Data Processing Agreement
This data processing agreement (the “Data Processing Agreement”) is part of and subject to the Euneo General Terms of Service and, where applicable, the service agreement on the Euneo Quality Suite, between Euneo Health ehf., reg. no. 461101-2590, Laufrima 31, 112 Reykjavík, Iceland (the “Processor”), and the Customer that accepts it, that is, a User in respect of their own Workspace or a Clinic in respect of the Clinic’s Workspace (the “Controller”). The agreement is made in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”) as implemented in Iceland by Act No. 90/2018.
Terms defined in the GDPR have the same meaning here. “Treatment Record” means the personal data described in Annex 1 and covered by the Data Processing Agreement. “Console” means the Processor’s web interface used by the Controller and its Users. “Workspace” means a defined area in the Console where the Controller’s patients are registered and their data is managed. “Users” means the clinicians who have access to the Controller’s Workspace, including the Controller itself if the Controller is an individual. “Treatment program” means a program that a User has created for a patient or taken over with the patient’s consent. “Exercise program” means a program that a patient has started on their own in the Processor’s app without the involvement of a User. Other terms have the same meaning as in the Euneo General Terms of Service.
The Controller accepts the Data Processing Agreement electronically in the Console or by electronic signature. The Processor keeps a record of the acceptance, including who accepted, when, and which version.
1. Subject matter of the processing
1.1 The subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subjects are set out in Annex 1.
1.2 The Controller determines the purposes and means of the processing of the Treatment Record and is responsible for having a legal basis for the processing under Articles 6 and 9 of the GDPR. The Processor processes the Treatment Record on behalf of the Controller.
2. Processing on instructions
2.1 The Processor processes the Treatment Record only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organization. The Controller’s instructions are this Data Processing Agreement, the Euneo General Terms of Service and, where applicable, the Service Agreement, together with the actions and settings that the Controller carries out in the Console.
2.2 If the Processor is required by the law to which it is subject to process personal data beyond the Controller’s instructions, it shall inform the Controller of that legal requirement before the processing begins, unless that law prohibits such information.
2.3 If the Processor considers that an instruction from the Controller infringes Act No. 90/2018 on Data Protection and the Processing of Personal Data, the GDPR or other data protection provisions, it shall inform the Controller immediately.
2.4 The Treatment Record follows the Controller’s Workspace. The Processor does not move patient registrations between Workspaces. If a User is disconnected from a Clinic’s Workspace, the Treatment Record remains in the Clinic’s Workspace.
3. Confidentiality
3.1 The Processor ensures that its employees and/or contractors who are authorized to process the Treatment Record have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
4. Security of processing
4.1 The Processor takes the technical and organizational measures required under Article 32 of the GDPR. The measures in place on the date of issue are set out in Annex 2. The Processor may change them provided that the overall level of security is not reduced.
5. Sub-processors
5.1 The Controller gives the Processor general written authorization to engage other processors. The sub-processors in place on the date of issue are listed in Annex 3.
5.2 The Processor notifies the Controller in writing of intended changes to sub-processors, whether an addition or a replacement, and gives the Controller thirty (30) days to object to the change. However, the Processor may replace sub-processors without prior notice in an emergency. In that case the Processor shall notify the Controller of the change as soon as possible.
5.3 The Processor imposes on each sub-processor, by contract, the same obligations as are set out in this Data Processing Agreement, in particular as regards sufficient guarantees of appropriate technical and organizational measures.
6. Rights of data subjects
6.1 The Processor assists the Controller, by appropriate technical and organizational measures and as far as possible, in fulfilling its obligation to respond to requests from data subjects to exercise their rights under Chapter III of the GDPR, taking into account the nature of the processing.
6.2 If the Processor receives such a request directly, it refers the request to the Controller and notifies the Controller of it.
7. Assistance with Articles 32 to 36
7.1 The Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to the Processor.
7.2 The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, cf. Article 33(2) of the GDPR, and provides the information the Controller needs to meet its obligations under Articles 33 and 34.
