Data Processing Agreement
Version 1.1 – effective from 26 August 2026 Classification: Public
Medibrix AS, with registered address at Sjøgata 5, 9405 Harstad, Norway, and organization number 912 540 863 ("Medibrix" or "Data Processor") processes personal data on behalf of the Customer as specified in the Terms and Conditions or the TIMIT platform ("Data Controller").
Medibrix and the Data Controller are individually referred to as a "Party" and collectively as the "Parties".
1. Introduction
This Agreement sets out the rights and obligations of the Data Controller and the Data Processor when the Data Processor processes Personal Data on behalf of the Data Controller.
This Agreement is designed to ensure both Parties comply with the European Parliament and Council Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR").
In connection with the delivery of services agreed under the main agreement called the Terms and Conditions for the TIMIT platform (the "Terms and Conditions"), the Data Processor shall process Personal Data on behalf of the Data Controller in accordance with this Agreement. This Agreement applies exclusively to processing activities for which Medibrix acts as a Data Processor.
In the event of a conflict between this Agreement and any other agreement between the Parties relating to data processing, this Agreement shall prevail.
There are three appendices to this Agreement which form an integral part hereof:
- Appendix A: Detailed information on the processing activities, including purpose, nature and types of Personal Data, categories of Data Subjects, and duration of processing.
- Appendix B: Conditions for the use of Sub-Processors and the list of approved Sub-Processors.
- Appendix C: The Data Controller's instructions for processing, minimum security measures to be implemented by the Data Processor, and procedures for audits.
This Agreement does not exempt the Data Processor from obligation imposed by the GDPR or other applicable data protection legislation.
2. Rights and obligations of the Data Controller
The Data Controller is responsible for ensuring that the processing of Personal Data complies with the GDPR principles of accountability and data protection, applicable data protection legislation and this Agreement.
The Data Controller shall determine the purposes of the processing and the means by which such processing is to be carried out.
The Data Controller is responsible for ensuring that there is a valid legal basis for the processing of Personal Data by the Data Processor in accordance with the Data Controller's instructions.
3. The Data Processor´s Obligation to Act on Instructions
The Data Processor shall only process Personal Data according to documented instructions from the Data Controller, unless otherwise required by applicable law. If the law requires the Data Processor to process data beyond these instructions, the Data Processor must inform the Data Controller, unless prohibited by law. The Data Controller may issue additional documented instructions at any time during processing.
If the Data Processor believes any instruction violates data protection laws or the GDPR, it must immediately notify the Data Controller.
4. Confidentiality
The Data Processor may only allow access to Personal Data to individuals under its authority who are required to follow instructions and are bound by confidentiality, either by contract or by law. Access must be limited to what is strictly necessary.
The data processor must be able to demonstrate, upon request, that all authorized individuals are subject to the required confidentiality obligation.
5. Security of Processing
Both the Data Controller and the Data Processor must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. This includes considering available technology, implementation costs, processing nature, and potential harm to individuals' rights and freedoms.
Depending on relevance, such measures may include:
a. Pseudonymisation and Encryption b. Maintaining confidentiality, integrity, availability and resilience of systems c. Restoring data access quickly in case of incidents d. Regular testing and evaluation of security measures.
The Data Processor must also independently assess the risks to individuals' rights and freedoms and implement relevant safeguards. The Data Controller must provide necessary information for this assessment.
The Data Processor must support the Data Controller´s compliance with its security obligations by providing details on existing safeguards and any other necessary information.
6. Use of Sub-Processors
The Data Processor may only engage another processor if certain conditions are met, including a written agreement ensuring equivalent data protection responsibilities.
Sub-Processors must be approved in writing by the Data Controller. General approval is given for those listed in Appendix B. Written agreements must be in place with sub-processors, ensuring they follow the same obligations as in this Agreement. The Data Processor remains fully responsible for Sub-Processors´ compliance.
If the Data Processor intends to appoint a new sub-processor, the Data Controller must be notified at least one month in advance. The Data Controller can object to the change within 15 days. If the Data Controller objects to the change, either party may terminate the agreement with 15 days' notice, within 5 days after the objection. If the Data Controller does not terminate the agreement, the new sub-processor is considered accepted.
A copy of the sub-processor agreement must be shared with the Data Controller upon request, excluding commercial terms not relevant to data protection.
If a Sub-Processor fails to meet its obligations, the Data Processor remains fully liable to the Data Controller in terms of fulfilling the Sub-Processor's obligations.
7. Transfers to Third Countries or International Organisations
The Data Processor may only transfer Personal Data to outside the EU/EEA with the controller's prior approval and in accordance with applicable safeguards, such as the EU's standard contractual clauses ("SCCs").
