Data Processing Agreement
AI4MEDIMAGING, SA
AI4CMR — Data Processing Agreement
Global Edition — incorporating GDPR (EU) requirements and a HIPAA Business Associate Addendum (US)
Version 1.1 · September 2026
This document forms an integral part of the AI4CMR Terms of Use (v1.2 or later). In case of conflict regarding the processing of personal data, this Data Processing Agreement prevails. Version 1.1 supersedes version 1.0 (July 2026).
1. Scope, Parties and Order of Precedence
1.1 This Data Processing Agreement (“DPA”) governs the processing of personal data by AI4MEDIMAGING, SA, a company incorporated under the laws of Portugal (“AI4MEDIMAGING”, the “Processor”), in the course of providing the AI4CMR cloud service (the “Service”) to the customer that has accepted the AI4CMR Terms of Use (the “Customer”, the “Controller”). This DPA is incorporated by reference into, and forms an integral part of, the AI4CMR Terms of Use (the “Terms”).
1.2 The Service is a Software as a Medical Device (SaMD) delivered exclusively as a cloud service, through which qualified healthcare professionals, acting on their own initiative, upload Cardiac Magnetic Resonance (CMR) studies for automated quantitative analysis. The full-cloud nature of the Service is an essential characteristic of its design: no on-premise deployment, local processing or alternative processing arrangement is offered or available.
1.3 Where the Customer is an institution, this DPA is entered into by the individual user on behalf of that institution, and the individual user warrants having authority to bind it. Where the Customer is an individual healthcare professional processing patient data under the responsibility of an institution, the Customer warrants that it is authorised by that institution to engage the Service and that all Controller obligations under this DPA are duly discharged by the Customer, the institution, or both.
1.4 Order of precedence: (i) the mandatory provisions of applicable data protection law, including any Standard Contractual Clauses incorporated under Section 11; (ii) this DPA; (iii) the Terms; (iv) any other document. This DPA supersedes Section 5 of the Terms of Use v1.0 in its entirety with respect to the subject matter of data protection.
1.5 This DPA is drafted as a single global instrument. Region-specific provisions (including the HIPAA Business Associate Addendum in Annex 5) apply only where and to the extent the corresponding law applies to the processing at hand. Nothing in this DPA shall be construed as a voluntary submission by AI4MEDIMAGING to any law, regulator or jurisdiction that does not mandatorily apply to it.
1.6 Application to Access Plans. This DPA applies to Study Data uploaded under any Access Plan that allows the Customer to upload studies, namely the Physician Packs (1, 10, 50 and 100), as defined in Section 3 of the Terms. Under the free Trial the Customer cannot upload, import or otherwise introduce any study or patient data into the Service; the Trial gives access exclusively to fictitious demonstration studies pre-installed by AI4MEDIMAGING solely for testing and demonstrating the features of the Service (“Demonstration Studies”), which do not correspond to any real patient or real clinical examination and do not constitute Study Data or personal data of the Customer’s patients. Accordingly, no controller-processor (or covered entity-business associate) relationship arises under a Trial, and Sections 3 to 14 of this DPA do not apply to it, except that: (i) Account Data of the Trial user is processed as described in Section 2.3; and (ii) should a Trial user, in breach of the Terms, succeed in introducing any personal data into the Service, AI4MEDIMAGING may delete such data immediately and without notice, the Customer remains solely responsible for it as Controller, and Sections 4.3 and 15 apply.
2. Definitions
2.1 “Data Protection Law” means all laws applicable to the processing of personal data under this DPA, including, as applicable: Regulation (EU) 2016/679 (“GDPR”); the UK GDPR and the UK Data Protection Act 2018; the Swiss FADP; the Brazilian Lei Geral de Proteção de Dados (Law 13.709/2018, “LGPD”); the US Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164 (“HIPAA”); and any other national or state law applicable to the Customer’s use of the Service.
2.2 “Study Data” means the CMR studies (DICOM images and associated metadata) uploaded to the Service by or on behalf of the Customer, together with the analysis results and reports generated by the Service from such studies. Study Data may contain personal data and special-category / protected health information of patients.
