Data Processing Agreement

Version 1 - 22 Mar 2023

This Processor Agreement (‘Agreement’) is an agreement between the user (s) of the dala.care Platform (‘Controller’) and Gangverk ehf, or any of its subsidiaries (‘Processor’).

This Agreement forms part of the Contract for Services under the dala.care Terms and Conditions of Use.

Preamble

A

You operate as the Data Controller for all data that users generate ('User Generated Data').

B

You function as the Data Subject concerning 'dala.care User Data.'

C

You intend to delegate certain services to Gangverk ehf, services which involve the processing of Personal Data.

D

Both parties aim to establish a data processing agreement adhering to the prevailing legal standards about data processing, especially the Regulation (EU) 2016/679 of the European Parliament and of the Council dated 27 April 2016. This regulation concerns the protection of individuals in relation to personal data processing and the free circulation of this data, replacing Directive 95/46/EC (known as the General Data Protection Regulation).

E

Both parties are keen to clarify and solidify their respective rights and responsibilities.

UNDERSTOOD AND CONFIRMED:

Participants

1

Gangverk ehf dala.care, inclusive of its subsidiary companies (referred to as 'Processor')

2

Home Care Service Provider / Accredited User (termed 'Controller')

Agreement

A

The Processor has developed "dala.care", a secure platform tailored for home care.

B

dala.care is offered by the Processor as a versatile platform, accessible via mobile or desktop devices, functioning as a service governed by the Processor from distant servers.

C

Beyond this, the Processor extends supplementary offerings, including but not limited to, implementation, training, and advisory services complementing its software.

D

The Controller, whether as an individual health professional or as part of a broader healthcare entity, is keen to harness the software and services presented by the Processor. In response, the Processor commits to delivering these provisions.

This Agreement encompasses:

-

The Agreement itself

-

Standard Terms and Definitions

-

Agreement on Data Processing

Engaging with the dala.care Platform signifies your acceptance of the Data Processing Agreement detailed herein. For a holistic understanding, we urge you to peruse the regulations and accords found at: https://dala.care/legal

Standard Terms and Definitions

Use Policy

Guidelines set by the Processor regarding the dala.care Platform's usage, aligned with best practices and healthcare standards.

Contact

Refers to this Data Processing Agreement.

Verified Users

Individuals granted permission to utilize the dala.care Platform as detailed:

Verified Users have registered a dala.care account. All Verified Users must adhere to dala.care Terms of Use, and Privacy Protocol.

User-Specific Data

Personal information related to the Verified Users on the dala.care Platform.

dala.care Platform

The unique software designed by the Processor, offering a secure space for delivering home care.

Controller, Processor, Data Individual, Health-related Data, Personal Details, Data Breach, Data Handling, and Adequate Safety Protocols: As outlined in the Data Safety Laws.

Data Safety Laws

The 2018 Data Protection Act embodying the General Data Protection Regulation (EU) 2016/679, subject to changes and inclusive of any legislative updates.

General Information

Refers to generic data that doesn't fall under User-Created Data or User-Specific Data categories.

Personal Information

Encompasses both User-Created Data and User-Specific Data.

Privacy Protocol

Processor's evolving privacy terms available at https://dala.care/legal

User-Generated Data

Information entered into the dala.care Platform either by the Controller, by Verified Users, or on behalf of the Controller by the Processor. This notably includes care recipient health records.

Data Processing Agreement

Personal Data

Within this Data Processing Agreement, dala.care operates in dual roles, acting both as the data controller and data processor concerning dala.care User Data. Notably, those using dala.care are considered data subjects.  

Additionally, it's recognized that the Authorized Users of the dala.care Platform retain control over User Generated Data, with dala.care operating as its processor.  
The stipulations of the Privacy Policy govern dala.care handling of both dala.care User Data and User Generated Data. The processing of these data categories by the Processor aligns strictly with Data Protection Legislation.

Data Processing

dala.care, as the Processor, will:

-

Handle Personal Data strictly within the scope and manner essential for service provision, aligning with the directives of the Privacy Policy. Personal Data will not be processed beyond these specifications unless mandated by any European Union member state. In such scenarios, the Processor will, where permissible, inform the Controller prior to such mandated processing.

-

Adhere to the Controller's specific directives during data processing.

Preservation and Elimination of Personal Data

-

dala.care platform offers the capability to either erase or export user data from its systems. Post deletion on the dala.care platform, any retained user data on your systems will be eradicated, barring the data within specified retention or backup periods. It's essential to note that user data shared with other dala.care Platform users is governed by those individual users and isn't influenced by the previously mentioned actions.

