تخطٍ إلى المحتوى
DrAxis
الميزات الأمان قانوني
EN FR AR
الميزات الأمان قانوني
→ العودة إلى الفهرس القانوني

قانوني

DrAxis — Data Processing Addendum

Controller-processor terms for B2B and hospital contracts under GDPR and equivalent laws.

آخر تحديث: 2026-08-23
⚠ مسودة — للمراجعة الداخلية. ليست استشارة قانونية.

DrAxis — Data Processing Addendum (DPA)

Status: DRAFT v1 — for internal team review. Not legal advice.
Must be reviewed by qualified legal counsel before signature.
Last updated: 2026-08-23

Document control

FieldValue
Document ownerDrAxis legal
Version0.1 (DRAFT)
Effective date[to be set at signature]
Review cycleAnnual, or upon material change
Languages (target)English, French, Arabic
Public URLhttps://draxis.app/legal/data-processing-addendum

1. Purpose and scope

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the master agreement between DrAxis ("Processor") and the contracting healthcare organization or institution ("Controller") (together, the "Parties"). It reflects the Parties' agreement on the processing of personal data under:

  • GDPR (Reg. (EU) 2016/679), in particular Art. 28.
  • Tunisian Organic Law n° 2004-63 (DPA).
  • KSA PDPL (Royal Decree M/19).
  • UAE PDPL (Federal Decree-Law n° 45/2022).
  • Any other applicable data protection law in the jurisdictions where the Controller operates.

This DPA applies to the processing of personal data by DrAxis on behalf of the Controller under the master agreement.


2. Definitions

Capitalized terms not defined here have the meaning given in the master agreement or in the GDPR. In particular:

  • "Controller" means the entity that determines the purposes and means of processing personal data.
  • "Processor" means DrAxis, processing personal data on behalf of the Controller.
  • "Personal Data", "Special Categories of Personal Data", "Data Subject", "Processing", "Sub-processor" have their GDPR meanings.
  • "Services" means the DrAxis platform services provided to the Controller under the master agreement.

3. Roles of the Parties

3.1 The Controller is the controller of personal data processed under the master agreement.

3.2 DrAxis acts as processor on the Controller's documented instructions, as set out in this DPA and the master agreement.

3.3 The Controller warrants that its instructions comply with applicable data protection law, and DrAxis will inform the Controller in writing if an instruction infringes applicable data protection law (GDPR Art. 28(3)(f)).


4. Details of processing

ItemDetail
Categories of Data SubjectsPatients whose data is entered into Calculators or shared via messaging by the Controller's authorized users; the Controller's authorized users (HCPs)
Categories of Personal DataIdentity, contact, professional credentials; clinical parameters entered into Calculators; message content; attachments
Special Categories (Art. 9 GDPR)Health data (patient clinical parameters, attachments)
Purposes of ProcessingProviding the Services to the Controller's authorized users
Duration of ProcessingDuration of the master agreement, subject to the retention schedule in 05-data-retention-policy.md
Sub-processorsAs listed in the Privacy Policy §6.1 and at https://draxis.app/legal/sub-processors

5. Processor obligations

DrAxis shall:

5.1 Process Personal Data only on the Controller's documented instructions, including with regard to transfers of Personal Data to a third country, unless required by EU or Member State law (GDPR Art. 28(3)(a)).

5.2 Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations enforceable under applicable law.

5.3 Implement appropriate technical and organizational measures (TOMs) as described in 09-information-security-policy.md, sufficient to ensure a level of security appropriate to the risk.

5.4 Assist the Controller in responding to Data Subject rights requests, where technically and organizationally feasible.

5.5 Assist the Controller in conducting Data Protection Impact Assessments (DPIAs) where required under GDPR Art. 35.

5.6 Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach (GDPR Art. 33).

5.7 Delete or return all Personal Data to the Controller after the end of the Services, and delete existing copies unless storage is required by EU or Member State law.

5.8 Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections by the Controller or an auditor mandated by the Controller.


6. Sub-processors

6.1 DrAxis may engage sub-processors listed at https://draxis.app/legal/sub-processors. The Controller may object to a new sub-processor on reasonable data-protection grounds by notifying DrAxis in writing within 30 days of the sub-processor being listed.

6.2 DrAxis remains liable for the acts and omissions of its sub-processors to the same extent as for its own acts (GDPR Art. 28(4)).

6.3 DrAxis imposes data protection terms on sub-processors at least as protective as those in this DPA.


7. Cross-border transfers

7.1 Where Personal Data is transferred outside the EU/EEA to a country not covered by an adequacy decision, the transfer relies on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/0147) between DrAxis and the sub-processor, supplemented by a Transfer Impact Assessment.

