Data Processing Agreement (DPA)
Template — effective on counter-signature. Last revised: 16 May 2026
This Data Processing Agreement is entered into between Project Line (קו פרויקטים, a sole proprietorship registered in Israel, business No. 310333984, D-U-N-S 532247086, Keren ha-Yesod 23/9, Ashdod 7740412, Israel) ('Processor') and the clinic identified in the Intelligent Clinic Management Platform account ('Controller'), pursuant to Article 28 of the UK GDPR and the Data Protection Act 2018. Where the Controller also serves patients in the EU, the equivalent provisions of Regulation (EU) 2016/679 (EU GDPR) apply in parallel.
1. Subject matter and duration
Processor will process personal data on behalf of Controller solely to provide the Intelligent Clinic Management Platform service. Processing continues for the term of the Service subscription.
2. Nature, purpose; categories of data subjects
Personal data processed: patient identifiers, contact details, appointment information, clinical notes, and limited financial data necessary for invoicing. Categories of data subjects: patients of the Controller, staff of the Controller, and authorised end-users. Special category data (Art. 9 UK GDPR) — health data — is processed under Art. 9(2)(h) UK GDPR (medical treatment) and Schedule 1 Part 1 of the Data Protection Act 2018.
3. Processor obligations (Art. 28(3) UK GDPR)
- Process personal data only on documented instructions from the Controller, including with regard to transfers to a third country or international organisation.
- Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organisational measures referred to in Art. 32 UK GDPR, as listed in the Privacy Policy §11.
- Engage sub-processors only with prior general authorisation, with at least 30 days' prior notice of changes (current list at /sub-processors).
- Assist the Controller in fulfilling data-subject requests under Arts. 12–23 UK GDPR.
- Notify the Controller of personal-data breaches without undue delay and within 72 hours of becoming aware (Art. 33 UK GDPR).
- Delete or return all personal data after the end of the provision of services, at the Controller's choice, within 30 days.
- Make available to the Controller all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits.
4. International transfers
UK transfers. For transfers of UK personal data outside the UK, the ICO's UK Addendum (B1.0) to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement (IDTA), applies together with a Transfer Risk Assessment. Israel is covered by the UK adequacy regulations. Transfers to Microsoft and Twilio may additionally rely on the UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge). Primary processing occurs in Azure Israel Central. Where the Controller also serves EU patients, EU Standard Contractual Clauses (Commission Decision 2021/914) and the EDPB Recommendations 01/2020 apply to onward EU transfers.
4A. Israel annex (Privacy Protection Law)
For clinics established in Israel this DPA also constitutes the controller–holder agreement required by Regulation 15 of the Privacy Protection (Data Security) Regulations 5777-2017: the processing purposes are those set out in §2; the database security level is High; the Processor implements the measures required by those Regulations (encryption, access control, tamper-evident audit logging), notifies the Controller of security incidents per §3, engages sub-processors per §5 and returns or deletes the data per §3.
5. Sub-processors
The Controller authorises the sub-processors listed at /sub-processors. The Processor will give the Controller at least 30 days' prior written notice of any intended addition or replacement; the Controller may object on reasonable grounds within that period.
6. Liability
Subject to the limitation of liability stated in the Terms of Service, each party is liable for damage caused by processing only where it has not complied with obligations of the UK GDPR directed specifically to processors, or where it has acted outside or contrary to lawful instructions of the Controller (Art. 82 UK GDPR).
7. Execution
Acceptance is recorded server-side via the Legal Acceptance dialog (signer name + title + email + IP + UTC timestamp). A counter-signed PDF copy is provided on email request to support@projectlineil.com.