Annex to the Terms of Service

Data Processing Agreement (Art. 28 GDPR)

This is the agreement Vitena concludes with every professional who records client or patient data on the platform. It is the document called an Auftragsverarbeitungsvertrag (AVV) in Germany, a verwerkersovereenkomst in the Netherlands and a contrato de encargado del tratamiento in Spain. One law, several names.

Version 1.1 In force since 2026-09-04

Previous versions:1.0 (2026-09-03 – 2026-09-04)

Provider

Service and platform: Vitenavitena.care

Full provider details (legal name, address, contact): Terms of Service

How this agreement is concluded. It is an annex to the Terms of Service, so it takes effect when you accept the Terms at signup. When a new version is published we email you before it takes effect, and using Vitena from that date on means the new version applies — there is no extra screen and nothing for you to sign. Art. 28(9) GDPR requires the agreement to be in writing, and electronic form satisfies that. If your professional body or insurer wants a copy on file, print this page; earlier versions stay available above.

This agreement covers the workspace side of the product — the clients, appointments, notes, questionnaires, documents and messages you keep about the people you care for. It does not cover your public directory profile or an enquiry someone sends before becoming your client; there Vitena acts as a controller in its own right, as explained on the data protection page.

1. Parties and roles

You — the professional or practice holding the Vitena account — are the controller under Art. 4(7) GDPR. Vitena is your processor under Art. 4(8) and processes personal data only for you and only to provide the service. Vitena does not process your clinical data for its own purposes, does not sell it, does not share it with other professionals on the platform, and does not use it to train AI models.

2. Subject matter, nature, purpose and duration

Subject matter and purpose: operating a practice management and client communication platform on your behalf. Nature of processing: collection, storage, organisation, retrieval, display, transmission, backup, deletion. Duration: for as long as your account exists, plus the deletion periods in clause 10.

3. Categories of data subjects and personal data

Data subjects: your clients or patients, people who enquire or book with you, and the members of your own team who use the account.

  • Identity and contact details — name, email address, telephone number, date of birth
  • Appointment and service records, payment status and invoices
  • Health data (Art. 9 GDPR) — questionnaire answers, measurements, session notes, plans, consent records, uploaded documents and images, and any personal summary you prepare
  • Messages exchanged through the platform and the client portal
  • Technical data needed to run the service — log records, IP address, device and browser information

Vitena is built on the assumption that special-category health data will be present. Establishing the lawful basis for it is yours as controller — usually Art. 9(2)(h) together with your national professional rules. The obligations in this agreement apply to all of the categories above, including free-text notes, internal private notes and files you upload, not only structured questionnaire fields.

4. Processing on your instructions

Vitena processes personal data only on your documented instructions. Your instructions are: this agreement, the Terms of Service, the settings you choose in the product, and the actions you take in it. Vitena will tell you if, in its opinion, an instruction infringes the GDPR. Where EU or member state law obliges Vitena to process data beyond your instructions, you will be informed before processing unless that law forbids it.

AI features are an instruction you give, one action at a time. No AI provider receives client content unless you deliberately start an AI action — drafting a plan, drafting a note, or reading a document you attached. If you never use those features, no client data ever reaches an AI provider. Neither AI provider trains models on content sent through their API.

5. Confidentiality

Every person on Vitena's side who may access personal data is bound by a duty of confidentiality that survives the end of their engagement, and is granted access only to the extent needed to operate, support and secure the service.

6. Security of processing (Art. 32)

Vitena maintains appropriate technical and organisational measures, set out in full in Annex A. Measures may be changed as technology develops, provided the level of protection is not reduced.

7. Subprocessors

You give general authorisation for Vitena to engage the subprocessors listed in Annex B. Vitena imposes on each of them data protection obligations no less protective than those in this agreement and remains fully liable to you for their performance. Before adding or replacing a subprocessor, Vitena will give you at least 15 days' notice so that you can object; if you object on reasonable data protection grounds and no solution is found, you may terminate the affected service.

8. Helping you answer your clients

Vitena assists you, so far as is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection. Most of these you can carry out yourself in the product; where you cannot, Vitena helps on request. If a data subject contacts Vitena directly about data in your workspace, Vitena will not answer on your behalf but will refer them to you.