The Data Controller has approved transfers listed in Appendix B. SCCs have been entered into with relevant third-countries and updated in line with new EU rules.
The Sub-Processors who are domiciled in the USA are all registered under the Data Privacy Framework subject to an adequacy decision.
8. Assistance to the Data Controller
The Data Processor must assist the Data Controller, where possible, in responding to requests from individuals exercising their rights (such as access, rectification, deletion, etc.). This includes helping the Data Controller meet its information obligations, as well as honoring individual rights including objection, data portability, and protection against automated decision-making.
The data processor must also assist with:
a. Reporting data breaches to the relevant data protection authority b. Notifying affected individuals of serious breaches c. Conducting data protection impact assessments d. Consulting authorities where high-risk processing cannot be mitigated.
The scope of technical and organizational measures for this assistance is detailed in Appendix C, including the level and type of support the Data Processor must provide.
9. Notification of Personal Data Breach
If a personal data breach occurs, the Data Processor must notify the Data Controller without undue delay after becoming aware of it.
This notification must be provided promptly so that the Data Controller can meet its obligation to report the breach to the data protection authority within the legally required timeframe.
The Data Processor must assist the Data Controller in preparing this report. This includes helping collect and provide the following information:
a. A description of the nature of the breach, including, when possible, the categories and approximate number of individuals and records affected. b. Likely consequences of the breach c. Measures taken or proposed to address the breach and, if relevant, mitigate its harmful effects.
10. Erasure and Return of Data
Upon termination of the data processing services, the Data Processor will notify the Data Controller of the upcoming deletion of Personal Data at least 30 days in advance, in accordance with the Terms and Conditions. The Data Controller is solely responsible for exporting, or confirming retention of, any Personal Data it is required to retain under applicable law - including statutory requirements for retention of patient journal records - before deletion.
Upon expiry of the notice period, the Data Processor must delete or destroy all personal data in its possession or control - whether on computers, devices, or in other formats - unless required to retain it by law or unless it exists in system backups retained under standard IT procedures, in which case such backup copies shall be deleted or destroyed in accordance with the Data Processor's standard backup rotation and remain subject to the security measures and confidentiality obligations of this Agreement until then.
The Data Controller may request to transfer their data in Medibrix's standard electronic format. Data Processor's work in this connection can be invoiced at the Medibrix´s applicable hourly rates. Alternatively, if agreed in writing, Medibrix may store the data on behalf of the Data Controller for a fee. In that case, this Agreement's terms will continue to apply.
11. Audit and Inspection
The Data Controller may carry out an audit once per year to assess how the Data Processor handles Personal Data. The Data Processor must support the audit. The Data Controller may also request a third party security audit. A report of that audit will be shared with the Data Controller upon request. The Data Processor may charge for audit-related work at the applicable hourly rates according to the Terms and Conditions.
The Data Processor will conduct internal security audits for relevant systems, and reports documenting these audits must be made available to the Data Controller upon request.
12. Liability
The liability terms set out in the Terms and Conditions also apply to any breaches of this Agreement.
13. Commencements and Termination
This Agreement enters into force at the same time as the Terms and Conditions and remains valid for as long as the Terms and Conditions is active.
14. Governing Law and Dispute Resolution
This Agreement is governed by the laws of Norway, without regard to its conflict of law principles.
Any dispute arising out of or in connection with this Agreement shall be attempted resolved through negotiations between the Parties. If not resolved within thirty (30) days, either Party may bring the dispute before the ordinary courts, with Oslo District Court as agreed venue.
Appendix A – Information about the processing
A.1. The purpose of the data processor's processing of personal data on behalf of the data controller is:
To provide the relevant and agreed services that the data controller has chosen in the Terms and Conditions. The data processor must not carry out any other processing than is necessary to fulfill these purposes.
A.2. The data processor's processing of personal data on behalf of the data controller shall mainly pertain to (the nature of the processing):
Providing the SaaS services, as described in the Terms and Conditions, including:
- collection (regarding appointment booking/registration, and when this is confirmed, a copy goes into the customer's journal in TIMIT platform),
- registration,
- storage (Interim storage of incomplete forms. Storage in the customer's record in TIMIT platform follows the patient record regulations)
- structuring
- organization in a database,
- adaptation or change
- retrieval,
- compilation,
- deletion or destruction (Registrants must have their data deleted within 30 days in Medibrix.app in accordance with the GDPR. Deletion in the customer's record in TIMIT platform follows the patient record regulations.)
- forwarding (including forwarding of images, consents, and self-declarations between professional users for treatment approval, and related SMS notifications),
- analysis and dissemination,
- handover by transfer (According to consent or with authority in law or regulations
- exchange of information with authorities.
