timit
/
Log in Start free
Legal

Data Processing Agreement

Version 1.0 – effective from 18 August 2026 Classification: Public

between

Medibrix AS, with registered address at Sjøgata 5, 9405 Harstad, Norway, and organization number 912 540 863 ("Medibrix" or "Data Processor")

and

The customer ("Data Controller")

each referred to as a "Party" and together the "Parties"

1. Introduction

  1. This Agreement sets out the rights and obligations of the Data Controller and the Data Processor when the Data Processor processes Personal Data on behalf of the Data Controller.

  2. This Agreement is designed to ensure both Parties comply with the European Parliament and Council Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR").

  3. In connection with the delivery of services agreed under the main agreement called the Terms and Conditions for the TIMIT platform (the "Terms and Conditions"), the Data Processor shall process Personal Data on behalf of the Data Controller in accordance with this Agreement. This Agreement applies exclusively to processing activities for which Medibrix acts as a Data Processor.

  4. In the event of a conflict between this Agreement and any other agreement between the Parties relating to data processing, this Agreement shall prevail.

  5. There are three appendices to this Agreement which form an integral part hereof:

    • Appendix A: Detailed information on the processing activities, including purpose, nature and types of Personal Data, categories of Data Subjects, and duration of processing.
    • Appendix B: Conditions for the use of Sub-Processors and the list of approved Sub-Processors.
    • Appendix C: The Data Controller's instructions for processing, minimum security measures to be implemented by the Data Processor, and procedures for audits.
  6. This Agreement does not exempt the Data Processor from obligation imposed by the GDPR or other applicable data protection legislation.

2. Rights and obligations of the Data Controller

  1. The Data Controller is responsible for ensuring that the processing of Personal Data complies with the GDPR principles of accountability and data protection, applicable data protection legislation and this Agreement.

  2. The Data Controller shall determine the purposes of the processing and the means by which such processing is to be carried out.

  3. The Data Controller is responsible for ensuring that there is a valid legal basis for the processing of Personal Data by the Data Processor in accordance with the Data Controller's instructions.

3. The Data Processor´s Obligation to Act on Instructions

  1. The Data Processor shall only process Personal Data according to documented instructions from the Data Controller, unless otherwise required by applicable law. If the law requires the Data Processor to process data beyond these instructions, the Data Processor must inform the Data Controller, unless prohibited by law. The Data Controller may issue additional documented instructions at any time during processing.

  2. If the Data Processor believes any instruction violates data protection laws or the GDPR, it must immediately notify the Data Controller.

4. Confidentiality

  1. The Data Processor may only allow access to Personal Data to individuals under its authority who are required to follow instructions and are bound by confidentiality, either by contract or by law. Access must be limited to what is strictly necessary.

  2. The data processor must be able to demonstrate, upon request, that all authorized individuals are subject to the required confidentiality obligation.

5. Security of Processing

  1. Both the Data Controller and the Data Processor must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. This includes considering available technology, implementation costs, processing nature, and potential harm to individuals' rights and freedoms.

    Depending on relevance, such measures may include:

    a. Pseudonymisation and Encryption b. Maintaining confidentiality, integrity, availability and resilience of systems c. Restoring data access quickly in case of incidents d. Regular testing and evaluation of security measures.

  2. The Data Processor must also independently assess the risks to individuals' rights and freedoms and implement relevant safeguards. The Data Controller must provide necessary information for this assessment.

  3. The Data Processor must support the Data Controller´s compliance with its security obligations by providing details on existing safeguards and any other necessary information.

6. Use of Sub-Processors

  1. The Data Processor may only engage another processor if certain conditions are met, including a written agreement ensuring equivalent data protection responsibilities.

  2. Sub-Processors must be approved in writing by the Data Controller. General approval is given for those listed in Appendix B. Written agreements must be in place with sub-processors, ensuring they follow the same obligations as in this Agreement. The Data Processor remains fully responsible for Sub-Processors´ compliance.

  3. If the Data Processor intends to appoint a new sub-processor, the Data Controller must be notified at least one month in advance. The Data Controller can object to the change within 15 days. If the Data Controller objects to the change, either party may terminate the agreement with 15 days' notice, within 5 days after the objection. If the Data Controller does not terminate the agreement, the new sub-processor is considered accepted.

  4. A copy of the sub-processor agreement must be shared with the Data Controller upon request, excluding commercial terms not relevant to data protection.

  5. If a Sub-Processor fails to meet its obligations, the Data Processor remains fully liable to the Data Controller in terms of fulfilling the Sub-Processor's obligations.

