PERSONAL DATA PROCESSING AGREEMENT
to the General Terms and Conditions of Use of “Morph Practice” DPK
This Data Processing Agreement (DPA) applies to you (“the Client”, “Controller”) and “Morf Praktis” DPK, a variable capital company established and existing under the laws of the Republic of Bulgaria, registered in the Commercial Register at the Registry Agency with UIC 208606913, with its registered office and address of management: Sofia, Postal Code 1404, Triaditsa District, Goce Delchev Residential Complex, 21 Louis Ayer Street, Apartment 11 (hereinafter referred to as “the Company,” “the Processor”), in connection with the processing of personal data.
This Agreement applies in conjunction with the Terms of Service. By accepting the Terms of Service and/or using the services provided on the Company’s platform, you agree to this Agreement.
Preamble
1.1The Customer engages the Company to provide services, including access to the online platform (“Platform(s)”) and related support services, configuration, technical support, hosting, and other services described in the General Terms and Conditions and/or the Order/Subscription Form, if applicable (“the Services”).
1.2. This Agreement is an integral part of the General Terms and Conditions and sets forth the terms agreed upon by the parties regarding the processing of personal data (including “Customer Data”) in accordance with applicable data protection laws.
1.3. In the course of providing the Services, the Company may process personal data on behalf of and for the account of the Client. The types of personal data and categories of data subjects are described in Appendix No. 1 to this Service Agreement.
Terms and Definitions
2.1. “Controller,” “Processor,” “Data Subject,” “Processing” have the meaning assigned to them in Regulation (EU) 2016/679 (EU) of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“General Data Protection Regulation,” “GDPR”).
2.2. “Data Protection Legislation” means the GDPR and any applicable national legislation regarding the protection of personal data, including binding guidelines issued by a supervisory authority.
2.3. “End User” means a natural person (data subject) whose personal data is entered into the Platform by the Client and/or processed by the Company on the Client’s instructions as part of the Services.
2.4. “Standard Contractual Clauses (SCCs)” means the European Commission’s standard clauses for transfers to third countries pursuant to Implementing Decision (EU) 2021/914 of June 4, 2021, as amended or supplemented.
2.5. “Security breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
2.6. “Processor” means a third party authorized to process personal data on behalf of the Company for the purpose of providing parts of the Services.
2.7. “Technical and organizational measures” means the measures referred to in Article 32 of the GDPR, as described in Annex 2 to this SOD.
III. Processing of Personal Data
3.1. Roles of the parties
The Parties confirm that, for the purposes of this Agreement:
(1) The client is the data controller;
(2) “Morf Praktis” DPC is a processor;
(3) The Company may engage subcontractors in accordance with the terms of Section V of this Agreement.
If, during the provision of the Services, the parties determine that the actual circumstances do not correspond to the above, they shall notify each other and act in good faith to clarify or amend the agreed roles, to the extent necessary.
3.2. Obligations of the Client (Administrator)
(1) The Customer warrants that it processes personal data in connection with the Platform’s Services in accordance with data protection laws.
(2) The Client’s instructions to the Company:
- are lawful;
- do not require the Company to engage in unlawful processing.
(3) The customer is solely responsible for:
- the accuracy and up-to-date nature of the data entered;
- the legal grounds under Article 6 and, where necessary, under Article 9 of the GDPR;
- the purposes for which end users’ personal data is processed;
- the provision of the necessary information/notifications to data subjects (including end users);
- maintaining valid consents, where applicable;
- entering only the data necessary for the purposes specified by the Data Controller;
- determining the retention periods for medical or therapeutic records;
- compliance with applicable ethical, professional, and regulatory requirements, including those regarding the confidentiality and retention of therapeutic documentation.
(4) The customer shall provide and maintain an up-to-date contact for notifications regarding data protection; notifications sent to this contact shall be deemed to have been duly delivered.
(5) The Customer represents and warrants that it provides the Company only with data that is objectively necessary for the provision of the services.
(6) The Client is responsible for determining and maintaining an up-to-date list of persons authorized to access (including administrative access) the Client’s account on the Platform, including when the Client is a legal entity and access is granted by its legal representative, authorized representative, employee, or other person acting on behalf of and for the account of the Client (“Authorized Person(s)”).
