DPA
Operational controls and processing commitments
The clinic acts as the controller or fiduciary for its patient data, and RehabDesk AI acts as the processor for the services described in this agreement. All processing occurs under the documented instructions of the clinic.
The processor implements administrative, technical, and organizational security controls including encryption, access control, environment segregation, logging, vulnerability management, and incident response procedures.
Personnel with access to protected systems are bound by confidentiality obligations, least-privilege access, and completion of security awareness requirements. Access is limited to the minimum needed for service delivery.
In the event of a security incident affecting customer data, RehabDesk AI will notify the clinic promptly, assess the impact, and cooperate in remediation and reporting steps required by the clinic's legal or regulatory obligations.