Annex to the Terms of Service

Data Processing Agreement (Art. 28 GDPR)

This is the agreement Vitena concludes with every professional who records client or patient data on the platform. It is the document called an Auftragsverarbeitungsvertrag (AVV) in Germany, a verwerkersovereenkomst in the Netherlands and a contrato de encargado del tratamiento in Spain. One law, several names.

Version 1.0 In force since 2026-09-03

How this agreement is concluded. It is an annex to the Terms of Service, so it takes effect when you accept the Terms — at signup, or on your next login after a new version is published. No separate signature is needed: Art. 28(9) GDPR requires the agreement to be in writing, and electronic form satisfies that. If your professional body or insurer wants a copy on file, print this page.

This agreement covers the workspace side of the product — the clients, appointments, notes, questionnaires, documents and messages you keep about the people you care for. It does not cover your public directory profile or an enquiry someone sends before becoming your client; there Vitena acts as a controller in its own right, as explained on the data protection page.

1. Parties and roles

You — the professional or practice holding the Vitena account — are the controller under Art. 4(7) GDPR. Vitena is your processor under Art. 4(8) and processes personal data only for you and only to provide the service. Vitena does not process your clinical data for its own purposes, does not sell it, does not share it with other professionals on the platform, and does not use it to train AI models.

2. Subject matter, nature, purpose and duration

Subject matter and purpose: operating a practice management and client communication platform on your behalf. Nature of processing: collection, storage, organisation, retrieval, display, transmission, backup, deletion. Duration: for as long as your account exists, plus the deletion periods in clause 10.

3. Categories of data subjects and personal data

Data subjects: your clients or patients, people who enquire or book with you, and the members of your own team who use the account.

  • Identity and contact details — name, email address, telephone number, date of birth
  • Appointment and service records, payment status and invoices
  • Health data (Art. 9 GDPR) — questionnaire answers, measurements, session notes, plans, consent records, uploaded documents and images, and any personal summary you prepare
  • Messages exchanged through the platform and the client portal
  • Technical data needed to run the service — log records, IP address, device and browser information

Vitena is built on the assumption that special-category health data will be present. Establishing the lawful basis for it is yours as controller — usually Art. 9(2)(h) together with your national professional rules. The obligations in this agreement apply to all of the categories above, including free-text notes, internal private notes and files you upload, not only structured questionnaire fields.

4. Processing on your instructions

Vitena processes personal data only on your documented instructions. Your instructions are: this agreement, the Terms of Service, the settings you choose in the product, and the actions you take in it. Vitena will tell you if, in its opinion, an instruction infringes the GDPR. Where EU or member state law obliges Vitena to process data beyond your instructions, you will be informed before processing unless that law forbids it.

AI features are an instruction you give, one action at a time. No AI provider receives client content unless you deliberately start an AI action — drafting a plan, drafting a note, or reading a document you attached. If you never use those features, no client data ever reaches an AI provider. Neither AI provider trains models on content sent through their API.

5. Confidentiality

Every person on Vitena's side who may access personal data is bound by a duty of confidentiality that survives the end of their engagement, and is granted access only to the extent needed to operate, support and secure the service.

6. Security of processing (Art. 32)

Vitena maintains appropriate technical and organisational measures, set out in full in Annex A. Measures may be changed as technology develops, provided the level of protection is not reduced.

7. Subprocessors

You give general authorisation for Vitena to engage the subprocessors listed in Annex B. Vitena imposes on each of them data protection obligations no less protective than those in this agreement and remains fully liable to you for their performance. Before adding or replacing a subprocessor, Vitena will give you notice so that you can object; if you object on reasonable data protection grounds and no solution is found, you may terminate the affected service.

8. Helping you answer your clients

Vitena assists you, so far as is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection. Most of these you can carry out yourself in the product; where you cannot, Vitena helps on request. If a data subject contacts Vitena directly about data in your workspace, Vitena will not answer on your behalf but will refer them to you.

9. Breaches, and help with Art. 32–36

Vitena notifies you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification under Art. 33 — what happened, which categories and roughly how many records are affected, the likely consequences, and the measures taken. Vitena also assists you, taking into account the nature of processing and the information available to it, with your obligations under Art. 32 to 36, including a data protection impact assessment where you need one.

