Back to Home
Data Protection

Data Processing Agreement

Between you as Controller and Cognivolt as Processor. Part of our Terms of Service — accepting those accepts this, with nothing separate to sign.

When a clinician lets an outside service handle patient data, data protection law requires a written agreement covering what that service may do with it. This is that agreement. It is written for the EU and UK GDPR and applies on the same terms in Canada, Australia, New Zealand and India — see the regional section for what changes.

1. What this agreement is

This Data Processing Agreement ("DPA") is between you — the clinician, practice or organisation using Cognivolt ("Controller") — and Cognivolt ("Processor", "we", "us"). It forms part of our Terms of Service and applies whenever we process personal data on your behalf.

You decide why and how patient data is used. We process it only to provide the service to you. In the language of the GDPR, you are the controller and we are the processor.

It is written for the EU and UK GDPR, and applies on the same terms where your own law requires a processor agreement — including Canada (PIPEDA and provincial health privacy law), Australia, New Zealand and India. Where your law requires something these terms do not cover, the regional section below applies.

2. The processing, in scope

Subject matter and purpose — providing clinical documentation and decision-support features to you.

Duration — for as long as your account is active, plus the deletion window below.

Nature of processing — recording, transcription, generation of clinical notes, storage and retrieval.

Types of personal data — patient names and identifiers, demographic details, consultation audio, transcripts, clinical notes and any documents you upload; and your own account details.

Categories of data subjects — your patients, and you and your staff.

Special category data — health data, processed under your instructions and your lawful basis.

3. Our obligations

We will:

Process personal data only on your documented instructions. Your use of the service, and these terms, are those instructions. If we believe an instruction breaches data protection law, we will tell you and may decline it.

Ensure anyone we authorise to process the data is bound by confidentiality.

Implement appropriate technical and organisational security measures as required by Art. 32 — including encryption in transit and at rest, access control, and audit logging of record access.

Not transfer personal data outside its region of storage except as set out below.

Assist you, so far as reasonably possible and taking into account the nature of the processing, with data subject requests, security, breach notification and data protection impact assessments. Where that assistance goes beyond the tools already in the service, we may charge for the time at our standard rates.

Make available the information reasonably necessary to demonstrate compliance with this DPA.

4. What we need from you

You are responsible for the lawfulness of what you send us. You confirm that:

You have a lawful basis for the processing, and have obtained any consent, authorisation or notice your law requires before recording a consultation or uploading patient data.

Your instructions to us comply with data protection law.

You will not send us personal data that the service is not designed to process, and will not send more than is necessary.

You are responsible for responding to your patients as the controller. We will refer any request that reaches us directly to you rather than answer it.

Clinical decisions and the accuracy of what enters a patient record remain yours.

5. Sub-processors

You give us general authorisation to engage sub-processors to deliver the service. Each is bound by written terms offering protection materially equivalent to this DPA, and we remain responsible to you for what they do.

A current list is published at cognivolt.app/subprocessors. We will give at least 30 days' notice before adding or replacing one, by updating that page and emailing the address on your account.

You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the service and receive a pro-rata refund of fees paid for the unused period. That is the sole remedy for such an objection.

6. Where data is stored, and transfers

Personal data is stored in the European Union by default.

Where providing the service requires a transfer outside the EEA or the UK — including access by our personnel, and processing by a sub-processor located elsewhere — that transfer takes place under the European Commission's Standard Contractual Clauses (Decision 2021/914), and the UK Addendum where UK data is involved, which are incorporated into this DPA by reference. Module Two applies where you are a controller and we are a processor.

Where any onward transfer relies on a mechanism other than the Clauses, we will apply a transfer mechanism valid under the law that applies to you.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and give you the information reasonably available to us so that you can meet your own notification duties.

Your notification obligations to a supervisory authority and to affected individuals remain yours. We will not notify your patients or your regulator on your behalf.

A notification, or our assistance with one, is not an admission of fault or liability.

Unsuccessful attempts that do not compromise personal data — blocked sign-ins, port scans, and comparable routine network activity — are not personal data breaches and are not notified individually. This paragraph is notice of them.

8. Audit

On written request, no more than once in any twelve-month period, we will provide the information reasonably necessary to demonstrate compliance with this DPA — normally by answering a security questionnaire and providing any current certifications, reports or summaries of our controls.

An on-site audit takes place only where that information is genuinely insufficient, where a supervisory authority requires it, or following a confirmed breach affecting your data. It must be on at least 30 days' notice, during business hours, must not disrupt the service or affect other customers, is subject to confidentiality, and is at your cost.

9. Deletion and return

On termination, or at your request, we will delete or return the personal data we process for you within 60 days, and delete existing copies. You can export your records from within the service at any time and should do so before that period ends.

We may retain personal data where law requires it, and in routine backups that expire on their own cycle. Anything retained stays subject to this DPA and is not processed for any other purpose.

10. Regional terms

These apply in addition to the above, according to where you practise.

Canada — we act as your service provider under PIPEDA and applicable provincial health privacy legislation, including Ontario's PHIPA and Quebec's Law 25. We will notify you of a confidentiality incident without undue delay so that you can meet your own reporting obligations.

Australia — we handle personal and health information consistently with the Australian Privacy Principles. You remain the entity accountable to individuals under APP 8 in relation to disclosures to us.

New Zealand — we handle health information consistently with the Privacy Act 2020 and the Health Information Privacy Code 2020.

India — we act as a data processor to you as data fiduciary under the Digital Personal Data Protection Act 2023, processing only on your instructions.

Where the service is not offered in a country that requires personal or health data to be stored within its borders, this DPA does not create an entitlement to such storage.

11. Liability and general

Our liability under this DPA is subject to the limitations and exclusions in the Terms of Service, and both together are the total liability between us for the processing.

Nothing here limits a liability that cannot lawfully be limited, or affects a data subject's rights against either of us under Art. 82.

If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where you are a US covered entity, the Business Associate Agreement governs protected health information instead of this DPA.

We may update this DPA where the law or our sub-processors change. Where a change materially reduces your rights, we will give reasonable notice before it takes effect.

This DPA takes effect when you accept our Terms and continues for as long as we process personal data for you.

Need a countersigned copy for your records?

We can provide one, including the Standard Contractual Clauses.

Contact Us