Last updated: 2026-08-18
This Data Processing Agreement ("DPA") forms part of the Terms of Service and reflects the parties' agreement under Article 28 of the GDPR. It is concluded electronically when you accept it at registration (Article 28(9): a DPA may be "in writing, including in electronic form").
You (the business) are the controller. Oriste AI — HAGERSTANT LTD, a limited liability company incorporated in the Republic of Cyprus (registration no. HE 496930, registered office: Strovolou 77, Strovolos Center, 4th floor, Flat/Office 401, 2018 Strovolos, Nicosia, Cyprus) — is the processor, processing personal data only on your documented instructions, which include this DPA, your order, configuration and authorised use of the service. We will tell you if an instruction appears to infringe data-protection law, unless law prohibits us from doing so. You remain responsible for the lawfulness, transparency, accuracy and scope of your instructions.
We process personal data to provide the service — appointment reminders, WhatsApp messaging, AI-assisted replies, voice transcription, calendar synchronisation and scheduling — for as long as your subscription is active, then during the documented return, deletion and backup periods below.
Collecting, receiving, encrypting, storing, organising, retrieving, transmitting, classifying, generating, restricting, deleting and otherwise using data only to send and receive messages on your behalf, assist staff, transcribe voice notes, describe relevant images, and maintain calendar, appointment and client records within the app.
For staff account administration, billing, service security and our own legal records, Oriste may act as a separate controller as described in the Privacy Notice. Those activities are not governed by the controller instructions in this DPA unless the context requires otherwise.
We limit access to personnel who need it to operate or support the service and ensure that people authorised to process personal data are bound by confidentiality obligations. We maintain access controls and remove access when it is no longer required.
You authorise us to engage the providers identified with the role Sub-processor on our service-providers page, each under appropriate data-processing or data-protection terms. Providers listed there with a different role (for example an independent controller such as a payment provider, or a controller-to-controller API counterparty) are not engaged as our sub-processors, and this authorisation does not apply to them. We will give at least 30 days' notice of any intended addition or replacement, during which you may object on reasonable data-protection grounds. We will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected service before the change. Each sub-processor must be bound by data-protection obligations that provide substantially the same protection as this DPA, and we remain responsible for its performance to the extent required by Article 28.
Some sub-processors may process or store personal data outside the European Economic Area (EEA). Before any such transfer is enabled for production, we require a valid basis under Chapter V of the GDPR. Depending on the destination and provider, this may be an adequacy decision or an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses (SCCs), together with a documented transfer assessment and supplementary safeguards where required.
We do not authorise the use of your data or your clients' data to train general-purpose AI models. An AI sub-processor is enabled for production only after its applicable terms, settings and retention mode have been reviewed and approved for this restriction. The service is not designed to make solely automated decisions producing legal or similarly significant effects, and must not be used for medical diagnosis, treatment decisions or emergency triage.
We assist you in responding to data-subject requests (access, erasure, portability) through available export and deletion tools and operational support. If a data subject contacts us about data you control, we will redirect the request to you and will not respond substantively unless instructed or legally required. We also assist with security, breach assessments, DPIAs and prior consultation under Articles 32–36, taking into account the nature of processing and the information available to us.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations. Where details are not yet available, we may provide them in phases. Notification is not an admission of fault or liability.
During the subscription you may export available data and request erasure. On termination we delete or return personal data as instructed, save where retention is required by law. Unless another written instruction applies, patient/client profiles are scheduled for deletion 30 days after cancellation; shorter content periods continue to run. Data in backups is isolated from ordinary use and expires through the approved backup rotation. Statistical metadata that is not personal data may be retained.
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, on reasonable notice and subject to confidentiality, security and non-disruption requirements. We may first provide current policies, reports and other evidence, and the parties will avoid duplicative audits where those materials reasonably demonstrate compliance. You must promptly inform us if information made available under this section indicates an instruction infringes the GDPR.
If this DPA conflicts with the Terms on personal-data processing, this DPA controls. It starts when accepted electronically or signed and continues while we process personal data on your behalf. The governing-law and dispute provisions in the Terms apply without limiting rights of data subjects or supervisory authorities.