Data Processing Addendum
Controller/processor terms, incorporated into your subscription.
- Effective
- September 15, 2026
- Last updated
- September 15, 2026
- Operator
- Artemius Labs LLC
CarePath is a documentation tool, not a healthcare provider. It does not practise medicine, diagnose, triage, prescribe, calculate doses or check interactions, and it never replaces a clinician's own judgment or instructions.
These are the controller–processor terms that apply automatically to every subscription where data protection law requires them. You do not need to ask for a DPA — you already have this one.
Incorporation and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Artemius Labs LLC (“Processor”) and the organization that subscribes (“Controller”), and applies where the Controller’s use of CarePath involves personal data subject to the GDPR, the UK GDPR, the Swiss FADP, or a US state privacy law that imposes equivalent terms.
No signature is needed: accepting the Terms accepts this DPA. If your procurement process requires a countersigned copy, request one at support@carepath.com.
The Controller determines the purposes and means of processing clinical content. The Processor processes it only to provide the service. For the Processor’s own account and billing records it acts as an independent controller, as described in the Privacy Policy.
Subject matter, duration and scope
- Subject matter. Converting clinician-authored instructions into patient-education comics, and the account and sharing features around that.
- Duration. For as long as the subscription is in effect, plus the retention periods in section 7.
- Nature and purpose. De-identification, storage, generation of text and images, hosting, transmission over share links, export to PDF, backup and deletion.
- Categories of data subject. The Controller’s clinicians, administrators and staff; and, in transit only, the patients whose material a clinician submits.
- Categories of personal data. Account identity and contact details, role and organization membership, audit records, billing contact; and clinical instruction text, which passes through de-identification and is stored only in de-identified form.
- Special category data. Health data may transit the de-identification boundary. It is not persisted. The Controller must not deliberately submit identifiers — see the Terms.
Processor obligations
The Processor will:
- process personal data only on the Controller’s documented instructions, of which the Terms and use of the product are the primary expression, unless required by law — in which case it will tell the Controller first, where lawful;
- ensure that personnel with access are bound by confidentiality;
- implement the technical and organisational measures described on the Security page, which satisfy Article 32;
- assist the Controller, taking account of the nature of processing, with data subject requests, data protection impact assessments and prior consultations;
- notify the Controller without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting its data;
- not sell personal data, not share it for cross-context behavioural advertising, and not use it outside the direct business relationship;
- not use Controller content to train or fine-tune models.
The Processor will tell the Controller if, in its opinion, an instruction infringes data protection law.
Controller obligations
The Controller warrants that it:
- has a lawful basis for the processing it instructs, and has given any notice or obtained any consent its jurisdiction requires;
- will not deliberately submit patient identifiers or other special category data beyond what the service is designed for;
- has assessed whether a Business Associate Agreement is required, and will not submit protected health information before one is in place if it is;
- will manage seats and remove leavers promptly, and will review comics before approving and sharing them;
- is responsible for the accuracy and legality of what it submits.
Subprocessing
The Controller gives general authorisation for the Processor to engage subprocessors. The current list, with purpose and data, is published at /legal/subprocessors.
The Processor will give at least 30 days’ notice by email before a new subprocessor begins processing, will impose data protection obligations on it no less protective than those in this DPA, and remains liable for its performance. The Controller may object on reasonable, documented data protection grounds within that period; the objection procedure and refund are described on the subprocessors page.
International transfers
Processing takes place primarily in the United States. Where personal data is transferred out of the EEA, the UK or Switzerland, the parties incorporate the European Commission’s Standard Contractual Clauses (Module Two, controller to processor; Module Three where the Controller is itself a processor) by reference, with the UK International Data Transfer Addendum for UK transfers and the FADP amendments for Swiss transfers.
- Clause 7 (docking) applies; Clause 9 option 2, general authorisation, with 30 days’ notice; Clause 11 without the independent dispute resolution option.
- Clause 17 governing law and Clause 18 forum: Ireland for EU transfers; England and Wales under the UK Addendum.
- Annexes I, II and III are populated by sections 2 and 5 of this DPA, the Security page, and the subprocessor list.
Where the SCCs and this DPA conflict, the SCCs prevail.
Return and deletion
The Controller can delete cases, revoke share links, and delete the organization at any time from within the product, and can export comics as PDFs before doing so.
On termination the Processor deletes remaining personal data within 30 days, except where retention is required by law (billing records) or where the data is already de-identified (the audit log). Deleted data falls out of encrypted backups on their ordinary rotation, at most 35 days. Certified deletion confirmation is available on request.
Audits
The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA, and will complete a reasonable security questionnaire once per twelve-month period.
On-site audits are available where a supervisory authority requires one or following a confirmed breach, on 30 days’ written notice, during business hours, no more than once a year, subject to confidentiality, and without access to other customers’ data or to systems that would compromise it. The Controller bears the cost of an audit it initiates.
Liability and precedence
Liability under this DPA is subject to the limitation of liability in the Terms of Service, to the extent permitted by applicable data protection law.
In the event of conflict, the order of precedence is: the Standard Contractual Clauses, then any signed Business Associate Agreement (for PHI), then this DPA, then the Privacy Policy, then the Terms of Service.
Questions about this document
Write to us and we'll answer within 5 business days. Use the email address on your account so we can find you.
support@carepath.comArtemius Labs LLC1209 Mountain Road Pl NE, Ste RCheyenne, WY 82001United States