01Parties and scope#
This Data Processing Agreement (the "Agreement") is between Modulon Health ("Modulon") and the healthcare provider or organization named in the order form that references it (the "Clinic"). It forms part of the master services agreement and order forms between them (together, the "Services Agreement").
It applies whenever Modulon processes personal data on the Clinic's behalf that is subject to the data protection law of the European Economic Area, the United Kingdom, Switzerland, or one of the six Gulf states named in Section 12. For clinics in the United States, our Business Associate Agreement applies instead. Where both apply, each governs the data within its scope.
02Definitions#
Terms such as controller, processor, data subject, personal data, processing, special categories of personal data and supervisory authority have the meanings given in the GDPR, and the equivalent terms in other Data Protection Laws have the corresponding meaning. In addition:
- "Data Protection Laws" means all laws on the protection of personal data that apply to the processing under this Agreement, including the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the laws listed in Section 12.
- "GDPR" means Regulation (EU) 2016/679.
- "Clinic Personal Data" means personal data that Modulon processes on behalf of the Clinic in providing the Services, including data about patients and the Clinic's staff.
- "Health Data" means Clinic Personal Data concerning health, which the GDPR treats as a special category of personal data and the laws in Section 12 treat as sensitive or health information.
- "Services" means the services Modulon provides under the Services Agreement.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Clinic Personal Data.
- "Subprocessor" means a processor Modulon engages to process Clinic Personal Data.
- "Hosting Region" means the region in which the Clinic's data is stored, as set out in Annex 1 and the Clinic's order form.
03Roles and instructions#
Roles
The Clinic is the controller of Clinic Personal Data, and Modulon is its processor. The Clinic is responsible for having a lawful basis, and where Health Data is involved a condition under Article 9 of the GDPR or its equivalent, for each processing it instructs, and for the notices it gives patients and staff.
Instructions
Modulon will process Clinic Personal Data only on the Clinic's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case Modulon will tell the Clinic first unless the law prohibits it. The Services Agreement, this Agreement, the Clinic's configuration of the Services, and the policies it sets in the platform are the Clinic's complete instructions. Modulon will tell the Clinic promptly if, in its opinion, an instruction infringes Data Protection Laws.
Restrictions
Modulon will not:
- Sell Clinic Personal Data, or use it for advertising or marketing.
- Use Clinic Personal Data, or data derived from it, to train or improve general-purpose artificial intelligence models, or allow any Subprocessor to do so.
- Combine Clinic Personal Data with data from other customers, except as the Services require.
- Store Clinic Personal Data outside the Hosting Region, except as Section 7 permits.
04Confidentiality#
Modulon will ensure that everyone it authorizes to process Clinic Personal Data is bound by a duty of confidentiality, has been trained in data protection, and has access only to the Clinic Personal Data their role requires. Where Health Data is concerned, they are bound by a duty of secrecy equivalent to professional secrecy.
05Security#
Modulon will implement and maintain the technical and organizational measures described in Annex 2, which are designed to ensure a level of security appropriate to the risk, as Article 32 of the GDPR requires, taking into account the sensitivity of Health Data.
Modulon may update those measures over time, provided that no update reduces the overall level of protection of Clinic Personal Data.
06Subprocessors#
The Clinic gives Modulon general authorization to engage Subprocessors. The Subprocessors engaged for each Hosting Region are listed on our subprocessors page, which forms Annex 3.
- Modulon will bind each Subprocessor by a written contract that imposes data protection obligations no less protective than those in this Agreement.
- Modulon will notify the Clinic at least 30 days before a new Subprocessor begins processing Clinic Personal Data. The Clinic may object on reasonable data protection grounds within that period. The parties will work in good faith to resolve the objection; if they cannot, the Clinic may end the affected Services without penalty and receive a refund of any fees prepaid for them.
- Modulon remains fully liable to the Clinic for the performance of its Subprocessors.
07Data location and transfers#
Hosting Region
Modulon stores Clinic Personal Data in the Hosting Region. For clinics in the European Economic Area and Switzerland that is the European Union; for clinics in the United Kingdom, the United Kingdom; for clinics in the UAE, Qatar, Saudi Arabia or Kuwait, the Clinic's own country; and for clinics in Bahrain or Oman, the UAE.
Transfers out of the Hosting Region
Modulon may transfer Clinic Personal Data out of the Hosting Region only where the transfer is permitted by Data Protection Laws and, where Section 12 sets stricter rules for Health Data, by those rules. In particular, where Modulon personnel outside the Hosting Region provide support at the Clinic's request, they access the data remotely, without copying it out of the Hosting Region, and only as the law of that region allows.
