Legal
GDPR & Data Processing
Last updated: 8 August 2026
This describes how AgiliMed processes personal data under the GDPR and the terms of our Data Processing Agreement (DPA), available on request.
Roles
For customer and PHI data processed through the product, the customer is the controller and AgiliMed is the processor. For our own marketing and account data, we are the controller.
Processing details
We process personal data only on documented instructions from the controller, for the purpose of providing the service, for the duration of the agreement.
Subprocessors
We use vetted subprocessors under written terms and maintain a current list, available on request. We give notice of changes so controllers can object.
International transfers
Where personal data is transferred outside its region, we rely on Standard Contractual Clauses and appropriate safeguards.
Security and breach notification
We apply appropriate technical and organizational measures and notify the controller without undue delay on becoming aware of a personal-data breach.
Data-subject rights and audit
We assist the controller in responding to data-subject requests and, subject to reasonable terms, support audits of our processing.
Requesting a DPA
To request a signed DPA with SCCs, contact hello@agilimed.com.