7.3 The Processor assists the Controller with data protection impact assessments under Article 35, where applicable, and with prior consultation with the Icelandic Data Protection Authority (Persónuvernd), or other applicable Supervisory Authority under Article 36.
8. Return or deletion at the end of the service
8.1 At the end of the service covered by the Data Processing Agreement, the Processor shall, at the Controller’s choice, delete the data that can be deleted or return it to the Controller, without the patient losing access to treatment. Data is deleted 90 days after the service ends, unless the law requires a longer retention period.
8.2 The Controller instructs the Processor to deliver to the patient a copy of the patient’s treatment programs in the patient’s account when the connection ends, in accordance with the Controller’s settings in the Console. From that time the Processor is the controller of the copy. The Controller’s Treatment Record remains unchanged up to the point at which the connection ends.
9. Information and audits
9.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 of the GDPR.
9.2 The Controller, or an independent auditor acting on its behalf, may carry out audits and inspections of the Processor’s operations to the extent necessary to verify compliance with this Data Processing Agreement and the GDPR. An audit shall take place during normal working hours and on at least thirty (30) days’ written notice. The auditor shall be bound by strict confidentiality regarding all data and information it is shown, and the Controller bears the cost of the audit itself, unless there is a material breach by the Processor.
Annex 1 · Subject matter of the processing
Referred to in 1.1.
Subject matter: hosting and servicing the treatment records of the Controller’s patients in the Console and in the patient’s app, together with the digital intake process.
Duration: from the Controller’s acceptance until the service ends, plus the period covered by Article 8.
Nature and purpose: collection, storage, organization, retrieval, use, disclosure by giving the Controller’s Users access, and deletion, for the purpose of enabling the Controller to provide treatment to its patients, create treatment programs for them, follow their progress, receive summaries of its own records and carry out systematic quality work, including through a patient survey and aggregated figures for each User.
Types of personal data: (1) the patient’s name and contact details; (2) treatment programs, including their names, changes to them, notes on individual exercises and phases (for example, a reminder always to do a certain exercise in the morning) and other communication between Users and the patient, such as chat through the Processor’s platform; (3) the patient's pain logs, answers to questionnaires and assessments, comments, and the exercises the patient logs in a treatment program; (4) the goals of the treatment program; (5) the patient’s answers to the Controller’s patient survey; and (6) the names of Users, timestamps of changes within the record, and summary figures on use, quality indicators, outcomes and the patient survey by User. Items 2 to 4 are data concerning health within the meaning of Article 9 of the GDPR.
Categories of data subjects: the Controller’s patients, including patient registrations that the Controller has created but not connected to a patient, and the Controller’s Users to the extent that their names and the figures under item 6 appear in the record and in the Euneo Quality Suite.
Scope: The Data Processing Agreement covers what the Controller and its Users record and what the patient records in a treatment program that the Controller has assigned or taken over with the patient’s consent, and the patient’s answers to the Controller’s patient survey. It does not cover the patient’s user account with the Processor, exercise programs that the Controller has not taken over, the user accounts of Users, or the Processor’s content; the Processor carries out that processing as an independent controller, and it is governed by the Processor’s privacy terms.
Annex 2 · Security measures
Referred to in 4.1. Measures in operation on the date of issue.
Encryption: All access to the Treatment Record is over TLS 1.2 or later. The Treatment Record is encrypted at rest with AES-256.
Access control: Access by the Processor’s staff is based on need and role, reviewed every six months, and the review is recorded. Individual accounts; shared accounts are not used for access to the Treatment Record. The Processor’s staff access infrastructure through Google or GitHub sign-in with two-factor authentication.
Hosting: Firestore and Cloud Storage in Belgium and the Netherlands (eur3), Railway in Amsterdam, hosting with Vercel in Frankfurt, Resend in Ireland and BigQuery in the EU multi-region, with the exceptions set out in Annex 3.
