Data Processing Agreement
Article 28 GDPR terms governing TP53 S.r.l.'s processing of patient data on your behalf.
Last updated: 9 September 2026
1. Roles and subject matter
This DPA forms an integral part of the agreement between the Customer (the "Data Controller") and TP53 S.r.l. (the "Data Processor") and governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the use of Scriva.
The Customer, as Data Controller, determines the purposes and means of the processing. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers, unless required to do so by applicable law.
2. Nature and purpose of processing
The processing consists of the real-time capture and processing of the audio stream of the clinical consultation, its automatic transcription on European infrastructure, the generation of draft clinical notes following pseudonymisation of identifying data, and the storage and making available of the outputs through the Service according to the periods chosen by the Controller.
Categories of data subjects
- Patients of the Customer
- Healthcare professionals and staff of the Customer
Categories of personal data
- Identification and contact data
- Real-time processed audio stream and related transcriptions
- Health data and other special categories of data (Art. 9 GDPR)
3. Duration
The processing lasts for the entire duration of the agreement. Upon termination, the Processor will delete or return the personal data in accordance with the section on data return and deletion.
4. Obligations of the Processor
- Process personal data only on documented instructions from the Controller.
- Ensure that persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Art. 32 GDPR).
- Assist the Controller in responding to data subjects' requests and in ensuring compliance with Articles 32–36 GDPR.
- Make available all information necessary to demonstrate compliance and allow for audits.
5. Sub-processors
The Controller authorizes the Processor to engage sub-processors (e.g. cloud hosting and infrastructure providers). The Processor imposes on each sub-processor data protection obligations equivalent to those set out in this DPA and remains fully liable for their performance.
The sub-processors currently engaged, together with their purpose and server location, are the following:
| Provider | Purpose | Server location |
|---|---|---|
| Vercel Inc. | Application hosting and compute | Frankfurt, EU |
| Neon Inc. | PostgreSQL database, primary storage | Frankfurt, EU |
| Cloudflare Inc. | Encrypted database backups | Western Europe, EU |
| Deepgram Inc. | Real-time voice transcription; no audio retained, not used for training | European Union |
| Anthropic PBC | Generation of clinical note drafts; no data used for training | United States |
| Resend Inc. | Transactional email | United States |
| Twilio Inc. | SMS for reminders and OTP codes | United States |
The Processor will notify the Controller at least thirty (30) days before adding or replacing a sub-processor, giving the Controller the opportunity to object.
6. International transfers
The primary storage and processing infrastructure is located in the European Union.
One component of the Service involves a transfer of personal data to the United States: the generation of draft clinical notes. Such transfers take place on the basis of the Standard Contractual Clauses adopted with Implementing Decision (EU) 2021/914, incorporated into the agreements entered into with the respective providers.
By accepting this DPA, the Controller authorises such transfers as documented instructions within the meaning of section 1.
7. Security measures
- Encryption of data in transit and at rest
- Access controls based on roles and least privilege
- Pseudonymisation of the patient's identifying data before transmission to the AI provider, with the mapping generated in memory and deleted at the end of the request
- Regular backups and business continuity procedures
8. Personal data breaches
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, providing the information necessary to enable the Controller to comply with its obligations under Articles 33 and 34 GDPR.
9. Return and deletion of data
Upon termination of the Service, the Processor will, at the Controller's choice, return or delete all personal data and existing copies, unless retention is required by applicable law.
10. Contact
For matters relating to this DPA: TP53 S.r.l., Via Pomposa 153, 44123 Ferrara (FE), Italia. Privacy: privacy@tp53health.com.
