Data processing agreement
Data processing terms
These terms summarize how Kin Health AS ("Kin Health", "Healable", "we") processes personal data on behalf of a healthcare organization that uses the Healable workspace. They form the basis of the data processing agreement entered into with each customer. Where a signed data processing agreement or customer agreement differs from this summary, that signed agreement takes precedence. This page is not legal advice.
Roles
For clinical and patient data that an organization places into a vault, the organization is the data controller and Healable is the data processor. We process that data only on the controller's documented instructions, unless required otherwise by law — in which case we inform the controller before processing, unless the law prohibits it.
Data controller
The healthcare organization
Data processor
Kin Health AS (Healable)
Subject matter, duration, nature and purpose
We process personal data to provide the Healable workspace: secure storage in access-controlled vaults, and AI-assisted drafting and organizing as work support for the controller's personnel. Processing lasts for as long as the customer agreement is in effect.
Categories of data and data subjects
Depending on how the controller uses the service, processing may involve the categories below. The data subjects are the controller's patients and its own staff who use the service.
| Category | Examples | Where it lives |
|---|---|---|
| Clinical content | Health and record material placed into vaults, which may include special categories of personal data under Article 9 GDPR | Encrypted, access-controlled vaults (EU/EEA) |
| Account data | Names, work email, and organization of the staff who use the service | Service database (EU/EEA) |
| Usage and technical data | Audit logs and technical operational logs | Service infrastructure (EU/EEA) |
Our obligations as processor
We commit to:
- Process personal data only on the controller's documented instructions.
- Ensure that people authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see below and our security page).
- Assist the controller, taking the nature of processing into account, in responding to data-subject requests and in meeting its obligations under Articles 32–36 GDPR, including data protection impact assessments.
- Make available the information needed to demonstrate compliance with Article 28 GDPR.
Security measures
We apply encryption in transit and at rest, personal and restricted access, audit logging, and purpose-bound isolation of data within vaults. The technical and organizational measures are described on our security page, and the specific measures for a customer are set out in the signed agreement.
Sub-processors
The controller gives general authorization for us to engage sub-processors to deliver the service. We bind each sub-processor to data-protection obligations equivalent to these terms under Article 28 GDPR, and we remain responsible for their performance. Our current sub-processors are:
| Sub-processor | Purpose | Data region | Safeguards |
|---|---|---|---|
| Google Cloud | Hosting and AI processing, including Vertex AI | EU EU regions | ISO 27001, SOC 1–3, EU data residency |
| Stripe | Payment processing for billing | EU Ireland (EU) | PCI DSS Level 1; card data not stored by Healable |
| Google Workspace (Gmail) | Transactional email, support, and operations | EU EU/EEA | Bound by a DPA; processed within the EU/EEA |
Changes to sub-processors
We will inform the controller of any intended addition or replacement of a sub-processor, giving the controller the opportunity to object on reasonable data-protection grounds. An up-to-date list is available on request at hei@healable.no.
Data location
We process personal data within the EU/EEA, on EU cloud regions. We do not transfer personal data outside the EEA.
Personal data breaches
If we become aware of a personal data breach affecting the controller's data, we notify the controller without undue delay and provide the information the controller needs to meet its own notification obligations under Articles 33 and 34 GDPR. The controller is responsible for notifying its supervisory authority and affected data subjects where required.
Audit
We make available to the controller the information needed to demonstrate compliance with these terms, and we allow for and contribute to audits, including inspections, conducted by the controller or an auditor it mandates, on reasonable prior notice and subject to confidentiality, as set out in the signed agreement.
Return and deletion
On termination of the service, we delete or return the controller's personal data in accordance with the customer agreement and the controller's documented instructions, and delete existing copies unless storage is required by law. The timing and method of deletion or return follow the customer agreement and the controller's instructions.
Governing law
These terms and the data processing agreement are governed by Norwegian law, without prejudice to mandatory data-protection rules.
Contact and supervisory authority
Questions about this agreement, or a request for the full signed agreement, can be directed to us. The controller may also lodge a complaint with the supervisory authority.
Data processor
Kin Health AS (Healable)
Supervisory authority
Datatilsynet
DPA, answered
Can we review the agreement before onboarding?
Yes. Ask for access and include that you want to review processor terms.
Does this page replace legal review?
No. It explains the approach; your organization should review the actual agreement.
Is this relevant for GDPR?
Yes. A data processing agreement is part of responsible GDPR handling when a processor handles personal data on behalf of a controller.