2.3 “Account Data” means data relating to the Customer and its authorised users (identification, professional and contact details, credentials, billing and usage records). Account Data is processed by AI4MEDIMAGING as an independent controller for the purposes of account administration, billing, security and legal compliance, and is not subject to the processor obligations of this DPA.
2.4 “Processing Region” means one of the geographic regions listed in Annex 4 in which AI4MEDIMAGING makes the Service available, each corresponding to Microsoft Azure cloud infrastructure located in that region.
2.5 The terms “controller”, “processor”, “data subject”, “personal data”, “personal data breach” and “processing” have the meanings given in the GDPR; the terms “covered entity”, “business associate”, “protected health information” (“PHI”) and “security incident” have the meanings given in HIPAA. Equivalent terms under other Data Protection Law (e.g. “operador” and “controlador” under the LGPD) shall be read accordingly.
3. Roles of the Parties
3.1 For all Study Data, the Customer (and/or the institution on whose behalf the Customer acts) is the Controller and AI4MEDIMAGING is the Processor. Under the LGPD, AI4MEDIMAGING acts as operador and the Customer as controlador. Under HIPAA, where the Customer is a covered entity or a business associate, AI4MEDIMAGING acts as a business associate (or subcontractor business associate) and the Business Associate Addendum in Annex 5 applies.
3.2 AI4MEDIMAGING has no direct relationship with the patients whose data are contained in Study Data, does not select or determine which studies are uploaded, and exercises no control over the purposes for which the Customer uses the Service. All uploads occur exclusively on the Customer’s own initiative.
3.3 AI4MEDIMAGING is under no obligation to monitor, review or verify the content or lawfulness of Study Data, and assumes no responsibility for it. Any processing operation performed by the Service is a strictly technical, automated operation applied identically to all studies.
4. Customer Obligations and Warranties
4.1 The Customer is solely responsible for the lawfulness of the Study Data and of the instructions it gives to AI4MEDIMAGING. In particular, the Customer represents and warrants, on a continuing basis, that:
- it has established a valid lawful basis under applicable Data Protection Law (including, where required, Article 9(2) GDPR or equivalent) for the processing of patient data through the Service, and has provided all required notices to, and obtained all required consents or authorisations from, data subjects, institutions, ethics committees and authorities;
- it will only upload studies that it is legally entitled to process through a third-party cloud service, and will not upload data of patients in respect of whom it has received an objection, restriction or withdrawal of consent effective against such processing;
- it will comply with any minimum-necessary, professional secrecy and medical records obligations applicable to it;
- it will only use the Service for clinical purposes in territories where AI4CMR holds active regulatory certification, in accordance with the Terms;
- the Processing Region assigned to its account under Section 10 is consistent with any data-residency obligations applicable to the Customer, and the Customer will notify AI4MEDIMAGING before uploading data subject to residency requirements that the assigned Processing Region cannot satisfy;
- it will maintain its own records, copies and backups of all source studies, and will download or export any analysis results and reports it wishes to retain before their automatic deletion under Section 9, being aware that the thirty (30) day retention runs per study from upload and is not extended by the validity of the Access Plan;
- it will not upload, or attempt to upload, any study or patient data under a Trial account, and will not use results generated from Demonstration Studies in the care of any patient.
4.2 This DPA, the Terms and the Service documentation constitute the Customer’s complete and final documented instructions to AI4MEDIMAGING. Additional or alternative instructions require prior written agreement of both parties and may be subject to additional fees. AI4MEDIMAGING may refuse instructions that it considers technically unfeasible, incompatible with the design of the Service, or unlawful.
4.3 The Customer shall defend, indemnify and hold harmless AI4MEDIMAGING from and against any claims, fines, penalties, damages and reasonable costs (including legal fees) arising from (i) the Customer’s breach of this DPA or of its obligations as Controller under Data Protection Law, (ii) the unlawfulness of Study Data or of the Customer’s instructions, or (iii) use of the Service in territories or for purposes not permitted by the Terms.
