← Tilbage til appen← Back to the app

Databehandleraftale (DPA)

Data Processing Agreement, artikel 28 i forordning (EU) 2016/679 · Version 1.0 for Danmark, oktober 2026

Kort fortalt: Når du opretter en klinik i Medenda, er du (klinikken) dataansvarlig for dine patienters oplysninger, og Medenda er databehandler, der udelukkende behandler dem efter din instruks. Ved at acceptere denne aftale, når klinikken oprettes, indgår du aftalen.

Parter

A. Dataansvarlig («Klinikken»): den klinik eller behandler, der opretter en konto og registrerer oplysningerne. Klinikkens identitet fremgår af tilmeldingen og faktureringsoplysningerne (herunder CVR-nummer).

B. Databehandler («Leverandøren»): NORTH DIGITAL LABS MONOPROSOPI I.K.E., reg.nr. (G.E.MI.) 194336303000, Leoforos Kifisias 265, 145 61 Kifisia, Grækenland, e-mail: privacy@medenda.ai.

Aftalen supplerer aftalen om levering af kliniksoftwaren «Medenda» («Tjenesten»), jf. Brugsvilkårene.

1. Genstand, varighed, karakter og formål

Leverandøren behandler personoplysninger på Klinikkens vegne udelukkende som led i leveringen af Tjenesten: hosting, lagring, organisering og tilgængeliggørelse af de oplysninger, Klinikken registrerer (aftaler, patientkartotek, betalinger og kommunikation), samt drift af AI-receptionisten Menda, der besvarer Klinikkens telefon, booker aftaler, tager imod beskeder og sender SMS-påmindelser. Behandlingen varer, så længe aftalen om Tjenesten løber.

2. Kategorier af oplysninger og registrerede

RegistreredeKategorier af oplysninger
Klinikkens patienter og personer, der ringer til KlinikkenIdentifikations- og kontaktoplysninger (navn, telefon, e-mail, fødselsdato), aftaleoplysninger, økonomiske oplysninger (betalinger), klinikkens noter, der kan indeholde helbredsoplysninger (særlig kategori, GDPR artikel 9), skriftlige transskriptioner og resuméer af telefonopkald (ingen lydoptagelser).
Klinikkens personaleBrugerkontooplysninger (navn, e-mail, rolle, login-tidspunkter).

3. Leverandørens forpligtelser

Leverandøren:

4. Underdatabehandlere

Klinikken giver en generel skriftlig godkendelse til brug af underdatabehandlere. Leverandøren underretter Klinikken om enhver påtænkt tilføjelse eller udskiftning, så Klinikken kan gøre indsigelse inden 15 dage. Ved aftalens indgåelse anvendes følgende underdatabehandlere:

UnderdatabehandlerYdelseDataplacering
Supabase Inc.Database og brugerloginEU, Frankfurt (AWS eu-central-1)
Vercel Inc.Hosting af appens hjemmeside (statisk indhold, gemmer ikke patientdata)Globalt CDN
ElevenLabs Inc.AI-receptionisten Menda: talegenkendelse, talesyntese og samtalestyring. ElevenLabs anvender sprogmodeller fra OpenAI til at forstå og formulere svar.USA (med EU-standardkontraktbestemmelser, SCC)
Zadarma Ltd.Telefoni (Mendas danske telefonnumre) og afsendelse af SMS-påmindelserEU
Viva.com (Viva Payments)Behandling af abonnementsbetalingerEU
Elorus (Bekraft I.K.E.)Udstedelse af fakturaerEU (Grækenland)
Google LLC (Google Calendar API)Valgfri tovejs-synkronisering af aftaler med klinikkens Google KalenderUSA / Googles globale infrastruktur (SCC)

Leverandøren pålægger underdatabehandlerne de samme databeskyttelsesforpligtelser som i denne aftale ved kontrakt eller andet retligt dokument.

5. Overførsler til tredjelande

Oplysningerne lagres udelukkende i EU. Undtagelsesvis overføres samtaledata i realtid til ElevenLabs Inc. (USA) for at drive AI-receptionisten, og til Google LLC (USA), hvis Klinikken vælger at forbinde Google Kalender. Disse overførsler er dækket af EU-Kommissionens standardkontraktbestemmelser (SCC) efter GDPR kapitel V. Enhver anden overførsel til et tredjeland sker kun med passende garantier efter GDPR kapitel V og efter underretning af Klinikken.

6. Brud på persondatasikkerheden

Leverandøren underretter Klinikken uden ugrundet ophold og senest 48 timer efter at være blevet bekendt med et brud på persondatasikkerheden, med alle tilgængelige oplysninger (bruddets karakter, kategorier og antal registrerede, sandsynlige konsekvenser, trufne foranstaltninger), så Klinikken kan opfylde sine forpligtelser efter GDPR artikel 33-34.

