Data processing agreement

Last updated: 14 September 2026

Version and acceptance

Version dated 20 September 2026. This document sets out the proposed processing terms and annexes. Incorporation into a contract must be identified in a versioned acceptance or signature. Publication alone proves neither acceptance nor retroactive amendment of earlier contracts. Applicable law and the DPA actually accepted govern data protection obligations.

1. Parties and roles

The controller is the contracting clinic or professional identified in its contract and professional account. The processor is Rayan Chelouati, a self-employed professional trading as VRET, tax ID Y2655152T, Calle Mezquita, Edificio Velázquez, 11202 Algeciras (Cádiz), Spain; contact: [email protected]. A change of service-provider entity requires applicable communication and formalisation. VRET separately acts as controller for its own contracting, billing, support and security.

2. Subject matter, duration and operations

Processing covers the provision of virtual reality and mobile companion software for clinical work for the service duration and applicable return, erasure and restricted retention periods. Operations include collection, organisation, storage, consultation, authorised transmission, export, correction, restriction and erasure. The controller determines the care purpose, lawful grounds and retention instructions.

3. Individuals and categories

Individuals are adult or child patients receiving care from the controller. Data include pseudonymous codes and technical identifiers, virtual reality sessions and events, biofeedback measurements, tasks and answers, notes and free clinical text, snapshots and associated files, mobile credentials and minimal operational metadata. These are personal data and special-category data when they concern health. The clinic retains the link to civil identity; VRET does not require patient identity documents. Free text requires minimisation because professionals can enter identifiers into it.

4. Instructions and limits

The processor shall act only on documented instructions, including international transfers, unless required by applicable law, of which it shall give prior notice where legally permitted. It shall immediately inform the controller if it considers an instruction unlawful and suspend the affected action pending clarification. Clinical data shall not be used for advertising, sale, model training or incompatible own purposes. A new feature involving additional processing requires assessment and instructions before activation.

5. Authorised persons and support

Authorised persons shall be bound by confidentiality and access only information necessary for their role. The clinic manages professional assignments and reports departures or changes. Exceptional support access requires a reason, defined scope, authorisation where applicable, time limit, access record and subsequent review; it does not authorise shared accounts or permanent unrestricted clinical access.

6. Security and assessment

The processor shall apply measures proportionate to risk: clinic and patient isolation, permissions, encryption, credential controls, professional MFA, log minimisation, vulnerability management, traceable erasure and recovery. An effective-measures annex must accompany acceptance: enforced MFA, cross-channel erasure and complete recovery are not current guarantees until verified and activated. Acceptance of this version with those controls remains pending that verification. It shall assist the controller with security, impact assessments and prior consultation using available information. Neither a passing test nor this annex establishes ISO or ENS certification or complete absence of risk.

7. Assistance with rights

The clinic verifies identity, determines applicable rights and decides legal exceptions. The processor shall forward requests received and assist with access, export, correction, restriction, objection, portability and erasure where applicable. Operations must retain identifiers and verifiable states distinguishing active-system deletion, pending files and backups. Correction does not authorise falsification of clinical history: necessary traceability must remain.

8. Incidents

The processor shall notify the controller of personal data breaches without undue delay after becoming aware. It shall progressively provide the nature, approximate categories and volume, likely consequences, measures and contact details, and retain a minimal record of facts and decisions. The clinic assesses notifications to authorities and individuals for which it is responsible. The 72-hour period in EU GDPR Article 33 concerns the controller’s notification to the authority where required; it is not a waiting period for the processor.

9. Subprocessors and transfers

Subprocessors require the controller’s prior specific or general written authorisation and equivalent contractual obligations. Under general authorisation, VRET shall give 30 days’ notice of additions or replacements, allowing reasoned objection and resolution before affected processing starts. VRET remains responsible to the controller for subprocessor obligations as required by law. Transfers need a valid safeguard assessed for the particular destination and service; citing standard terms or selecting a European region is insufficient.

10. Termination, return and erasure

At the controller’s choice, data shall be returned or erased at termination and copies removed unless retention is legally required. Exceptions must identify category, ground, restricted access, owner and expiry. Loss of commercial access is not an instruction to erase clinical records. File and third-party tasks shall be retriable and their outcomes verified. The independent suppression record shall be reapplied before permitting access after restoration.

11. Verification and cooperation

The processor shall make available information necessary to demonstrate compliance with the processing terms and allow and contribute to audits, including inspections by the controller or its authorised auditor. Confidentiality, other clinics’ security and proportionate arrangements shall be coordinated without undermining that right. Findings shall have an owner, deadline and closure evidence. The processor shall cooperate with competent authorities as legally required.