10. Deletion and return of data

You can export your data at any time while the account is active, and you can delete individual records yourself. When the contract ends, Vitena deletes the personal data it processes for you, unless EU or member state law requires it to be kept. Deletion from live systems happens within 30 days of the end of the contract. Backups are kept on a rolling window and are overwritten in the ordinary course, so a deleted record disappears from backups within that window at the latest — see Annex A for the current retention period. Backups are never used to restore data that you deleted deliberately.

11. Information and audit rights

Vitena makes available to you all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate. In the first instance this is satisfied by this document, Annex A and Annex B. Beyond that, you may ask specific written questions and Vitena will answer them; an on-site inspection may be requested where a documented reason makes it necessary, with reasonable notice, during business hours, without disrupting operations, and subject to confidentiality.

12. Where data is processed, and transfers outside the EEA

Your workspace data is stored in the European Union, in AWS's Frankfurt region (eu-central-1). There is one exception, and it is under your control: the two AI providers in Annex B are based in the United States, and content reaches them only when you start an AI action. Those transfers are made on the European Commission's Standard Contractual Clauses. Vitena's operating company is established in Türkiye; company seat and data location are two different things, and support access from outside the EEA is covered by the same contractual safeguards.

13. Term, changes and precedence

This agreement runs for as long as your Vitena account exists. If it is amended, the new version is published here with a new version number and effective date, and you are notified before it takes effect. Acceptances already given remain tied to the version that was in force at the time. Where this agreement and the Terms of Service conflict on a data protection question, this agreement prevails.

Annex A — Technical and organisational measures (Art. 32)

Described as implemented, not as aspiration. Where a measure is not in place, it is not listed.

Protection here is layered rather than resting on any single control. Each practice is isolated from every other; access inside a practice is limited by role; everything in transit is encrypted; files and documents are encrypted where they are stored; the database is unreachable from the internet; and every change to the running system goes through a reviewed, automated pipeline. A weakness in one layer does not open the record, because the next layer still has to be passed.

Access control and separation

  • Each practice's records are held separately from every other practice's, and a request made with one account's credentials cannot reach another account's data; where the data layer cannot attribute a request to exactly one practice it refuses the request rather than falling back to a shared view
  • Role-based permissions inside the account, so an assistant does not automatically see clinical content
  • Private notes are stored in a separate field that is never sent to the client portal
  • Passwords are stored only as salted one-way hashes using an established password-hashing algorithm (bcrypt), never in readable form; a minimum length and complexity policy is enforced
  • Sessions use short-lived signed tokens; portal and questionnaire links are single-purpose, expire, and can be revoked by reissuing them
  • Two-factor authentication (TOTP, RFC 6238) is available for the professional's own login, switched on per user from account settings and backed by one-time recovery codes; signing in through a Google account with two-step verification is the alternative second factor

Transmission and storage

  • All traffic between browser, mobile app and servers is encrypted with TLS; plain HTTP is redirected
  • Uploaded files and documents are stored in EU object storage with server-side encryption at rest (AES-256) and no public access; they are served only through short-lived signed links
  • The database is not reachable from the internet: it has no public address and accepts connections only from the application itself
  • Secrets and API keys are held in a managed parameter store, never in source code
  • Email notifications are written so that they announce that something is available and never carry clinical content in the message body

Availability and resilience

  • Automated daily database backups with point-in-time recovery, retained for 7 days and then overwritten
  • Deletion protection on the database, so it cannot be removed by an infrastructure change
  • Managed, automatically scaled hosting with monitoring and alerting on error rates and resource limits

Organisational measures

  • Access to production systems is limited to the people who operate them, under a confidentiality obligation
  • Changes reach production through a reviewed, automated deployment pipeline, not by hand on the server
  • Activity in an account is logged, so it can be reconstructed who did what and when
  • Data export and account deletion are available to you in the product, without asking support

Stated plainly: what is not in place

Vitena does not hold an ISO 27001 or SOC 2 certificate, and does not claim one. It is not a HIPAA business associate and does not offer a BAA, because it does not serve the United States health market. Nor is there a formal penetration-testing report to hand over: security is reviewed as part of how the product is built and run, not certified by a third party.

Annex B — Approved subprocessors

The current list, with what each one is used for and where it processes data, is published and kept up to date on the data protection page. It is part of this agreement by reference, so that a change to the list does not require a new version of the contract while still reaching you as a notice under clause 7.

Questions, or a copy for your files

Write to info@vitena.care with the name under which you practise and the country you work in. There is no charge, and this agreement applies on the free plan as well as on paid plans.

Related: data protection, hosting and subprocessors · GDPR and your clients' rights · Terms of Service · Privacy Policy