7.2 For transfers of KSA-residents' Personal Data outside KSA, DrAxis complies with PDPL Art. 29 and 30, relying on explicit consent or NDMO approval as required.

7.3 The Controller is responsible for ensuring that any transfer of Personal Data to DrAxis from its own jurisdiction is lawful under the applicable data protection law.


8. Technical and organizational measures (TOMs)

The TOMs implemented by DrAxis are described in 09-information-security-policy.md and include:

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Access controls (role-based, least privilege, MFA for admin).
  • Audit logging of access to Personal Data.
  • Regular security review and penetration testing.
  • Incident response procedures (08-incident-response-plan.md).
  • Data minimization (transient calculator inputs not persisted).
  • Backups and disaster recovery.

9. Personal Data Breach notification

9.1 DrAxis will notify the Controller without undue delay and in any event within 72 hours after becoming aware of a Personal Data Breach.

9.2 The notification will include:

  • The nature of the breach, including categories and approximate number of Data Subjects and Personal Data records concerned.
  • The likely consequences.
  • The measures taken or proposed to address the breach and mitigate its adverse effects.
  • The contact point for further information.

9.3 DrAxis will cooperate with the Controller in notifying the competent supervisory authority and the Data Subjects where required.


10. Data Subject rights

10.1 DrAxis will assist the Controller in fulfilling its obligations to respond to Data Subject rights requests (access, rectification, erasure, portability, objection), by:

  • Providing the Personal Data in a structured, machine-readable format.
  • Deleting Personal Data upon the Controller's instruction.
  • Rectifying inaccurate Personal Data upon the Controller's instruction.

10.2 DrAxis will not respond directly to Data Subject requests without the Controller's prior authorization, except to confirm that the request relates to the Controller's data and to direct the Data Subject to the Controller.


11. Audit rights

11.1 The Controller may audit DrAxis's compliance with this DPA once per calendar year, on at least 30 days' written notice, during normal business hours, and in a manner that does not disrupt DrAxis's operations.

11.2 The audit may be conducted by the Controller's internal staff or by a third-party auditor bound by confidentiality, and not more than once per calendar year unless a Personal Data Breach has occurred.

11.3 DrAxis will provide reasonable cooperation and access to relevant records, policies, and systems.

11.4 The Controller bears the cost of the audit unless a material non-compliance is identified, in which case DrAxis bears the cost.


12. Deletion or return of data

12.1 Upon termination of the master agreement, DrAxis will, at the Controller's choice:

  • Return all Personal Data to the Controller in a structured, machine-readable format; and
  • Delete all existing copies of the Personal Data,

unless storage is required by EU or Member State law (e.g., audit log retention under Tunisian medical ethics).

12.2 DrAxis will certify deletion in writing upon request.


13. Liability and indemnity

13.1 Each Party's liability under this DPA is subject to the limitations of liability set out in the master agreement.

13.2 DrAxis's liability for Personal Data Breaches shall not be subject to the aggregate cap where the breach results from DrAxis's gross negligence or willful misconduct.

13.3 DrAxis indemnifies the Controller against direct claims by Data Subjects or supervisory authorities arising from DrAxis's breach of this DPA, subject to the liability limitations in the master agreement.


14. Governing law and jurisdiction

14.1 This DPA is governed by the law of the master agreement.

14.2 Any dispute shall be resolved in accordance with the dispute resolution clause of the master agreement.


15. Changes to this DPA

15.1 DrAxis may update this DPA to reflect changes in applicable law or its TOMs. Material changes will be notified to the Controller at least 30 days before taking effect.

15.2 The Controller may terminate the master agreement if it cannot accept a material change to this DPA, by written notice within 30 days of the notification.


16. Contact

  • DrAxis DPO: dpo@draxis.app
  • DrAxis legal: legal@draxis.app
  • Controller contact: [CONTROLLER_CONTACT]

17. Signature

PartyNameTitleSignatureDate
DrAxis (Processor)
[Controller name] (Controller)
→ العودة إلى الفهرس القانوني
DrAxis

ذكاء سريري للأطباء المعتمدين.

صُنع في تونس للعالم.

المنتج

الميزاتالأمان

قانوني

سياسة الخصوصية شروط الخدمة إخلاء المسؤولية الطبية الاستخدام المقبول الاحتفاظ بالبيانات ملحق المعالجة سياسة ملفات تعريف الارتباط

الشركة

legal@draxis.appdpo@draxis.appالدعم

© DrAxis. جميع الحقوق محفوظة.