Data Processing Agreement (DPA)
Template — effective on counter-signature. Last revised: May 16, 2026
This Data Processing Agreement is entered into between Project Line (קו פרויקטים, a sole proprietorship registered in Israel, business No. 310333984, D-U-N-S 532247086, Keren ha-Yesod 23/9, Ashdod 7740412, Israel) ('Processor') and the clinic identified in the Intelligent Clinic Management Platform account ('Controller'), pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).
1. Subject matter and duration
Processor will process personal data on behalf of Controller solely to provide the Intelligent Clinic Management Platform service. Processing continues for the term of the Service subscription.
2. Nature, purpose; categories of data subjects
Personal data processed: patient identifiers, contact details, appointment information, clinical notes, and limited financial data necessary for invoicing. Categories of data subjects: patients of the Controller, staff of the Controller, and authorized end-users. Special categories (Art. 9 GDPR) — health data — are processed under Art. 9(2)(h) GDPR (medical treatment).
3. Processor obligations (Art. 28(3) GDPR)
- Process personal data only on documented instructions from the Controller, including with regard to transfers to a third country or international organization.
- Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organizational measures referred to in Art. 32 GDPR, as listed in the Privacy Policy §11.
- Engage sub-processors only with prior general authorization, with at least 30 days' prior notice of changes (current list at /sub-processors).
- Assist the Controller in fulfilling data-subject requests under Arts. 12–23 GDPR.
- Notify the Controller of personal-data breaches without undue delay and within 72 hours of becoming aware.
- Delete or return all personal data after the end of the provision of services, at the Controller's choice, within 30 days.
- Make available to the Controller all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits.
4. International transfers
Primary processing occurs in Azure Israel Central. Israel is recognized as an adequate country under Commission Implementing Decision 2011/61/EU. Where data is transferred to other jurisdictions (e.g., OpenAI US, Stripe US/EU, Twilio US), Standard Contractual Clauses (Commission Decision 2021/914) apply and additional safeguards under the EDPB Recommendations 01/2020 are implemented.
UK transfers. For transfers of UK personal data, the ICO's UK Addendum (B1.0) to the EU SCCs or the UK International Data Transfer Agreement (IDTA) applies, together with a Transfer Risk Assessment. Israel is covered by the UK adequacy regulations; transfers to Microsoft and Twilio may additionally rely on the UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge).
4A. Israel annex (Privacy Protection Law)
For clinics established in Israel this DPA also constitutes the controller–holder agreement required by Regulation 15 of the Privacy Protection (Data Security) Regulations 5777-2017: the processing purposes are those set out in §2; the database security level is High; the Processor implements the measures required by those Regulations (encryption, access control, tamper-evident audit logging), notifies the Controller of security incidents per §3, engages sub-processors per §5 and returns or deletes the data per §3. The parties act under the Privacy Protection Law 5741-1981 (as amended by Amendment 13) in addition to the GDPR provisions of this DPA. Transfers abroad follow Regulation 2(4) of the Privacy Protection (Transfer of Data Abroad) Regulations 5761-2001.
5. Sub-processors
The Controller authorizes the sub-processors listed at /sub-processors. The Processor will give the Controller at least 30 days' prior written notice of any intended addition or replacement; the Controller may object on reasonable grounds within that period.
6. Liability
Subject to the limitation of liability stated in the Terms of Service, each party is liable for damage caused by processing only where it has not complied with obligations of the GDPR directed specifically to processors, or where it has acted outside or contrary to lawful instructions of the Controller (Art. 82 GDPR).
7. Execution
Acceptance is recorded server-side via the Legal Acceptance dialog (signer name + title + email + IP + UTC timestamp). A counter-signed PDF copy is provided on email request to support@projectlineil.com.