5. Processor Obligations
5.1 AI4MEDIMAGING shall:
- process Study Data only on the documented instructions of the Customer as defined in Section 4.2, including with regard to international transfers, unless required to do otherwise by European Union or Member State law to which AI4MEDIMAGING is subject, in which case it shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest;
- ensure that persons authorised to process Study Data are bound by contractual or statutory obligations of confidentiality;
- implement the technical and organisational measures described in Annex 2, in accordance with Article 32 GDPR and, where applicable, the HIPAA Security Rule;
- respect the conditions of Sections 8 (sub-processors) and 11 (international transfers);
- taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to data subject requests, as set out in Section 12;
- assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to AI4MEDIMAGING;
- delete Study Data in accordance with the retention and deletion regime of Section 9, which the parties agree satisfies the deletion obligation of Article 28(3)(g) GDPR;
- make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits under the conditions of Section 14.
5.2 AI4MEDIMAGING shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable Data Protection Law. AI4MEDIMAGING is not obliged to perform a legal review of the Customer’s instructions, and such information duty does not constitute legal advice nor shift any Controller responsibility to AI4MEDIMAGING.
6. Purpose Limitation — No Secondary Use, No Anonymisation
6.1 AI4MEDIMAGING processes Study Data exclusively to provide the Service to the Customer: receipt of uploaded studies, automated analysis, generation of results and reports, making the results available in the Customer’s account, and related technical support and security operations.
6.2 AI4MEDIMAGING does not retain Study Data for its own purposes, does not use Study Data to train, develop or improve algorithms or artificial intelligence models, does not sell or share Study Data, and does not create anonymised, pseudonymised, de-identified or aggregated datasets from Study Data. Study Data exists in the Service solely within the Customer’s account, for the Customer’s own use, in its original (non-anonymised) form as uploaded and as analysed, and is automatically deleted under Section 9.
6.3 Any future programme involving secondary use of data (e.g. research collaborations) would be subject to a separate written agreement and appropriate legal bases, and is expressly outside the scope of this DPA and of the Service.
7. Confidentiality
7.1 AI4MEDIMAGING shall treat all Study Data as strictly confidential. Access by AI4MEDIMAGING personnel is limited to what is strictly necessary for service operation, support and security, is role-based, logged, and subject to confidentiality undertakings. AI4MEDIMAGING support staff access the content of a Customer’s Study Data only in connection with a support request or incident affecting that Customer.
8. Sub-processors
8.1 The Customer grants AI4MEDIMAGING a general written authorisation to engage the sub-processors listed in Annex 3 and to replace or add sub-processors, provided that AI4MEDIMAGING (i) imposes on each sub-processor data protection obligations materially equivalent to those of this DPA, and (ii) remains liable to the Customer for the performance of the sub-processor’s obligations.
8.2 AI4MEDIMAGING shall give the Customer at least fifteen (15) days’ prior notice of any intended addition or replacement of a sub-processor that processes Study Data (notice may be given by e-mail or through the Service). The Customer may object in writing on reasonable, documented data protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer’s sole and exclusive remedy is to terminate the affected subscription and cease uploading studies; fees already paid for consumed credits or elapsed periods are not refundable.
8.3 For clarity, providers that process only Account Data (e.g. billing, invoicing, CRM providers) are not sub-processors of Study Data and are outside the scope of this Section.
9. Storage, Retention and Automatic Deletion (30 Days per Study)
9.1 The Service operates a fixed, non-configurable retention cycle, which is an integral design feature of the Service and of its cloud infrastructure management: each study and the analysis results generated from it are retained in the Customer’s account for thirty (30) days counted from the moment of upload of that study, and are then automatically, permanently and irreversibly deleted from production systems. The retention period runs per study and is not affected by any subsequent processing, editing or consultation of that study, nor by the purchase of additional credits. Residual copies in encrypted backups, where they exist, are overwritten in accordance with the backup rotation described in Annex 2 and are in any event deleted no later than thirty (30) additional days after the production deletion, and are not accessible for restoration of individual studies.
9.2 Study Data is stored in its original form as uploaded by the Customer. AI4MEDIMAGING does not anonymise or otherwise modify the content of Study Data, because the data exists solely for the Customer’s clinical use during the retention window, and any alteration would compromise its clinical integrity and the traceability of the analysis to the source study.