-

dala.care delineates and observes all data retention periods in our structured data retention timeline.

-

Upon the culmination of this agreement, it's imperative to initiate all actions required to remove pertinent user data from the dala.care Platform. Moreover, ensuring all associated data processed by dala.care and affiliated subprocessors is terminated, unless legally mandated data retention protocols state otherwise.  

-

For a comprehensive understanding of our data retention timelines, we invite you to get in touch.

Security Provisions

The Processor commits to initiating all necessary technical and structural measures to safeguard Personal Data against any unauthorized or illicit processing.

The Controller is tasked with continual supervision and requisite updates to amplify Personal Data security measures.  

Employee Protocols

The Processor pledges to:

A

Endeavor to validate the credibility of employees accessing Personal Data;  

B

Ensure Personal Data accessibility is restricted to only those employees whose roles necessitate it;  

C

Limit data access to only essential segments pertinent to an employee's job functions;

D

Mandate all engaged employees to uphold the confidentiality of Personal Data and undergo extensive training about Data Protection Legislation and best practices.

Subprocessors

dala.care, as the Processor, will only enlist a third-party subprocessor to handle the Personal Data if:  

A

Prior consent has been obtained from the Controller (which shouldn't be unreasonably denied), given the Processor has furnished exhaustive details of the proposed subprocessor;

B

The subprocessor's agreement ensures its data protection clauses mirror, in essence, those detailed in this Data Processing Commitment.

The Controller explicitly approves the processing of Personal Data by the subsequent Sub-Processors:

Subprocessor: Amazon Web Services (AWS)
Information: dala.care uses AWS as our Cloud Provider.
Data storage location: Ireland
Processed data: User data, User Generated data, Operational data
More information: All data is encrypted at rest and in transit.

Subprocessor: SendGrid
Information: dala.care uses SendGrid for outgoing emails.
Data storage location: SendGrid uses Twilio infrastructure in USA.
Processed data: Outgoing emails may contain user information such as names and encrypted links to verify identity.
More information: https://www.twilio.com/en-us/legal/security-overview

Subprocessor: Segment
Information: dala.care uses Segment to better understand how users interact with our applications. This is essential to ensure we can continue to improve our service and better serve our customers. Data sent to Segment only reflects user behaviour and never includes any personally identifiable data.
Data storage location: Ireland
Processed data: No personally identifiable data.

Protection of Data Subject Rights

The Processor commits to empowering the Controller with fitting technical and organizational strategies, within reasonable capabilities, to facilitate the Controller’s adherence to their responsibilities. This pertains to addressing requests aimed at exercising the Data Subject's rights as delineated in Articles 12 to 23 of the GDPR (Rights of the Data Subject). A collaborative, good-faith dialogue will be undertaken by the Parties to justly distribute the associated expenses.

In instances where a Data Subject presents complaints or queries concerning the Processing of User Generated Data, the Processor is obliged to promptly relay such communications to the Controller. The responsibility for adequately managing and responding to such requests rests primarily with the Controller.

Adherence to Compliance Protocols

The Processor is committed to:

-

Swiftly adhering to any directive from the Controller that necessitates the amendment, transfer, or deletion of Personal Data.

-

On request by the Controller, furnishing a copy of all Personal Data in its possession, presented in a format and via media as reasonably determined by the Controller.

-

Erasing the Controller's User Data upon receiving a directive to do so from the Controller.

-

Immediate notification to the Controller if there is an awareness of any unauthorized or unlawful processing, or in cases of loss, damage, or destruction of Personal Data.

-

Keeping meticulous, accurate records and information as a testament to its compliance with the obligations as set out in this Data Processing Agreement.

-

Safeguarding the integrity of the Personal Data, preventing any unauthorized alterations, and ensuring that the Personal Data remains distinct from any other created information.

Documentation and Audit Procedures

The Processor commits to providing the Controller with access to all necessary records and information required to validate compliance with the obligations specified in this Data Processing Agreement.

The Controller reserves the right to conduct inspections directly or through appointed representatives. This includes the examination of facilities, equipment, documentation, and electronic data pertinent to the Processor’s handling of Personal Data. A minimum notice of 5 days should be given for such inspections by the Controller, except in cases where the Controller suspects that the Processor might be violating the terms specified in this Data Processing Agreement, whereby the notice requirement may be waived.

For communications or queries directed at dala.care Data Protection Officer (DPO), the designated email contact is: finnur@dala.care

Contact

dala.care
support@dala.care
Ármúli 1
105 Reykjavík
Iceland