Healable

Data processing agreement

Data processing terms

Last updated: 21 June 2026.

These terms summarize how Kin Health AS ("Kin Health", "Healable", "we") processes personal data on behalf of a healthcare organization that uses the Healable workspace. They form the basis of the data processing agreement entered into with each customer. Where a signed data processing agreement or customer agreement differs from this summary, that signed agreement takes precedence. This page is not legal advice.

Roles

For clinical and patient data that an organization places into a vault, the organization is the data controller and Healable is the data processor. We process that data only on the controller's documented instructions, unless required otherwise by law — in which case we inform the controller before processing, unless the law prohibits it.

Data controller

The healthcare organization

Determines the purposes and means of processingResponsible for the lawful basis and for informing patients

Data processor

Kin Health AS (Healable)

Processes personal data on the controller's behalfActs only on the controller's documented instructions

Subject matter, duration, nature and purpose

We process personal data to provide the Healable workspace: secure storage in access-controlled vaults, and AI-assisted drafting and organizing as work support for the controller's personnel. Processing lasts for as long as the customer agreement is in effect.

Work support, not a medical device Healable produces drafts for review and organizes the clinician's own source material. It produces no independent clinical findings and makes no diagnostic, prognostic, monitoring, or treatment decisions. It is a work-support tool, not a decision-support tool, and is not a CE-marked medical device; the controller's personnel remain responsible for any content they finalize.

Categories of data and data subjects

Depending on how the controller uses the service, processing may involve the categories below. The data subjects are the controller's patients and its own staff who use the service.

Special-category data stays in EU vaults Clinical content, including Article 9 health data, is stored encrypted in access-controlled vaults hosted in the EU/EEA and is processed only to deliver the service on the controller's instructions.
CategoryExamplesWhere it lives
Clinical contentHealth and record material placed into vaults, which may include special categories of personal data under Article 9 GDPREncrypted, access-controlled vaults (EU/EEA)
Account dataNames, work email, and organization of the staff who use the serviceService database (EU/EEA)
Usage and technical dataAudit logs and technical operational logsService infrastructure (EU/EEA)

Our obligations as processor

We commit to:

  • Process personal data only on the controller's documented instructions.
  • Ensure that people authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see below and our security page).
  • Assist the controller, taking the nature of processing into account, in responding to data-subject requests and in meeting its obligations under Articles 32–36 GDPR, including data protection impact assessments.
  • Make available the information needed to demonstrate compliance with Article 28 GDPR.

Security measures

We apply encryption in transit and at rest, personal and restricted access, audit logging, and purpose-bound isolation of data within vaults. The technical and organizational measures are described on our security page, and the specific measures for a customer are set out in the signed agreement.

Sub-processors

The controller gives general authorization for us to engage sub-processors to deliver the service. We bind each sub-processor to data-protection obligations equivalent to these terms under Article 28 GDPR, and we remain responsible for their performance. Our current sub-processors are:

Sub-processorPurposeData regionSafeguards
Google CloudHosting and AI processing, including Vertex AI EU EU regions ISO 27001, SOC 1–3, EU data residency
StripePayment processing for billing EU Ireland (EU) PCI DSS Level 1; card data not stored by Healable
Google Workspace (Gmail)Transactional email, support, and operations EU EU/EEA Bound by a DPA; processed within the EU/EEA

Changes to sub-processors

We will inform the controller of any intended addition or replacement of a sub-processor, giving the controller the opportunity to object on reasonable data-protection grounds. An up-to-date list is available on request at hei@healable.no.

Data location

We process personal data within the EU/EEA, on EU cloud regions. We do not transfer personal data outside the EEA.

Personal data breaches

If we become aware of a personal data breach affecting the controller's data, we notify the controller without undue delay and provide the information the controller needs to meet its own notification obligations under Articles 33 and 34 GDPR. The controller is responsible for notifying its supervisory authority and affected data subjects where required.

Audit

We make available to the controller the information needed to demonstrate compliance with these terms, and we allow for and contribute to audits, including inspections, conducted by the controller or an auditor it mandates, on reasonable prior notice and subject to confidentiality, as set out in the signed agreement.

Return and deletion

On termination of the service, we delete or return the controller's personal data in accordance with the customer agreement and the controller's documented instructions, and delete existing copies unless storage is required by law. The timing and method of deletion or return follow the customer agreement and the controller's instructions.

Governing law

These terms and the data processing agreement are governed by Norwegian law, without prejudice to mandatory data-protection rules.

Contact and supervisory authority

Questions about this agreement, or a request for the full signed agreement, can be directed to us. The controller may also lodge a complaint with the supervisory authority.

Data processor

Kin Health AS (Healable)

Ringveien 36A1482 Nittedal, Norwayhei@healable.no

Supervisory authority

Datatilsynet

P.O. Box 458 Sentrum0105 Oslo, Norwaydatatilsynet.no

DPA, answered

Can we review the agreement before onboarding?

Yes. Ask for access and include that you want to review processor terms.

Does this page replace legal review?

No. It explains the approach; your organization should review the actual agreement.

Is this relevant for GDPR?

Yes. A data processing agreement is part of responsible GDPR handling when a processor handles personal data on behalf of a controller.