Oasis
Sign in

Processing under Art. 28 GDPR between practitioner and Oasis.

Data processing agreement

1. Parties and subject matter

This English text is a translation for convenience. The German version is legally binding and prevails in the event of any discrepancy.

The practitioner is the controller. The processor is Yhab Hammoud, Sandkamp 7, 22111 Hamburg, Deutschland. This agreement is concluded on acceptance of the practitioner terms and lasts for the duration of the relationship.

The subject matter is the processing of clients' personal data in the course of platform use, in particular appointment management, intake forms and session notes.

2. Nature, scope and purpose

Data subjects
The practitioner's clients.
Data categories
Identity data, contact data, appointment data, payment status, and health data under Art. 9 GDPR from intake forms and session notes.
Operations
Collection, storage, organisation, retrieval, disclosure to recipients determined by the controller, erasure.
Place of processing
European Union (Frankfurt am Main).

3. Processor obligations

  • Processing solely on the controller's documented instructions.
  • Confidentiality commitments from everyone with access.
  • Technical and organisational measures under Art. 32 GDPR, in particular encryption in transit and at rest and tenant-separated access control at database level (row level security).
  • Assistance with data subject rights, data protection impact assessments and breach notifications.
  • Notification of personal data breaches without undue delay, and no later than 24 hours after becoming aware.
  • Deletion or return of all data on termination, at the controller's choice; machine-readable export is available at any time.
  • Evidence of compliance on request; audits are permitted.

4. Sub-processors

The controller consents to the sub-processors listed below. Changes are notified at least 30 days in advance and may be objected to for good cause.

ServicePurposeLocationSafeguard
Supabase (Supabase Inc.)Datenbank, Authentifizierung, Datei-SpeicherEU (Frankfurt, eu-central-1)AVV nach Art. 28 DSGVO; Verarbeitung ausschließlich in der EU
Vercel (Vercel Inc.)Hosting und Auslieferung der AnwendungEU (Frankfurt, fra1) mit globalem CDNAVV nach Art. 28 DSGVO; EU-US Data Privacy Framework
Resend (Resend Inc.)Versand von Transaktions-E-Mails (Buchungsbestätigungen, Erinnerungen)EU / USAAVV nach Art. 28 DSGVO; Standardvertragsklauseln

Data processing agreement