Does amaise provide a data processing agreement (DPA)?
Yes. amaise provides a data processing agreement (Data Processing Agreement / DPA) that meets the requirements of relevant data protection regulations — including GDPR Art. 28, the Swiss nDSG, and applicable US data protection laws. The DPA is signed as part of the customer contract.
For US healthcare customers: amaise signs a Business Associate Agreement (BAA) upon request, addressing the specific requirements of the HIPAA Security Rule and Privacy Rule.
The DPA includes:
Complete list of subprocessors (named, with locations)
Data categories and processing purposes
Retention periods
Security obligations and technical measures
Audit rights for the customer
Obligation to notify in advance of changes to subprocessors with right to object
Deletion procedures and data return at contract end
Reporting obligations for data breaches (including HIPAA-specific deadlines for BAA customers)
Processing is primarily based on contractual necessity, not consent. For US customers, applicable State Privacy Law requirements are also addressed.
Data protection officer: Markus Baumgartner (CTO) is appointed as data protection officer (DPO). Contact: [email protected].
