Data Processing Agreement
Last updated:
This Data Processing Agreement (DPA) supplements the master agreement between the contracting hospital (Controller) and My Health Online (Processor) and governs the processing of personal data described in the Privacy Notice. It is drafted to satisfy Art. 28 GDPR, KVKK Md. 12, and UZ PDL Art. 16 simultaneously.
1. Roles
The hospital is the Controller. My Health Online is the Processor. My Health Online processes personal data only on the documented instructions of the hospital, including the technical configuration of the platform deployed for that hospital.
2. Subject matter and duration
Subject matter: provision of the My Health Online platform. Duration: the term of the master agreement plus the deletion/return period set out below.
3. Nature and purpose of processing
Hosting, transmitting, indexing, and backing up pseudonymized clinical case content; producing tamper-evident audit logs; sending in-app and email notifications; providing access-control enforcement; producing data exports for DSAR.
4. Categories of data and data subjects
Data subjects: (a) authorized clinicians and hospital staff; (b) patients whose pseudonymized clinical data is uploaded by the hospital.
- Identification — names and emails (clinicians only).
- Professional — title, department, specialty, role, MFA status.
- Health — pseudonymized clinical case content, imaging studies, consultations.
- Behavioral — audit log entries (action, timestamp, IP).
5. Security measures
My Health Online implements appropriate technical and organisational measures, including:
- Strict tenant isolation enforced at the database query layer via Prisma client extensions; cross-tenant reads require an explicitly marked privileged context.
- Hash-chained audit log with database triggers and advisory locks — any tampering is detectable by recomputing the chain.
- Encryption in transit (TLS 1.2+) and at rest for case attachments and database backups.
- Role-based access control with four roles (Doctor, Specialist, HospitalAdmin, SystemAdmin) and an external-share permission model with explicit expiry.
- MFA (TOTP + recovery codes) optional for clinicians, required for hospital administrators.
- Server-side session revocation via per-user session epoch.
- Quarterly restore drills, with restore markers logged in the audit chain.
6. Sub-processors
My Health Online may engage sub-processors for hosting infrastructure, email delivery, and observability. The current list is published in-app at /admin/subprocessors. My Health Online will give the Controller at least 30 days' notice of any intended changes; the Controller may object on reasonable grounds.
7. Cross-border transfers
Default deployments process and store data within the country of deployment. For any transfer to a third country, My Health Online uses the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or KVKK-approved equivalent commitments. Transfers initiated by clinicians (case sharing across borders) are logged in the audit chain.
8. Personal-data breach notification
My Health Online will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal-data breach, providing the categories of data affected, approximate counts, and the remedial measures taken. My Health Online supports the Controller's reporting obligations to the KVKK Board, the Centre for Personal Data Protection of Uzbekistan, and applicable EU supervisory authorities.
9. Assistance to the Controller
My Health Online will assist the Controller in responding to data-subject requests (KVKK Md. 11, GDPR Art. 15-22, UZ PDL Art. 22) by providing per-user data exports (/api/auth/dsar/export) and tooling for rectification, erasure, and restriction.
10. Return or deletion on termination
On termination of the master agreement, My Health Online will, at the Controller's option, return or delete all personal data within 30 days, save for the audit log which is retained for the statutory minimum period before deletion.
11. Audit rights
My Health Online makes available all information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, on reasonable notice and during normal business hours.