Back to home
Legal center

DPA

Data Processing Agreement

Operational controls and processing commitments

1. Roles

The clinic acts as the controller or fiduciary for its patient data, and RehabDesk AI acts as the processor for the services described in this agreement. All processing occurs under the documented instructions of the clinic.

2. Security of processing

The processor implements administrative, technical, and organizational security controls including encryption, access control, environment segregation, logging, vulnerability management, and incident response procedures.

3. Confidentiality

Personnel with access to protected systems are bound by confidentiality obligations, least-privilege access, and completion of security awareness requirements. Access is limited to the minimum needed for service delivery.

4. Breach handling

In the event of a security incident affecting customer data, RehabDesk AI will notify the clinic promptly, assess the impact, and cooperate in remediation and reporting steps required by the clinic's legal or regulatory obligations.