Legal

Data Processing Agreement

Draft processor terms for healthcare and care organizations using the Mantis platform.

Draft document. This text is provided as a starting point and must be reviewed and adapted by qualified legal counsel before publication. Placeholders such as [Legal Entity Name], [Registered Address], and [Data Protection Contact] must be completed.

Last updated: [Effective Date]

1. Scope and Roles

These terms apply where [Legal Entity Name] (the processor) processes personal data on behalf of a customer organization (the controller) in connection with the Mantis Clinic and Mantis Care services.

The controller determines the purposes and means of processing. The processor acts only on the controller's documented instructions, including with regard to international transfers, unless required otherwise by law.

2. Subject Matter and Duration

Subject matter: capture, transcription, structuring, storage, and delivery of healthcare and care documentation. Duration: the term of the underlying agreement plus any agreed return or deletion period.

3. Nature and Purpose of Processing

Processing is carried out to convert healthcare and care interactions into structured draft documentation for professional review, to support shift handover and follow-up tasks, to enable approved family updates where configured, and to integrate approved records with the controller's systems.

4. Categories of Data and Data Subjects

The processing may involve:

  • Data subjects: patients, residents, family contacts, healthcare professionals, care staff, and administrative users.
  • Data categories: identifiers, contact details, professional role data, audio recordings, transcripts, clinical and care documentation, and system audit metadata.
  • Special categories: data concerning health, and where applicable data revealing related sensitive characteristics contained in clinical narratives.

5. Processor Obligations

The processor shall:

  • Process personal data only on documented instructions from the controller.
  • Ensure that personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational measures, as described in the security annex.
  • Not engage a subprocessor without prior general or specific authorization, and impose equivalent obligations on any subprocessor.
  • Assist the controller with data subject requests, data protection impact assessments, and prior consultations, taking into account the nature of the processing.
  • Notify the controller without undue delay after becoming aware of a personal data breach.
  • At the controller's choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless retention is required by law.
  • Make available information necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality.

6. Security Measures

Measures include encryption in transit and at rest, de-identification options, role-based access control, audit logging of access and approvals, environment segregation, secure software development practices, backup and recovery procedures, and configurable retention. Deployment may be cloud, regional cloud, hybrid, or on-premise as selected by the controller.

7. Subprocessors

A current list of authorized subprocessors, including name, function, and processing location, is maintained at [Subprocessor List Reference]. The processor will inform the controller of intended changes and allow a reasonable period to object.

8. International Transfers

Any transfer outside the country of origin will be carried out under an adequacy decision, standard contractual clauses, or another mechanism recognized under the GDPR and KVKK, together with any required supplementary measures. On-premise or regional deployment may be selected to avoid transfers.

9. Breach Notification

The processor will provide the controller with information reasonably available about the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed, to support the controller's regulatory notification duties.

10. Liability and Order of Precedence

Liability under these terms is subject to the limitations in the underlying agreement. In the event of conflict, these data processing terms prevail on data protection matters.

This draft must be reviewed by legal counsel and executed as an annex to the master services agreement before processing begins.