9.3 The Customer acknowledges and agrees that: (i) the 30-day automatic deletion constitutes a standing documented instruction from the Customer to delete; (ii) it is the Customer’s sole responsibility to download and preserve, within the retention window, any studies, results and reports required for the patient’s medical record or by applicable medical records retention law — the Service is not a medical archive, a PACS, nor a system of record; and (iii) after deletion, AI4MEDIMAGING has no technical ability to recover Study Data and shall have no liability whatsoever for any inability of the Customer to access Study Data after its scheduled deletion.
9.4 Retention is independent of the Access Plan validity. The validity period of an Access Plan (for example, twelve (12) months for Physician Packs 10, 50 and 100, or one (1) month for Physician Pack 1) determines only the period during which the Customer may submit studies and consume credits. It does not extend, and shall not be construed as extending, the retention of any study beyond thirty (30) days from its upload. A study uploaded on the first day of a twelve-month Pack is therefore deleted thirty (30) days after upload, even though the Pack remains valid for the remaining eleven (11) months.
9.5 Trial. Because the Customer cannot upload studies under a Trial (Section 1.6), the retention and deletion regime of this Section 9 does not apply to the Trial. The Demonstration Studies remain available for the duration of the Trial period only. At the end of the Trial period (seven (7) days from activation, unless earlier terminated) the Trial account is deactivated and all its contents, including any results, edits or annotations made by the Trial user, are permanently deleted by AI4MEDIMAGING.
9.6 The regime in this Section 9 satisfies the return-or-deletion obligations of Article 28(3)(g) GDPR and of 45 CFR 164.504(e)(2)(ii)(J) upon termination: upon expiry of the last valid Pack or termination of the Access Plan, any Study Data still within its retention window remains accessible to the Customer for consultation and export until its scheduled deletion and is then deleted through the same cycle, at the latest thirty (30) days after the last upload, without the need for any additional request; where access is terminated for breach of the Terms, AI4MEDIMAGING may delete all Study Data immediately. A written confirmation of deletion may be requested by the Customer within sixty (60) days of termination.
10. Regional Processing and Data Residency
10.1 The Service is delivered exclusively from Microsoft Azure cloud infrastructure. AI4MEDIMAGING makes the Service available only in the Processing Regions listed in Annex 4, corresponding to geographic areas where suitable Azure infrastructure is available. Processing Regions are defined at the level of world regions (e.g. Europe, North America, South America, Asia-Pacific), not at the level of individual countries.
10.2 Each Customer account is assigned to a single Processing Region, determined by AI4MEDIMAGING on the basis of the Customer’s declared country at registration. Study Data uploaded by the Customer is stored and processed at rest exclusively within the assigned Processing Region. Study Data is not transferred to, or stored in, another Processing Region, except in the transient, security-related or support-related circumstances described in Sections 10.4 and 11.
10.3 The availability of the Service in any given territory is strictly conditional on the availability of Azure infrastructure in a Processing Region serving that territory, in addition to the regulatory certification conditions set out in the Terms. AI4MEDIMAGING may, at its sole discretion and with thirty (30) days’ notice where reasonably practicable, add, modify, migrate (within the same world region) or withdraw Processing Regions, including where Microsoft modifies or discontinues the underlying Azure regions. If a Processing Region is withdrawn and no alternative within the same world region is available, the affected subscriptions may be terminated with a pro-rata refund of unused prepaid amounts as the Customer’s sole remedy.
10.4 Remote access for platform administration, deployment, support and security monitoring may be performed by AI4MEDIMAGING personnel located in Portugal (and, where applicable, other EU locations), under the safeguards of Annex 2. Such access does not alter the storage location of Study Data. Where such access constitutes an international transfer under applicable law, Section 11 applies.
10.5 The parties acknowledge that a world-region residency model necessarily means that data may be stored in a country of the region other than the Customer’s own country (e.g. a South American Customer’s data stored in the Brazil Azure region). The Customer is responsible for confirming, before use, that this model satisfies any residency rules applicable to it (Section 4.1).
