GDPR data processing agreement

Version v1.1.0 · Effective

Introduction

This Data Processing Agreement ("DPA") forms part of the agreement under which Velarya LLC, a California limited liability company ("Velarya," "we," "us," or "our"), provides the Velarya platform to a practice (the "Customer"). That agreement is the service agreement between Velarya and the Customer or, where no service agreement has been signed, the Velarya Terms of Service (the "Agreement").

This DPA sets out the terms required by Article 28 of the GDPR for the processing Velarya carries out on the Customer's behalf. It is the agreement known in German as an Auftragsverarbeitungsvertrag (AVV), in French as a contrat de sous-traitance, in Spanish as a contrato de encargado del tratamiento, and in Dutch as a verwerkersovereenkomst.

This DPA applies to practices in every member state of the European Union; in Iceland, Liechtenstein, and Norway, which together with the European Union form the European Economic Area; in the United Kingdom, under the UK GDPR; and in Switzerland, under the Swiss Federal Act on Data Protection. It applies whenever Velarya processes Customer Personal Data that is subject to Data Protection Laws. It takes effect when the Customer accepts the Agreement or signs this DPA, whichever happens first, and remains in effect for as long as Velarya processes Customer Personal Data. A copy of this DPA signed by Velarya is available on request at hello@velarya.com.

This DPA is separate from the Business Associate Agreement that Velarya signs with practices subject to HIPAA in the United States, and does not replace it.

1. Definitions

The terms "controller," "processor," "data subject," "personal data," "personal data breach," "processing," "special categories of personal data," and "supervisory authority" have the meanings given to them in the GDPR. In addition:

"Customer Personal Data" means personal data that Velarya processes on behalf of the Customer in providing the Services, including personal data about the Customer's patients and clients and about its staff.

"Data Protection Laws" means, to the extent they apply to the processing, Regulation (EU) 2016/679 (the "GDPR") and the national data protection laws of member states of the European Economic Area that supplement it; the GDPR as it forms part of the law of the United Kingdom (the "UK GDPR") and the UK Data Protection Act 2018; and the Swiss Federal Act on Data Protection of 25 September 2020 (the "FADP").

"Services" means the Velarya platform and related services provided under the Agreement, including the clinic dashboard, the mobile applications built on the Velarya platform, and the Velarya API.

"Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

"Subprocessor" means a processor that Velarya engages to process Customer Personal Data.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

2. Roles and Instructions

Roles. The Customer is the controller of Customer Personal Data, and Velarya is its processor. Personal data that Velarya processes as a controller, such as the business contact and billing details it needs to administer the Customer's account, is outside this DPA and is covered by the Velarya Privacy Policy.

Documented instructions. Velarya processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers of personal data to a third country. The Agreement, this DPA, and the Customer's use and configuration of the Services are the Customer's instructions. Further instructions must be given in writing and be consistent with the Agreement. Where Velarya is required by law to process Customer Personal Data other than on the Customer's instructions, it will inform the Customer of that requirement before processing, unless that law prohibits doing so on important grounds of public interest.

Unlawful instructions. Velarya will inform the Customer immediately if, in its opinion, an instruction infringes Data Protection Laws.

Purpose limitation. Velarya will not process Customer Personal Data for any purpose other than providing the Services on the Customer's instructions. It will not sell Customer Personal Data, and will not use it to develop or train machine learning or artificial intelligence models for the benefit of any party other than the Customer.

Customer responsibilities. The Customer is responsible for the lawfulness of the processing it instructs, including having a legal basis for processing data concerning health, giving data subjects the information they are entitled to receive, and keeping the records its practice is required to keep.

3. Details of the Processing

Subject matter and duration. Velarya processes Customer Personal Data to provide the Services, for the term of the Agreement and for the period after it described in section 10.

Nature and purpose. Hosting, storage, retrieval, transmission, and deletion of Customer Personal Data in order to provide the Services, including appointment booking and scheduling; client records and clinical charting; forms and consents; photos; payments; memberships and loyalty programs; notifications and messages to clients; and support the Customer requests.

Data subjects. The Customer's patients and clients, including prospective clients; the Customer's staff, practitioners, and other users it authorizes; and people who contact the Customer through the Services.

Categories of personal data. Identity and contact details; appointment, booking, and purchase history; membership, wallet, and loyalty records; payment references, excluding full card numbers, which Stripe holds; clinical records, including treatment notes, charts, forms, consents, and photos; messages exchanged through the Services; and device identifiers and push notification tokens.

Special categories. Customer Personal Data includes data concerning health, a special category of personal data under Article 9 of the GDPR. Velarya protects it with the measures in section 11, including field-level encryption of the most sensitive free-text fields, permissions for health data that are granted separately from operational access, and an audit record for every request that touches it.

Frequency. Continuous, for as long as the Customer uses the Services.

Location. Customer Personal Data is stored and processed on Amazon Web Services in the US East (Northern Virginia) region, and by the Subprocessors listed in section 12. Velarya developers and support staff who maintain the Services and provide support may access Customer Personal Data remotely for those purposes.

