Pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679
The User
A licensed psychotherapist, psychologist, coach, or counselor who subscribes to the AITACS CRM Service.
The Controller determines the purposes and means of processing End Client personal data.
Artem Chukov / AITACS CRM
Sole proprietor, registered in the State of Israel (עוסק פטור 345086623).
The Processor processes personal data solely on behalf of and under the documented instructions of the Controller.
This Data Processing Agreement ("DPA") forms part of and supplements the Terms of Service between the Controller and the Processor (together, the "Parties").
2.1. The Processor shall process personal data on behalf of the Controller solely for the purpose of providing the AITACS CRM Service, including data storage, synchronization, and AI-assisted clinical analysis.
2.2. The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which the Processor is subject (Art. 28(3)(a) GDPR).
2.3. This DPA applies for the duration of the Controller's active subscription to the Service and for 90 days following termination (the data retention period).
In accordance with Article 28(3) of the GDPR, the Processor shall:
5.1. The Controller shall ensure that there is a lawful basis for all processing of personal data that it instructs the Processor to carry out, including obtaining explicit consent from End Clients for the processing of special category data (health data) pursuant to Article 9(2)(a) of the GDPR.
5.2. The Controller shall provide End Clients with an informed consent form prior to entering their data into the Platform. A template is provided at Informed Consent Template.
5.3. The Controller shall use pseudonyms (nicknames) exclusively when entering client data into AI-enabled sections of the Platform, as indicated by the application interface.
5.4. The Controller shall comply with the minimum security requirements set forth in the User Security Requirements document.
5.5. The Controller shall notify the Processor without undue delay if it becomes aware of any data breach involving data processed through the Platform.
6.1. The Controller provides general written authorization for the Processor to engage the subprocessors listed in the Subprocessor List as of the effective date of this DPA.
6.2. The Processor shall notify the Controller at least 14 days in advance of any intended addition or replacement of subprocessors, providing the Controller with the opportunity to object.
6.3. If the Controller objects to a new subprocessor on reasonable data protection grounds and the Processor cannot accommodate the objection, the Controller may terminate the affected service component without penalty.
6.4. The Processor shall impose the same data protection obligations as set out in this DPA on each subprocessor by way of a contract (Art. 28(4) GDPR). The Processor remains fully liable for the performance of each subprocessor's obligations.
6.5. Current subprocessors and their data protection status:
| Subprocessor | Country | Function | Data Received | Safeguard |
|---|---|---|---|---|
| OpenAI, LLC | USA | AI processing | Pseudonym + de-identified clinical context only. No PHI per Safe Harbor. | OpenAI Data Processing Addendum (incorporates EU SCCs); zero-retention policy (0 days); data not used for model training; de-identified per 45 CFR §164.514(b) |
| Hetzner Online GmbH | Germany | MySQL database | All CRM data (encrypted in transit) | Hetzner Online GmbH DPA (incorporates EU SCCs); TLS 1.2+; server access controls |
| Google Firebase | USA | Authentication | Email, UID | Google Cloud Data Processing Terms (incorporates EU SCCs) |
| PayPal Holdings, Inc. | USA | Subscription payments (AITACS CRM); one-time purchases (ELIA); referral affiliate payouts | Billing data only (name, payment card, billing address). No clinical or patient data. | PayPal Privacy Policy and DPA; SCCs for EU users; PCI DSS Level 1 |
| Daily.co, Inc. | USA | WebRTC video session infrastructure (live therapy sessions — AITACS CRM) | Real-time audio/video streams during live sessions (not stored by Daily.co after session end) | Daily.co DPA incorporating EU SCCs. ⚠ No HIPAA BAA — see BAA §5 for US CE requirements. GDPR: SCCs in place; streaming data only. |
| OpenAI LLC — Whisper API | USA | Real-time audio transcription (AITACS CRM session recordings) | Raw audio file (temporary). Subject to OpenAI zero-retention policy (0-day retention). | OpenAI Data Processing Addendum (incorporates EU SCCs); zero-retention policy. ⚠ No HIPAA BAA for standard Whisper API — see BAA §5. |
| Google LLC — Calendar API | USA | OAuth calendar synchronisation — session scheduling (AITACS CRM) | Appointment metadata only (date, time, CE-defined event title). Transmitted to CE's own Google Calendar account. | Google Cloud Data Processing Terms (incorporates EU SCCs). PHI risk depends on CE's event naming practices. |
| Google LLC — Gemini API | USA | AI holonic analysis (NEVY Navigator; model: gemini-2.0-flash) | User-submitted goal, reality context, and meditation text. No PHI or identifying data transmitted. | Google Cloud Data Processing Terms (incorporates EU SCCs); data not used for model training under API terms. |
| Paddle.com Market Limited | Ireland 🇮🇪 (EEA) | Merchant of Record for NEVY Navigator subscription payments | Billing data only (name, payment card, billing address). No clinical or patient data. | Paddle DPA incorporating EU SCCs; PCI DSS Level 1; EEA entity (no adequacy decision needed for EU→IE transfers). |
7.1. The Processor may transfer personal data to subprocessors located outside the EU/EEA (currently: United States) only where appropriate safeguards are in place in accordance with Chapter V of the GDPR.