12. Children and territorial scope

The clinic is responsible for age-appropriate information, capacity assessment, representation and relevant healthcare authorisations for children, without centralising identity documents in VRET. Intended scope is Spain, the EU and the UK; clinics established in the United States are outside the included customer market, separately from assessment of provider transfers. UK GDPR and current UK legislation apply to processing within their scope. Transfers from the UK to Spain are covered by the UK adequacy regulations for the EEA, with no need for an IDTA or standard contractual clauses. VRET is established in Spain and acts as processor on a B2B basis: it does not offer the clinical service directly to patients in the UK and does not determine the purposes of the processing of their data, so the current assessment is that Article 3(2) UK GDPR does not apply to it and, consequently, neither does the Article 27 representative obligation. Where that Article becomes applicable, VRET will designate a representative and give notice. This assessment was externally reviewed on 20 September 2026 and remains subject to periodic review and to any change in the service model.

Annex A. Recovery and retention

The approved, not yet verified and non-guaranteed recovery objective is 30 days, with necessary auxiliary backup references retained for at most 37 days. Target maximum data loss is 15 minutes and target service recovery is under two hours; these are objectives subject to complete recovery drills.

Transition status, 14 September 2026: older backup copies still exist. The new retention ceiling has not yet been demonstrated across every location. Historical copies will be removed through a recorded inventory after a complete restoration has been verified. The previous seven-day statement was inaccurate.

Deletion from active systems, pending file deletion and backup expiry are separate stages. Backup data must remain unavailable for ordinary use; restoration must reapply subsequent erasures before any user access. A clinic’s justified clinical-record retention is a separate obligation and does not justify keeping every technical backup indefinitely.

Annex B. Provider inventory and evidence status

This inventory distinguishes technical use from contractual evidence. A provider’s standard terms do not by themselves prove acceptance, a specific processing region or a transfer safeguard. The clinic may request the applicable supplier and contractual record at [email protected].

ServiceProcessingVerified scope
IONOS / self-managed infrastructureApplication server, PostgreSQL and MinIO objects (including the patient app exercise audio). Daily encrypted backup on operator-managed equipment at a separate physical location.Infrastructure observed and both locations in the EU. The specific physical region of the server and of the backup equipment are NOT documented: pending verification against the provider contract. No public surface names a country.
CloudflareProxy, TLS, network protection and delivery. Receives IP addresses and metadata and can access the traffic it decrypts.In use. Global network; account terms, subprocessors and transfers require review.
SentryTechnical errors with clinical-data and credential filters; client session replay disabled. From headset version 1.42.0, also headset errors and crashes (errors only: no sessions, traces or screenshots), without clinical data or patient identifiers. Prepared but not enabled in the patient app.Configured for web, API and headsets (from 1.42.0). EU region for events; the provider’s accounts, organisation settings and integrations may reside in the US. Project region, retention and contract evidence pending.
Resend / operational emailProfessional communications and alerts. Clinical information must not be included in email.Resend configured; verify every relay and mailbox in use, its terms and retention.
StripeProfessional subscriptions, payments and billing; not a recipient of clinical records.Configured for contracting; establish the roles and safeguards of the service used.
Auth0 / Okta (OIDC)Professional identity and access when the configured issuer is used; not patient records.OIDC support present; issuer, actual use, region and contract awaiting verification.
CalendlyCall scheduling: professional contact, calendar information and the originating campaign name (only with advertising-measurement consent).Public-site integration; activation and terms require verification. Do not use for clinical appointment content.
Google Analytics (GA4)Optional public-site analytics under VRET’s controllership and applicable consent.Integration conditional on configuration and consent; account region, transfers and retention require verification.
Microsoft ClarityOptional public-site visual analytics, with controls excluding the clinical area.Consent-gated integration; account configuration and safeguards require verification.
LinkedInOptional commercial-site advertising measurement; no authorised clinical content.Consent-gated integration; activation and transfer terms awaiting verification.
ProtonHuman contact, privacy and security mailboxes; avoid clinical attachments.Listed in the internal inventory; contract, retention and configuration require verification.
Grafana Cloud / Better StackTechnical metrics and availability, using an allowlist and no authorised clinical content.Configuration documented; review destinations, labels, retention and whether metrics can identify individuals.

Public-site analytics, scheduling, human mailboxes and identity-provider services require a separate inventory according to their actual activation. They are not authorised to receive clinical content. Optional analytics require the applicable consent controls. Conversational AI is disabled in the reviewed production configuration; new AI or cloud services require prior assessment and contractual approval.

Annex C. Control evidence

The evidence dossier must record deployed code and configuration, isolation and MFA tests, log canaries, erasure retries, restoration with suppression replay, physical-device results, assigned owners and review dates. Unresolved critical controls and missing formal obligations prevent closure of their scope. The dossier may be requested through [email protected]; synthetic test records are separated from production verification.

Data Processing Agreement (DPA) · VRET