⚠️ IMPORTANT LEGAL NOTICE
By using any of OWNIT ' software products, services, or applications (including but not limited to Optical Shop Management Software, Clinic Management System, or any SaaS solution), you hereby acknowledge and agree that a Data Processing Agreement (DPA) is automatically formed between OWNIT and your Clinic/Organization. The specific roles and responsibilities depend on your deployment method as outlined below. Continued use of our services constitutes your binding acceptance of this DPA.
SECTION 1
1. Cloud Infrastructure Details (Online Instance)
Data Flow Architecture
Clinic User → Cloudflare CDN → OVH Gravelines (EU) → Secure Database
All traffic encrypted end-to-end via TLS 1.3
OVH Gravelines Data Center
Location: Gravelines, Hauts-de-France, France (EU Region)
Compliance: GDPR compliant, ISO 27001 certified, HDS certified (French healthcare data hosting)
Physical Security: 24/7 monitoring, biometric access controls, redundant power and cooling
Data Residency: All patient data, PHI, and clinic records remain within EU borders
Cloudflare Global Network
Traffic Routing: All HTTPS requests routed through Cloudflare's global edge network
Security Features: DDoS protection, WAF (Web Application Firewall), SSL/TLS encryption
Data Processing: Cloudflare acts as a reverse proxy - no PHI is stored or logged by Cloudflare
GDPR Compliance: Cloudflare is GDPR compliant with Data Processing Addendum available
🇪🇺 EU Data Residency Guarantee: All clinic and patient data stored in the OVH Gravelines (France) data center. No data is replicated outside the European Union. OWNIT does not transfer or store any PHI outside EU borders.
SECTION 2
2. Two Deployment Scenarios - Roles Defined
OWNIT offers its software in two distinct deployment models. Your data processing roles and responsibilities depend entirely on which deployment you have chosen:
Scenario A: Cloud / SaaS Deployment (Data stored on OVH Gravelines servers)
Data Storage Location: OVH Gravelines (France) - OWNIT ' secure cloud infrastructure
Data Routing: Traffic passes through Cloudflare CDN for performance and security - no data storage occurs at Cloudflare
OWNIT Role: Data Processor - OWNIT processes and stores clinic data on behalf of the clinic on OVH infrastructure
Clinic Role: Data Controller - Clinic determines purposes and means of processing
DPA Applicability: This DPA applies in full. OWNIT acts as a processor handling PHI and personal data stored in OVH Gravelines.
Scenario B: On-Premise / Offline Deployment (Data stored on Clinic's own servers)
Data Storage Location: Clinic's own servers, local infrastructure, or clinic-controlled cloud
Data Routing: No data passes through OWNIT infrastructure. Application runs entirely on clinic's premises.
OWNIT Role: Software Provider Only - OWNIT provides the application software but DOES NOT access, store, or process any clinic data
Clinic Role: Sole Data Controller & Data Processor - Clinic has full control and responsibility for all data storage, security, and processing
DPA Applicability: This DPA serves as an acknowledgment that NO data processing occurs by OWNIT. Clinic assumes all data protection responsibilities.
SECTION 3
3. Responsibility Comparison by Deployment Type
| Responsibility Area |
Cloud/SaaS (OVH Gravelines + Cloudflare) |
On-Premise/Offline (Clinic Servers) |
| Data Storage Location |
OVH Gravelines, France (EU Region) |
Clinic's own servers / infrastructure |
| Data Processing by OWNIT |
YES - OWNIT processes data on OVH infrastructure |
NO - OWNIT never accesses clinic data |
| Data Routing |
Via Cloudflare (no storage, DDoS protection) |
Direct clinic network (no third-party routing) |
| Data Security Responsibility |
Shared - OWNIT secures OVH/Cloudflare infrastructure, Clinic secures access |
Clinic solely responsible |
| Data Backup Responsibility |
OWNIT manages automated backups within OVH infrastructure |
Clinic manages own backups |
| GDPR Compliance |
OWNIT ensures EU data residency (OVH Gravelines), Cloudflare GDPR compliant |
Clinic fully responsible for own GDPR compliance |
| Data Breach Notification |
OWNIT notifies clinic within 24 hours |
Clinic responsible for own breach detection/notification |
| Patient Data Access Requests |
Clinic responsible; OWNIT facilitates |
Clinic solely responsible |
| Data Deletion on Termination |
OWNIT deletes data from OVH servers upon request |
Clinic manages own data deletion |
SECTION 4
4. Cloud / SaaS Deployment - Infrastructure & Security Details
Applicable to: Clinics using OWNIT's cloud-hosted version where data resides on OVH Gravelines servers.