(7) The Client warrants that the Authorized Persons have the necessary authority and instructions to enter personal data into the Platform and to process such data on behalf of the Clients, including to maintain professional confidentiality where applicable.
(8) In the event that any Authorized Person:
(a) ceases to have the right to represent the Client or act on the Client’s behalf; and/or
(b) terminates an employment, service, or contractual relationship with the Client; and/or
(c) loses the access rights granted to them under the Client’s internal rules,
The customer is required, without undue delay, to:
- revoke or restrict the relevant access;
- update the user account credentials/access data (including the access password, authentication method, etc.);
- designate a new Authorized Person when necessary for the administration of the account.
(9) Until the actions described in the preceding paragraph are completed, any use of the account via the Client’s credentials/access is deemed to have been made on behalf of the Client, and the Client is responsible for taking measures to protect personal data, including preventing unauthorized access.
(10) The Company shall not be liable for unauthorized access, security breaches, or unlawful processing resulting from:
a) the Customer’s failure to fulfill its obligations under this clause;
b) failure to take timely action to revoke or modify access;
c) compromised credentials under the control of the Customer and/or its Authorized Persons.
(11) At the Client’s request, the Company shall provide reasonable assistance in technically restricting or terminating access to the account, to the extent possible through the Platform’s standard features and in compliance with applicable law and security measures.(12) The Customer agrees to implement appropriate organizational and technical security measures regarding access to the Platform, including (where applicable) the use of strong passwords, a “need-to-know” principle with respect to its Authorized Persons, periodic review of access rights, and immediate revocation of access when no longer necessary.
(13) The Client acknowledges and agrees that the Company provides solely technical infrastructure and has no involvement in or control over the professional decisions, objectives, or methods of the therapeutic practice. Determining the retention periods for medical or therapeutic documentation is entirely within the competence and responsibility of the Client as the Data Controller.
(14) The customer acknowledges that the AI dictation feature is optional and is activated and used solely at the customer’s discretion.
(15) The Client agrees to instruct its Authorized Representatives not to include any personally identifiable information about End Users (patients) in the audio recordings.
(16) The Customer is responsible for ensuring that there is an appropriate legal basis under Article 6 and, where applicable, under Article 9 of the GDPR for the use of the AI dictation feature with respect to End Users, including providing the necessary information and notifications when using the feature.
3.3. Obligations of the Company (the Data Controller)
(1) The Company processes personal data solely on the basis of the Client’s pre-documented instructions, and only to the extent and for the purposes necessary for the proper provision of the Services, as described in detail in Annex 1 to this Agreement.
Instructions are considered documented when provided through the Platform’s features, via a ticket system or email from a registered Client contact, or through another official written channel.
(2) The Company shall not be liable and shall have no obligation to exercise control or supervision over the lawfulness of the collection, the basis for processing, the content, accuracy, or legitimacy of the personal data provided by the Client, nor over the processing activities carried out by the Client with respect to End Users (patients).
(3) If the Company has reasonable grounds to suspect or concludes that a Client’s instruction conflicts with Regulation (EU) 2016/679 or other applicable data protection legislation, it shall notify the Client in writing without undue delay. In such a case, the Company shall be entitled to suspend the execution of the relevant instruction until it receives lawful, clear, and enforceable instructions from the Client, without this being considered a breach of contract.
(4) The Company ensures that all persons authorized to process personal data on its behalf are bound by a contractual or legal obligation of confidentiality, which remains in effect even after the termination of the relevant legal relationship, and that access to personal data is granted only on a need-to-know basis.
(5) The Company takes reasonable and proportionate measures to ensure that, when using the AI functionality, personal data is processed solely for the purpose of providing the transcription results and is not used for training or improving models by the AI Sub-processor, where such an option is contractually and technically available.
(6) The Company requires the AI Processor to apply retention restrictions, including deletion or deactivation of storage, where possible under the selected service plan.
(7) If there is a change in the AI Sub-Processor’s terms and conditions that would result in broader processing (e.g., retention, training, secondary purposes), the Company shall notify the Client in accordance with Section V, and the Client may discontinue use of the functionality.