9. Breaches, and help with Art. 32–36

Vitena notifies you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification under Art. 33 — what happened, which categories and roughly how many records are affected, the likely consequences, and the measures taken. Vitena also assists you, taking into account the nature of processing and the information available to it, with your obligations under Art. 32 to 36, including a data protection impact assessment where you need one.

10. Deletion and return of data

You can export your data at any time while the account is active, and you can delete individual records yourself. When the contract ends, Vitena deletes the personal data it processes for you, unless EU or member state law requires it to be kept. Deletion from live systems happens within 30 days of the end of the contract. Backups are kept on a rolling window and are overwritten in the ordinary course, so a deleted record disappears from backups within that window at the latest — see Annex A for the current retention period. Backups are never used to restore data that you deleted deliberately.

11. Information and audit rights

Vitena makes available to you all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate. In the first instance this is satisfied by this document, Annex A and Annex B. Beyond that, you may ask specific written questions and Vitena will answer them; an on-site inspection may be requested where a documented reason makes it necessary, with reasonable notice, during business hours, without disrupting operations, and subject to confidentiality.

12. Where data is processed, and transfers outside the EEA

Your workspace data is stored in the European Union, in AWS's Frankfurt region (eu-central-1). Two transfers outside the EEA exist, and both are named here rather than left to be inferred. First, the two AI providers in Annex B are based in the United States, and content reaches them only when you deliberately start an AI action. Second, Vitena's operating company is established in Türkiye and its operator can reach the production systems in order to run the service. Both are made on the European Commission's Standard Contractual Clauses; the second is set out in full, with the assessment behind it, in Annex C.

13. Term, changes and precedence

This agreement runs for as long as your Vitena account exists. If it is amended, the new version is published here with a new version number and effective date, and you are notified before it takes effect. Acceptances already given remain tied to the version that was in force at the time. Where this agreement and the Terms of Service conflict on a data protection question, this agreement prevails.

Annex A — Technical and organisational measures (Art. 32)

Described as implemented, not as aspiration. Where a measure is not in place, it is not listed.

Protection here is layered rather than resting on any single control. Each practice is isolated from every other; access inside a practice is limited by role; everything in transit is encrypted; files and documents are encrypted where they are stored; the database is unreachable from the internet; and every change to the running system goes through a reviewed, automated pipeline. A weakness in one layer does not open the record, because the next layer still has to be passed.

Access control and separation

  • Each practice's records are held separately from every other practice's, and a request made with one account's credentials cannot reach another account's data; where the data layer cannot attribute a request to exactly one practice it refuses the request rather than falling back to a shared view
  • Role-based permissions inside the account, so an assistant does not automatically see clinical content
  • Private notes are stored in a separate field that is never sent to the client portal
  • Passwords are stored only as salted one-way hashes using an established password-hashing algorithm (bcrypt), never in readable form; a minimum length and complexity policy is enforced
  • Sessions use short-lived signed tokens; portal and questionnaire links are single-purpose, expire, and can be revoked by reissuing them
  • Two-factor authentication (TOTP, RFC 6238) is available for the professional's own login, switched on per user from account settings and backed by one-time recovery codes; signing in through a Google account with two-step verification is the alternative second factor

Transmission and storage

  • All traffic between browser, mobile app and servers is encrypted with TLS; plain HTTP is redirected
  • Uploaded files and documents are stored in EU object storage with server-side encryption at rest (AES-256) and no public access; they are served only through short-lived signed links
  • The database is not reachable from the internet: it has no public address and accepts connections only from the application itself
  • Secrets and API keys are held in a managed parameter store, never in source code
  • Email notifications are written so that they announce that something is available and never carry clinical content in the message body

Availability and resilience

  • Automated daily database backups with point-in-time recovery, retained for 7 days and then overwritten
  • Deletion protection on the database, so it cannot be removed by an infrastructure change
  • Managed, automatically scaled hosting with monitoring and alerting on error rates and resource limits

Organisational measures

  • Access to production systems is limited to the people who operate them, under a confidentiality obligation
  • Changes reach production through a reviewed, automated deployment pipeline, not by hand on the server
  • Activity in an account is logged, so it can be reconstructed who did what and when
  • Data export and account deletion are available to you in the product, without asking support

Stated plainly: what is not in place

Vitena does not hold an ISO 27001 or SOC 2 certificate, and does not claim one. It is not a HIPAA business associate and does not offer a BAA, because it does not serve the United States health market. Nor is there a formal penetration-testing report to hand over: security is reviewed as part of how the product is built and run, not certified by a third party.