4.1 OVH Gravelines Data Center (Prime Hosting Location)
- Location: Gravelines, France (Hauts-de-France region) - within European Union
- Certifications: ISO 27001, ISO 27017, ISO 27018, HDS (Hébergement de Données de Santé - French healthcare data hosting certification)
- Physical Security: 24/7 on-site security, biometric access controls, CCTV surveillance
- Resilience: N+1 power redundancy, multiple fiber optic routes, Tier III equivalent infrastructure
- Data Replication: All data stored within OVH Gravelines data center - no cross-border data transfers
4.2 Cloudflare Global Edge Network (Traffic Routing Only)
- Role: Reverse proxy, DDoS mitigation, SSL/TLS termination, content delivery acceleration
- Data Processing: Cloudflare DOES NOT store, cache, or log any PHI or patient data
- Security Features: Web Application Firewall (WAF), rate limiting, bot mitigation
- Compliance: Cloudflare GDPR compliant, Data Processing Addendum (DPA) available upon request
- Data Residency: No data is stored on Cloudflare's edge nodes - all requests are proxied directly to OVH Gravelines
4.3 OWNIT as Data Processor (Cloud Deployment)
- OWNIT processes personal data and PHI only on documented instructions from the Clinic
- OWNIT implements AES-256 encryption for data at rest on OVH infrastructure
- OWNIT enforces TLS 1.3 encryption for all data in transit (clinic ↔ Cloudflare ↔ OVH)
- OWNIT notifies Clinic within 24 hours of any data breach affecting Clinic data
- OWNIT signs a Business Associate Agreement (BAA) upon request for HIPAA-covered entities
- OWNIT maintains GDPR compliance documentation and EU representative if required
4.4 Subprocessors (Cloud Deployment)
- Primary Hosting: OVH SAS (Gravelines, France) - Healthcare data certified (HDS)
- CDN & Security: Cloudflare, Inc. (reverse proxy only - no data storage)
- Database Services: Managed database services within OVH infrastructure
- Monitoring & Logging: Performance monitoring tools (anonymized metrics, no PHI)
- A complete list of subprocessors and their DPAs is available upon request
SECTION 5
5. On-Premise / Offline Deployment - Detailed Terms
Applicable to: Clinics using the on-premise version where data resides entirely on clinic-controlled infrastructure.
- Data Location: Clinic's own servers, local workstations, or clinic-managed cloud environment
- OWNIT Role: Software licensor only - provides the application code and updates
- No Data Access: OWNIT has no ability to access, view, retrieve, or process clinic data
- No Data Transmission: No clinic data is ever transmitted to OWNIT infrastructure (including OVH or Cloudflare)
- Clinic Responsibilities: Full responsibility for data security, backups, access controls, breach notification, and compliance with GDPR/HIPAA/local laws
- Support: OWNIT provides technical support for the software application but does not access clinic data during support
✅ Key Distinction: In on-premise deployment, NO DPA is required between OWNIT and Clinic regarding data processing because OWNIT never touches clinic data. This agreement serves as acknowledgment that the clinic is the sole controller and processor of all patient data.
SECTION 6
6. Data Breach Response (Cloud Deployment Only)
In the event of a personal data breach affecting data stored on OVH Gravelines infrastructure, OWNIT shall:
- Immediate Investigation: Initiate incident response protocol within 1 hour of breach detection
- Controller Notification: Notify Clinic within 24 hours via email and phone call
- Breach Details Provided: Provide description of breach, categories of data affected, number of affected individuals (if known), potential consequences, and mitigation measures taken
- Remediation: Take immediate steps to contain, investigate, and remediate the breach
- Regulatory Coordination: Cooperate with Clinic to notify affected patients and regulatory authorities as required by law (CNIL for French clinics, relevant EU DPA)
- Documentation: Maintain breach records for minimum of 6 years and provide to Clinic upon request
Note: This section applies ONLY to Cloud/SaaS deployment. For on-premise deployment, breach detection and notification is solely the Clinic's responsibility.
SECTION 7
7. Data Deletion & Return (Cloud Deployment Only)
Upon termination of services or Clinic's written request:
- OWNIT shall, at Clinic's choice, return all personal data to Clinic in a structured, machine-readable format (CSV, JSON, or XML) OR securely delete all personal data from OVH Gravelines infrastructure
- Data deletion shall be completed within 30 days of termination (or 60 days for archived backups)
- OWNIT shall provide written certification of data deletion within 14 days after completion
- Deidentified data (data rendered anonymous with no ability to re-identify) may be retained by OWNIT for product improvement and analytics
Note: For on-premise deployment, data deletion is solely the Clinic's responsibility as OWNIT never possesses the data.