top of page

Order processing agreement

1. Subject Matter of the Agreement

In the course of providing services in accordance with the Usage Agreement dated 09 August 2024, the processor processes personal data for which the client acts as the controller and the processor acts as the processor in the data protection sense ("client data"). This agreement sets out the data protection obligations and rights of the parties in connection with the processing of client data for the purpose of providing the services under the main agreement.

2. Instructions Authority of the Client

2.1.    The processor shall process the client data exclusively on behalf of and in accordance with the instructions of the client, unless the processor is legally obligated to process the data. In such a case, the processor shall inform the client of the legal requirements prior to processing, unless the relevant law prohibits such notification on grounds of important public interest.

2.2.     The processing of client data by the processor shall take place exclusively in the manner, scope, and for the purpose as set out in Annex 1. The processing relates exclusively to the categories of personal data and data subjects specified therein.

2.3.     The duration of the processing corresponds to the term of the main agreement.

2.4.     The client reserves the right to issue instructions at any time regarding the nature, scope, purposes, and means of processing the client data.

2.5.     The client warrants that no legal or contractual confidentiality obligations preclude the transfer.

2.6.    The client warrants that the transfer of processing to the processor is permissible in accordance with data protection principles.

3. Confidentiality Obligation

The processor undertakes to maintain confidentiality and ensures that all persons entrusted with the processing of client data under its responsibility are likewise bound by a confidentiality obligation.

4. Data Security

4.1.    The processor shall implement appropriate technical and organizational measures to ensure an adequate level of protection for the client data. In doing so, it shall take into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the data processing. Additionally, the likelihood and severity of the risks to the rights and freedoms of the data subjects shall be considered.

4.2.    Prior to commencing data processing, the processor must implement the technical and organizational measures set out in Annex 2 and maintain them throughout the entire term of the agreement. It shall ensure that data processing is carried out in accordance with these measures.

5. Sub-processors

5.1.    The client grants the processor general permission to engage sub-processors for the processing of client data. The processor's current sub-processors are listed in Annex 3.

5.2.    The processor shall inform the client of any planned changes regarding the engagement or replacement of sub-processors. The client has the right to object to any planned change. In the event of an objection, the planned change may not be carried out; however, the right of termination under the main agreement remains unaffected. For approved changes, the processor shall update the list of sub-processors in Annex 3 accordingly and make it available to the client.

5.3.    The processor shall contractually obligate each sub-processor to comply with the same data protection obligations that apply to the processor itself.

5.4.    The processor shall verify, both prior to and regularly during the engagement, that the sub-processors have implemented appropriate technical and organizational measures to ensure that the processing of client data is carried out in accordance with this agreement.

6. Rights of Data Subjects

6.1.    The processor shall support the client, to a reasonable extent and by means of appropriate technical and organizational measures, in fulfilling its obligation to respond to requests from data subjects.

6.2.    The processor shall in particular:

a)    promptly inform the client if a data subject contacts the processor directly with a request to exercise their rights in relation to client data;

 

b)    provide the client, upon request, with all information available to it regarding the processing of client data that the client requires to respond to a data subject's request and which the client does not already have in its possession.

7. Further Support Obligations of the Processor

7.1.    The processor shall promptly notify the client as soon as it becomes aware of a breach of the protection of client data. This includes events leading to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to client data.

7.2.    The notification should, where possible, include the following:

a)    a description of the nature of the breach of client data protection, including the categories affected and the approximate number of data subjects and records concerned;

b)    the likely consequences of the breach;

c)    the measures taken or proposed by the processor to address the breach and, where applicable, measures to mitigate its possible adverse effects.

7.3.    If the client is obligated to notify supervisory authorities and/or data subjects, the processor shall, upon the client's request, support the client in fulfilling these obligations.

7.4.    The processor shall support the client, to a reasonable extent, in conducting any data protection impact assessments and, where applicable, any subsequent consultations with supervisory authorities.

8. Data Deletion and Return

Upon instruction from the client, the processor shall, upon termination of the main agreement, either completely and irreversibly delete all client data or return it to the client, unless statutory provisions obligate the processor to retain such data beyond that point.

9. Evidence and Audits

9.1.    The processor must ensure and regularly verify that the processing of client data is carried out in accordance with this agreement and the instructions of the client, including the scope set out in Annex 1.

9.2.    The processor shall document the fulfilment of these obligations and provide the client with appropriate evidence upon request.

9.3.    In particular, the processor shall document:

a)    the confidentiality obligations of persons processing client data;

b)    all breaches of the protection of client data within its sphere of influence, including all relevant facts, impacts, and measures taken;

c)    all contracts with sub-processors and their review in accordance with clause 6;

d)    all deletions of client data carried out upon instruction of the client.

9.4.    The client is entitled to audit the processor, independently or through a third party, both prior to the commencement of client data processing and regularly throughout the term of the agreement, with regard to compliance with this agreement, including the implementation of the technical and organizational measures set out in Annex 2.

9.5. The processor shall support such audits through appropriate and reasonable measures, including:

a)    granting the necessary access and inspection rights; and

b)    providing all necessary information.

Annex 1 – Nature, Purpose, and Scope of the Processing of Personal Data

Processing

The processor processes client data for the purpose of providing the services in accordance with the main agreement, in particular:

  • Generation of Medical Documentation: The processor processes personal data using machine learning models for the transcription and creation of medical documents based on a recorded consultation or similar conversations.

