Skip to content

Data processing agreement

Printable version

This agreement applies between OPALEVI and every practice or educational institution that uses OPALEVI ("the customer"), wherever the law requires a written agreement for the processing of personal data on someone else's behalf. It forms part of the terms the customer accepted.

Roles

The customer is the controller of the personal data it keeps in OPALEVI and decides what is recorded and why. OPALEVI L.L.C. ("OPALEVI") is the processor: it processes that data only to provide the service and only on the customer's documented instructions, which are these terms and the customer's use of the service.

Subject, duration and purpose

The processing is the hosting and operation of OPALEVI for the customer: storing, retrieving, displaying, printing and transmitting the records the customer's users enter. It lasts as long as the customer's account, and until the data is deleted after the account ends.

Data and people concerned

  • Users: the customer's staff, teachers and students — names, e-mail addresses, telephone numbers, roles, sign-in records and the record of their work.
  • Patients and clients: the records a practice keeps about them, which may include health data. In a classroom clinic of OPALEVI for Education these are fictional and no real patient's data is processed.

OPALEVI's obligations

  • It processes the data only on the customer's documented instructions, and tells the customer if it believes an instruction breaks the law.
  • Everyone at OPALEVI who can reach the data is bound to keep it confidential.
  • It keeps the data secure with the measures listed below.
  • It uses other processors only as listed below, under written terms that give the data the same protection, and tells customers before adding or replacing one by updating this page and the privacy policy.
  • It helps the customer answer requests from people exercising their rights, and with assessments and consultations the law requires.
  • It tells the customer without undue delay, and at the latest within 72 hours of becoming aware, of a personal data breach affecting the customer's data, with what it knows and what it is doing about it.
  • When the account ends, it deletes the data, or returns a copy first if the customer asks, within 30 days of the customer's request; backups are overwritten within a further 30 days.
  • It gives the customer the information needed to show that these obligations are met, and answers reasonable audit questions once a year, or after a breach.

For a customer in Nigeria, these obligations are also those a data processor owes under the Nigeria Data Protection Act 2023, and the parties will cooperate with the Nigeria Data Protection Commission where the law requires it.

Other processors

  • Paddle.com, our merchant of record for card payments, processes those payments and the billing details it needs.
  • Freemius, Inc., merchant of record for subscriptions paid through its checkout, processes those payments and the billing details it needs.
  • Privy provides the wallet connection used for payments in EURC or USDC.
  • The hosting provider that runs our servers and database stores the data on our behalf.
  • Supabase stores the sign-in credentials (each password only as a hash) and checks them when you sign in.
  • Cloudflare delivers this website and runs the security check on its public forms, which looks at your browser and connection to tell people from automated programs.
  • PostHog (PostHog Inc., United States) measures how our public website is used: which pages are opened, where people click and how far they scroll, how fast pages load, and whether a registration or a contact message is completed. It also keeps screen recordings of visits to the public pages, with everything typed into a form hidden, and may ask a one-question survey. It sets no cookies, stores nothing in your browser, never sees the application itself, and receives page addresses without their query strings. The registration form and the payment receipt are counted but not recorded. This data is processed in the United States, under the European Commission's standard contractual clauses.
  • Google Analytics (Google Ireland Limited; data may be processed by Google LLC in the United States under the EU–US Data Privacy Framework and standard contractual clauses) measures how our public website is used: which pages are opened, from which country and kind of device, and which site or campaign brought the visitor. It runs on the public pages and the registration page only, never inside the application, and receives no clinic or patient data. Advertising features are switched off.
  • For each clinic, identified only by its number, PostHog also receives how the service is used: when the clinic registered, when it added its first patient and its first visit, changes to its subscription and the payments made, and for each day of use, counts such as how many staff worked in it and which parts of the service were opened. No names, no e-mail addresses and no patient data are included.
  • Sentry (Functional Software, Inc., data stored in the EU, Frankfurt) receives technical reports when the service fails or is slow: the kind of error, where in our code it happened, which part of the service was in use, the affected clinic's number and how long pages and requests took. Names, e-mail addresses, record numbers, anything typed and the query strings of addresses are removed before a report is sent, and screens are never recorded.
  • Brevo (Sendinblue SAS, France) delivers the service's emails, such as invitations, password resets, account confirmations and reminders, to their recipients.
  • Infobip sends the WhatsApp messages and text messages (SMS) that a practice has switched on for its patients. It receives the mobile number of the patient or the animal's owner and the fixed text of the message.
  • WhatsApp, a service of Meta, delivers the WhatsApp messages to the recipient's WhatsApp account, and receives the number and the message as it does for any WhatsApp message.

Each of them processes the data only to provide its part of the service, under a written agreement with OPALEVI.

Security measures

  • Each customer's data is kept apart: every request is limited to the organisation the signed-in user belongs to.
  • Access inside an organisation follows each person's role, set by the customer's administrators.
  • Passwords are stored only as hashes; a person can add a second factor to their own sign-in.
  • The service runs over encrypted HTTPS connections only.
  • Changes to records and administrative actions are written to an activity log that cannot be edited.
  • The database is backed up every day and backups are kept for up to 30 days.

Where the data is processed

The servers and the database are in data centres in the European Union. Where a provider listed above processes data outside it, the privacy policy says so, and the transfer rests on the safeguards the GDPR provides, such as the European Commission's standard contractual clauses.

Governing law and disputes

This agreement is governed by the law of the Republic of Kosovo. The parties will first try to settle any dispute by talking to each other; a dispute that cannot be settled that way goes to the competent courts in Prishtina.

Contact

For any question about this document, or to make a request about your data, write to us at [email protected]. We answer within 30 days.