11. International Data Transfers
11.1 Transfers of Study Data subject to the GDPR outside the EU/EEA (including remote access from outside the EU/EEA, where applicable) shall occur only under a valid transfer mechanism: an adequacy decision of the European Commission; the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“SCCs”); or another mechanism valid under Chapter V GDPR. Where SCCs are required between the Customer and AI4MEDIMAGING, Module Two (controller-to-processor) is hereby incorporated by reference, completed as set out in Annex 1 (Annexes I and II of the SCCs) with the optional docking clause included, the option in Clause 9(a) set to general written authorisation with 15 days’ notice, Portuguese law as governing law under Clause 17, and the courts of Portugal under Clause 18. In case of conflict, the SCCs prevail over this DPA.
11.2 For transfers subject to the UK GDPR, the SCCs as incorporated above apply as amended by the UK International Data Transfer Addendum issued by the UK Information Commissioner. For transfers subject to the Swiss FADP, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner. For transfers subject to the LGPD or other Data Protection Law, the parties shall rely on the mechanisms recognised by such law, and the SCCs shall serve as contractual safeguards mutatis mutandis to the extent permitted.
11.3 AI4MEDIMAGING shall not be deemed in breach of this Section by reason of processing carried out by Microsoft as hosting sub-processor within the Processing Region assigned to the Customer, provided the corresponding transfer safeguards in AI4MEDIMAGING’s agreement with Microsoft are in place.
12. Assistance and Data Subject Rights
12.1 Given the nature of the Service (short retention, data accessible to the Customer in its own account), the Customer is normally able to satisfy data subject requests directly, by consulting, exporting or deleting studies from its account. AI4MEDIMAGING shall provide reasonable additional assistance where the Customer cannot satisfy a request through the Service itself.
12.2 If AI4MEDIMAGING receives a request or complaint directly from a data subject, or an enquiry from a supervisory authority, concerning Study Data, it shall (to the extent legally permitted) redirect the requester to the Customer without responding on the merits, and notify the Customer. AI4MEDIMAGING does not hold the information necessary to identify or authenticate patients and assumes no obligation to respond to data subjects on the Controller’s behalf.
12.3 Assistance under this Section and under Section 5.1 that is disproportionate, repetitive, or arises from the Customer’s own non-compliance may be charged at AI4MEDIMAGING’s then-current professional services rates. AI4MEDIMAGING may provide standard documentation (including this DPA and Annex 2) in satisfaction of DPIA-assistance requests, unless specific additional information is strictly necessary and available.
13. Personal Data Breach
13.1 AI4MEDIMAGING shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting the Customer’s Study Data, providing the information reasonably available at the time (nature of the breach, categories and approximate numbers concerned, likely consequences, measures taken or proposed), supplemented as further information becomes available.
13.2 As between the parties, the Customer, as Controller, is solely responsible for assessing the breach’s risk, and for deciding on and making any notifications to supervisory authorities and communications to data subjects required by Data Protection Law. AI4MEDIMAGING shall provide reasonable cooperation. AI4MEDIMAGING shall not notify authorities or data subjects on the Customer’s behalf unless required by law applicable to AI4MEDIMAGING itself.
13.3 A notification under this Section, and any remedial action taken, shall not be construed as an acknowledgement by AI4MEDIMAGING of any fault, defect or liability. Unsuccessful security events that do not compromise Study Data (e.g. blocked attacks, port scans, failed login attempts) do not require notification.
14. Audits
14.1 AI4MEDIMAGING shall demonstrate compliance with this DPA primarily by making available relevant documentation: this DPA, Annex 2, third-party certifications and audit reports covering the Service or its hosting infrastructure (including Microsoft Azure compliance documentation), and written responses to reasonable security questionnaires. The Customer agrees to accept such documentation in satisfaction of its audit rights wherever it reasonably addresses the matter in question.