7.2. The primary safeguard mechanism is Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914), incorporated via each subprocessor's own Data Processing Agreement: OpenAI (GPT-4 & Whisper) — OpenAI Data Processing Addendum (incorporates EU SCCs); Google Firebase / Calendar API / Gemini API — Google Cloud Data Processing Terms (incorporates EU SCCs); Hetzner Online GmbH — Hetzner Online GmbH DPA (incorporates EU SCCs); Daily.co — Daily.co DPA (incorporates EU SCCs); PayPal — PayPal DPA with SCCs; Paddle.com Market Limited — registered in Ireland (EEA entity; no adequacy decision required for EU→EEA transfer).
7.3. For data transmitted to OpenAI specifically: this data is de-identified per HIPAA Safe Harbor (45 CFR §164.514(b)) before transmission. De-identified data does not constitute personal data under GDPR Article 4(1) where no reasonable means exist to re-identify the individual, providing an additional layer of transfer risk mitigation.
OpenAI (GPT-4): Low risk — data is de-identified before transfer; OpenAI DPA with SCCs;
zero-retention policy; API data not used for training.
OpenAI (Whisper): Medium risk — raw audio may contain voice biometrics; zero-retention
policy applies; no HIPAA BAA (US CEs: see BAA §5).
Hosting (Hetzner): Medium risk — mitigated by TLS encryption, access controls, and
Hetzner DPA with SCCs. Data remains in EU (Germany).
Firebase: Low risk — limited to email and UID; Google Cloud DPA with SCCs.
Google Calendar API: Low-to-medium risk — scheduling metadata only; PHI risk depends
on CE naming practices; Google Cloud DPA with SCCs.
Google Gemini API: Low risk — no PHI transmitted; de-identified goal/reality text;
Google Cloud DPA with SCCs.
Daily.co: Medium risk (GDPR) / High risk (HIPAA) — real-time AV streams; SCCs in
place for GDPR; no HIPAA BAA (US CEs: see BAA §5).
PayPal: Low risk — billing data only; no clinical data; PCI DSS Level 1; SCCs.
Paddle: Low risk — billing data only; EEA entity; no PHI; PCI DSS Level 1.
9.1. The Processor shall notify the Controller of any confirmed or suspected personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the GDPR.
9.2. The notification shall include:
a) A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned;
b) The name and contact details of the Processor's contact point;
c) A description of the likely consequences of the breach;
d) A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
9.3. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of each breach.
9.4. For the parallel HIPAA breach notification obligation (60-day window per 45 CFR §164.410), see the Business Associate Agreement.
10.1. Where the Controller is required to carry out a Data Protection Impact Assessment (DPIA) under Article 35 of the GDPR, the Processor shall provide reasonable assistance, taking into account the nature of processing and the information available to the Processor.
10.2. Given that the Platform processes special category data (health data) using automated means (AI analysis), the Controller is advised to conduct a DPIA before commencing use of the Platform in jurisdictions where this is required.
11.1. This DPA shall remain in effect for the duration of the Controller's subscription to the Service and for as long as the Processor processes personal data on behalf of the Controller.
