Islania Holistics

Personal Data Processing Agreement (DPA)

Annex to the Practitioner Collaboration Agreement

1. Purpose and Framework

This agreement defines the respective obligations of the Platform and the Practitioner concerning the processing of Users' personal data, in the context of the performance of the Practitioner Collaboration Agreement, in accordance with the GDPR (EU) 2016/679 and the Belgian Act of 30 July 2018.

2. Allocation of Roles

2.1 The Platform is the Data Controller for: account management, connection, payments, security and the operation of the service.

2.2 The Practitioner is the autonomous Data Controller for the notes and information they choose to collect within the care relationship with the User. The Platform neither requests nor stores a medical record; any sensitive information spontaneously shared falls under the sole responsibility of the Practitioner and of the User who chose to share it.

2.3 For the provision of the calendar tool and the technical hosting of certain data entered by the Practitioner, the Platform may act as the Practitioner's Data Processor. In this case, Articles 4 to 10 apply.

3. Nature and Purpose of the Processing (processing on behalf)

  • Subject matter: hosting and technical processing of Users' data to enable the provision of the service.
  • Duration: the duration of the Agreement.
  • Nature of the operations: collection, recording, storage, consultation, structuring.
  • Categories of data subjects: the Practitioner's Users / patients.
  • Categories of data: identification, contact details, appointments and appointment proposals (dates, times, workplaces, prices, statuses, cancellation logs), messages exchanged in the internal messaging system and associated attachments (images, PDFs), traceable legal acceptances and consents (Terms, Privacy Policy, Booking Terms, Health Disclaimer, waiver of the 14-day right of withdrawal for training courses), and, where applicable, personal information or feelings that the User chooses to share spontaneously with the Practitioner.

4. Obligations of the Platform as Data Processor

The Platform undertakes to:

  • process the data only on the documented instruction of the Practitioner;
  • ensure confidentiality (staff bound by a confidentiality obligation);
  • implement the appropriate security measures (Art. 32 GDPR): encryption, access control, backups, logging;
  • engage sub-processors only with authorisation and by imposing the same obligations on them;
  • assist the Practitioner in responding to requests to exercise rights and with their security, breach notification and impact assessment obligations;
  • notify the Practitioner of any data breach as soon as possible (at the latest 48 hours after becoming aware of it);
  • at the end of the agreement, return or delete the data at the Practitioner's choice, unless there is a legal retention obligation.

5. Obligations of the Practitioner

The Practitioner undertakes to:

  • process only the data that is strictly necessary (minimisation);
  • have a valid legal basis for each processing, and obtain the User's explicit consent (Art. 9.2.a) before documenting any sensitive information the latter may have shared;
  • inform Users of their own processing operations;
  • respect professional secrecy and ethical rules;
  • document their processing operations (record) and secure their own access.

6. Sub-processors

The Practitioner authorises the Platform to make use of the technical processors listed in the Privacy Policy (host, payment, email, etc.). The Platform informs the Practitioner of any change and allows them to object on legitimate grounds.

7. Transfers Outside the EU

No transfer outside the EEA is carried out without appropriate safeguards (standard contractual clauses, adequacy decision).

8. Rights of Data Subjects

The Platform provides the technical features enabling the Practitioner and Users to exercise the rights of access, rectification, erasure, portability, etc., and assists the Practitioner in processing these requests.

9. Data Breach

Each Party cooperates to identify, document and, where applicable, notify the Data Protection Authority (within 72 hours) and the data subjects of any personal data breach presenting a risk.

10. Audit

The Practitioner may, subject to reasonable notice and while respecting the confidentiality of the Platform's other clients, request a demonstration of compliance with the obligations of this agreement (documentation, certificates, certifications).

11. Duration

This agreement takes effect for the entire duration of the Practitioner Collaboration Agreement and for the entire period during which data is processed.