14.2 Where an audit beyond Section 14.1 is required by mandatory Data Protection Law or by a supervisory authority, the Customer (or an independent auditor bound by confidentiality and not a competitor of AI4MEDIMAGING) may audit AI4MEDIMAGING’s compliance with this DPA, subject to: (i) at least thirty (30) days’ written notice; (ii) a maximum of one audit in any 12-month period, save in case of a confirmed personal data breach affecting the Customer; (iii) execution during business hours, without disrupting operations, and in compliance with AI4MEDIMAGING’s security policies; (iv) no access to data of other customers, to systems not used to process Study Data, or to AI4MEDIMAGING’s proprietary algorithms and source code; and (v) the Customer bearing all costs of the audit, including AI4MEDIMAGING’s reasonable internal costs of supporting it. Physical access to data centres operated by Microsoft is excluded; the corresponding controls are evidenced through Microsoft’s own certifications and audit reports.
15. Liability
15.1 Each party’s liability arising out of or related to this DPA (including the SCCs, to the maximum extent they permit) is subject to the exclusions and limitations of liability set out in the Terms, and the aggregate liability cap in the Terms applies jointly to claims under the Terms and this DPA taken together. In no event shall AI4MEDIMAGING be liable for indirect or consequential damages, loss of profits, or loss of data resulting from the automatic deletion regime of Section 9 or from the Customer’s failure to export data within the retention window.
15.2 Nothing in this Section limits liability that cannot be limited under mandatory applicable law, nor data subjects’ own rights under Data Protection Law. As between the parties, each party is liable for administrative fines imposed on it in accordance with the allocation of responsibility set out in Article 82 GDPR and equivalent provisions.
16. Term, Termination and Survival
16.1 This DPA takes effect upon acceptance of the Terms and remains in force as long as AI4MEDIMAGING processes Study Data for the Customer. Termination of the Terms terminates this DPA, without prejudice to provisions that by their nature survive (Sections 1.6, 4.3, 6, 7, 9.6, 13, 15 and Annex 5 §9).
16.2 AI4MEDIMAGING may update this DPA with thirty (30) days’ notice where required by changes in Data Protection Law, regulatory guidance, sub-processor terms or the Service architecture; updates required by law may take effect immediately upon notice. Continued use of the Service after the effective date constitutes acceptance. If an update materially reduces the protections of this DPA, the Customer may terminate the affected subscription as its sole remedy.
17. Governing Law and Jurisdiction
17.1 This DPA is governed by Portuguese law, without prejudice to (i) mandatory provisions of Data Protection Law applicable to the processing, and (ii) the governing-law provisions of any SCCs or of Annex 5 where mandatorily applicable. Disputes shall be resolved as set out in the Terms.
Annex 1 — Details of Processing (Art. 28(3) GDPR / Annex I–II SCCs)
A. List of parties
Data exporter / Controller: the Customer identified in the account registration (contact details as per Account Data). Role: controller. Data importer / Processor: AI4MEDIMAGING, SA, Portugal (contact: [email protected]). Role: processor.
B. Description of processing
| Item | Description |
|---|---|
| Subject matter | Automated quantitative analysis of CMR studies through the AI4CMR cloud service. |
| Duration | Duration of the Access Plan (Physician Pack 1: 1 month; Physician Packs 10/50/100: 12 months) plus the residual 30-day retention window of the last study uploaded; each study retained max. 30 days from upload, irrespective of plan validity (Section 9). Not applicable to the Trial (no Study Data). |
| Nature and purpose | Receipt, temporary storage, automated AI analysis, generation of results/reports, availability in Customer account, technical support and security operations. No secondary use. |
| Categories of data subjects | Patients whose CMR studies are uploaded by the Customer. |
| Categories of personal data | DICOM images and metadata of CMR studies as uploaded by the Customer (may include patient identifiers such as name, date of birth, patient ID, study identifiers, technical acquisition data); analysis results and reports derived from them. |
| Special categories | Data concerning health (Art. 9 GDPR / PHI under HIPAA). Restrictions applied: purpose limitation (Section 6), 30-day deletion (Section 9), TOMs (Annex 2), regional storage (Section 10). |
| Frequency | Continuous, at the Customer’s initiative (per upload). |
| Retention | 30 days from upload of each study, independent of the remaining validity of the Access Plan, then automatic irreversible deletion; backups purged within a further 30 days. Trial: no Study Data; Demonstration Studies and Trial account contents deleted at the end of the 7-day Trial. |
| Sub-processor transfers | Hosting by Microsoft Azure within the assigned Processing Region (Annex 3 and 4). |
C. Competent supervisory authority (SCCs)
Where the GDPR applies, the supervisory authority of the EU Member State in which the data exporter is established; otherwise as determined under Clause 13 SCCs. For Portuguese-established parties: CNPD (Comissão Nacional de Proteção de Dados).