Backup and recovery: Regular backups with a tested recovery process and deletion of backups within a defined period. The recovery process is tested internally every 12 months.
Event logging: System and administrator events are logged. Administrator events and the access log in Google Cloud are kept for 400 days and system events for 30 days. Changes to treatment programs are logged.
Vulnerability management and software development: The underlying systems are operated by Google Cloud and Vercel, which update them continuously. Third-party packages are updated as they are released, and security updates are applied as soon as they become known. Code review takes place before release.
Staff: Written confidentiality undertakings and data protection training at the start of employment. Data protection training is repeated every 12 months.
Sub-processors: Go through due diligence before a contract is made, and the contract contains at least obligations equivalent to those in this Data Processing Agreement under 5.3.
Incident response: A documented response plan that takes account of the notification obligation under 7.2.
Annex 3 · Sub-processors
Referred to in 5.1. Sub-processors that process the Treatment Record on the date of issue.
| Sub-processor | Role | Region |
|---|---|---|
| Firestore and Cloud Storage | Main database and file storage | Belgium and the Netherlands (eur3) |
| BigQuery | Summaries for the Controller of its own records | Within Europe |
| Railway | Hosting and running the web service | Amsterdam |
| Vercel and Vercel Blob | Vercel: hosting of the web interface and file storage. Vercel Blob: images and videos of system errors, if uploaded with feedback from Users | Vercel in Frankfurt; Vercel Blob in Dublin |
| Resend | Email for the service, including invitations to a patient that carry the patient’s name and the User’s name | Registered in Ireland; storage in practice in the United States, on the basis of standard contractual clauses and DPF certification |
| Twilio | SMS invitations that carry the User’s name and a connection code | Dublin, Ireland |
| Google Workspace | Handling of support requests that may contain content from the Treatment Record | Within Europe |
Date of issue: 6 October 2026.
These terms are also available in Icelandic. If the two versions differ, the English version prevails.
Clinic’s acceptance
By signing, the Clinic accepts the Euneo Data Processing Agreement above as Controller. The person signing confirms that they are authorized to bind the Clinic.
| Clinic | |
|---|---|
| Name | [ ] |
| Reg. no. (kennitala) | [ ] |
| Signed on behalf of the Clinic | |
|---|---|
| Name | [ ] |
| ID no. (kennitala) | [ ] |
| Position | [ ] |
This document is signed electronically.
Vinnslusamningur
Þessi vinnslusamningur („Vinnslusamningur”) er hluti af og fellur undir Almenna þjónustuskilmála Euneo og, ef við á, þjónustusamning um Gæðakerfi Euneo, milli Euneo Health ehf., kt. 461101-2590, Laufrima 31, 112 Reykjavík, Íslandi (hér eftir „Vinnsluaðili”), og þess Viðskiptavinar sem samþykkir hann, þ.e. Notanda vegna eigin Vinnusvæðis eða Stofu vegna Vinnusvæðis Stofu (hér eftir „Ábyrgðaraðili”). Samningurinn er gerður í samræmi við 28. gr. reglugerðar (ESB) 2016/679 („GDPR”) eins og hún hefur verið innleidd á Íslandi með lögum nr. 90/2018.
Hugtök sem skilgreind eru í GDPR hafa hér sömu merkingu. „Meðferðarskrá” merkir þær persónuupplýsingar sem lýst er í Fylgiskjali 1 og Vinnslusamningurinn tekur til. „Stjórnborð” merkir það vefviðmót Vinnsluaðila sem Ábyrgðaraðili og Notendur hans nota. „Vinnusvæði” merkir afmarkað svæði í Stjórnborðinu þar sem skjólstæðingar Ábyrgðaraðila eru skráðir og unnið er með gögn um þá. „Notendur” merkir þá meðferðaraðila sem hafa aðgang að Vinnusvæði Ábyrgðaraðila, þ.m.t. Ábyrgðaraðila sjálfan ef hann er einstaklingur. „Meðferðaráætlun” merkir áætlun sem Notandi hefur útbúið fyrir skjólstæðing eða tekið yfir með samþykki hans. „Æfingaáætlun” merkir áætlun sem skjólstæðingur hefur sjálfur hafið í smáforriti Vinnsluaðila án aðkomu Notanda. Önnur hugtök hafa sömu merkingu og í Almennum þjónustuskilmálum Euneo.
