Data Processing Agreement
Agreement under Article 28 of Regulation (EU) 2016/679, governing the relationship between you, the professional using the platform for your patients, and the operator of the platform.
Versione 2.1, in force from 7 settembre 2026. Acceptance is recorded with the date, time and version of the text.
1. Ruoli
By registering, you are the data controller for your patients' data. beassessed (the platform operator) acts as data processor under Article 28 GDPR, limited to the data processed through this tool.
2. Oggetto e finalità
The processor processes the data (personal details and health data) solely in order to provide you with the service of administering questionnaires, calculating scores automatically and generating the technical report, in accordance with your documented instructions (your use of the platform itself).
3. Obligations of the processor
- It processes the data only for the purposes stated above and in accordance with your documented instructions, unless otherwise required by law, in which case it informs you before proceeding.
- Confidentiality. Persons authorised to process the data are bound to confidentiality by law or by a written undertaking. Access to your patients' data is reserved to you: raw scores and the scoring keys of the instruments are not accessible to other registered professionals, and access to clinical records is logged.
- Garantisce misure di sicurezza adeguate ai sensi dell'art. 32: connessione cifrata; credenziali personali con password conservate come impronta; secondo fattore di autenticazione disponibile su ogni account; limitazione dei tentativi di accesso; isolamento dei dati per professionista; protezione dei moduli contro invii forzati da altri siti; registro degli accessi ai dati clinici, tenuto in sola aggiunta; cifratura dei contenuti clinici a riposo nel database, con chiave che non è conservata nel database stesso; copie di sicurezza cifrate. Un limite dichiarato invece che taciuto: la chiave di cifratura risiede sul server, quindi la misura protegge dalla sottrazione del solo database, non dalla compromissione dell'intera macchina.
- It uses the following sub-processors, which you authorise by accepting this agreement:
- OVH (hosting), technical infrastructure, data kept on servers in the European Union;
- Nessun fornitore di modelli linguistici, al momento. L'elaborazione automatica dei contenuti clinici è disattivata: nessuna risposta, nessun punteggio e nessun testo dei tuoi pazienti viene trasmesso a un fornitore esterno per essere elaborato. I referti vengono prodotti dai soli punteggi e dalle fasce degli strumenti. Quando l'elaborazione verrà riattivata, questo accordo cambierà versione e ti verrà richiesta una nuova accettazione: è il motivo per cui questo elenco fa fede.
- Stripe Payments Europe Ltd (Ireland) for collecting payments: it receives the payer's email address and the amount, never clinical data or the patient's name. The Stripe group may also process data in the United States, on the basis of the Standard Contractual Clauses. Note one point that concerns you too: for collection Stripe acts as processor on the controller's behalf, but for its own fraud-prevention and anti-money-laundering purposes it acts as an independent controller, and in that part it does not act on our instructions. Its own data processing agreement states this, incorporating the Standard Contractual Clauses in both the controller-to-processor and the controller-to-controller module;
- Register.it S.p.A. (Italy) for outgoing email: the recipient, the subject and the body of service emails pass through it. No transfer outside the European Union;
- iubenda S.r.l. (Italy) for managing the privacy notice and the cookie banner: it processes site visitors' browsing data, not your patients' data.
- It informs you of any change of sub-processor, leaving you the possibility to object.
- It assists you, within the limits of what is technically possible, in responding to requests from data subjects exercising their rights.
- It notifies you without undue delay of any personal data breach that comes to its knowledge.
- It assists you, taking into account the nature of the processing and the information available, in meeting the obligations of security, breach notification and, where required, impact assessment (Articles 32-36 GDPR).
- At the end of the relationship it will, at your choice, delete your patients' data or make it available for export. Export in machine-readable format is available at any time from your private area.
- Demonstrability and audits. It makes available to you all information necessary to demonstrate compliance with the obligations of Article 28 and allows for audits, including inspections, conducted by you or an appointed auditor, with reasonable notice and in a manner that does not compromise the confidentiality of other professionals' data. On request it provides you with a copy of the access log relating to your patients.
- It warrants that it holds the rights and licences necessary to make available on the platform the questionnaires and tests offered for self-administration with automatic return of scores.
4. Your responsibilities as controller
It remains your responsibility to obtain valid consent or another lawful basis from your patients, to provide them with an adequate privacy notice, and to use the tool in accordance with your professional code of conduct.
How the platform helps you meet it. At the moment your patient gives consent, the page shows them your name, your VAT number and your contact details, stating that you are the data controller and that beassessed acts on your behalf as processor. If you have given the address of your privacy notice in your private area, the patient also finds the link to read it there before consenting. This is how Article 13(1)(a) GDPR is complied with at the moment the data is collected.
beassessed does not draft or supply your privacy notice: it is a legal document you answer for, and a text written by someone else would leave you signing a description that might not match how you actually work. If you also process your patients' data outside the platform, or if other people have access to it, that processing must be described, and the responsibility for doing so is yours. In your private area you can give the address where your notice is published, and your patients will find it on the consent screen. It is not a condition of using the platform, but it remains an obligation you owe them (Article 13 GDPR).
Instruments available on the platform: the questionnaires and tests made available are prepared and managed exclusively by beassessed, which warrants that they may lawfully be used in the manner offered (direct completion, automatic return of scores). You neither upload nor configure any test: you simply select, for each of your patients, which of the instruments already available on the platform to make accessible. If you need a specific instrument that is not yet present, contact beassessed so that its addition to the library can be considered.
5. Conservazione e cancellazione
The platform keeps pathway data for 10 years from the patient's last activity, a period aligned with the ordinary limitation period under Italian law (Article 2946 of the Civil Code); once it has passed, the data is deleted by a periodic procedure. By accepting this agreement you adopt this period as a documented instruction under Article 28(3)(a). If you state a different period to your patients in your own notice, the responsibility for that statement is yours: for a shorter period you can delete at any time from your area, for a longer one you must export and keep the data by your own means before expiry.
6. Durata
This agreement remains in force for as long as you use the platform.