image

Data Processing Agreement (DPA)

Between OWNIT and Medical/Healthcare Clinics

Cloud/SaaS Deployment On-Premise/Offline Deployment EU Data Residency (OVH Gravelines)
⚠️ IMPORTANT LEGAL NOTICE
By using any of OWNIT ' software products, services, or applications (including but not limited to Optical Shop Management Software, Clinic Management System, or any SaaS solution), you hereby acknowledge and agree that a Data Processing Agreement (DPA) is automatically formed between OWNIT and your Clinic/Organization. The specific roles and responsibilities depend on your deployment method as outlined below. Continued use of our services constitutes your binding acceptance of this DPA.
SECTION 1

1. Cloud Infrastructure Details (Online Instance)

Data Flow Architecture

Clinic User → Cloudflare CDNOVH Gravelines (EU)Secure Database

All traffic encrypted end-to-end via TLS 1.3

OVH Gravelines Data Center

Location: Gravelines, Hauts-de-France, France (EU Region)

Compliance: GDPR compliant, ISO 27001 certified, HDS certified (French healthcare data hosting)

Physical Security: 24/7 monitoring, biometric access controls, redundant power and cooling

Data Residency: All patient data, PHI, and clinic records remain within EU borders

Cloudflare Global Network

Traffic Routing: All HTTPS requests routed through Cloudflare's global edge network

Security Features: DDoS protection, WAF (Web Application Firewall), SSL/TLS encryption

Data Processing: Cloudflare acts as a reverse proxy - no PHI is stored or logged by Cloudflare

GDPR Compliance: Cloudflare is GDPR compliant with Data Processing Addendum available

🇪🇺 EU Data Residency Guarantee: All clinic and patient data stored in the OVH Gravelines (France) data center. No data is replicated outside the European Union. OWNIT does not transfer or store any PHI outside EU borders.
SECTION 2

2. Two Deployment Scenarios - Roles Defined

OWNIT offers its software in two distinct deployment models. Your data processing roles and responsibilities depend entirely on which deployment you have chosen:

Scenario A: Cloud / SaaS Deployment (Data stored on OVH Gravelines servers)

Data Storage Location: OVH Gravelines (France) - OWNIT ' secure cloud infrastructure

Data Routing: Traffic passes through Cloudflare CDN for performance and security - no data storage occurs at Cloudflare

OWNIT Role: Data Processor - OWNIT processes and stores clinic data on behalf of the clinic on OVH infrastructure

Clinic Role: Data Controller - Clinic determines purposes and means of processing

DPA Applicability: This DPA applies in full. OWNIT acts as a processor handling PHI and personal data stored in OVH Gravelines.

Scenario B: On-Premise / Offline Deployment (Data stored on Clinic's own servers)

Data Storage Location: Clinic's own servers, local infrastructure, or clinic-controlled cloud

Data Routing: No data passes through OWNIT infrastructure. Application runs entirely on clinic's premises.

OWNIT Role: Software Provider Only - OWNIT provides the application software but DOES NOT access, store, or process any clinic data

Clinic Role: Sole Data Controller & Data Processor - Clinic has full control and responsibility for all data storage, security, and processing

DPA Applicability: This DPA serves as an acknowledgment that NO data processing occurs by OWNIT. Clinic assumes all data protection responsibilities.

SECTION 3

3. Responsibility Comparison by Deployment Type

Responsibility Area Cloud/SaaS (OVH Gravelines + Cloudflare) On-Premise/Offline (Clinic Servers)
Data Storage Location OVH Gravelines, France (EU Region) Clinic's own servers / infrastructure
Data Processing by OWNIT YES - OWNIT processes data on OVH infrastructure NO - OWNIT never accesses clinic data
Data Routing Via Cloudflare (no storage, DDoS protection) Direct clinic network (no third-party routing)
Data Security Responsibility Shared - OWNIT secures OVH/Cloudflare infrastructure, Clinic secures access Clinic solely responsible
Data Backup Responsibility OWNIT manages automated backups within OVH infrastructure Clinic manages own backups
GDPR Compliance OWNIT ensures EU data residency (OVH Gravelines), Cloudflare GDPR compliant Clinic fully responsible for own GDPR compliance
Data Breach Notification OWNIT notifies clinic within 24 hours Clinic responsible for own breach detection/notification
Patient Data Access Requests Clinic responsible; OWNIT facilitates Clinic solely responsible
Data Deletion on Termination OWNIT deletes data from OVH servers upon request Clinic manages own data deletion
SECTION 4

4. Cloud / SaaS Deployment - Infrastructure & Security Details

Applicable to: Clinics using OWNIT's cloud-hosted version where data resides on OVH Gravelines servers.