A.3. The processing includes the following types of personal data about data subjects:
The SaaS service includes a range of personal data such as:
- personal contact information - name, telephone number, e-mail address, physical address, etc.
- identification number, gender and GP
- work-related information – position/role, organisation, company, telephone number/e-mail/physical address for work
- payment information – credit card number, expiry date, CVV number, other cardholder information, financial transactions, recipient, account number, amount, date/time/place of purchase, etc.
- device information – brand and model, IP address, MAC address, serial number, location data (only anonymised personal data)
- profiling data – analyzes and reports on registered persons (only anonymised health and personal data)
- health information (special categories of personal information) as the service can also be linked to services that are subject to health legislation. This will depend on which services have been chosen by the data controller. For example for the Contact Lens Subscription service specifically, this includes contact lens prescription data such as sphere (SPH), cylinder (CYL), axis, base curve (BC), lens prescription, date of eye examination, and recommended lens types
- content of messages the user sends to/from the TIMIT platform.
A.4. The processing includes the following categories of data subject:
The service typically includes an individual who is an end customer or user of the data controller, typically patients, but may also include children/pupils, guardians/legal representatives and healthcare personnel and employees, former healthcare personnel/employees and relatives.
Appendix B – Authorised sub-processors
B.1. Approved sub-processors and geographical location
On commencement of the Clauses, the data controller authorises the engagement of the following sub-processors:
| Name | Comp. no. | Address | Description | Categories | Location / Data Privacy Framework (DPF) |
|---|---|---|---|---|---|
| Edlib AS | 912 349 403 | 8432 ALSVÅG, Norway | Development | Customer and user data: personal data | EU/EEA |
| iTeams AS | 951 445 746 | Kongens gate 51, 8514 NARVIK, Norway | Operation of Microsoft Azure, Office 365, IT-operations | Customer and user data: encrypted personal data and encrypted sensitive information | EU/EEA |
| Microsoft Ireland Operations Ltd | 70 Sir John Rogerson´s Quay, DUBLIN 2, D02R296, Ireland | Cloud provider Microsoft Azure / Office 365 | Customer and user data: encrypted personal data and encrypted sensitive information | EU/EEA. Data does not leave the EU/EEA – Lockbox has been implemented. | |
| Helse Liaison AS | 919 678 356 | Gullstølsbotn 18, 5153 BØNES, Norway | Message exchange through NHN. Backup VPN | Customer and user data: personal data and sensitive information | EU/EEA |
| Stø AS | 927 611 929 | Biskop Gunnerus' gate 14A, 0185 OSLO, Norway | BankID | Customer and user data: personal data and sensitive information, date of birth | EU/EEA |
| Signicat AS | 989 584 022 | Beddingen 16, 7042 TRONDHEIM, Norway | Backup BankID | Customer and user data: personal data and sensitive information, date of birth | EU/EEA |
| Link Mobility AS | 992 434 643 | Universitetsgata 2, 0164 OSLO, Norway | SMS solution / payment solution | Customer and user data: tel. number and card number etc. | EU/EEA |
| Strex AS | 985 867 569 | Drammensveien 133, 0277 OSLO, Norway | SMS solution / payment solution | Customer and user data: tel. number and card number etc. | EU/EEA |
Service-specific data processors:
| Name | Comp. no. | Address | Description | Categories | Location / Data Privacy Framework (DPF) |
|---|---|---|---|---|---|
| Norsk Helsenett SF | 994 598 759 | Abels gate 9, 7030 TRONDHEIM, Norway | Communicationos via Norwegian Helsenett and various related registries | Customer and user data: personal data and sensitive information | EU/EEA |
| Atlassian Inc. | 350 Bush Street, Floor 13, San Francisco, California 94104, USA | Statuspage for operational notifications in the platform | Customer and user data: e-mail adress | USA. Covered by DPF | |
| Zisson AS | 989 849 492 | Nedre Vollgate 5, 0158 OSLO, Norway | Solution for customer support | Customer and user data: contact details and content of messages | EU/EEA |
| Talkmore AS | 876 839 342 | Karvesvingen 5, 0579 OSLO, Norway | Mobile company network | Customer and user data: contact details | EU/EEA |
| Make AS | 993 555 002 | Sandakerveien 116, 0484 OSLO, Norway | Newsletter | Customer and user data: e-mail adress | EU/EEA |
| Twilio, Inc. | 645 Harrison Street, Third Floor, San Francisco, California 94107, USA | Video technology | Customer and user data: e-mail adress | USA. Covered by DPF | |
| Stripe, Inc. | 354 Oyster Point Boulevard, South San Francisco, California, 94080, USA | Payment solution end users | Customer and user data: tel. number and card number etc. | USA. Covered by DPF | |
| Hubspot, Inc. | 25 1ST St Ste 200, Cambridge, Massachusetts 02141-1802, USA | Customer follow-up | Customer data; name, phone number, email address | USA. Covered by DPF | |
| Scrive ApS | 368 906 49 | Farvergade 2, 4., 1463 København, Denmark | Digital signing via Contractbook | Customer and user data - contact details | EU/EEA |
On commencement of the Clauses, the controller has approved the use of the above-mentioned sub-processors for the processing activity described above.
