Data Processing Agreement

Article 28 GDPR terms governing TP53 S.r.l.'s processing of patient data on your behalf.

Last updated: 9 September 2026

1. Roles and subject matter

This DPA forms an integral part of the agreement between the Customer (the "Data Controller") and TP53 S.r.l. (the "Data Processor") and governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the use of Scriva.

The Customer, as Data Controller, determines the purposes and means of the processing. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers, unless required to do so by applicable law.

2. Nature and purpose of processing

The processing consists of the real-time capture and processing of the audio stream of the clinical consultation, its automatic transcription on European infrastructure, the generation of draft clinical notes following pseudonymisation of identifying data, and the storage and making available of the outputs through the Service according to the periods chosen by the Controller.

Categories of data subjects

  • Patients of the Customer
  • Healthcare professionals and staff of the Customer

Categories of personal data

  • Identification and contact data
  • Real-time processed audio stream and related transcriptions
  • Health data and other special categories of data (Art. 9 GDPR)

3. Duration

The processing lasts for the entire duration of the agreement. Upon termination, the Processor will delete or return the personal data in accordance with the section on data return and deletion.

4. Obligations of the Processor

  • Process personal data only on documented instructions from the Controller.
  • Ensure that persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Art. 32 GDPR).
  • Assist the Controller in responding to data subjects' requests and in ensuring compliance with Articles 32–36 GDPR.
  • Make available all information necessary to demonstrate compliance and allow for audits.

5. Sub-processors

The Controller authorizes the Processor to engage sub-processors (e.g. cloud hosting and infrastructure providers). The Processor imposes on each sub-processor data protection obligations equivalent to those set out in this DPA and remains fully liable for their performance.

The sub-processors currently engaged, together with their purpose and server location, are the following:

ProviderPurposeServer location
Vercel Inc.Application hosting and computeFrankfurt, EU
Neon Inc.PostgreSQL database, primary storageFrankfurt, EU
Cloudflare Inc.Encrypted database backupsWestern Europe, EU
Deepgram Inc.Real-time voice transcription; no audio retained, not used for trainingEuropean Union
Anthropic PBCGeneration of clinical note drafts; no data used for trainingUnited States
Resend Inc.Transactional emailUnited States
Twilio Inc.SMS for reminders and OTP codesUnited States

The Processor will notify the Controller at least thirty (30) days before adding or replacing a sub-processor, giving the Controller the opportunity to object.

6. International transfers

The primary storage and processing infrastructure is located in the European Union.

One component of the Service involves a transfer of personal data to the United States: the generation of draft clinical notes. Such transfers take place on the basis of the Standard Contractual Clauses adopted with Implementing Decision (EU) 2021/914, incorporated into the agreements entered into with the respective providers.

By accepting this DPA, the Controller authorises such transfers as documented instructions within the meaning of section 1.

7. Security measures

  • Encryption of data in transit and at rest
  • Access controls based on roles and least privilege
  • Pseudonymisation of the patient's identifying data before transmission to the AI provider, with the mapping generated in memory and deleted at the end of the request
  • Regular backups and business continuity procedures

8. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, providing the information necessary to enable the Controller to comply with its obligations under Articles 33 and 34 GDPR.

9. Return and deletion of data

Upon termination of the Service, the Processor will, at the Controller's choice, return or delete all personal data and existing copies, unless retention is required by applicable law.

10. Contact

For matters relating to this DPA: TP53 S.r.l., Via Pomposa 153, 44123 Ferrara (FE), Italia. Privacy: privacy@tp53health.com.