according to Art. 28 GDPR — Version 1.3, July 2026
between
[Therapist - Name inserted at signup]
[Address inserted at signup]
- hereinafter "Controller" or "Client" -
and
Intermac systems
Sendnicher Str. 58a
56072 Koblenz
Germany
Email: nd@intermac.de
- hereinafter "Processor" or "Service Provider" -
The Processor provides a web-based platform for:
This DPA applies for the duration of the Controller's use of the platform.
Processing serves exclusively to provide the platform functions for therapy documentation.
(1) The Processor processes personal data exclusively according to documented instructions from the Controller, unless required by EU or German law to process.
(2) Instructions are issued through:
(3) If the Processor considers an instruction to be unlawful, they will inform the Controller immediately.
The Controller undertakes, where personal patient data is processed via the platform, to obtain the necessary consents from their patients for data processing according to Art. 6, 9 GDPR.
The Controller is solely responsible for:
The Controller is responsible for the accuracy and currency of entered data.
The Processor commits all persons involved in processing to confidentiality.
The Processor implements appropriate technical and organizational measures according to Art. 32 GDPR, in particular:
A detailed description of TOMs is provided in Annex 1.
The Processor reports data breaches immediately (within 24h at the latest) to the Controller with all relevant information according to Art. 33 GDPR.
(1) The Processor is aware that the Controller is bound by the criminally sanctioned professional secrecy obligation under § 203(1) of the German Criminal Code (StGB) as a member of a profession subject to professional confidentiality.
(2) The Processor undertakes to maintain secrecy regarding all information accessible to them in the course of the data processing that qualifies as a secret under § 203 StGB. The Processor has been informed pursuant to § 203(4) StGB that unauthorized disclosure of such secrets constitutes a criminal offense.
(3) The Processor obligates all persons involved in the processing as well as any engaged sub-processors to the same secrecy and informs them of the criminal liability under § 203(4) StGB.
(4) This obligation continues beyond the termination of the contract.
The Controller hereby consents to the engagement of the following sub-processors:
| Sub-processor | Service | Location | Note |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting, data center | Germany (EU) | DPA in place, BSI C5 Type 2, ISO 27001:2022 |
| Microsoft Ireland Operations Ltd. | Key management (Azure Key Vault) | Germany (Frankfurt, Germany West Central) | Microsoft Products and Services DPA per Art. 28 GDPR |
| OpenAI Ireland Ltd. | AI processing (transcription, documentation) | EU (Data Residency, Zero Data Retention) | DPA per Art. 28 GDPR in place, additional BAA |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) | DPA in place, PCI DSS Level 1 |
| Resend | Transactional emails | EU | DPA in place, SOC 2 |
When planning to add or change sub-processors, the Processor will inform the Controller at least 14 days in advance via email. The Controller may object within 14 days for data protection reasons.
The Processor obligates sub-processors to the same data protection obligations as themselves.
The Processor appropriately supports the Controller in fulfilling data subject rights (access, rectification, deletion, etc.).
If a data subject contacts the Processor directly, they will be referred to the Controller without delay.
The platform offers the following functions to fulfill data subject rights:
After termination of use, the Processor deletes all personal data of the Controller within 30 days, unless legal retention obligations exist.
The Controller can download all data via the export function before contract termination.
Data in encrypted backups will be deleted after the regular backup cycle (max. 90 days).
The Processor provides the Controller with information demonstrating compliance with obligations upon request:
The Controller has the right to conduct an audit once a year or have it conducted by an independent third party bound to confidentiality. Costs are borne by the Controller.
Additional audits are permissible in case of concrete suspicion of data protection violations.
(1) Liability is governed by the statutory provisions of the GDPR, in particular Art. 82 GDPR.
(2) The Processor is only liable for damages arising from breach of their obligations under this DPA.
(3) The Controller is liable for all damages arising from unlawful instructions or lack of patient consent.
Both parties commit to treating all information obtained in the course of this agreement as confidential.
Amendments and supplements to this agreement require written form (electronic form also permissible).
Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.
German law applies.
Place of jurisdiction is Koblenz, Germany.
I have read and accept the Data Processing Agreement (DPA) and Privacy Policy.
Date: [Automatic at signup]
Therapist: [Name at signup]
Accepted by: Electronic consent at account creation
A Data Protection Impact Assessment (DPIA) was conducted with the result:
Note: This agreement is concluded electronically during registration. Consent is given by activating the checkboxes during the signup process.