Annex to the Terms of Service
This is the agreement Vitena concludes with every professional who records client or patient data on the platform. It is the document called an Auftragsverarbeitungsvertrag (AVV) in Germany, a verwerkersovereenkomst in the Netherlands and a contrato de encargado del tratamiento in Spain. One law, several names.
How this agreement is concluded. It is an annex to the Terms of Service, so it takes effect when you accept the Terms — at signup, or on your next login after a new version is published. No separate signature is needed: Art. 28(9) GDPR requires the agreement to be in writing, and electronic form satisfies that. If your professional body or insurer wants a copy on file, print this page.
This agreement covers the workspace side of the product — the clients, appointments, notes, questionnaires, documents and messages you keep about the people you care for. It does not cover your public directory profile or an enquiry someone sends before becoming your client; there Vitena acts as a controller in its own right, as explained on the data protection page.
You — the professional or practice holding the Vitena account — are the controller under Art. 4(7) GDPR. Vitena is your processor under Art. 4(8) and processes personal data only for you and only to provide the service. Vitena does not process your clinical data for its own purposes, does not sell it, does not share it with other professionals on the platform, and does not use it to train AI models.
Subject matter and purpose: operating a practice management and client communication platform on your behalf. Nature of processing: collection, storage, organisation, retrieval, display, transmission, backup, deletion. Duration: for as long as your account exists, plus the deletion periods in clause 10.
Data subjects: your clients or patients, people who enquire or book with you, and the members of your own team who use the account.
Vitena is built on the assumption that special-category health data will be present. Establishing the lawful basis for it is yours as controller — usually Art. 9(2)(h) together with your national professional rules. The obligations in this agreement apply to all of the categories above, including free-text notes, internal private notes and files you upload, not only structured questionnaire fields.
Vitena processes personal data only on your documented instructions. Your instructions are: this agreement, the Terms of Service, the settings you choose in the product, and the actions you take in it. Vitena will tell you if, in its opinion, an instruction infringes the GDPR. Where EU or member state law obliges Vitena to process data beyond your instructions, you will be informed before processing unless that law forbids it.
AI features are an instruction you give, one action at a time. No AI provider receives client content unless you deliberately start an AI action — drafting a plan, drafting a note, or reading a document you attached. If you never use those features, no client data ever reaches an AI provider. Neither AI provider trains models on content sent through their API.
Every person on Vitena's side who may access personal data is bound by a duty of confidentiality that survives the end of their engagement, and is granted access only to the extent needed to operate, support and secure the service.
Vitena maintains appropriate technical and organisational measures, set out in full in Annex A. Measures may be changed as technology develops, provided the level of protection is not reduced.
You give general authorisation for Vitena to engage the subprocessors listed in Annex B. Vitena imposes on each of them data protection obligations no less protective than those in this agreement and remains fully liable to you for their performance. Before adding or replacing a subprocessor, Vitena will give you notice so that you can object; if you object on reasonable data protection grounds and no solution is found, you may terminate the affected service.
Vitena assists you, so far as is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection. Most of these you can carry out yourself in the product; where you cannot, Vitena helps on request. If a data subject contacts Vitena directly about data in your workspace, Vitena will not answer on your behalf but will refer them to you.
Vitena notifies you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification under Art. 33 — what happened, which categories and roughly how many records are affected, the likely consequences, and the measures taken. Vitena also assists you, taking into account the nature of processing and the information available to it, with your obligations under Art. 32 to 36, including a data protection impact assessment where you need one.
You can export your data at any time while the account is active, and you can delete individual records yourself. When the contract ends, Vitena deletes the personal data it processes for you, unless EU or member state law requires it to be kept. Deletion from live systems happens within 30 days of the end of the contract. Backups are kept on a rolling window and are overwritten in the ordinary course, so a deleted record disappears from backups within that window at the latest — see Annex A for the current retention period. Backups are never used to restore data that you deleted deliberately.
Vitena makes available to you all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate. In the first instance this is satisfied by this document, Annex A and Annex B. Beyond that, you may ask specific written questions and Vitena will answer them; an on-site inspection may be requested where a documented reason makes it necessary, with reasonable notice, during business hours, without disrupting operations, and subject to confidentiality.
Your workspace data is stored in the European Union, in AWS's Frankfurt region (eu-central-1). There is one exception, and it is under your control: the two AI providers in Annex B are based in the United States, and content reaches them only when you start an AI action. Those transfers are made on the European Commission's Standard Contractual Clauses. Vitena's operating company is established in Türkiye; company seat and data location are two different things, and support access from outside the EEA is covered by the same contractual safeguards.
This agreement runs for as long as your Vitena account exists. If it is amended, the new version is published here with a new version number and effective date, and you are notified before it takes effect. Acceptances already given remain tied to the version that was in force at the time. Where this agreement and the Terms of Service conflict on a data protection question, this agreement prevails.
Described as implemented, not as aspiration. Where a measure is not in place, it is not listed.
Protection here is layered rather than resting on any single control. Each practice is isolated from every other; access inside a practice is limited by role; everything in transit is encrypted; files and documents are encrypted where they are stored; the database is unreachable from the internet; and every change to the running system goes through a reviewed, automated pipeline. A weakness in one layer does not open the record, because the next layer still has to be passed.
Vitena does not hold an ISO 27001 or SOC 2 certificate, and does not claim one. It is not a HIPAA business associate and does not offer a BAA, because it does not serve the United States health market. Nor is there a formal penetration-testing report to hand over: security is reviewed as part of how the product is built and run, not certified by a third party.
The current list, with what each one is used for and where it processes data, is published and kept up to date on the data protection page. It is part of this agreement by reference, so that a change to the list does not require a new version of the contract while still reaching you as a notice under clause 7.
Write to info@vitena.care with the name under which you practise and the country you work in. There is no charge, and this agreement applies on the free plan as well as on paid plans.
Related: data protection, hosting and subprocessors · GDPR and your clients' rights · Terms of Service · Privacy Policy