Back to home

Data Processing Agreement

This Data Processing Agreement (DPA) governs the processing of personal data carried out by Scriva on behalf of the Customer under the Terms and Conditions.

Last updated: June 2026

1. Roles and subject matter

This DPA forms an integral part of the agreement between the Customer (the "Data Controller") and TP53 S.r.l. (the "Data Processor") and governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the use of Scriva.

The Customer, as Data Controller, determines the purposes and means of the processing. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers, unless required to do so by applicable law.

2. Nature and purpose of processing

The processing consists of the recording of audio during clinical encounters, automatic transcription, generation of clinical notes and related drafts, storage and making available of the outputs through the Service.

Categories of data subjects

  • Patients of the Customer
  • Healthcare professionals and staff of the Customer

Categories of personal data

  • Identification and contact data
  • Audio recordings and transcriptions
  • Health data and other special categories of data (Art. 9 GDPR)

3. Duration

The processing lasts for the entire duration of the agreement. Upon termination, the Processor will delete or return the personal data in accordance with the section on data return and deletion.

4. Obligations of the Processor

  • Process personal data only on documented instructions from the Controller.
  • Ensure that persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Art. 32 GDPR).
  • Assist the Controller in responding to data subjects' requests and in ensuring compliance with Articles 32-36 GDPR.
  • Make available all information necessary to demonstrate compliance and allow for audits.

5. Sub-processors

The Controller authorizes the Processor to engage sub-processors (e.g. cloud hosting and infrastructure providers). The Processor imposes on each sub-processor data protection obligations equivalent to those set out in this DPA and remains fully liable for their performance.

An up-to-date list of sub-processors is available on request. The Processor will inform the Controller of any intended changes, giving the Controller the opportunity to object.

6. International transfers

Personal data is processed within the European Economic Area. Where a transfer to a third country is necessary, it will take place only on the basis of an adequacy decision or appropriate safeguards under Articles 44-49 GDPR, such as the Standard Contractual Clauses.

7. Security measures

  • Encryption of data in transit and at rest
  • Access controls based on roles and least privilege
  • Logging and monitoring of access and operations
  • Regular backups and business continuity procedures

8. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, providing the information necessary to enable the Controller to comply with its obligations under Articles 33 and 34 GDPR.

9. Return and deletion of data

Upon termination of the Service, the Processor will, at the Controller's choice, return or delete all personal data and existing copies, unless retention is required by applicable law.

10. Contact

For matters relating to this DPA: TP53 S.r.l., Via Pomposa 153, 44123 Ferrara (FE), Italia. Privacy: privacy@tp53.com.