4. Velarya's Obligations

Confidentiality. Velarya will ensure that every person it authorizes to process Customer Personal Data is bound by an appropriate duty of confidentiality and is trained on the obligations in this DPA.

Professional secrecy. Where the Customer is subject to a duty of professional secrecy under the law of its country, such as section 203 of the German Criminal Code (Strafgesetzbuch), Velarya will keep confidential any information protected by that duty, will require every person it authorizes to access that information to do the same, and acknowledges that the Customer has informed it that a breach of this obligation may be a criminal offense.

Security. Velarya implements the technical and organizational measures described in section 11 to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. Velarya may change those measures over time, provided the overall level of security is not reduced.

Assistance. Taking into account the nature of the processing and the information available to it, Velarya will assist the Customer in meeting its obligations under Articles 32 to 36 of the GDPR, which cover security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with a supervisory authority. On request, Velarya will provide its Security and Privacy Overview and written confirmation of the status of each Subprocessor agreement to support that work.

Records. Velarya will keep a record of the processing it carries out on the Customer's behalf, as required by Article 30(2) of the GDPR.

5. Subprocessors

Authorization. The Customer gives Velarya general written authorization to engage Subprocessors. The Subprocessors engaged when this DPA takes effect are listed in section 12.

Changes. Velarya will notify the Customer by email at least 30 days before engaging a new Subprocessor or replacing an existing one, and will update section 12 at the same time. The Customer may object to the change on reasonable data protection grounds within that period. If Velarya cannot resolve the objection, the Customer may terminate the Services affected by the change, without penalty, before the change takes effect.

Obligations. Velarya will engage each Subprocessor under a written contract that imposes data protection obligations no less protective than those in this DPA, including sufficient guarantees to implement appropriate technical and organizational measures. Velarya remains fully liable to the Customer for the performance of each Subprocessor's obligations.

6. Personal Data Breaches

Velarya will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent then known, the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences of the breach; the measures taken or proposed to address it and mitigate its effects; and a contact point at Velarya for further information. Information that is not available at first will follow as soon as it is.

Velarya will take reasonable steps to contain, investigate, and remedy the breach, and will cooperate with the Customer so that it can meet its own notification obligations. Notice of a breach is not an acknowledgment of fault or liability.

7. Data Subject Requests

Velarya will assist the Customer, through appropriate technical and organizational measures, in responding to requests from data subjects who exercise their rights under Chapter III of the GDPR. The Services let the Customer export its client list, correct client records, and archive or permanently delete a client record directly from the dashboard. Where the Customer cannot fulfill a request through the Services, Velarya will provide the assistance it needs within 10 business days of a written request.

If Velarya receives a request directly from a data subject concerning Customer Personal Data, it will refer the data subject to the Customer and will not respond to the request itself, except to confirm the referral or where the law requires it to.

8. Information and Audits

Velarya will make available to the Customer all information necessary to demonstrate compliance with Article 28 of the GDPR, including its Security and Privacy Overview and written confirmation of the status of each Subprocessor agreement.

Velarya will also allow for and contribute to audits, including inspections, conducted by the Customer or by an independent auditor the Customer mandates, where the information made available is not sufficient to demonstrate compliance or where a supervisory authority requires it. The Customer will give at least 30 days' written notice of an audit. Audits take place no more than once in any 12 months, except following a personal data breach or at the direction of a supervisory authority; are conducted during business hours and remotely where possible; and are subject to appropriate confidentiality obligations. Each party bears its own costs of an audit.

9. International Transfers

Transfers from the European Economic Area. Velarya is established in the United States and processes Customer Personal Data there. Where Customer Personal Data is transferred from the European Economic Area to Velarya, the Standard Contractual Clauses, Module Two (transfer controller to processor), are incorporated into this DPA by reference, with the Customer as data exporter and Velarya as data importer. They are completed as follows: Clause 7 (docking clause) applies; in Clause 9(a), Option 2 (general written authorization) applies, with a notice period of 30 days; the optional language in Clause 11(a) does not apply; the competent supervisory authority under Clause 13 is the supervisory authority of the member state in which the Customer is established; under Clause 17, the Clauses are governed by the law of the EU member state in which the Customer is established or, where that law does not allow for third-party beneficiary rights, by the law of Ireland; and under Clause 18(b), disputes are resolved by the courts of the EU member state in which the Customer is established.

Annexes. For the purposes of the Standard Contractual Clauses, Annex I.A is completed with the Customer as data exporter and controller, using the contact details the Customer provides under the Agreement, and Velarya LLC as data importer and processor, contactable at hello@velarya.com, with each party's signature and date being those of its acceptance of the Agreement or this DPA; Annex I.B is completed with the details in section 3; Annex I.C is completed with the supervisory authority identified above; Annex II is completed with the measures in section 11; and Annex III is completed with the Subprocessors in section 12.

Transfers from the United Kingdom. Where Customer Personal Data is transferred from the United Kingdom, the UK Addendum is incorporated into this DPA by reference. Table 1 is completed with the parties and contact details in this DPA; Table 2 with the Standard Contractual Clauses as completed above; Table 3 with sections 3, 11, and 12 of this DPA; and in Table 4, either party may end the UK Addendum as set out in its Section 19.