7. Ansvar og øvrige vilkår

Hver part er ansvarlig efter GDPR artikel 82. Denne aftale har forrang for modstridende vilkår i hovedaftalen, for så vidt angår behandling af personoplysninger. Aftalen er underlagt græsk ret med værneting ved domstolene på Leverandørens hjemsted; ufravigelige regler i GDPR og dansk databeskyttelsesret berøres ikke.

Bilag A: Tekniske og organisatoriske sikkerhedsforanstaltninger

Den danske version er en oversættelse; i tilfælde af uoverensstemmelse har den engelske version forrang. Spørgsmål om aftalen: privacy@medenda.ai · NORTH DIGITAL LABS MONOPROSOPI I.K.E.

Brugsvilkår · Privatlivspolitik

Data Processing Agreement (DPA)

Article 28 of Regulation (EU) 2016/679 · Version 1.0 for Denmark, October 2026

In short: when you create a clinic in Medenda, you (the clinic) are the controller of your patients' data and Medenda is the processor, handling it strictly on your instructions. By accepting this agreement when creating the clinic, you enter into it.

Parties

A. Controller (the «Clinic»): the clinic or practitioner that creates an account and enters the data. The Clinic's identity follows from the sign-up and billing details (including CVR number).

B. Processor (the «Provider»): NORTH DIGITAL LABS MONOPROSOPI I.K.E., reg. no. (G.E.MI.) 194336303000, Leoforos Kifisias 265, 145 61 Kifisia, Greece, e-mail: privacy@medenda.ai.

This agreement supplements the agreement for the provision of the «Medenda» clinic software (the «Service»), see the Terms of Service.

1. Subject matter, duration, nature and purpose

The Provider processes personal data on behalf of the Clinic solely in the course of providing the Service: hosting, storing, organising and making available the data the Clinic enters (appointments, patient records, payments and communication), and operating the Menda AI receptionist that answers the Clinic's phone, books appointments, takes messages and sends SMS reminders. Processing lasts for the duration of the Service agreement.

2. Categories of data and data subjects

Data subjectsCategories of data
The Clinic's patients and people calling the ClinicIdentification and contact details (name, phone, e-mail, date of birth), appointment data, financial data (payments), clinic notes which may contain health data (special category, GDPR Article 9), written transcripts and summaries of phone calls (no audio recordings).
The Clinic's staffUser account details (name, e-mail, role, login times).

3. Obligations of the Provider

The Provider:

4. Sub-processors

The Clinic gives general written authorisation for the engagement of sub-processors. The Provider informs the Clinic of any intended addition or replacement, giving the Clinic the opportunity to object within 15 days. At the time of this agreement the sub-processors are:

Sub-processorServiceData location
Supabase Inc.Database and user authenticationEU, Frankfurt (AWS eu-central-1)
Vercel Inc.Hosting of the app's website (static content, stores no patient data)Global CDN
ElevenLabs Inc.The Menda AI receptionist: speech recognition, speech synthesis and conversation handling. ElevenLabs uses OpenAI language models to understand and formulate replies.USA (with EU Standard Contractual Clauses, SCCs)
Zadarma Ltd.Telephony (Menda's Danish phone numbers) and sending of SMS remindersEU
Viva.com (Viva Payments)Processing of subscription paymentsEU
Elorus (Bekraft I.K.E.)Issuing of invoicesEU (Greece)
Google LLC (Google Calendar API)Optional two-way sync of appointments with the clinic's Google CalendarUSA / Google's global infrastructure (SCCs)

The Provider imposes on sub-processors the same data protection obligations as set out in this agreement, by contract or other legal act.

5. Transfers outside the EEA

Data is stored exclusively in the EU. By exception, conversation data is transmitted in real time to ElevenLabs Inc. (USA) to operate the AI receptionist, and to Google LLC (USA) if the Clinic chooses to connect Google Calendar. These transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) under Chapter V of the GDPR. Any other transfer to a third country takes place only with appropriate safeguards under Chapter V of the GDPR and after informing the Clinic.

6. Personal data breaches

The Provider notifies the Clinic without undue delay and at the latest within 48 hours of becoming aware of a personal data breach, providing all available information (nature of the breach, categories and number of data subjects, likely consequences, measures taken), so the Clinic can meet its obligations under GDPR Articles 33-34.

7. Liability and other terms

Each party is liable as set out in GDPR Article 82. This agreement prevails over any conflicting term of the main agreement as regards the processing of personal data. It is governed by Greek law with jurisdiction of the courts at the Provider's registered office; mandatory provisions of the GDPR and Danish data protection law are not affected.

Annex A: Technical and organisational security measures

The Danish version is a translation; in case of discrepancy the English version prevails. Questions about this agreement: privacy@medenda.ai · NORTH DIGITAL LABS MONOPROSOPI I.K.E.

Terms of Service · Privacy Policy