Annex 2 — Technical and Organisational Measures
AI4MEDIMAGING implements, and requires its hosting sub-processor to implement, security measures appropriate to the risk of processing health data, including at minimum:
- Encryption in transit: TLS 1.2 or higher for all connections; encryption at rest: AES-256 (or equivalent) for all storage holding Study Data, including backups.
- Regional isolation: Study Data stored and processed exclusively within the assigned Azure Processing Region; logical tenant separation between customers.
- Access control: role-based access on a strict need-to-know basis; individual named accounts; multi-factor authentication for administrative access; privileged access logged and reviewed; support access to Study Data content only upon a Customer request or incident.
- Automatic deletion: enforced 30-day retention cycle with automated, monitored deletion jobs; deletion propagated to backups within the backup rotation cycle (max. 30 additional days).
- Network security: segregation of environments (production/non-production), firewalls, hardening, vulnerability management and periodic penetration testing.
- Operations security: logging and monitoring of security events; capacity and availability management on Azure infrastructure; documented incident response procedure supporting the 72-hour notification commitment.
- Personnel: confidentiality undertakings; data protection and security training; disciplinary consequences for violations.
- Organisation: information security management aligned with the requirements applicable to a globally certified SaMD manufacturer (including ISO 13485 quality system and applicable cybersecurity guidance for medical devices); appointed Data Protection Officer contactable at [email protected].
- Physical security of data centres: assured by Microsoft Azure and evidenced by Microsoft’s certifications (including ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, HITRUST) available through the Microsoft Trust Center.
- Resilience: infrastructure redundancy within the Processing Region; restoration procedures tested periodically. Note: the Service is not a backup or archival service for the Customer (Section 9.3).
AI4MEDIMAGING may update these measures provided the overall level of security is not materially reduced.
Annex 3 — Authorised Sub-processors (Study Data)
| Sub-processor | Role | Location of processing |
|---|---|---|
| Microsoft Corporation / Microsoft Ireland Operations Ltd (Microsoft Azure) | Cloud hosting and infrastructure services for the Service | Azure region(s) within the Processing Region assigned to the Customer (Annex 4) |
Providers processing only Account Data (e.g. payment, invoicing and CRM providers) are independent-service providers outside the scope of this DPA (Section 8.3). The current list of sub-processors is available from AI4MEDIMAGING on request and updates are notified under Section 8.2.
Annex 4 — Processing Regions
The Service is available only in the following Processing Regions, subject to availability of Microsoft Azure infrastructure and to the regulatory conditions of the Terms. Assignment is per account, based on the Customer’s declared country. AI4MEDIMAGING may update this Annex under Section 10.3.
| Processing Region | Territories served (indicative) | Azure infrastructure (indicative) |
|---|---|---|
| Europe | EU/EEA, United Kingdom, Switzerland and other European territories | Azure EU regions (e.g. West Europe — Netherlands; North Europe — Ireland) |
| North America | United States of America and Canada | Azure US regions (e.g. East US) |
| South America | Brazil and other South American territories | Azure Brazil regions (e.g. Brazil South) |
| Asia-Pacific | Territories in Asia and Oceania where the Service is offered | Azure Asia-Pacific regions (e.g. Southeast Asia — Singapore) |
Where no Processing Region serves a territory, the Service is not offered in that territory, irrespective of regulatory certification status. The specific Azure regions used within each Processing Region are selected by AI4MEDIMAGING and may change within the same world region (Section 10.3).
