Data Processing Addendum
1. Roles of the parties
For account data, you are the controller and we are the processor. We process it only to provide the service, on your documented instructions, which for self-serve use are the instructions embodied in the product and these terms.
For clinical records, we are neither controller nor processor, because we do not process them at all. Analysis executes in your browser. You remain the sole controller of that data throughout, and it never enters our systems.
2. Subject matter, duration, nature and purpose
- Subject matter. Provision of the Vivantal application and account services.
- Duration. For as long as your account exists, plus the retention windows set out in the Privacy Policy.
- Nature and purpose. Authentication, storing your preferences, recording counts of analyses run, billing where applicable, and sending transactional email you request.
- Categories of data subject. Your personnel who hold accounts. Not patients.
- Categories of personal data. Name or email, organisation name, role, product preferences, analysis counts, billing identifiers. No special-category data, no health data, no patient identifiers.
3. Our obligations as processor
- Process account data only on your instructions, and inform you if an instruction appears to breach applicable data-protection law.
- Ensure that anyone authorised to process account data is bound by confidentiality. Currently that is one person: the operator.
- Implement the technical and organisational measures described in the Security Overview, which is incorporated here by reference.
- Assist you, so far as we reasonably can, with data-subject requests, security obligations, breach notification, and any impact assessment you must complete.
- On termination, delete account data within the windows stated in the Privacy Policy, or return it on request before deletion.
- Make available the information reasonably necessary to demonstrate compliance with this Addendum, and permit audits as described in section 6.
4. Subprocessors
You give general authorisation for the subprocessors listed in the Security Overview: Cloudflare (hosting and CDN), Supabase (authentication and account database), Stripe (payments), and Resend (transactional email). Each is engaged under terms no less protective than those in this Addendum, and we remain liable to you for their performance.
We will publish any change to that list before the new subprocessor begins processing, giving you the opportunity to object.
5. International transfers
Account data may be processed in the United States and in other jurisdictions where our subprocessors operate. Where a transfer is subject to the GDPR, it is made on the basis of the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, and we will execute the Clauses on request.
Clinical records cross no border by way of Vivantal, because they are not transmitted at all. Whichever jurisdiction you are in, that data stays there.
6. Audit
You may verify our compliance by: reviewing the Security Overview; independently confirming the no-egress property using your browser's developer tools, as described on our live self-audit page; and submitting a written security questionnaire, which we will complete within 30 days.
We do not currently hold SOC 2 or ISO 27001, and cannot provide an audit report we do not have. On-site audit is not available at present. We would rather state this than imply a programme that does not exist.
7. Personal data breach
We will notify you without undue delay, and within 72 hours of confirming a breach affecting your account data, with the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken. Full process is set out in the Security Overview.
8. HIPAA and Business Associate status
Because clinical records are neither transmitted to nor maintained by us, we do not create, receive, maintain or transmit protected health information on a covered entity's behalf. That is the test defining a Business Associate under 45 CFR 160.103, and on the standard workflow we do not meet it.
We state this as our analysis, not as a determination binding on you. Whether a Business Associate Agreement is required is your covered entity's judgement about its own compliance posture. If your privacy office concludes one is warranted, we will execute a reasonable BAA rather than contest the point. Contact partnerships@vivantal.com.
Note one boundary precisely: the optional local Autopilot agent runs on your infrastructure and may hold identifiers. Data it processes stays on your machine and is outside our custody, which is a deployment decision you control rather than a service we operate.
9. Precedence and changes
This Addendum forms part of the Terms of Service. Where it conflicts with the Terms on data protection, this Addendum governs. A negotiated agreement signed by both parties takes precedence over both.
Material changes will be reflected in the version above. For a countersigned copy, a standalone DPA on your paper, or SCCs, write to partnerships@vivantal.com.
← Back to Vivantal · Privacy Policy · Terms of Service · Security Overview
Research & quality-improvement tool — not a diagnostic device. Vivantal surfaces process gaps for human review. It does not diagnose.