3.4. End-to-end encryption (E2EE) and access to content
(1) The data entered by the Client regarding its end users (patients) into the Platform, comprising communication content, medical information, and other personal data as defined by the GDPR, is stored and processed using end-to-end encryption, also known as “end-to-end encryption,” in which cryptographic keys are generated and stored in a manner that does not allow the Company to have normal access to the personal data or to read its content.
(2) The encryption method described in the preceding paragraph applies to the content of the data. The data required to create and maintain a user account and for identification (e.g., the Client’s/Professional’s email address, login credentials, and technical metadata) is processed separately and does not constitute part of the encrypted content within the meaning of the preceding paragraph.
(3) In limited, exceptional, and duly justified cases-including, but not limited to, technical support, security incident investigation, prevention or mitigation of harm, or emergency system recovery-a specifically authorized individual may obtain technical access to a cryptographic environment or mechanism, only to the extent objectively necessary, subject to strict internal controls, logging, and confidentiality, in accordance with Annex No. 2 to this SLA and the Company’s internal policies.
(4) To the extent necessary for security, diagnostics, and reporting, the Company may process limited technical data (metadata/logs) regarding the use of the AI functionality (such as request time, account ID, processing status, etc.) without processing the content of the recording beyond the agreed scope.
Rights of data subjects
4.1. Complaints and General Requests
(1) The Company shall notify the Client without undue delay upon receipt of a complaint, report, or other inquiry from a data subject or supervisory authority, to the extent that such communication relates to the Client’s obligations as a Data Controller within the meaning of the GDPR.
(2) The Company does not respond to such complaints or requests on its own initiative, unless expressly authorized by the Client or required by applicable law.
(3) The notification shall be made to the extent and in the manner permitted by applicable law, including rules regarding confidentiality and restrictions on the disclosure of information.
4.2. Requests from entities
(1) If the Company receives a request from a data subject to exercise rights under Articles 15-22 of the GDPR (including the right of access, rectification, erasure, restriction of processing, data portability, or objection), the Company shall notify the Client without undue delay and, as a rule, no later than 3 business days after receipt of the request.
(2) The Company will not take any substantive action on such a request unless expressly instructed in writing by the Client or unless required to do so by applicable law.
(3) The Company shall provide reasonable and proportionate assistance to the Customer in fulfilling its obligations under Articles 12-23 of the GDPR, to the extent that:
(a) The customer is unable to fulfill the request on their own using the Platform’s available features;
(b) the requested assistance is legally permissible and technically feasible.
(4) The cooperation referred to in the preceding paragraph is limited to providing the information and technical support available to the Company in its capacity as a Data Processor.
(5) To the extent that providing assistance requires extraordinary technical measures, additional development, retrieval of archived data, or disproportionate resources, the associated costs shall be borne by the Client, unless the parties expressly agree otherwise in writing.
Subcontractors
5.1. Appointment and General Authorization
(1) The Client, in its capacity as the Controller, grants the Company general prior authorization to engage processors (“Processors”) for the purpose of providing the Services.
(2) The Company maintains an up-to-date list of Subprocessors (“List of Subprocessors”), which includes at a minimum the name, country of establishment, and a description of the service provided, and makes it available to the Client upon request or by publishing it in a secure environment.Publication/Updating of the List
(3) The Company shall notify the Client of any planned change involving the addition or replacement of a Subprocessor, providing sufficient information to enable the Client to exercise its right to object.
Notification is provided by sending an email to the address specified in the Customer’s Profile and is deemed to have been received on the day it is sent.
5.2. Right to object
(1) The client has the right to object to the appointment of a new processor on legitimate grounds related to the protection of personal data by submitting a written, reasoned objection within 5 (five) business days of receiving the notification.
(2) If no objection is raised within the specified time limit, the subcontractor is deemed to have been approved.
(3) In the event of a dispute, the parties shall discuss possible alternative solutions in good faith. The Company may, at its discretion:
(a) not to engage the relevant Subprocessor;
(b) to propose a technical or organizational solution to restrict the processing;
(c) if this is objectively impossible, to terminate the relevant part of the Service.
(4) The Customer acknowledges that an objection to a specific Subcontractor may result in a limitation of functionality, a delay in the provision of the Services, or a change in the remuneration, where such change is objectively necessitated by the need for an alternative solution.
