
- Centralised logging and monitoring of access to production systems, with alerting on anomalous activity.
- Documented incident response process covering detection, containment, notification, and post-incident review.
- Vulnerability management and timely patching of platform and dependencies; periodic security testing, including annual penetration testing.
- Staff bound by written confidentiality obligations and required to complete security awareness training.
- Multi-factor authentication required for administrative access to production infrastructure.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU — Frankfurt (Supabase Inc., US; EU data region, SCCs) |
| Vercel | Application hosting and serverless functions | EU — Frankfurt (Vercel Inc., US; SCCs) |
| Stripe | Payment processing and billing | EU / US (Stripe Payments Europe Ltd; SCCs for US processing) |
| OpenAI | AI-assisted drafting and document generation (API only; no training on customer data) | US (SCCs) |
| Groq | AI-assisted literature search and drafting (API only; no training on customer data) | US (SCCs) |
| Zoho (Zoho Corporation B.V.) | Transactional and notification email | EU (zoho.eu data centre) |
This list is kept current. Qmedify will give notice of any addition or replacement of a sub-processor in accordance with section 5.