  • Communication: The processor uses personal data to communicate with persons employed or engaged by the client, e.g. in response to support requests via email. For this purpose, the processor processes the personal content of the communication as well as log data regarding the nature and timing of the communication.

  • Operation and Improvement of the App: The processor uses personal data to ensure the smooth operation of the app and to continuously improve it (e.g. adaptation or development of new content). For this purpose, the processor may, among other things, evaluate statistics on the usage of the app or app content.

 

Categories of Personal Data

The following categories of client data are processed by the processor:

Personal Data:

  • Contact data such as first and last name

  • Master data such as age and social security number (AHV number)

Sensitive Personal Data:

  • Health data such as medical history (anamnesis)

  • Possible: political, religious, or ideological beliefs

  • Possible: racial and ethnic origin

  • Possible: sex life or sexual orientation

Categories of Data Subjects

Personal data is processed in connection with the provision of services under the main agreement for the following categories of natural persons:

Staff: 

  Persons employed or engaged by the client who may be mentioned in client data, including:

  • Physicians, nursing staff, paramedics, and other clinical personnel

  • Administrative staff involved in the coordination or documentation of patient contacts

  • IT personnel responsible for integration or technical operations

  • Support staff who process or are mentioned in support requests related to client data

  • Decision-makers and authorized contact persons of the client with user access to the system

Patients and Related Persons: 

Natural persons whose personal data may be recorded or referenced in client data, including:

  • Patients whose health-related information is recorded, dictated, or processed in accordance with the main agreement

  • Third parties mentioned during clinical interactions (e.g. family members, caregivers, or emergency contacts), insofar as these persons are referenced in dictated notes, voice recordings, transcriptions, or associated metadata

Locations of Data Processing

Client data is processed at the following locations:

  • Zurich, Switzerland (processing)

  • Gävle, Sweden (processing)

  • St. Ghislain, Belgium (processing)

  • Frankfurt, Germany (processing and storage)

All data at rest and data in transit are encrypted.

Annex 2 – Technical and Organizational Security Measures

The following describes the technical and organizational measures implemented by the processor in connection with the processing of client data and the fulfilment of its obligations under this data processing agreement.

Ensuring Confidentiality

The processor implements the following measures to ensure that processed client data is only accessible to authorized persons:

  • Access Control: The processor assigns access rights on a need-to-know basis. This means that access to client data is restricted to persons who require it to carry out their professional activities.

  • Physical Access Control: The processor restricts access to the physical premises in which client data is processed to identified and authorized persons who require access in the course of their work. These security areas are protected by appropriate access controls to ensure that only authorized employees are granted entry.

  • User Control: Through careful assessment of professional and personal suitability, as well as comprehensive onboarding and training of employees, the processor ensures that employees understand their responsibilities and are suited for the intended data processing activities.

Ensuring Availability and Integrity

The processor implements the following measures to ensure that processed client data is available when needed and cannot be altered without authorization or unintentionally:

  • Storage Media and Storage Control: To ensure the security and availability of client data, data on storage systems is automatically deleted after successful processing and, where technically feasible, encrypted in accordance with currently applicable industry standards. Access is restricted to authorized persons through two-factor authentication. Access rights and the granting of authorizations are continuously reviewed. These measures aim to prevent, as far as possible, unauthorized persons from accessing, storing, copying, modifying, moving, deleting, or destroying data.

  • Recovery: The processor does not create backups of client data.

  • Availability: The availability of client data is reduced to a minimal duration. The storage systems and operationally relevant components of the data processing systems are not designed with redundancy in terms of power supply, server, network, and storage systems.

  • Reliability: All events and log data are collected centrally and processed and evaluated using analysis tools. This ensures that any malfunctions in the system are detected and reported.

  • Data Integrity: The storage systems and operationally relevant components of the data processing systems are not designed with redundancy.

  • System Security: The processor ensures that information on technical vulnerabilities of the IT systems in use is made available in a timely manner, that the organization's exposure to these vulnerabilities is assessed, and that appropriate measures are taken to minimize the associated risk. In addition, all IT risks within the organization are regularly identified, analyzed, assessed, treated, and monitored. The processor's infrastructure is subject to regular review in collaboration with external partners.

Ensuring Traceability

The processor implements the following measures to ensure that client data is processed in a traceable manner:

  • Input Control: The processor ensures that any access to data processing systems is traceable via audit logs and restricted to authorized employees. This allows for a complete review of which data was processed, at what time, and by whom.

Annex 3 – List of Sub-processors

Processing and Storage:

Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855, Luxembourg Server locations:

  • "eu-central-1", Frankfurt, GER

Processing:

Microsoft EMEA, One Microsoft Place, South County Business Park, Dublin 18, Ireland Server locations:

  • "switzerland north", Region Zurich, CH

  • "eu west", Amsterdam, NED

  • "sweden central", Gävle, SWE

 

Processing:

Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016, United States Server locations:

  • "belgium", St. Ghislain, BEL

intonate.

Intonate is a technology startup based in Zurich. We are convinced that the latest developments in generative AI offer the greatest opportunity to improve healthcare systems in Europe. Intonate contributes to reducing the overwhelming administrative burden in healthcare by simplifying the documentation of doctors' daily work.

  • LinkedIn

Intonate

Technoparkstrasse 1

8005 Zürich

+41 44 513 75 56

CHE-281.993.625

Legal

Legal Notice

Privacy policy

GTC

© intonate.ch

bottom of page