Annex 5 — HIPAA Business Associate Addendum (US)
This Business Associate Addendum (“BAA”) applies only where and to the extent the Customer is a covered entity or business associate under HIPAA and Study Data includes PHI. In such case, the Customer is the “Covered Entity” (or upstream business associate) and AI4MEDIMAGING is the “Business Associate”. In case of conflict between this BAA and the rest of the DPA with respect to PHI, this BAA prevails to the extent required by HIPAA.
1. Permitted uses and disclosures
Business Associate shall use and disclose PHI only: (i) to provide the Service to Covered Entity as described in the Terms and this DPA; (ii) as required by law; and (iii) for the proper management and administration of Business Associate and to carry out its legal responsibilities, provided any disclosure for such purposes is required by law or made subject to reasonable assurances of confidentiality and breach notification from the recipient. Business Associate shall not use or disclose PHI in any manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity. Business Associate does not de-identify PHI, does not aggregate PHI across customers, and does not use PHI for research, product improvement or marketing.
2. Safeguards
Business Associate shall use appropriate administrative, physical and technical safeguards, and shall comply with Subpart C of 45 CFR Part 164 (Security Rule) with respect to electronic PHI, as implemented through the measures in Annex 2, to prevent use or disclosure of PHI other than as provided for by this BAA.
3. Reporting
Business Associate shall report to Covered Entity: (i) any use or disclosure of PHI not provided for by this BAA of which it becomes aware; (ii) any security incident of which it becomes aware, provided that this BAA constitutes notice, without further reporting, of routine unsuccessful security incidents (e.g. pings, port scans, blocked attacks); and (iii) breaches of unsecured PHI as required by 45 CFR 164.410, without unreasonable delay and in no case later than the timeline in Section 13.1 of the DPA after discovery. Covered Entity is solely responsible for notifications to individuals, the Secretary of Health and Human Services and the media under 45 CFR 164.404–164.408.
4. Subcontractors
Business Associate shall ensure, in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), that any subcontractor that creates, receives, maintains or transmits PHI on its behalf (Annex 3) agrees to restrictions and conditions at least as restrictive as those in this BAA.
5. Individual rights
Taking into account that PHI is retained for a maximum of 30 days and is directly accessible to Covered Entity in its account: (i) Business Associate shall make PHI in a designated record set available to Covered Entity as necessary to satisfy 45 CFR 164.524; (ii) shall make PHI available for amendment and incorporate amendments as directed by Covered Entity per 45 CFR 164.526, to the extent technically feasible during the retention window; and (iii) shall document and make available to Covered Entity the information required for an accounting of disclosures per 45 CFR 164.528. The parties agree the Service does not constitute the designated record set of Covered Entity, which remains in Covered Entity’s own systems (Section 9.3 of the DPA).
6. Access by HHS
Business Associate shall make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with HIPAA.
7. Minimum necessary
Business Associate shall limit uses, disclosures and requests of PHI to the minimum necessary. Covered Entity shall not agree to any restriction under 45 CFR 164.522 that affects the Service without Business Associate’s prior written consent, and represents that no such restriction currently applies.
8. Term and termination
This BAA is effective while Business Associate processes PHI for Covered Entity. Either party may terminate the Service as provided in the Terms if the other party materially breaches this BAA and fails to cure within thirty (30) days of written notice. Upon termination, PHI is destroyed through the automatic deletion regime of Section 9 of the DPA, which the parties agree satisfies 45 CFR 164.504(e)(2)(ii)(J); where retention of residual copies in backups is temporarily infeasible to avoid, the protections of this BAA continue to apply to such copies until destruction, which shall occur within the backup rotation period.
9. Survival and interpretation
The obligations of this BAA survive termination with respect to any PHI pending destruction. This BAA shall be interpreted to permit compliance with HIPAA and shall be automatically amended to the extent required by amendments to HIPAA; any ambiguity shall be resolved in favour of a meaning that complies with HIPAA. No third-party beneficiary rights are created, including for patients. Nothing in this BAA makes Business Associate an agent of Covered Entity.
Version history: v1.0 July 2026 · v1.1 September 2026 (application to Access Plans, Trial regime, retention independent of plan validity, Annex 1).
— End of Data Processing Agreement —