4.1 OVH Gravelines Data Center (Prime Hosting Location)

  • Location: Gravelines, France (Hauts-de-France region) - within European Union
  • Certifications: ISO 27001, ISO 27017, ISO 27018, HDS (Hébergement de Données de Santé - French healthcare data hosting certification)
  • Physical Security: 24/7 on-site security, biometric access controls, CCTV surveillance
  • Resilience: N+1 power redundancy, multiple fiber optic routes, Tier III equivalent infrastructure
  • Data Replication: All data stored within OVH Gravelines data center - no cross-border data transfers

4.2 Cloudflare Global Edge Network (Traffic Routing Only)

  • Role: Reverse proxy, DDoS mitigation, SSL/TLS termination, content delivery acceleration
  • Data Processing: Cloudflare DOES NOT store, cache, or log any PHI or patient data
  • Security Features: Web Application Firewall (WAF), rate limiting, bot mitigation
  • Compliance: Cloudflare GDPR compliant, Data Processing Addendum (DPA) available upon request
  • Data Residency: No data is stored on Cloudflare's edge nodes - all requests are proxied directly to OVH Gravelines

4.3 OWNIT as Data Processor (Cloud Deployment)

  • OWNIT processes personal data and PHI only on documented instructions from the Clinic
  • OWNIT implements AES-256 encryption for data at rest on OVH infrastructure
  • OWNIT enforces TLS 1.3 encryption for all data in transit (clinic ↔ Cloudflare ↔ OVH)
  • OWNIT notifies Clinic within 24 hours of any data breach affecting Clinic data
  • OWNIT signs a Business Associate Agreement (BAA) upon request for HIPAA-covered entities
  • OWNIT maintains GDPR compliance documentation and EU representative if required

4.4 Subprocessors (Cloud Deployment)

  • Primary Hosting: OVH SAS (Gravelines, France) - Healthcare data certified (HDS)
  • CDN & Security: Cloudflare, Inc. (reverse proxy only - no data storage)
  • Database Services: Managed database services within OVH infrastructure
  • Monitoring & Logging: Performance monitoring tools (anonymized metrics, no PHI)
  • A complete list of subprocessors and their DPAs is available upon request
SECTION 5

5. On-Premise / Offline Deployment - Detailed Terms

Applicable to: Clinics using the on-premise version where data resides entirely on clinic-controlled infrastructure.

  • Data Location: Clinic's own servers, local workstations, or clinic-managed cloud environment
  • OWNIT Role: Software licensor only - provides the application code and updates
  • No Data Access: OWNIT has no ability to access, view, retrieve, or process clinic data
  • No Data Transmission: No clinic data is ever transmitted to OWNIT infrastructure (including OVH or Cloudflare)
  • Clinic Responsibilities: Full responsibility for data security, backups, access controls, breach notification, and compliance with GDPR/HIPAA/local laws
  • Support: OWNIT provides technical support for the software application but does not access clinic data during support
✅ Key Distinction: In on-premise deployment, NO DPA is required between OWNIT and Clinic regarding data processing because OWNIT never touches clinic data. This agreement serves as acknowledgment that the clinic is the sole controller and processor of all patient data.
SECTION 6

6. Data Breach Response (Cloud Deployment Only)

In the event of a personal data breach affecting data stored on OVH Gravelines infrastructure, OWNIT shall:

  1. Immediate Investigation: Initiate incident response protocol within 1 hour of breach detection
  2. Controller Notification: Notify Clinic within 24 hours via email and phone call
  3. Breach Details Provided: Provide description of breach, categories of data affected, number of affected individuals (if known), potential consequences, and mitigation measures taken
  4. Remediation: Take immediate steps to contain, investigate, and remediate the breach
  5. Regulatory Coordination: Cooperate with Clinic to notify affected patients and regulatory authorities as required by law (CNIL for French clinics, relevant EU DPA)
  6. Documentation: Maintain breach records for minimum of 6 years and provide to Clinic upon request

Note: This section applies ONLY to Cloud/SaaS deployment. For on-premise deployment, breach detection and notification is solely the Clinic's responsibility.

SECTION 7

7. Data Deletion & Return (Cloud Deployment Only)

Upon termination of services or Clinic's written request:

  • OWNIT shall, at Clinic's choice, return all personal data to Clinic in a structured, machine-readable format (CSV, JSON, or XML) OR securely delete all personal data from OVH Gravelines infrastructure
  • Data deletion shall be completed within 30 days of termination (or 60 days for archived backups)
  • OWNIT shall provide written certification of data deletion within 14 days after completion
  • Deidentified data (data rendered anonymous with no ability to re-identify) may be retained by OWNIT for product improvement and analytics

Note: For on-premise deployment, data deletion is solely the Clinic's responsibility as OWNIT never possesses the data.