5.3. Contractual Warranties and Liability
(1) The Company guarantees that a written agreement has been concluded with each Processor, imposing obligations that are, in substance, no less stringent than those set forth in this Agreement and that comply with the requirements of Article 28, paragraphs 3 and 4 of the GDPR.
(2) The Company remains fully liable to the Client for the performance of the Subprocessors’ obligations relating to the processing of personal data, in accordance with Article 28(4) of the GDPR.
(3) When a processor is located outside the European Economic Area, the Company ensures that an appropriate transfer mechanism is in place in accordance with Chapter V of the GDPR.
5.4. AI Features Developer
1) To the extent that the Customer expressly activates and uses the AI dictation/transcription functionality (“AI Functionality”), the Customer consents to the Company engaging an external AI service provider as a Processor for the purposes of performing transcription/processing of voice data.
(2) The Company guarantees that a Personal Data Processing Agreement has been entered into with the AI Processor.
(3) When the AI processor is established outside the EEA or grants access from a third country, the requirements of Chapter V of the GDPR apply.
Technical and organizational security measures
6.1. Technical and organizational security measures
(1) The Company implements and maintains appropriate technical and organizational security measures (“TOMS”) within the meaning of Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.
(2)The applicable TMS are described in Annex 2 to this SOD and include measures to ensure:
(a) the confidentiality, integrity, availability, and resilience of processing systems and services;
(b) the ability to restore the availability and access to personal data in a timely manner following a technical or physical incident;
(c) procedures for regularly testing, evaluating, and reviewing the effectiveness of the measures.
(3)The Company has the right to update the TOMs in response to technological developments or changes in risk, provided that the level of protection is not significantly reduced.
6.2. Data breach
(1) If the Company becomes aware of a personal data breach (“Breach”) within the meaning of Article 4(12) of the GDPR, affecting personal data processed on behalf of the Client, the Company shall notify the Client without undue delay, in accordance with Article 33(2) of the GDPR.
(2) The notice contains the information currently available regarding:
(a) the nature of the breach;
(b) the categories and approximate number of data subjects and records affected;
(c) the likely consequences;
(d) the measures taken or proposed to mitigate and remedy the consequences.
(3) The Company shall not be liable for any Breaches arising from acts or omissions of the Client, its end users (patients), or third parties beyond the Company’s control.
6.3. Assessment of the Adequacy of the Measures
(1)The Client declares that it has conducted its own risk assessment regarding the processing and has determined that the Company’s technical and organizational security measures are appropriate for the purposes and nature of the personal data it processes.
(2) The parties agree that the level of security should be proportionate to the risk and that absolute security cannot be guaranteed.
VII. Restoring and Deleting Data
7.1. Primary responsibility
Upon termination or expiration of the Services, as well as upon the Client’s written request, the Company, at the Client’s discretion, shall return or delete all personal data processed on behalf of the Client, except to the extent that retention is necessary to comply with an applicable legal obligation or to establish, exercise, or defend legal claims.
7.2. Data Retrieval
(1) Upon request, the Company shall provide the Customer with their personal data in a structured, commonly used, and machine-readable format, to the extent that this is technically feasible and proportionate.
(2) Unless otherwise agreed, data is returned using the Platform’s standard functionality. Additional or extraordinary actions may be subject to separate compensation.
7.3. Deletion and Time Limits
(1) In the absence of an explicit request for the return of the data, the Company will proceed to delete or irreversibly anonymize it 12 months after the termination of the Services, unless otherwise specified in the General Terms and Conditions or in the specific subscription plan.
(2) During this period, the Customer may have limited access to the data, to the extent that such access is functionally provided for within the Platform.
(3) Deletion is considered complete once the data has been removed from the Company’s active systems.
7.4. Lawful detention
If applicable law requires certain data to be retained for a specified period, the Company may retain such data for the period required by law; during this period, the data will be restricted from further processing, and access to it will be strictly controlled.
7.5. Confirmation
Upon the Customer’s written request, the Company shall provide written confirmation of the deletion or anonymization.
VIII. Audits and Assistance
8.1. Provision of Information
(1) The Company shall provide the Client with the information reasonably necessary to demonstrate compliance with this Data Processing Agreement and the requirements of Article 28 of the GDPR.
