Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) template applies to clinic and enterprise customers using Phyzioline Clinic ERP to process patient data on their behalf.
Parties
- Data Controller: The clinic or healthcare organization (Customer).
- Data Processor: Phyzioline — the cloud platform provider.
Scope of processing
Patient demographics, appointments, clinical notes, attachments, and billing data stored in the system for care delivery and clinic operations.
Phyzioline obligations
- Process data only on Customer instructions and applicable law.
- Technical and organizational security (HTTPS, RBAC, audit logging).
- No sale of patient data to third parties.
- Breach notification within legally required timeframes.
- Support access and deletion requests via in-product privacy tools.
Executed copy
For a countersigned DPA for your clinic or hospital, contact us via Contact Us with subject Privacy / Data Request.