intakeScribe abhix-aiLog inSign up
Legal

Data Processing Addendum

Draft — pending review by legal counsel. Not a binding agreement.

1. Roles

This Data Processing Addendum ("DPA") supplements the Terms of Service and governs the processing of personal data under applicable data protection laws (including GDPR, CCPA, and equivalents). The Customer acts as the Data Controller; abhix-ai acts as the Data Processor for personal data processed via the intakeScribe Service.

2. Processing Scope

abhix-ai processes personal data solely on documented instructions from the Customer, as described in the Service Agreement and these Terms. Processing activities include: intake session management, AI-assisted structuring of patient responses, payload signing, authentication, and billing. The subject matter, duration, nature, and purpose of processing are defined by the Service Agreement.

3. Subprocessors

We engage the following sub-processors for data processing activities:

  • Anthropic — Natural language processing (Claude API). Data is processed under Anthropic's data processing terms.
  • Railway — Infrastructure hosting (EU/US regions). Processes infrastructure and application data.
  • Vercel — Frontend hosting and CDN. Processes request logs and edge telemetry.
  • Stripe — Payment processing. Processes billing information only; does not receive health data.

We will notify Customers of any intended changes to this subprocessor list, providing at least 30 days' notice before a new subprocessor begins processing Customer data.

4. International Transfers

Data may be processed in the United States and other countries where our subprocessors maintain infrastructure. Where transfers occur outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission, or equivalent transfer mechanisms, to ensure an adequate level of protection.

5. Security Measures

We implement technical and organizational measures appropriate to the risk, including: (a) encryption of data in transit using TLS 1.2 or higher; (b) encryption of data at rest using AES-256; (c) role-based access controls and least-privilege principles; (d) audit logging of access to personal data; (e) regular vulnerability assessments; and (f) employee security training and confidentiality obligations.

6. Data Subject Requests

abhix-ai will, taking into account the nature of the processing, assist the Customer in responding to data subject requests (access, rectification, erasure, portability, objection) by implementing appropriate technical and organizational measures. Requests received directly by abhix-ai will be forwarded to the relevant Customer without undue delay.

7. Audits

Upon reasonable written notice (not less than 30 days), abhix-ai will make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits shall be conducted at the Customer's expense and in a manner that minimizes disruption to normal operations.