(2) Where applicable, the obligation set forth in the preceding paragraph may be fulfilled by providing up-to-date audit reports, certificates, attestations, or summary documentation regarding the technical and organizational measures.
(3)The parties agree that, as a general rule, proof of compliance and cooperation under this section shall be provided remotely through the submission of documentation, questionnaire responses, audit reports, certificates, attestations, and/or other reasonable evidence available to the Company.
8.2. Right to an audit
(1) The Client has the right to conduct an audit of the Company’s processing of personal data no more than once (1) per calendar year, unless there are grounds for an extraordinary audit pursuant to Section 8.3.
(2) The audit:
a) shall be carried out during working hours and upon reasonable written notice of not less than 30 days;
b) is carried out in a manner that minimally disrupts the Company’s operations;
c) is limited to verifying the processing carried out on behalf of the Client;
d) is carried out in compliance with measures to protect trade secrets, confidential information, and the security of other clients
e) As a rule, it is conducted remotely by reviewing the documentation provided and/or a completed questionnaire; an on-site audit is permitted only when there is a justified need, when the Client cannot reasonably obtain sufficient assurance through remote means, and provided that the scope is strictly limited to what is necessary.
(3) The Company reserves the right to deny access to information that is not related to the processing of the Customer’s data or that would disclose sensitive information regarding security or other customers.
(4) The audit may be conducted by an independent external auditor bound by a confidentiality agreement, provided that the auditor is not a competitor of the Company.
(5) When requesting an on-site audit, the Client shall provide a written justification of the need, including why a remote audit is insufficient. The Company may propose alternative measures (e.g., additional documentation, a questionnaire, or a meeting) which, if reasonable and sufficient, may replace the on-site audit.
8.3. Special audit
(1)A special audit may be requested:
(a) upon explicit instruction or order from a competent supervisory authority;
(b) in the event of a personal data breach affecting the Customer’s data.
(2) The special audit is limited to the subject matter and scope related to the event in question.
8.4. Expenses
The Client shall bear the costs of the audit, unless the Client determines that the Company has committed a material breach of this Agreement.
- Data Protection Impact Assessment and Consultation with a Supervisory Authority
9.1. Duty to notify
(1)If the Company becomes aware of circumstances from which it can reasonably conclude that a specific processing operation carried out on behalf of the Client is likely to result in a high risk to the rights and freedoms of natural persons within the meaning of Article 35 of the GDPR, the Company shall notify the Client without undue delay.
(2) The notification referred to in the preceding paragraph does not relieve the Client of its obligation to conduct its own risk assessment and determine the need for an impact assessment.
9.2. Assistance in conducting an impact assessment
(1) The Company shall provide reasonable and proportionate assistance to the Client in conducting a data protection impact assessment pursuant to Article 35 of the GDPR, to the extent that the processing is carried out on behalf of the Client and the necessary information is available to the Company.
(2) Cooperation may include providing information regarding:
(a) the nature of the processing;
(b) the technical and organizational measures implemented;
(c) the system architecture and security measures;
(d) previous assessments or audit results, where applicable.
9.3. Consultations with a supervisory authority
(1) Where prior consultation with a competent supervisory authority is required under Article 36 of the GDPR, the Company shall provide reasonable assistance to the Client in connection with the provision of information regarding the processing carried out on the Client’s behalf.
(2)The Company does not communicate directly with a regulatory authority on behalf of the Client, unless expressly authorized to do so or unless required by law.
9.4. Expenses
To the extent that cooperation under this section requires extraordinary technical actions, specialized analyses, or significant resources beyond the standard agreed-upon functionality, the associated costs shall be borne by the Client, unless the parties agree otherwise in writing.
Transfers outside the European Economic Area
10.1. General principle
(1) The Company does not transfer, grant access to, or arrange for the processing of personal data outside the European Economic Area (“EEA”), unless such a transfer is made on a valid legal basis in accordance with Chapter V of the GDPR.
(2) The legal basis for data transfer may be:
(a) a decision on an adequate level of protection pursuant to Article 45 of the GDPR;
(b) appropriate safeguards pursuant to Article 46 of the GDPR, including standard contractual clauses;
(c) binding corporate rules;
(d) an applicable exception under Article 49 of the GDPR, where permissible.