Ábyrgðaraðili samþykkir Vinnslusamninginn á rafrænu formi í Stjórnborðinu eða með rafrænni undirskrift. Vinnsluaðili varðveitir skrá um samþykkið, þ.m.t. hver samþykkti, hvenær og hvaða útgáfu.
1. Efni vinnslunnar
1.1 Efni og tímalengd vinnslunnar, eðli hennar og tilgangur, tegundir persónuupplýsinga og flokkar skráðra einstaklinga eru tilgreind í Fylgiskjali 1.
1.2 Ábyrgðaraðili ákvarðar tilgang og aðferðir við vinnslu Meðferðarskráarinnar og ber ábyrgð á því að hafa heimild til vinnslunnar samkvæmt 6. og 9. gr. GDPR. Vinnsluaðili vinnur Meðferðarskrána fyrir hönd Ábyrgðaraðila.
2. Vinnsla samkvæmt fyrirmælum
2.1 Vinnsluaðili vinnur Meðferðarskrána eingöngu samkvæmt skjalfestum fyrirmælum Ábyrgðaraðila, þ.m.t. að því er varðar flutning persónuupplýsinga til þriðja lands eða alþjóðastofnunar. Fyrirmæli Ábyrgðaraðila eru þessi Vinnslusamningur, Almennir þjónustuskilmálar Euneo og ef við á Þjónustusamningur ásamt þeim aðgerðum og stillingum sem Ábyrgðaraðili framkvæmir í Stjórnborðinu.
2.2 Sé Vinnsluaðila skylt samkvæmt lögum sem hann heyrir undir að vinna persónuupplýsingar umfram fyrirmæli Ábyrgðaraðila skal hann tilkynna Ábyrgðaraðila um þá lagaskyldu áður en vinnsla hefst, nema viðkomandi lög banni slíka tilkynningu.
2.3 Telji Vinnsluaðili að fyrirmæli Ábyrgðaraðila brjóti gegn lögum um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018 (pvl.), GDPR eða öðrum ákvæðum um persónuvernd skal hann tilkynna Ábyrgðaraðila það tafarlaust.
2.4 Meðferðarskráin fylgir Vinnusvæði Ábyrgðaraðila. Vinnsluaðili flytur ekki skráningar skjólstæðinga á milli Vinnusvæða. Sé tengingu Notanda við Vinnusvæði Stofu slitið verður Meðferðarskráin áfram á Vinnusvæði Stofunnar.
3. Trúnaður
3.1 Vinnsluaðili tryggir að þeir starfsmenn og/eða verktakar hans sem hafa heimild til að vinna Meðferðarskrána hafi undirgengist trúnaðarskyldu eða séu bundnir þagnarskyldu samkvæmt lögum.
4. Öryggi vinnslu
4.1 Vinnsluaðili gerir þær tæknilegu og skipulagslegu ráðstafanir sem krafist er samkvæmt 32. gr. GDPR. Þær ráðstafanir sem eru í gildi á útgáfudegi eru tilgreindar í Fylgiskjali 2. Vinnsluaðili má breyta þeim að því tilskildu að heildarstig öryggis lækki ekki.
5. Undirvinnsluaðilar
5.1 Ábyrgðaraðili veitir Vinnsluaðila almenna skriflega heimild til að ráða aðra vinnsluaðila. Þeir undirvinnsluaðilar sem eru til staðar á útgáfudegi eru tilgreindir í Fylgiskjali 3.
