Anamnesix Română

Legal documents

Data Processing Agreement

Version 24 September 2026 · Processor: Lava Labs SRL

Parties and purpose of this agreement

This Data Processing Agreement (the Agreement) is concluded between the doctor who creates an Anamnesix account (the Controller) and Lava Labs SRL, registered office [TODO: registered office], registration number [TODO: registration number], contact [TODO: contact email] (the Processor).

The Agreement follows the standard contractual clauses for the relationship between controllers and processors adopted by the European Commission through Implementing Decision (EU) 2021/915 under Article 28(7) of Regulation (EU) 2016/679 (GDPR). Where this Agreement is shorter than those clauses, the clauses are to be read into it. Where this Agreement is stricter, this Agreement applies.

The Controller accepts this Agreement by switching on the acceptance control on the sign-in screen of the Anamnesix app. The app records the accepted version and the time of acceptance on the Controller's phone. A new version of this Agreement is presented for acceptance at the next sign-in.

Clause 1: Purpose and scope

  1. The purpose of these clauses is to ensure compliance with Article 28(3) and (4) GDPR.
  2. The Controller determines the purposes and means of processing the personal data of the Controller's patients. The Processor processes that data only on behalf of the Controller and only in the ways described in Annex I.
  3. These clauses apply to the processing described in Annex I.
  4. Annexes I to III form an integral part of this Agreement.

Clause 2: Invariability of the clauses

The parties undertake not to modify the clauses, except for adding information to the annexes or updating the annexes. The Controller may not rely on clauses that were removed or altered outside this process.

Clause 3: Interpretation

Terms defined in the GDPR have the same meaning here. These clauses are read in harmony with the GDPR and not in a way that conflicts with the rights and obligations it provides.

Clause 4: Hierarchy

In the event of a contradiction between these clauses and any other agreement between the parties, including the Terms of Service, these clauses prevail.

Clause 5: Description of the processing

The details of the processing, in particular the categories of personal data and the purposes for which the personal data are processed on behalf of the Controller, are specified in Annex I.

Clause 6: Obligations of the parties

6.1 Instructions

  1. The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law. The instructions are: store the encrypted files the Controller uploads, keep encrypted database backups, hold the encrypted recovery envelope, and transcribe the audio memos the Controller submits for dictation. Using the corresponding feature in the app is the documented instruction for that processing.
  2. The Processor immediately informs the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other data protection law.

6.2 Purpose limitation

The Processor processes the personal data only for the specific purposes set out in Annex I, unless it receives further instructions from the Controller.

6.3 Duration of the processing

The processing lasts for the duration set out in Annex I.

6.4 Security of the processing

  1. The Processor implements the technical and organisational measures specified in Annex II to ensure the security of the personal data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
  2. In assessing the appropriate level of security, the parties have taken into account that the data concerns health, a special category under Article 9 GDPR, and that the Controller's files are encrypted on the phone before they reach the Processor.
  3. The Processor grants access to the personal data only to members of its personnel strictly necessary for the performance of the contract, bound by confidentiality, and only to the extent the design of the service makes such access technically possible.

6.5 Sensitive data

The processing involves data concerning health. The Processor applies the specific restrictions and safeguards described in Annex II, in particular end-to-end encryption of stored files and database backups, plaintext processing of audio only for the time needed to return a transcript, and immediate deletion of audio and transcript at the transcription provider once the app confirms receipt.

6.6 Documentation and compliance

  1. The parties demonstrate compliance with these clauses.
  2. The Processor deals promptly with enquiries from the Controller about the processing.
  3. The Processor makes available to the Controller the information necessary to demonstrate compliance, consisting of this Agreement, the Technical and Organisational Measures, the Sub-processor list and, once a year on request, a written summary of the security measures in force and any changes made during the year.
  4. The Controller may audit the processing. Given the size of the Processor and the encrypted design of the service, audits are carried out through written information and the yearly summary. An on-site inspection or an audit by a mandated auditor takes place only at the request of a supervisory authority or in the twelve months following a personal data breach affecting the Controller's data, on reasonable notice and at reasonable intervals.
  5. The Processor makes the information in this clause available to the supervisory authority on request.

6.7 Use of sub-processors

  1. The Controller gives a general authorisation for the engagement of the sub-processors listed in Annex III.
  2. The Processor informs the Controller in writing, by email to the account address, of any intended addition or replacement of a sub-processor at least 30 days in advance. The Controller may object within that period. If the parties cannot resolve the objection, the Controller may terminate the account under Clause 8 without penalty.
  3. Where a sub-processor processes data on behalf of the Controller, the Processor concludes a contract with the sub-processor that imposes, in substance, the same data protection obligations as this Agreement, including sufficient guarantees on technical and organisational measures.
  4. The Processor remains fully responsible to the Controller for the performance of the sub-processor's obligations.
  5. On request, the Processor provides the Controller with a copy of the sub-processor agreement, with commercial terms removed.

6.8 International transfers

  1. Any transfer of data to a third country or an international organisation by the Processor takes place only on documented instructions from the Controller or to meet a specific requirement of Union or Member State law, and in compliance with Chapter V GDPR.
  2. Personal data of patients is stored and processed in the European Union. Where a sub-processor is established outside the European Economic Area, the transfer mechanism is stated in Annex III. The Controller agrees that the Processor may use the standard contractual clauses adopted by the European Commission or a decision of adequacy, including the EU-US Data Privacy Framework, as the transfer mechanism.