7. Transfers to Third Countries or International Organisations

  1. The Data Processor may only transfer Personal Data to outside the EU/EEA with the controller's prior approval and in accordance with applicable safeguards, such as the EU's standard contractual clauses ("SCCs").

  2. The Data Controller has approved transfers listed in Appendix B. SCCs have been entered into with relevant third-countries and updated in line with new EU rules.

  3. The Sub-Processors who are domiciled in the USA are all registered under the Data Privacy Framework subject to an adequacy decision.

8. Assistance to the Data Controller

  1. The Data Processor must assist the Data Controller, where possible, in responding to requests from individuals exercising their rights (such as access, rectification, deletion, etc.). This includes helping the Data Controller meet its information obligations, as well as honoring individual rights including objection, data portability, and protection against automated decision-making.

  2. The data processor must also assist with:

    a. Reporting data breaches to the relevant data protection authority b. Notifying affected individuals of serious breaches c. Conducting data protection impact assessments d. Consulting authorities where high-risk processing cannot be mitigated.

  3. The scope of technical and organizational measures for this assistance is detailed in Appendix C, including the level and type of support the Data Processor must provide.

9. Notification of Personal Data Breach

  1. If a personal data breach occurs, the Data Processor must notify the Data Controller without undue delay after becoming aware of it.

  2. This notification must be provided promptly so that the Data Controller can meet its obligation to report the breach to the data protection authority within the legally required timeframe.

  3. The Data Processor must assist the Data Controller in preparing this report. This includes helping collect and provide the following information:

    a. A description of the nature of the breach, including, when possible, the categories and approximate number of individuals and records affected. b. Likely consequences of the breach c. Measures taken or proposed to address the breach and, if relevant, mitigate its harmful effects.

10. Audit and Inspection

  1. The Data Controller may carry out an audit once per year to assess how the Data Processor handles Personal Data. The Data Processor must support the audit. The Data Controller may also request a third party security audit. A report of that audit will be shared with the Data Controller upon request. The Data Processor may charge for audit-related work at the applicable hourly rates according to the Terms and Conditions.

  2. The Data Processor will conduct internal security audits for relevant systems, and reports documenting these audits must be made available to the Data Controller upon request.

11. Liability

The liability terms set out in the Terms and Conditions also apply to any breaches of this Agreement.

12. Commencements and Termination

This Agreement enters into force at the same time as the Terms and Conditions and remains valid for as long as the Terms and Conditions is active.

13. Governing Law and Dispute Resolution

  1. This Agreement shall be governed by and construed in accordance with the laws of Norway, without regard to its conflict of law principles.

  2. Any dispute arising out of or in connection with this Agreement, including any question regarding its existence, validity or termination, shall be finally settled under the Rules of Arbitration of the International Chamber of Commerce (ICC) by one arbitrator appointed in accordance with said Rules. The seat of arbitration shall be London, England. The language of the arbitration shall be English.

Appendix A – Information about the processing

A.1. The purpose of the data processor's processing of personal data on behalf of the data controller is:

To provide the relevant and agreed services that the data controller has chosen in the Terms and Conditions. The data processor must not carry out any other processing than is necessary to fulfill these purposes.

A.2. The data processor's processing of personal data on behalf of the data controller shall mainly pertain to (the nature of the processing):

Providing the SaaS services, as described in the Terms and Conditions, including:

  • collection (regarding appointment booking/registration, and when this is confirmed, a copy goes into the customer's journal in TIMIT platform),
  • registration,
  • storage (Interim storage of incomplete forms. Storage in the customer's record in TIMIT platform follows the patient record regulations)
  • structuring
  • organization in a database,
  • adaptation or change
  • retrieval,
  • compilation,
  • deletion or destruction (Registrants must have their data deleted within 30 days in Medibrix.app in accordance with the GDPR. Deletion in the customer's record in TIMIT platform follows the patient record regulations.)
  • forwarding,
  • analysis and dissemination,
  • handover by transfer (According to consent or with authority in law or regulations
  • exchange of information with authorities.

A.3. The processing includes the following types of personal data about data subjects:

The SaaS service includes a range of personal data such as:

  • personal contact information - name, telephone number, e-mail address, physical address, etc.
  • identification number, gender and GP
  • work-related information – position/role, organisation, company, telephone number/e-mail/physical address for work
  • payment information – credit card number, expiry date, CVV number, other cardholder information, financial transactions, recipient, account number, amount, date/time/place of purchase, etc.
  • device information – brand and model, IP address, MAC address, serial number, location data (only anonymised personal data)
  • profiling data – analyzes and reports on registered persons (only anonymised health and personal data)
  • health information (special categories of personal information) as the service can also be linked to services that are subject to health legislation. This will depend on which services have been chosen by the data controller. For example for the Contact Lens Subscription service specifically, this includes contact lens prescription data such as sphere (SPH), cylinder (CYL), axis, base curve (BC), lens prescription, date of eye examination, and recommended lens types
  • content of messages the user sends to/from the TIMIT platform.