5.2 Vinnsluaðili tilkynnir Ábyrgðaraðila skriflega um fyrirhugaðar breytingar á undirvinnsluaðilum, hvort sem er viðbót eða skipti, og veitir honum þrjátíu (30) daga frest til að andmæla breytingunni. Þó hefur Vinnsluaðili heimild til að skipta undirvinnsluaðilum út án þess að tilkynna það fyrirfram ef um neyðartilfelli er að ræða. Þá skal Vinnsluaðili tilkynna breytinguna svo fljótt sem auðið er.
5.3 Vinnsluaðili leggur á hvern undirvinnsluaðila, með samningi, sömu skyldur og mælt er fyrir um í þessum Vinnslusamningi, einkum um fullnægjandi tryggingu fyrir viðeigandi tæknilegum og skipulagslegum ráðstöfunum.
6. Réttindi skráðra einstaklinga
6.1 Vinnsluaðili aðstoðar Ábyrgðaraðila, með viðeigandi tæknilegum og skipulagslegum ráðstöfunum og eftir því sem framast er unnt, við að uppfylla skyldu sína til að svara beiðnum skráðra einstaklinga um að neyta réttinda sinna samkvæmt III. kafla GDPR, að teknu tilliti til eðlis vinnslunnar.
6.2 Berist Vinnsluaðila slík beiðni beint vísar hann henni til Ábyrgðaraðila og tilkynnir honum um það.
7. Aðstoð við 32. til 36. gr.
7.1 Vinnsluaðili aðstoðar Ábyrgðaraðila við að tryggja að skyldum samkvæmt 32. til 36. gr. GDPR sé fullnægt, að teknu tilliti til eðlis vinnslunnar og þeirra upplýsinga sem Vinnsluaðili hefur yfir að ráða.
7.2 Vinnsluaðili tilkynnir Ábyrgðaraðila án ótilhlýðilegrar tafar eftir að hann verður var við öryggisbrot sbr. 2. mgr. 33. gr. GDPR, og lætur í té þær upplýsingar sem Ábyrgðaraðili þarf til að uppfylla skyldur sínar samkvæmt 33. og 34. gr.
7.3 Vinnsluaðili aðstoðar Ábyrgðaraðila við mat á áhrifum á persónuvernd skv. 35. gr. ef við á, og við fyrirframsamráð við Persónuvernd skv. 36. gr.
8. Skil eða eyðing við lok þjónustu
8.1 Við lok þeirrar þjónustu sem Vinnslusamningurinn tekur til skal Vinnsluaðili, að vali Ábyrgðaraðila, eyða þeim upplýsingum sem hægt er eða afhenda þær Ábyrgðaraðila, þó án þess að skjólstæðingur missi aðgang að meðferð. Eyðing upplýsinga fer fram 90 dögum eftir að þjónustu lýkur, nema að lög kveði á um lengri varðveislutíma.
8.2 Ábyrgðaraðili felur Vinnsluaðila að afhenda skjólstæðingi afrit af meðferðaráætlunum hans á aðgang hans þegar tengingu er slitið, í samræmi við stillingar Ábyrgðaraðila í Stjórnborðinu. Frá þeim tíma er Vinnsluaðili ábyrgðaraðili afritsins. Meðferðarskrá Ábyrgðaraðila helst óbreytt fram að þeim tímapunkti að tenging slitnar.
9. Upplýsingagjöf og úttektir
9.1 Vinnsluaðili gerir Ábyrgðaraðila aðgengilegar allar upplýsingar sem nauðsynlegar eru til að sýna fram á að skyldum samkvæmt 28. gr. GDPR sé fullnægt.
9.2 Ábyrgðaraðili eða óháður úttektaraðili á hans vegum getur framkvæmt úttektir og skoðanir á starfsemi Vinnsluaðila að því marki sem nauðsynlegt er til að sannreyna fylgni við Vinnslusamning þennan og GDPR. Úttekt skal fara fram á venjulegum vinnutíma gegn a.m.k. þrjátíu (30) daga skriflegum fyrirvara. Úttektaraðili skal bundinn fyllstu trúnaði um öll gögn og upplýsingar sem hann fær að sjá, og ber Ábyrgðaraðili sjálfur kostnað af úttektinni, nema um verulega vanefnd Vinnsluaðila sé að ræða.