11.2. Upon termination of the Service, the Processor shall, at the Controller's choice:
a) Return all personal data to the Controller in a structured, commonly used, machine-readable format (JSON export); or
b) Delete all personal data and certify such deletion in writing.
11.3. If the Controller makes no election within the 90-day retention period, the Processor shall permanently delete all personal data.
11.4. The obligations of this DPA that by their nature should survive termination (including confidentiality, data deletion, and cooperation with audits relating to the processing period) shall survive termination.
11.5. Extended retention — session transcripts. Notwithstanding the 90-day standard retention period, session transcripts and AI-generated clinical notes may be retained for up to seven (7) years from the date of creation in accordance with applicable HIPAA and state mental health record retention requirements, as described in the Privacy Policy §10.7. The protective obligations of this DPA — including confidentiality, security, data subject rights, and sub-processor requirements — shall continue to apply in full to all such retained data for the entire duration of its retention, regardless of whether the Controller's subscription has terminated. This DPA shall be deemed to survive termination solely for the purpose of governing such retained data until it is permanently deleted.
12.1. Each Party shall be liable for damage caused by processing that infringes the GDPR in accordance with Article 82 of the GDPR.
12.2. The Processor shall be liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to lawful instructions of the Controller (Art. 82(2) GDPR).
12.3. The Processor's aggregate liability under this DPA shall not exceed the amounts set forth in Section 7 of the Terms of Service.
13.1. This DPA shall be governed by and construed in accordance with the laws of the State of Israel, without prejudice to the mandatory provisions of the GDPR applicable to the Controller. In the event of any conflict between the provisions of this DPA or Israeli law and the requirements of the GDPR with respect to the processing of personal data of data subjects in the EU/EEA, the provisions of the GDPR shall take precedence as lex specialis.
13.2. Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution mechanism set forth in the Terms of Service.
14.1.1. A formal Data Protection Officer (DPO) pursuant to Article 37 GDPR has not been designated. The Processor is a sole proprietor whose core activities do not constitute large-scale systematic processing of special categories of personal data within the meaning of Article 37(1)(c) GDPR. The designation obligation under Art. 37(1)(b) is likewise not applicable, as the Processor's core activities do not consist of systematic monitoring of data subjects on a large scale.
14.1.2. All functions typically performed by a DPO — monitoring compliance, advising on processing activities, and acting as contact point for supervisory authorities and data subjects — are carried out directly by the Processor (Artem Chukov). The Processor's data protection contact is set out in §14.3 below.
14.2.1. Art. 13 GDPR (direct collection). When personal data is collected directly from Users (therapists, coaches, and other licensed professionals), the required information under Art. 13 GDPR — identity and contact details of the Processor, purposes and legal basis of processing, categories of recipients, retention periods, data subject rights, right to withdraw consent, and the right to lodge a complaint with a supervisory authority — is provided in the Privacy Policy (§§1–6, §10, §13).
14.2.2. Art. 14 GDPR (indirect collection — End Clients). Personal data of End Clients (therapy patients, coaching clients) is not collected directly by the Processor from the data subjects — it is entered into the Service by the Controller (the therapist). The Art. 14 GDPR information obligation for End Clients is therefore the responsibility of the Controller. The Processor provides the Informed Consent Template as a practical instrument to assist Controllers in meeting their Art. 14 obligations toward End Clients, including disclosure of: the identity of the Controller and Processor, the purposes and legal basis of processing, categories of recipients and subprocessors, retention periods, and the rights of the data subject under GDPR Articles 15–22.
14.2.3. Data subjects (End Clients) may exercise their rights under GDPR Articles 15–22 by contacting the Controller (their therapist or coach). The Controller shall involve the Processor where technically necessary, in accordance with DPA §4, obligation 5.
For DPA-related inquiries, data subject right requests, breach reports, or supervisory authority matters:
Artem Chukov — Data Processor / Data Protection Contact
Email: aitacs@skillbuilder.club
Web: skillbuilder.club | aitacscrm.app
Terms of Service · Privacy Policy · Business Associate Agreement (BAA) · Subprocessor List · User Security Requirements · Informed Consent Template · Incident Response Policy