Skip to main content

Does amaise provide a data processing agreement (DPA)?

Written by amaise Support

Does amaise provide a data processing agreement (DPA)?

Yes. amaise provides a data processing agreement (Data Processing Agreement / DPA) that meets the requirements of relevant data protection regulations — including GDPR Art. 28, the Swiss nDSG, and applicable US data protection laws. The DPA is signed as part of the customer contract.

For US healthcare customers: amaise signs a Business Associate Agreement (BAA) upon request, addressing the specific requirements of the HIPAA Security Rule and Privacy Rule.

The DPA includes:

  • Complete list of subprocessors (named, with locations)

  • Data categories and processing purposes

  • Retention periods

  • Security obligations and technical measures

  • Audit rights for the customer

  • Obligation to notify in advance of changes to subprocessors with right to object

  • Deletion procedures and data return at contract end

  • Reporting obligations for data breaches (including HIPAA-specific deadlines for BAA customers)

Processing is primarily based on contractual necessity, not consent. For US customers, applicable State Privacy Law requirements are also addressed.

Data protection officer: Markus Baumgartner (CTO) is appointed as data protection officer (DPO). Contact: [email protected].

Did this answer your question?