Fylgiskjal 1 · Efni vinnslunnar
Vísað til í 1.1.
Efni: hýsing og þjónusta við meðferðarskrár skjólstæðinga Ábyrgðaraðila í Stjórnborðinu og í smáforriti skjólstæðings ásamt stafrænu innritunarferli.
Tímalengd: frá samþykki Ábyrgðaraðila og þar til þjónustu lýkur, að viðbættu því tímabili sem 8. gr. tekur til.
Eðli og tilgangur: söfnun, varðveisla, skipulagning, endurheimt, notkun, miðlun með aðgangi Notenda Ábyrgðaraðila og eyðing, í þeim tilgangi að Ábyrgðaraðili geti veitt skjólstæðingum sínum meðferð, útbúið meðferðaráætlanir fyrir þá, fylgst með framvindu þeirra, fengið samantektir um eigin skrár og sinnt skipulegu gæðastarfi, þ.m.t. með þjónustukönnun og samanteknum gögnum eftir Notendum.
Tegundir persónuupplýsinga: (1) nafn og samskiptaupplýsingar skjólstæðings; (2) meðferðaráætlanir, þ.m.t. heiti þeirra, breytingar á þeim, nótur við einstakar æfingar og fasa (t.d. að muna að gera ákveðna æfingu alltaf að morgni dags) og önnur samskipti Notenda við skjólstæðing, s.s. spjall í gegnum lausn Vinnsluaðila; (3) verkjaskráning skjólstæðings, svör við spurningalistum og mati, athugasemdir og skráning á æfingum sem skjólstæðingur færir inn á meðferðaráætlun; (4) markmið meðferðaráætlunar; (5) svör skjólstæðings við þjónustukönnun Ábyrgðaraðila; og (6) nöfn Notenda, tímastimplar breytinga innan skrárinnar og samanteknar tölur um notkun, gæðavísa, árangur og þjónustukönnun eftir Notendum. Liðir 2 til 4 teljast heilsufarsupplýsingar í skilningi 9. gr. GDPR.
Flokkar skráðra einstaklinga: skjólstæðingar Ábyrgðaraðila, þ.m.t. skráningar skjólstæðinga sem hann hefur stofnað en ekki tengt skjólstæðingi, og Notendur Ábyrgðaraðila að því marki sem nöfn þeirra og tölur skv. 6. lið koma fram í skránni og í Gæðakerfi Euneo.
Afmörkun: Vinnslusamningurinn tekur til þess sem Ábyrgðaraðili og Notendur hans skrá og þess sem skjólstæðingur skráir á meðferðaráætlun sem Ábyrgðaraðili hefur úthlutað eða tekið yfir með samþykki skjólstæðings, og svara skjólstæðings við þjónustukönnun Ábyrgðaraðila. Hann tekur ekki til notendareiknings skjólstæðings hjá Vinnsluaðila, æfingaáætlana sem Ábyrgðaraðili hefur ekki tekið yfir, notendareikninga Notenda eða efnis Vinnsluaðila; þá vinnslu stundar Vinnsluaðili sem sjálfstæður ábyrgðaraðili og um hana gilda persónuverndarskilmálar hans.
Fylgiskjal 2 · Öryggisráðstafanir
Vísað til í 4.1. Ráðstafanir sem eru í rekstri á útgáfudegi.
Dulkóðun: Allur aðgangur að Meðferðarskránni fer um TLS 1.2 eða nýrri. Meðferðarskráin er dulkóðuð í geymslu með AES-256.
Aðgangsstýring: Aðgangur starfsfólks Vinnsluaðila eftir þörf og hlutverki, endurskoðaður á sex mánaða fresti og endurskoðunin skráð. Einstaklingsbundnir aðgangar; sameiginlegir aðgangar eru ekki notaðir að Meðferðarskránni. Starfsfólk Vinnsluaðila kemst að innviðum um Google- eða GitHub-innskráningu með tvíþátta auðkenningu.
