Data Processing Agreement (DPA)
Processor obligations for clinical data: sub-processors, safeguards, audit and deletion.
Last updated:
Processor obligations for clinical data: sub-processors, safeguards, audit and deletion.
Last updated:
This agreement is entered into between the clinic or therapist using psisula (the “Controller”) and Psisula (İstanbul, Türkiye — the “Processor”) under art. 12 of Law No. 6698, and forms an integral part of the Terms of Use.
The Controller determines the purposes and means of processing its clients’ personal data. The Processor processes that data solely to provide the Service and on the Controller’s instructions.
| Subject matter | Provision of the psisula practice management software |
| Duration | The subscription term plus the deletion period in clause 8 |
| Purpose | Appointments, client records, clinical documentation, assessments and progress tracking, client portal, reminders and reporting |
| Categories of data | Identity and contact details, appointment records, session notes, treatment plans, diagnoses, assessment answers and scores, homework, portal messages, uploaded documents, fees and payment status, session transcripts |
| Data subjects | The Controller’s clients and team members |
| Special categories | Yes — health data is processed |
The Processor shall:
The Controller authorises the following sub-processors:
| Sub-processor | Service | Data received | Location |
|---|---|---|---|
| Our hosting, database and file-storage provider | Infrastructure | All data held in the system (encrypted) | EU (Alkmaar, Netherlands) |
| OpenAI | Transcription, note drafting, summaries, score readings | The relevant audio and text | USA |
| Twilio | SMS | Phone number and message text | USA |
| Resend | Email address and message text | USA | |
| Sentry | Error monitoring | Technical logs — no client data | EU (Frankfurt) |
| Zoom, Google Meet | Telehealth links | Meeting title and time (only if an account is connected) | USA |
Every sub-processor other than hosting can be switched off by disabling the corresponding feature.
We notify account holders by email at least 30 days before adding or replacing a sub-processor. If the Controller objects on reasonable grounds and the parties cannot agree on a resolution, the Controller may terminate the subscription without penalty.
The current list is on the Security page. Data is not end-to-end encrypted; search, reporting and AI features require the server to read it.
On the Controller’s request we provide, within a reasonable time, the information needed to demonstrate compliance with this agreement. We hold no independent audit report (SOC 2, ISO 27001); if we obtain one it will be published on the Security page. We will accommodate reasonable audit requests made on prior written notice, no more than once a year and without disrupting operations.
Data is hosted in the EU (Alkmaar, Netherlands), which constitutes a transfer abroad under KVKK art. 9. Transfers to the US-based sub-processors are limited to the scope in clause 4. The Controller is responsible for informing its clients about these transfers; the KVKK Disclosure Notice contains information that can be used in such a notice.
When the subscription ends, the Controller may export its data for 30 days. At the end of that period, or on the Controller’s earlier request, the data is deleted. Copies in backups fall away when the backup retention period expires; until then backups are protected by the same measures.
Cases where law requires retention are reserved.