10.2. Subcontractors outside the EEA
(1)When a Processor is located outside the EEA or grants access to personal data from a third country, the Company ensures that the transfer is carried out in accordance with the requirements of Chapter V of the GDPR and subject to appropriate contractual and technical safeguards.
(2)Разрешение за подписване на стандартни договорни клаузи
10.3. Authorization to Sign Standard Contractual Clauses
(1) The Client may authorize the Company to enter into standard contractual clauses with Subprocessors on behalf of and for the account of the Client, to the extent necessary for the provision of the Services.
(2) In the event of such authorization, the Company shall act solely within the scope of the authority granted and under conditions that do not reduce the level of protection agreed upon by the parties.
10.4. Additional guarantees
(1)Where applicable, the Company conducts an assessment of the impact of the transfer and implements additional technical and organizational measures where necessary to ensure a level of protection that is essentially equivalent.
(2)In the event of a change in the legal framework or a decision by a competent court or supervisory authority that affects the validity of the transfer mechanism used, the parties shall cooperate in good faith to implement an alternative lawful solution.
Liability and Compensation
11.1. Applicability of the restrictions
(1) Unless the parties have expressly agreed otherwise in writing, the limitations and exclusions of liability set forth in the General Terms and Conditions or the main service agreement shall apply to this Personal Data Processing Agreement.
(2) Nothing in this section excludes or limits liability that cannot be excluded or limited under applicable law, including liability for fraud and wilful misconduct.
11.2. Total liability limit
(1)The Company’s total liability arising out of or in connection with this Agreement, including for breaches of data protection obligations, shall be limited to the total amount of fees paid by the Client for the Services during the twelve months preceding the event giving rise to such liability.
(2) The limit set forth in the preceding paragraph represents the aggregate maximum for all claims under this Agreement.
11.3. The Company’s Liability
(1) The Company shall be liable for direct and actual damages resulting from a proven breach of this Agreement or applicable data protection laws committed by the Company or its Subprocessor.
(2) The Company shall not be liable where it has acted in accordance with the Client’s documented instructions or where the breach results from the Client’s acts or omissions.
11.4. Compensation from the Company
The Company shall compensate the Customer for direct damages, fines, or penalties imposed as a result of a breach of this Agreement by the Company, to the extent that such damages, fines, or penalties are a direct and immediate consequence of the Company’s wrongful conduct.
11.4. Compensation from the Client
The Customer shall indemnify the Company against all claims, penalties, fines, or damages arising from:
(a) unlawful instructions given by the Client itself;
(b) lack of a valid legal basis for processing under Article 6 or Article 9 of the GDPR;
c) failure to comply with the Client’s obligations in its capacity as a Controller;
b) processing beyond the agreed scope at the Client’s initiative.
XII. Primate
12.1. Conflict between the General Terms and Conditions and this Agreement
In the event of a conflict between the provisions of this Data Processing Agreement and the General Terms and Conditions, the provisions of this Agreement shall prevail to the extent that the conflict relates to the processing of personal data.
12.2. Unresolved issues
For all matters not expressly provided for in this Agreement, the provisions of the General Terms and Conditions shall apply.
XIII. Applicable legislation
13.1. Applicable law
This Data Processing Agreement shall be governed by and construed in accordance with the applicable laws of the Republic of Bulgaria, subject to the directly applicable provisions of European Union law in the field of personal data protection.
13.2. Disputes
All disputes arising out of or in connection with this Agreement shall be submitted for resolution to the competent court in the Republic of Bulgaria.
ANNEX 1 to this Agreement on the Processing of Personal Data
Description of the processing of personal data
Purpose of processing
The processing is carried out solely in connection with the provision of the services under the contract, including providing access to the Platform, hosting and infrastructure support, configuring user profiles, technical support, data backup and recovery, ensuring information security, and related functionalities.
Nature and processing operations
In its capacity as a data controller, the Company carries out the following categories of processing operations:
a) storing personal data in a secure cloud environment;
b) structuring and organizing data using the platform’s functionalities;
c) ensuring that only the relevant Specialist has access to the data;
d) automated data backup and recovery;
e) implementation of information security measures (access control, logging, encryption, protection against unauthorized access);
f) deletion or anonymization of data upon receiving instructions from the administrator or upon termination of the contract.