A.4. The processing includes the following categories of data subject:

The service typically includes an individual who is an end customer or user of the data controller, typically patients, but may also include children/pupils, guardians/legal representatives and healthcare personnel and employees, former healthcare personnel/employees and relatives.


Appendix B – Authorised sub-processors

B.1. Approved sub-processors and geographical location

On commencement of the Clauses, the data controller authorises the engagement of the following sub-processors:

Name Comp. no. Address Description Categories Location / Data Privacy Framework (DPF)
Edlib AS 912 349 403 8432 ALSVÅG, Norway Development Customer and user data: personal data EU/EEA
iTeams AS 951 445 746 Kongens gate 51, 8514 NARVIK, Norway Operation of Microsoft Azure, Office 365, IT-operations Customer and user data: encrypted personal data and encrypted sensitive information EU/EEA
Microsoft Ireland Operations Ltd 70 Sir John Rogerson´s Quay, DUBLIN 2, D02R296, Ireland Cloud provider Microsoft Azure / Office 365 Customer and user data: encrypted personal data and encrypted sensitive information EU/EEA. Data does not leave the EU/EEA – Lockbox has been implemented.
Helse Liaison AS 919 678 356 Gullstølsbotn 18, 5153 BØNES, Norway Message exchange through NHN. Backup VPN Customer and user data: personal data and sensitive information EU/EEA
Stø AS 927 611 929 Biskop Gunnerus' gate 14A, 0185 OSLO, Norway BankID Customer and user data: personal data and sensitive information, date of birth EU/EEA
Signicat AS 989 584 022 Beddingen 16, 7042 TRONDHEIM, Norway Backup BankID Customer and user data: personal data and sensitive information, date of birth EU/EEA
Link Mobility AS 992 434 643 Universitetsgata 2, 0164 OSLO, Norway SMS solution / payment solution Customer and user data: tel. number and card number etc. EU/EEA
Strex AS 985 867 569 Drammensveien 133, 0277 OSLO, Norway SMS solution / payment solution Customer and user data: tel. number and card number etc. EU/EEA

Service-specific data processors:

Name Comp. no. Address Description Categories Location / Data Privacy Framework (DPF)
Norsk Helsenett SF 994 598 759 Abels gate 9, 7030 TRONDHEIM, Norway Communicationos via Norwegian Helsenett and various related registries Customer and user data: personal data and sensitive information EU/EEA
Atlassian Inc. 350 Bush Street, Floor 13, San Francisco, California 94104, USA Statuspage for operational notifications in the platform Customer and user data: e-mail adress USA. Covered by DPF
Zisson AS 989 849 492 Nedre Vollgate 5, 0158 OSLO, Norway Solution for customer support Customer and user data: contact details and content of messages EU/EEA
Talkmore AS 876 839 342 Karvesvingen 5, 0579 OSLO, Norway Mobile company network Customer and user data: contact details EU/EEA
Make AS 993 555 002 Sandakerveien 116, 0484 OSLO, Norway Newsletter Customer and user data: e-mail adress EU/EEA
Twilio, Inc. 645 Harrison Street, Third Floor, San Francisco, California 94107, USA Video technology Customer and user data: e-mail adress USA. Covered by DPF
Stripe, Inc. 354 Oyster Point Boulevard, South San Francisco, California, 94080, USA Payment solution end users Customer and user data: tel. number and card number etc. USA. Covered by DPF
Hubspot, Inc. 25 1ST St Ste 200, Cambridge, Massachusetts 02141-1802, USA Customer follow-up Customer data; name, phone number, email address USA. Covered by DPF
Scrive ApS 368 906 49 Farvergade 2, 4., 1463 København, Denmark Digital signing via Contractbook Customer and user data - contact details EU/EEA

On commencement of the Clauses, the controller has approved the use of the above-mentioned sub-processors for the processing activity described above.


Appendix C – Instructions pertaining to the use of personal data

C.1. The subject of instruction

The processing as agreed in Appendices A and B.

C.2. Information security

The Data processor has the right and duty to make decisions about which technical and organizational security measures are to be implemented in order to establish the necessary (and agreed) security level. Safety measures are described below.