Annex B — Approved subprocessors

The current list, with what each one is used for and where it processes data, is published and kept up to date on the data protection page. It is part of this agreement by reference, so that a change to the list does not require a new version of the contract while still reaching you as a notice under clause 7.

Annex C — Access from Türkiye, and transfers outside the EEA

Your workspace data is stored in the European Union, in AWS's Frankfurt region, and it stays there; no copy of it is kept in Türkiye. Vitena is operated by a sole proprietorship registered in Türkiye, and running the service requires that its operator can reach the production systems — to deploy changes, investigate a fault you report, restore a backup or answer a support question. That access is remote, it is exercised by one named person, and it may be exercised from Türkiye. Because the operator is established outside the EEA, making data available to them counts as a transfer under Chapter V GDPR even though the data itself never leaves Frankfurt. This annex is the safeguard for that transfer, stated openly rather than left to be inferred from the company address.

What this access is not: it is not access by other practices, whose records are separated at the data layer; it is not routine reading of clinical content, which does not happen as part of running the service; and it is not access by staff, because no one else has production access today. If that changes, clause 5 and Annex A apply to them in the same way.

The safeguard: Standard Contractual Clauses

The transfer is made on the European Commission's Standard Contractual Clauses, adopted by Implementing Decision (EU) 2021/914, Module Two (controller to processor). Those Clauses are incorporated into this agreement by reference and concluded between you, as data exporter, and Vitena, as data importer, in the same way as the rest of this agreement. Where the Clauses and this agreement say different things about a transfer, the Clauses prevail.

The options the Clauses leave open are settled as follows: the docking clause (Clause 7) applies; subprocessors are covered by Option 2, general written authorisation, with at least 15 days' notice before one is added or replaced; the optional independent dispute resolution in Clause 11 is not selected; and both the governing law and the forum are those of the Member State in which you are established.

The Annexes to the Clauses are filled in from this agreement rather than repeated: the parties are you as controller and Vitena as processor, at the address in the Terms; the description of the transfer — data subjects, categories of personal data including Art. 9 health data, purpose, nature and duration — is the one in clauses 2 and 3, with continuous availability but occasional actual access and the retention periods in clause 10; the competent supervisory authority is that of the Member State in which you are established; the technical and organisational measures are Annex A together with the measures below; and the subprocessor list is Annex B.

The assessment behind it

Türkiye has a general data protection law — Law no. 6698 (KVKK), modelled on the earlier EU Directive 95/46/EC — an independent authority, and statutory security and breach-notification duties. Türkiye is not on the European Commission's adequacy list, so this does not remove the need for the Clauses; it bears on how likely and how constrained a public-authority request would be.

A Turkish authority can address a lawful order to a business established in Türkiye. What could be produced is limited by what the operator can reach: data held in the EU on AWS infrastructure, reachable only through the production application and its administrative interfaces. There is no local copy, no local backup and no Türkiye-facing service built on your data. To date Vitena has received no request for customer data from any public authority, in Türkiye or elsewhere.

Supplementary measures in place today:

  • Storage stays in the European Union under a contract with AWS EMEA, and the operator keeps no local copies
  • Administrative access is limited to one named person, under a duty of confidentiality
  • The database has no public address and accepts connections only from the application itself
  • Administrative queries against production are logged with a timestamp, so that administrative access can be reconstructed afterwards
  • The cloud account's owner login is protected by two-factor authentication
  • Traffic is encrypted in transit, uploaded files are encrypted at rest, and secrets and keys are held in a managed parameter store

If a binding request ever arrives, Vitena will notify you of it unless legally prohibited from doing so — and in that case will seek a waiver of the prohibition; will challenge a request that appears unlawful or excessive, including on appeal; will disclose no more than the minimum required; and will keep a record of any request received and make it available to you.

With the Clauses in force and the measures above, the level of protection for data made available from Türkiye is not undermined in practice. This assessment is reviewed if the operating structure changes, if the applicable law changes materially, or at the latest when a new version of this agreement is published.

Questions, or a copy for your files

Write to info@vitena.care with the name under which you practise and the country you work in. There is no charge, and this agreement applies on the free plan as well as on paid plans.

Related: data protection, hosting and subprocessors · GDPR and your clients' rights · Terms of Service · Privacy Policy