III. Purpose of processing
“Morph Practice” DPC does not independently determine the purposes and means of processing. The company processes patients’ personal data solely for the purposes specified by the relevant specialist-the data controller-and set forth in the contractual relationship between the parties. Within the scope of the service provided, this may include:
a) providing, maintaining, and improving the functionality of the Platform;
b) managing client/patient information by the professional;
c) managing schedules, services, appointments, and payments;
d) storing notes, documents, and information for the purposes of the practice;
e) transcribing/facilitating documentation in accordance with the Client’s instructions;
f) ensuring security, preventing misuse, and providing technical support.
Personal data is entered, managed, and controlled by specialized administrators through the functionalities of the online platform. The Company provides only the technical environment for its storage, structure, and protection.
Categories of data subjects
The processing may concern the following categories of data subjects:
a) patients or clients of the professionals (end users);
b) where applicable, legal representatives (e.g., parents/guardians of minors).
- Категории лични данни - криптирани в режим от край до край и некриптираниIn its capacity as a processor, the Company processes personal data entered by a Data Controller (a mental health professional) via the platform, which may include:
(a) Identification and contact information - first and last name, date of birth, age, gender, phone number, email address, and other identifying information entered by the specialist;
(b) Socio-demographic data - occupation, marital status, information about current family, partner (in couples or family therapy), information about family of origin and relatives;
(c) Data regarding the therapeutic process - reasons for seeking consultation, the specialist’s notes and conclusions, therapeutic process, client status (current/on hold/completed), internal categorizations and tags created by the specialist;
(d) Session data - date and time of scheduled and conducted consultations/sessions/meetings, meeting status, session notes (including any information regarding the patient’s life and personality, including health information), results/treatment plans/other professional notes, history of consultations, session (meeting) reminders;
(e) Payment data - billing, patient payment status, amount, payment date;
(f) Library data - files, documents, or forms attached by the specialist in connection with the therapeutic process;
(g) Data regarding health and mental status - psychiatric diagnosis, data on medication, information regarding mental status, and other information related to mental health;
(h) Technical and metadata generated during use of the platform - date and time of actions, user ID, access logs, IP address.
- Recipients of personal data:
“Morph Practice” DPC does not disclose Patients’ personal data to third parties, except:
a) to duly authorized employees or contractors of the Company, solely to the extent necessary for the provision of the Services.
b) to subcontractors (processors) engaged for hosting, infrastructure, maintenance, or security, in accordance with Section V of the Agreement.
c) when required by law;
d) upon explicit instruction from the administrator.
VII. The point at which personal data processing begins
The processing of personal data in the “Patients” Registry begins at the moment when the relevant Specialist-in their capacity as an independent data controller-enters, uploads, or otherwise creates personal data on the Company’s online platform. The Company’s processing consists solely of:
a) automated storage and structuring of the entered data;
b) providing technical access to the data to the relevant Specialist;
c) generating technical logs and metadata related to the use of the platform;
d) archiving and restoring data as necessary;
e) deleting or returning data upon explicit instruction from the Administrator or upon termination of the contractual relationship.
VIII. Storage periods
Personal data is retained for the following periods, unless other periods are expressly provided for in a regulatory act:
a) for the duration of the contract with the relevant Controller;
b) for an additional period of 12 (twelve) months following the termination of the contract, during which the Controller has limited access to the data in accordance with the General Terms and Conditions;
c) upon expiration of this period, the data is deleted or anonymized, unless the Controller has provided explicit instructions to the contrary.
The company does not independently determine the retention periods for medical records.
Transfer outside the European Economic Area
When a processor is established outside the EEA or grants access to personal data from a third country, the transfer is carried out on a valid legal basis in accordance with Chapter V of the GDPR.
List of subcontractors
ANNEX 2 to this Agreement on the Processing of Personal Data
List of technical and organizational measures
Laptops
(Remote access)
Password-protected - complex passwords, with access restricted to authorized users only.
Antivirus/anti-malware software installed and running at all workstations; Software to block websites with a high risk of malware; Security alerts; Virus definition files that are automatically updated daily.