Transfer mechanisms
For transfers that require them, the parties agree that:
- For data subject to the GDPR, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module Two, controller to processor, and Module Three, processor to processor) are incorporated into this Agreement, with Clause 7 included, Option 2 of Clause 9(a) with the notice period in Section 6, the optional wording in Clause 11 omitted, and Irish law and courts chosen under Clauses 17 and 18. The annexes to the Clauses are completed by Annexes 1 to 3 of this Agreement.
- For data subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner is incorporated, with the Standard Contractual Clauses above as the Approved EU SCCs, and neither party may end it under its Section 19.
- For data subject to Swiss law, the Standard Contractual Clauses apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority and references to the GDPR read as references to the Swiss Federal Act on Data Protection.
Modulon has assessed the law and practice of each country to which it transfers data and will help the Clinic with its own transfer assessment on request.
08Data subject rights#
Taking into account the nature of the processing, Modulon will help the Clinic, by appropriate technical and organizational measures, to respond to requests from data subjects to exercise their rights, including access, rectification, erasure, restriction, portability and objection. The platform lets the Clinic find, export, correct and delete a patient's data itself.
If Modulon receives a request directly, it will forward it to the Clinic within five business days and will not respond itself, other than to say it has passed the request on, unless the Clinic directs it to.
09Personal data breaches#
Modulon will notify the Clinic without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach, so the Clinic can meet any duty to notify a supervisory authority within 72 hours.
The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed to address it and mitigate its effects, together with a contact for more information. Modulon will supplement the notice as more becomes known, cooperate with the Clinic's investigation, and not notify supervisory authorities or data subjects on the Clinic's behalf unless the Clinic asks it to or the law requires it.
10Impact assessments and consultation#
Modulon will give the Clinic reasonable assistance with any data protection impact assessment, and any prior consultation with a supervisory authority, that relates to the Services, including the information the Clinic needs about Modulon's processing, its AI features and its safeguards. Modulon maintains a data protection impact assessment of the Services that it will share with the Clinic on request.
11Records and audits#
Modulon will keep a record of its processing activities on the Clinic's behalf, and make available to the Clinic all information necessary to demonstrate compliance with this Agreement and Article 28 of the GDPR.
Once a year, and following any Personal Data Breach, Modulon will on request give the Clinic a completed security questionnaire, a summary of its latest risk assessment and independent security testing, and its current list of Subprocessors. Where that information is not enough to demonstrate compliance, or a supervisory authority requires it, the Clinic or an independent auditor it appoints, bound by confidentiality, may audit Modulon once a year on 30 days' notice, during business hours and without disrupting the Services, at the Clinic's cost.
12Regional terms#
United Arab Emirates
- Modulon will process Health Data in accordance with Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields and its implementing regulations, and will store and process it inside the UAE, transferring it outside the UAE only in the cases those rules allow.
- Modulon will comply with the health data and information security standards of the health authority that licenses the Clinic, such as the Department of Health Abu Dhabi's Healthcare Information and Cyber Security Standard, and the Dubai Health Authority's policies, as they apply to Modulon's role.
- Where the Clinic is established in the Dubai International Financial Centre, Dubai Healthcare City or the Abu Dhabi Global Market, Modulon will also meet the processor obligations of the DIFC Data Protection Law, the DHCC Health Data Protection Regulation, or the ADGM Data Protection Regulations, as applicable.
- Because UAE law requires health records to be kept for at least 25 years, Modulon will not delete Health Data at the end of this Agreement until it has returned it to the Clinic, or transferred it to a system the Clinic names, so the Clinic can meet that duty.
Qatar
- Modulon will process Clinic Personal Data in accordance with Law No. 13 of 2016 on the Protection of Personal Data Privacy and the guidelines of the National Data Privacy Office, and will store Health Data in Qatar.
- The Clinic is responsible for any permit or approval it needs to process personal data of a special nature, and Modulon will provide the information the Clinic needs to obtain it.
- Modulon will meet the requirements of the Ministry of Public Health that apply to its role, and, where the Clinic is established in the Qatar Financial Centre, the processor obligations of the QFC Data Protection Regulations.
Saudi Arabia
- Modulon will process Clinic Personal Data in accordance with the Personal Data Protection Law and its implementing regulations, store Health Data in the Kingdom, and transfer it outside the Kingdom only as the Regulation on Personal Data Transfer outside the Kingdom allows.
- Modulon will meet the National Cybersecurity Authority's Essential Cybersecurity Controls and Cloud Cybersecurity Controls, and the Ministry of Health's requirements, as they apply to its role.
