Data Processing Agreement Template
Last updated: 28 Mar 2025
Versions▾
Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) is entered into by and between:
________________ (“Controller”), a healthcare organization or technical supplier subject to the General Data Protection Regulation (GDPR), with its principal place of business at ________________,
and
Inquira Technologies B.V. (“Processor” or “InquiraHealth”), a Dutch private limited liability company with its principal place of business at Rotterdam, The Netherlands, registered with the Dutch Chamber of Commerce under number 95495460,
(each a “Party” and collectively the “Parties”).
This DPA is annexed to and forms an integral part of any underlying agreement or contract for services (“Master Agreement” or “Service Agreement”) between the Parties. In the event of conflict between this DPA and any other agreement, this DPA shall prevail with regard to data protection and privacy obligations.
1. Purpose and Scope
1.1 Purpose. This DPA sets forth the terms under which Processor will process Personal Data (defined below) on behalf of Controller for the purpose of providing Conversational AI services and related functionalities (the “Services”).
1.2 GDPR Compliance. This DPA is intended to fulfill the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), as well as any applicable national laws (including Dutch or German data protection laws).
2. Definitions
For the purposes of this DPA, the following definitions apply:
- “GDPR”: Regulation (EU) 2016/679, including any implementing and related national legislation (e.g., the Dutch Implementation Act, the German Bundesdatenschutzgesetz).
- “Personal Data”: Any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
- “Processing” (and its variations “Process,” “Processes,” “Processed”): Any operation or set of operations performed on Personal Data, whether or not by automated means (GDPR Article 4(2)).
- “Data Subject”: An identified or identifiable natural person about whom Personal Data is processed.
- “Sub-Processor”: Any third party engaged by Processor who receives Personal Data from Processor for the purpose of Processor’s provision of the Services to Controller.
- “EEA”: European Economic Area.
Any capitalized terms not defined herein shall have the meaning given to them under the GDPR.
3. Subject Matter and Duration
3.1 Subject Matter. Processor will process Personal Data solely for the purpose of performing the Services described in the Master Agreement, including but not limited to scheduling, voice or chat interactions, appointment reminders, and other Conversational AI workflows.
3.2 Duration. The Processing will continue until the Master Agreement expires or is terminated, or until all Personal Data is deleted in accordance with Section 13 below.
4. Categories of Data and Data Subjects
4.1 Categories of Personal Data. The types of Personal Data that Controller may submit to the Services include:
- Patient Identifiers: Name, phone number, date of birth, national ID number, patient ID, email address, etc.
- Appointment Details: Scheduled times, dates, locations, clinics/doctors, department names, appointment notes.
- Medical Information: Collected symptoms, triage data, medication adherence, diagnostic details, or other health-related information.
- Interaction Data: Call recordings, chat messages, transcripts, uploaded files (e.g., medical documents).
4.2 Data Subjects. May include:
- Patients (including prospective or former patients)
- Healthcare staff or other individuals, as relevant to the workflows
4.3 Controller Responsibility. Controller determines the scope and purpose of the Personal Data collected. Processor has no control over the types of Personal Data submitted.
5. Obligations of Controller
5.1 Lawfulness of Processing. Controller warrants it has obtained all necessary consents or lawful bases required under GDPR.
5.2 Instructions. Processor shall only process Personal Data in accordance with Controller’s documented instructions.
5.3 Accuracy and Minimization. Controller is responsible for ensuring data is accurate, current, and limited to necessary details.
6. Obligations of Processor
6.1 Processing Only on Instructions. Processor shall only process data as instructed.
6.2 Confidentiality. Processor ensures all personnel are bound by confidentiality.
6.3 Technical and Organizational Measures. Processor will maintain TOMs to protect data, as outlined in Annex 2.
6.4 Assistance. Processor will assist Controller with GDPR obligations (Articles 32–36).
6.5 Data Subject Requests. Processor will notify Controller of any Data Subject request and will not respond directly unless authorized.
6.6 Deletion or Return of Data. Upon termination, Processor will return or delete data per Controller’s choice, unless otherwise required by law.
7. Sub-Processors
7.1 Authorized Sub-Processors. Listed at: https://www.inquira.health/en/legal/sub-processors
7.2 Notification of Changes. Controller may review updates and subscribe to notifications.
7.3 Sub-Processor Obligations. Sub-Processors will be subject to contractual terms equivalent to this DPA.
8. International Data Transfers
8.1 Data Hosting Location. No transfers outside the agreed hosting region unless necessary (e.g., billing with Stripe in the U.S.).
8.2 Safeguards. Processor will implement GDPR-approved safeguards (e.g., SCCs) for such transfers.
9. Security and Personal Data Breach Notification
9.1 Security Measures. Maintained as per Annex 2.
9.2 Personal Data Breach. Processor will notify Controller without undue delay and provide:
- Description of the breach
- Likely consequences
- Measures taken or proposed
Controller is responsible for regulatory notifications.
10. Audit Rights
10.1 Audits. Controller may audit with at least 30 days’ notice, during business hours.
10.2 Limitations. Audits must not interfere with operations. Limited to once per year unless otherwise required.
10.3 Results. Audit results are confidential.
11. Liability
11.1 Liability Cap. Subject to Master Agreement terms unless restricted by law.
11.2 Data Subject Claims. Each Party liable only for its own GDPR violations.
12. Governing Law and Jurisdiction
12.1 Governing Law. Dutch law (or as defined in the Master Agreement).
12.2 Jurisdiction. Courts of Rotterdam, unless local mandatory laws apply.
13. Return or Deletion of Personal Data
13.1 Controller’s Choice. Upon termination, Controller may request:
- Return of all Personal Data
- Secure deletion/anonymization of all Personal Data
13.2 Survival. Data may be retained as legally required, still subject to this DPA’s terms.
14. Miscellaneous
14.1 Entire Agreement. This DPA is part of and governed by the Master Agreement.
14.2 Variations. Must be in writing and signed by both Parties.
14.3 Severability. Invalid provisions will be enforced to the extent possible; remainder remains in effect.
15. Signatures
For the Controller:
Company Name: ____________________________
Name & Title: _____________________________
Signature: ________________________________
Date: ____________________________________
For Processor (Inquira Technologies B.V.):
Name & Title: _____________________________
Signature: ________________________________
Date: ____________________________________
Contact Information
Inquira Technologies B.V.
Dutch Chamber of Commerce Number (KvK): 95495460
Westplein 12, 3016 BM, Rotterdam, The Netherlands
For responsible disclosure of security vulnerabilities, please visit our responsible disclosure page.