Transfers from Switzerland. Where Customer Personal Data is transferred from Switzerland, the Standard Contractual Clauses as completed above apply with these changes: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "member state" is not interpreted to prevent data subjects in Switzerland from bringing claims in their place of habitual residence. Where a transfer is subject to both the GDPR and the FADP, the completions above apply to the extent the GDPR governs the transfer.

Requests from public authorities. Velarya will provide the information the Customer reasonably needs to assess its transfers under Clause 14 of the Standard Contractual Clauses. If a public authority requests access to Customer Personal Data, Velarya will act as Clause 15 requires, including notifying the Customer where the law permits, challenging a request it considers unlawful, and disclosing no more than the minimum the request requires.

10. Return and Deletion

When the Agreement ends, Velarya will, at the Customer's choice, return Customer Personal Data to the Customer or delete it, and will delete existing copies unless the law of the European Union or a member state requires their storage. The Customer will make its choice within 60 days after the Agreement ends, and Velarya will give the Customer a reasonable opportunity to export its data in a machine-readable format before any deletion takes place.

Copies held in backup media are deleted in the ordinary course of Velarya's backup retention cycle and remain protected by this DPA until they are.

The Customer remains responsible for keeping the records it is required to keep, including patient documentation that its practice must retain for a fixed period under national law, and should export those records before deletion.

11. Technical and Organizational Measures

Hosting. The platform runs on Amazon Web Services in the US East (Northern Virginia) region, under a Business Associate Addendum between Velarya and Amazon Web Services.

Encryption. The most sensitive free-text fields are encrypted at the field level with AES-256-GCM, using data keys generated by AWS Key Management Service under a dedicated customer-managed key with automatic rotation. Each practice's identifier is bound to its ciphertext, so data belonging to one practice cannot be decrypted in the context of another. Uploaded files are stored in Amazon S3 with AES-256 server-side encryption and are served through short-lived presigned URLs. All traffic is served over TLS with HTTP Strict Transport Security, and the application connects to its database with TLS required.

Access control. Users sign in with one-time passcodes sent by SMS or email, so there are no passwords to steal or reuse. Access tokens expire after fifteen minutes; refresh tokens are stored only as hashes, rotate on every use, and revoke every session for the user if a used token is presented again. Sign-in and session endpoints are rate limited. Access is governed by roles and permissions, with permissions for health data granted separately from operational access, and staff can be limited to specific locations. A practice can restrict dashboard access to a set of IP addresses.

Support access. Velarya support views a practice's account only with the practice's permission, through a time-limited impersonation session that expires automatically and is recorded on every resulting audit record.

Separation between practices. Every application query is scoped to the practice identified in the verified session, never to a value supplied by the caller, and a dedicated regression suite tests that one practice cannot reach another practice's data.

Audit logging. Every request that touches health data writes an audit record identifying the practice, the acting user, the action and resource, the result, the originating IP address, and the time. Denied attempts are recorded as well as successful ones, and audit records are retained rather than deleted.

Secrets and privileges. Application secrets are held in encrypted AWS secret storage and injected at runtime, and the application can use its field-encryption key only to generate and decrypt data keys.

Secure development. Changes that touch health data, permissions, or audit logging receive a targeted security review before release, and the platform receives periodic full-codebase security audits. Every production release runs the type check and the full automated test suite of more than 8,000 tests, and production deploys are started by a person, never automatically.

Personnel. Velarya requires everyone it authorizes to access Customer Personal Data to keep it confidential, and trains them on their obligations under this DPA.

Deletion. Permanently deleting a client record purges the associated records, including clinical records, rather than hiding them.

12. Current Subprocessors

Amazon Web Services, Inc. United States. Hosting, compute, database, file storage, key and secrets management, transactional email through Amazon SES, and text message delivery as it moves to Amazon Web Services.

Stripe, Inc. United States. Card processing and payment method storage. Card numbers are handled by Stripe and are not stored on Velarya systems.

Twilio Inc. United States. Text message delivery, including appointment reminders and sign-in passcodes, and two-way messaging and calls where the Customer uses them.

Google LLC. United States. Push notification delivery through Firebase Cloud Messaging, and app crash reporting through Firebase Crashlytics.

Vercel Inc. United States. Hosting of the clinic dashboard web application.

13. General Terms

Liability. Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except to the extent Data Protection Laws or the Standard Contractual Clauses do not permit those limitations.

Order of precedence. With respect to Customer Personal Data, this DPA prevails over any conflicting term of the Agreement, and the Standard Contractual Clauses and the UK Addendum prevail over this DPA.

Governing law. This DPA is governed by the law that governs the Agreement, except that the Standard Contractual Clauses and the UK Addendum are governed as set out in section 9.

Updates. Velarya may update this DPA to reflect changes in law, in its Subprocessors, or in the Services, and will publish each version on this page with its effective date. No update will reduce the protection this DPA gives Customer Personal Data without the Customer's agreement.

14. Contact

Questions about this DPA, requests for a signed copy, and notices under it can be sent to Velarya at the address below.

Velarya LLC Email: hello@velarya.com Website: https://velarya.com