Hýsing: Firestore og Cloud Storage í Belgíu og Hollandi (eur3), Railway í Amsterdam, hýsing hjá Vercel í Frankfurt, Resend á Írlandi og BigQuery á ESB-fjölsvæði, með þeim undantekningum sem greinir í Fylgiskjali 3.
Afritun og endurheimt: Regluleg öryggisafrit með prófuðu endurheimtarferli og eyðingu afrita innan skilgreinds frests. Endurheimtarferlið er prófað innanhúss á 12 mánaða fresti.
Atburðaskráning: Kerfis- og stjórnandaatburðir eru skráðir. Stjórnandaatburðir og aðgangsskrá í Google Cloud eru varðveittir í 400 daga og kerfisatburðir í 30 daga. Breytingar á meðferðaráætlunum eru skráðar.
Veikleikastjórnun og hugbúnaðarþróun: Undirliggjandi kerfi eru rekin af Google Cloud og Vercel, sem uppfæra þau samfellt. Aðfengnir pakkar eru uppfærðir jafnóðum og öryggisuppfærslur settar á um leið og þær koma í ljós. Kóðarýni fer fram fyrir útgáfu.
Starfsfólk: Skriflegar trúnaðaryfirlýsingar og fræðsla um persónuvernd við upphaf starfs. Persónuverndarfræðsla er endurtekin á 12 mánaða fresti.
Undirvinnsluaðilar: Fara í gegnum áreiðanleikamat fyrir samningsgerð og samningur inniheldur að lágmarki skyldur til jafns við vinnslusamning þennan skv. 5.3.
Viðbrögð við atvikum: Skjalfest viðbragðsáætlun sem tekur mið af tilkynningarskyldu skv. 7.2.
Fylgiskjal 3 · Undirvinnsluaðilar
Vísað til í 5.1. Undirvinnsluaðilar sem vinna með Meðferðarskrána á útgáfudegi.
| Undirvinnsluaðili | Hlutverk | Svæði |
|---|---|---|
| Firestore og Cloud Storage | Aðalgagnagrunnur og skráageymsla | Belgía og Holland (eur3) |
| BigQuery | Samantekt til Ábyrgðaraðila um eigin skrár | Innan Evrópu |
| Railway | Hýsing og keyrsla vefþjónustu | Amsterdam |
| Vercel og Vercel Blob | Vercel: Hýsing vefviðmóts og skráageymsla og Vercel Blob: Myndir/myndbönd af kerfisvillum ef þeim er hlaðið upp með endurgjöf Notenda. | Vercel í Frankfurt; Vercel Blob Dublin. |
| Resend | Tölvupóstur vegna þjónustunnar, þ.m.t. boð til skjólstæðings sem ber nafn hans og nafn Notanda | Skráð Írland; geymsla í reynd í Bandaríkjunum, á grundvelli staðlaðra samningsskilmála og DPF skírteinis (certified) |
| Twilio | SMS-boð sem ber nafn Notanda og tengikóða | Dublin, Írland |
| Google Workspace | Meðhöndlun þjónustuerinda sem kunna að hafa að geyma efni úr Meðferðarskrá | Innan Evrópu |
Útgáfudagur: 6. október 2026.
Euneo Health ehf., kt. 461101-2590, privacy@euneohealth.com
Samþykki Stofu
Með undirritun sinni samþykkir Stofan Vinnslusamning Euneo hér að framan sem Ábyrgðaraðili. Sá sem undirritar staðfestir að hann hafi heimild til að skuldbinda Stofuna.
| Stofa | |
|---|---|
| Heiti | [ ] |
| Kennitala | [ ] |
| Undirritað fyrir hönd Stofu | |
|---|---|
| Nafn | [ ] |
| Kennitala | [ ] |
| Staða | [ ] |
Skjalið er undirritað með rafrænni undirskrift.