Technical measures

Security measures Description
Encryption – data in transit All data transfer between system components, including between the frontend and the cloud solution and towards subcontractors, is encrypted with TLS or VPN.
Encryption – data at rest All stored data is encrypted. The cloud provider does not have access to encrypted personal and health information without prior written consent from Medibrix and provision of the encryption key.
Handling of encryption keys Encryption keys are stored in dedicated "key vaults" with a "lockbox" function. The cloud service provider has no access to the keys.
Data isolation Customer data is kept logically separate from other customers' data in the platform. Access control and data structure ensure that no customer can access another customer's information.
Authentication and access Login to TIMIT platform supports BankID or equivalent.
Internal access control Technical personnel use "Just in time access" (JIT) limited to the necessary IP number and time period, combined with "Privileged Identity Management" (PIM) and role-based access control to get access only to the resource they need for the time they need it. Developers only have access to the development environment; a limited number of experienced developers can run scripts against production databases, but without access to personal data in clear text. The Cloud provider has no access to encryption keys or databases.
Logging and monitoring Healthcare personnel's access to patient data is always logged. Internal activity in the CMS is logged for Medibrix personnel. In the production environment, logging is controlled via PIM, where developers must have prior consent from senior personnel. Development and test environments do not contain any customer data and do not have the same logging requirements.
Anonymization and statistics Personal data is filtered out before being stored in logs, analysis systems, backups and test and development environments used for purposes other than primary processing. Application logs are automatically filtered so that no personally identifiable information is recorded. Medibrix does not use client-side tools to track end-user behavior in the application. Technical operational monitoring is performed server-side and is not linked to individual users or customer data. This processing is performed by Medibrix as the data controller and is not part of the processing on behalf of the customer.
Separate environments Development, test and production are technically separated. Production data and health information are only available in the production environment.
Change management Significant changes to system architecture, infrastructure or security configuration undergo a formal change process with risk assessment before implementation in the production environment. Changes are documented and approved by responsible personnel.
Backup and availability Automatic backup with permanent assurance of integrity and availability. A notification system for abnormal events ensures continuous uptime. Events are handled according to defined procedures with clear distribution of responsibilities, escalation and follow-up.
Security testing Medibrix conducts continuous security and penetration testing of the platform.
Vulnerability management Medibrix conducts ongoing vulnerability scanning of infrastructure and applications. Identified vulnerabilities are handled according to risk-based prioritization with defined deadlines for remediation.
Physical storage Data is stored exclusively in cloud-based data centers (no local storage). Primary storage is in the Netherlands with backup in Ireland. Data for the European market is not stored outside the EU/EEA.

Organisational measures

Security measures Description
Home/remote workplaces Equipment used for processing sensitive data must have access control, encrypted VPN, 2-factor authentication and virus protection. Sensitive data must not be stored locally, but only accessed via a secure connection to a central cloud solution as required by the business.
Confidentiality and integrity All Medibrix personnel are subject to contractual confidentiality obligations (employment agreements and confidentiality agreements). Customers enter into agreements based on standard contractual terms with data processor terms.
Personnel training Medibrix personnel with access to personal data undergo training in information security and privacy upon employment and regularly thereafter. The training covers applicable regulations, internal procedures and handling of sensitive health information.
Handling of information requests from cloud service provider Medibrix always refuses cloud providers' requests for disclosure of personal data from the platform, regardless of the reason.
Risk assessment Continuous risk assessments are carried out for all parts of the infrastructure and services, in line with the requirements of the Norm, GDPR and ISO/IEC 27001.
Availability restoration system Medibrix has an automatic notification system for abnormal events to ensure continuous uptime. Incidents are handled according to procedures for security and privacy incidents. The procedures contain instructions on escalation to the correct technical personnel, who serves as the backup in case the relevant personnel are unavailable, who has which responsibilities in handling the incident, what steps to take to analyze, troubleshoot and correct the problem, what follow-up work has to be done, etc.
Internal audit An internal audit of the information security management system (ISMS) is carried out annually.

Compliance and framework

Security measures Description
GDPR Medibrix complies with current regulations and is continuously working to meet new requirements.
ISO 27001 Medibrix is certified according to ISO 27001, which is the world's most recognized standard for information security. Medibrix continuously works to ensure that personal data remains protected.

Sub-processors and transfer basis

Security measures Description
Sub-processors within EU/EEA All sub-processors have entered into strict data processing agreements with Medibrix. Processing is limited to the delivery of services. Sub-processors are subject to the same obligations for information security and privacy as set out in this instruction.
Transfers outside the EU/EEA Medibrix's policy is that personal data shall not be processed outside the EU/EEA. A limited number of suppliers are located outside the EU/EEA; in most cases, they do not process personal data (as the data is encrypted). Where sub-processors process contact information and payment information, a valid transfer basis (SCCs) has been established and adequate security measures are in place.