Kuwait
Modulon will process Clinic Personal Data in accordance with the Data Privacy Protection Regulation issued by the Communication and Information Technology Regulatory Authority, and store Health Data in Kuwait as its Cloud Computing Regulatory Framework requires.
Bahrain
Modulon will process Clinic Personal Data in accordance with Law No. 30 of 2018 on the Protection of Personal Data. Health Data is stored in the UAE; the parties agree that this Agreement provides the safeguards for that transfer, and Modulon will support the Clinic in obtaining any authorization the Personal Data Protection Authority requires.
Oman
Modulon will process Clinic Personal Data in accordance with the Personal Data Protection Law issued by Royal Decree No. 6 of 2022 and its executive regulations. The Clinic is responsible for the permit it needs to process Health Data, and Modulon will provide the information the Clinic needs to obtain it. Health Data is stored in the UAE under the cross-border transfer conditions those regulations set.
Breach notices under local law
Where a law in this section requires the Clinic to notify a regulator or data subjects of a breach within a set period, Modulon's notice under Section 9 will reach the Clinic in time for it to do so.
13Term, return and deletion#
This Agreement takes effect when the Clinic signs an order form that references it, and continues for as long as Modulon processes Clinic Personal Data.
When the Services end, the Clinic may export its data for 30 days. Within 60 days after the Services end, Modulon will, at the Clinic's choice, return or delete all Clinic Personal Data it and its Subprocessors hold, and certify the deletion in writing, unless the law of the Hosting Region requires it to keep some of it, in which case Modulon will keep protecting that data under this Agreement and process it only for the purpose the law requires. Data in encrypted backups is deleted as those backups expire, within 90 days after the Services end.
14General#
Precedence
If this Agreement conflicts with the Services Agreement on any matter relating to personal data, this Agreement controls. If it conflicts with the Standard Contractual Clauses, the Clauses control.
Liability
Each party's liability under this Agreement is subject to the limitations in the Services Agreement, except where Data Protection Laws or the Standard Contractual Clauses do not allow it to be limited.
Changes in law
The parties will amend this Agreement as necessary to comply with any change in Data Protection Laws, or with new transfer mechanisms adopted under them.
Governing law
Except where the Standard Contractual Clauses or a law in Section 12 require otherwise, this Agreement is governed by the law that governs the Services Agreement.
Notices
Notices to the Clinic are sent to the contacts named in its order form or in the platform's settings. Notices to Modulon, including to our data protection officer, are sent to hello@modulonhealth.com.
15Annex 1: Description of processing#
| Data subjects | The Clinic's patients and their representatives, callers and texters, and the Clinic's staff |
| Personal data | Names, dates of birth, contact details and identifiers; call recordings and transcripts; messages; appointments, referrals, intake forms and documents; insurance and payment records; staff account and activity records |
| Special categories | Health Data, such as visit reasons, symptoms described, medications, results, visit audio and drafted notes, protected by the measures in Annex 2 |
| Nature and purpose | Answering calls and texts, scheduling, intake, drafting visit notes, routing refills and results, insurance and billing tasks and patient payments, on the Clinic's instructions |
| Frequency | Continuous, for the duration of the Services |
| Retention | For the duration of the Services, then as Section 13 sets out; visit audio is deleted once the provider signs the note unless the Clinic chooses to keep it |
| Hosting Region | As set out in Section 7 and the Clinic's order form |
| Competent authority | The supervisory authority of the country in which the Clinic is established |
16Annex 2: Security measures#
- Encryption of all data in transit with TLS 1.2 or higher, and at rest with AES-256.
- Logical separation of each clinic's data, enforced in the database and the application.
- Role-based access, unique accounts, multi-factor authentication and automatic sign-out for clinic staff.
- Production access limited to a small number of engineers, time-limited, on managed devices, and logged.
- An audit trail of every action by staff or by the AI, kept for at least six years.
- Clinic policies enforced in software, which the AI cannot override; clinical content approved by staff.
- Continuous encrypted backups, restored regularly to prove they work, and a tested contingency plan.
- Vulnerability scanning at least every six months, and independent penetration testing every year.
- Background checks, confidentiality agreements and annual data protection training for everyone with access.
- A written incident response plan, rehearsed every year.
Our Security page describes these measures in more detail.
17Annex 3: Subprocessors#
The Subprocessors for each Hosting Region, what each one does and where it processes data, are listed on our subprocessors page, which is updated as Section 6 provides. To request a signed copy of this Agreement, or to send us your own terms, write to hello@modulonhealth.com.
Questions about this page? Write to hello@modulonhealth.com.