Clause 7: Assistance to the Controller

  1. The Processor promptly notifies the Controller of any request it receives from a data subject. It does not respond to the request itself, unless authorised by the Controller.
  2. The Processor assists the Controller in fulfilling the Controller's obligation to respond to data subject requests, taking into account that the Processor cannot read the Controller's encrypted files. In practice, the Controller answers access, rectification and erasure requests from the app on the phone, and the Processor assists with the deletion of cloud copies and, where needed, with confirmation that deletion has occurred.
  3. The Processor assists the Controller in ensuring compliance with the obligations on security, breach notification, data protection impact assessment and prior consultation, taking into account the nature of the processing and the information available to the Processor. The Processor's Data Protection Impact Assessment and Technical and Organisational Measures are made available for that purpose.

Clause 8: Notification of personal data breach

  1. In the event of a personal data breach affecting data processed by the Processor, the Processor notifies the Controller without undue delay and at the latest 48 hours after becoming aware of it.
  2. The notification contains at least: the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; the contact point for further information; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it is provided in phases without undue further delay.
  3. The Processor cooperates with the Controller and assists the Controller in complying with the Controller's obligations under Articles 33 and 34 GDPR. Because stored files and backups are encrypted with keys the Processor never holds, the Processor documents in its notification whether the breach concerned ciphertext only.

Clause 9: Non-compliance and termination

  1. Without prejudice to the GDPR, if the Processor breaches its obligations under these clauses, the Controller may instruct the Processor to suspend the processing until compliance is restored or the account is terminated.
  2. The Controller may terminate this Agreement and the account if the Processor is in substantial or persistent breach, or fails to comply with a binding decision of a court or supervisory authority.
  3. The Processor may terminate the account if the Controller insists on an instruction that the Processor has flagged as infringing data protection law.
  4. Termination happens through the account deletion function of the app or, if the app is unavailable, by written notice to the Processor's contact address.

Clause 10: Deletion at the end of the processing

  1. When the Controller deletes the account, the Processor deletes all files, backups and recovery envelopes stored for the Controller and deletes the account record. Rows in the audit log are kept in anonymised form, without any reference to the Controller.
  2. When a Premium subscription lapses, the Processor keeps the encrypted files readable for 90 days so the Controller can restore them, then deletes them permanently.
  3. Until deletion, the Processor continues to ensure compliance with these clauses.
  4. The Controller is responsible for keeping the patient records on the phone for as long as medical record retention rules require. The Processor's cloud copies are a backup, not the record of reference.

Annex I: Description of the processing

Parties

  • Controller: the natural person or legal entity, licensed to practise medicine in Romania, identified by the email address of the Anamnesix account.
  • Processor: Lava Labs SRL, [TODO: registered office], [TODO: registration number], [TODO: contact email].

Categories of data subjects

  • Patients of the Controller.
  • The Controller, as user of the app, for account data processed by the Processor as a controller under its own Privacy Policy.

Categories of personal data

  • Identification data of patients: name, date of birth, sex, phone number, patient number.
  • Data concerning health, a special category under Article 9 GDPR: obstetric and gynaecological history, pregnancies and their outcomes, screening results, diagnoses with codes, allergies, surgeries, family history, lifestyle information, consultation notes, laboratory results, scanned documents and prescriptions, prescribed medication and adherence, reminders, and voice memos with their transcripts.
  • Form in which the Processor receives the data: as ciphertext for every file, thumbnail, voice memo and database backup uploaded to cloud storage, and as the recovery envelope, which is the root key wrapped under a recovery code known only to the Controller; and as plaintext audio and the resulting transcript, only for the dictation feature and only for the time needed to transcribe and deliver the memo.

Nature and purpose of the processing

  • Storage of encrypted files and encrypted database backups so the Controller can restore the patient records on a new phone.
  • Storage of the recovery envelope so the Controller can unlock the backup with the recovery code.
  • Transcription of voice memos through a transcription sub-processor, on the Controller's instruction, returning the text to the app and deleting audio and transcript at the sub-processor once the app confirms receipt.
  • Metering of storage and transcription usage against the Controller's plan, which uses counters and identifiers, never patient content.

Duration

  • For the duration of the Controller's account.
  • Encrypted files and backups: the newest seven backups are kept; after a subscription lapses, files remain readable for 90 days and are then deleted.
  • Transcription: audio and transcript are deleted at the sub-processor when the app acknowledges receipt, or by a reconciliation job within a day if the acknowledgement never arrives. Identifiers of transcription sessions are scrubbed 30 days after settlement.

Annex II: Technical and organisational measures

The technical and organisational measures are described in the document Technical and Organisational Measures, available in the app under Settings, Legal, and at https://anamnesix.com/toms. That document, in the version current at the time of acceptance and as updated under Clause 6.6, forms Annex II.

Annex III: List of sub-processors

The sub-processors authorised by the Controller are listed in the document Sub-processors, available in the app under Settings, Legal, and at https://anamnesix.com/sub-processors. That document, as updated under the notice process in Clause 6.7, forms Annex III.

Governing law and jurisdiction

This Agreement is governed by Romanian law. Disputes are brought before the courts of the Processor's registered office, without prejudice to the rights of data subjects and to the competence of supervisory authorities.