Appendix C – Instructions pertaining to the use of personal data
C.1. The subject of instruction
The processing as agreed in Appendices A and B.
C.2. Information security
The Data processor has the right and duty to make decisions about which technical and organizational security measures are to be implemented in order to establish the necessary (and agreed) security level. Safety measures are described below.
Technical measures
| Security measures | Description |
|---|---|
| Encryption – data in transit | All data in transit is is encrypted (TLS or VPN). |
| Encryption – data at rest | All stored data is encrypted. The cloud provider has no access to unencrypted personal and health information. |
| Handling of encryption keys | Encryption keys are stored in dedicated key management infrastructure separate from the data storage. The cloud service provider has no access to the keys. |
| Data isolation | Customer data is kept logically separate from other customers' data, and no customer can access another customer's information. |
| Authentication and access control | Login to TIMIT platform supports BankID or equivalent. |
| Internal access control | Access to personal data by Medibrix personnel is limited on a need-to-know basis, time-limited, and role-based. Access to production systems is restricted to authorized personnel only. The cloud provider has no access to encryption keys or personal data in clear text. The Cloud provider has no access to encryption keys or databases. |
| Logging and monitoring | Access to patient data is logged. Internal access to personal data by Medibrix personnel is logged and subject to prior authorization. Development and test environments do not contain personal data. |
| Anonymization and statistics | Personal data is filtered out of logs, analysis systems, backups and test and development environments not used for primary processing. Technical operational monitoring does not track individual users. This monitoring is performed by Medibrix as the data controller and is not part of the processing on behalf of the customer. |
| Separate environments | Development, test and production are technically separated. Production data and health information are only available in the production environment. |
| Change management | Changes to system architecture, infrastructure or security configuration undergo a formal risk-assessed change process production deployment. Changes are documented and approved by responsible personnel. |
| Backup and availability | Automatic backup with integrity and availability and an automatic notification system for abnormal events. Incidents are handled according to defined procedures with clear distribution of responsibilities, escalation and follow-up. |
| Security testing | Medibrix conducts continuous security and penetration testing of the platform. |
| Vulnerability management | Medibrix conducts ongoing vulnerability scanning and remediates findings based on risk-based prioritization. |
| Physical storage | Data is stored exclusively in cloud-based data centers (no local storage). Primary and backup storage are located within the EU/EEA. Data for the European market is not stored outside the EU/EEA. |
Organisational measures
| Security measures | Description |
|---|---|
| Home/remote workplaces | Equipment used to process sensitive data must use access control, encrypted VPN, two-factor authentication and virus protection. Sensitive data must not be stored locally, and is only accessible via a secure connection to the central cloud solution. |
| Confidentiality and integrity | All Medibrix personnel are subject to contractual confidentiality obligations (employment agreements and confidentiality agreements). |
| Personnel training | Medibrix personnel with access to personal data receive training in information security and privacy at onboarding and regularly thereafter. The training covers applicable regulations, internal procedures and handling of sensitive health information. |
| Handling of information requests from cloud service provider | Medibrix always refuses cloud providers' requests for disclosure of personal data from the platform, regardless of the reason. |
| Risk assessment | Continuous risk assessments are carried out for all parts of the infrastructure and services, in line with the requirements of the Norm, GDPR and ISO/IEC 27001. |
| Internal audit | An internal audit of the information security management system (ISMS) is carried out annually. |
Compliance and framework
| Security measures | Description |
|---|---|
| GDPR | Medibrix complies with current regulations and is continuously working to meet new requirements. |
| ISO 27001 | Medibrix is certified to ISO 27001, which is the world's most recognized standard for information security and works continuously to to keep personal data protected accordingly. |
Sub-processors and transfer basis
| Security measures | Description |
|---|---|
| Sub-processors within EU/EEA | All sub-processors have entered into data processing agreements with Medibrix. Processing is limited to the delivery of services. Sub-processors are subject to the same obligations for information security and privacy as set out in this instruction. |
| Transfers outside the EU/EEA | Medibrix's policy is that personal data shall not be processed outside the EU/EEA. A limited number of suppliers are located outside the EU/EEA; in most cases, they do not process personal data (as the data is encrypted). Where sub-processors process contact information and payment information, a valid transfer basis (SCCs) has been established and adequate security measures are in place. |