Data Processing Agreement
[REVIEW: ...] must be filled during tenant onboarding and confirmed by counsel for enterprise tenants.Preamble
The Controller is a licensed healthcare facility processing patient health information in the course of providing care. Vedge supplies the Controller with SaaS infrastructure (the “Service”) and in doing so Processes Personal Data on the Controller’s behalf. This DPA sets out the terms on which that Processing takes place.
1. Definitions
- DPA 2012 — the Ghana Data Protection Act 2012 (Act 843).
- Personal Data, Processing, Controller, Processor, Data Subject, Special Category Data — as defined in the DPA 2012.
- Patient Data — Personal Data relating to patients of the Controller, including clinical records, demographics, and identifiers.
- Authorised Sub-processor — a third party listed on our current Sub-processors page.
2. Roles + responsibilities
The parties agree that for Patient Data, the Controller is the Controller and Vedge is the Processor. For data Vedge collects directly from the Controller’s staff (e.g. login records, billing contact), Vedge acts as Controller and its Privacy Policy applies.
3. Scope of processing
The Processing by Vedge is:
- Subject matter: delivery of the Service — electronic health records, appointment management, billing, clinical workflow, analytics.
- Duration: the term of the subscription plus the export window defined in §13.
- Nature + purpose: storage, retrieval, analysis, transmission, and deletion of Patient Data as instructed by the Controller through use of the Service.
- Categories of Data Subjects: the Controller’s patients, dependants, and staff.
- Types of Personal Data: identity, demographics, contact, clinical observations, diagnoses, prescriptions, lab + imaging results, insurance claim data, appointment history, billing records.
4. Controller instructions
Vedge Processes Personal Data only on the Controller’s documented instructions, which are:
- Use of the Service by the Controller’s Authorised Users according to its configured settings.
- Any written instruction sent to dpo@tryvedge.com.
Vedge will inform the Controller without undue delay if, in its opinion, an instruction infringes the DPA 2012 or any other applicable law.
5. Security measures
Vedge implements the technical and organisational measures described in Annex III, including encryption at rest and in transit, role-based access control, audit logging, and multi-tenant schema isolation.
6. Staff confidentiality
Every Vedge employee or contractor with potential access to Personal Data signs a written confidentiality undertaking before access is granted, and receives data-protection training annually.
7. Sub-processors
The Controller grants Vedge general written authorisation to engage the Sub-processors listed on our Sub-processors page. Vedge will notify the Controller by email at least 30 days before adding or replacing a Sub-processor. The Controller may object on reasonable data protection grounds within that window; if the objection cannot be resolved, the Controller may terminate its subscription for convenience with pro-rata refund of prepaid fees.
Vedge imposes on every Sub-processor contractual obligations at least as protective as those in this DPA and remains liable to the Controller for Sub-processor performance.
8. International transfers
Where Vedge transfers Patient Data outside Ghana, the transfer is executed under Standard Contractual Clauses and only to jurisdictions providing an adequate level of protection under §§47–48 DPA 2012, or with explicit Data Subject consent where that is the operative lawful basis.
9. Data subject rights
Taking into account the nature of the Processing, Vedge assists the Controller in responding to Data Subject requests under §§32–36 DPA 2012. Requests received directly by Vedge are forwarded to the Controller without undue delay, and the Controller remains responsible for the substantive response.
10. DPIAs + prior consultation
Vedge assists the Controller in carrying out Data Protection Impact Assessments and prior consultations with the Data Protection Commission, to the extent reasonable given the information available to Vedge as Processor.
11. Breach notification
If Vedge becomes aware of a Personal Data Breach affecting Patient Data, Vedge notifies the Controller without undue delay and in any case within 48 hours of confirmation. The notification will include:
- The nature of the breach and categories of data affected.
- The approximate number of Data Subjects concerned.
- The likely consequences and the measures Vedge has taken or proposes to take.
- The Vedge contact point for follow-up enquiries.
The Controller remains responsible for notifying the Data Protection Commission and affected Data Subjects under §§31 DPA 2012; Vedge will provide the information reasonably required for the Controller to do so.
12. Audit
Vedge makes available to the Controller, on reasonable written request at no more than annual cadence, the information necessary to demonstrate compliance with this DPA. Where the Controller requires an on-site audit, the parties will agree scope, timing, and costs in good faith, acting so as not to unreasonably disrupt the Service for other tenants. Vedge undertakes to provide, on request, its most recent SOC 2 / ISO 27001 evidence package once obtained.
13. Return + deletion
On termination of the subscription, Vedge will:
- Make the Controller’s data available for export for 60 days in the following formats: PostgreSQL dump (tenant schema), CSV bundle per entity, FHIR R4 bundle (selected resources).
- Delete or irreversibly anonymise the data after the export window, subject to retention obligations imposed by law (billing records, audit log) or by the Controller’s own retention policy.
- Certify the deletion in writing on request.
14. Term + liability
This DPA takes effect on the commencement of the Controller’s subscription and remains in force for as long as Vedge Processes Personal Data on the Controller’s behalf, including during the export window in §13. Liability under this DPA is subject to the cap in the Terms of Service, save that either party’s breach of its data-protection obligations is excluded from that cap to the extent required by the DPA 2012.
Annex I — Processing details
See §3 above. Processing details are fixed for the life of the subscription unless the parties agree otherwise in writing.
Annex II — Approved sub-processors
The authoritative, current list is the Sub-processors page. That page incorporates by reference into this DPA and is updated in accordance with §7.
Annex III — Security measures
The current, detailed description of Vedge’s technical and organisational measures is published on our Security page and incorporated by reference. Vedge will not degrade its security posture during the term of the subscription and will notify the Controller of material changes to the posture.