psisula

Data Processing Agreement (DPA)

Processor obligations for clinical data: sub-processors, safeguards, audit and deletion.

1. Parties and subject matter

This agreement is entered into between the clinic or therapist using psisula (the “Controller”) and Psisula (İstanbul, Türkiye — the “Processor”) under art. 12 of Law No. 6698, and forms an integral part of the Terms of Use.

The Controller determines the purposes and means of processing its clients’ personal data. The Processor processes that data solely to provide the Service and on the Controller’s instructions.

2. Nature of the processing

Subject matter Provision of the psisula practice management software
Duration The subscription term plus the deletion period in clause 8
Purpose Appointments, client records, clinical documentation, assessments and progress tracking, client portal, reminders and reporting
Categories of data Identity and contact details, appointment records, session notes, treatment plans, diagnoses, assessment answers and scores, homework, portal messages, uploaded documents, fees and payment status, session transcripts
Data subjects The Controller’s clients and team members
Special categories Yes — health data is processed

3. Processor obligations

The Processor shall:

  1. Process personal data only on the Controller’s documented instructions, whether written or given through the Service interface. If an instruction appears unlawful, the Processor informs the Controller.
  2. Limit access to personnel who need it for their role, and bind those people to confidentiality.
  3. Apply the technical and organisational measures in clause 5.
  4. Assist the Controller, to a reasonable extent, in responding to data subject requests under KVKK art. 11. The Service includes functions to export and to delete all records for a given client.
  5. Notify the Controller without undue delay and within 72 hours of becoming aware of a data breach, describing its nature, the categories of data affected and the measures taken. Notifying the Personal Data Protection Board and the data subjects remains the Controller’s duty.
  6. Never use clinical data for its own purposes, for product development, or to train AI models.

4. Sub-processors

The Controller authorises the following sub-processors:

Sub-processor Service Data received Location
Our hosting, database and file-storage provider Infrastructure All data held in the system (encrypted) EU (Alkmaar, Netherlands)
OpenAI Transcription, note drafting, summaries, score readings The relevant audio and text USA
Twilio SMS Phone number and message text USA
Resend Email Email address and message text USA
Sentry Error monitoring Technical logs — no client data EU (Frankfurt)
Zoom, Google Meet Telehealth links Meeting title and time (only if an account is connected) USA

Every sub-processor other than hosting can be switched off by disabling the corresponding feature.

We notify account holders by email at least 30 days before adding or replacing a sub-processor. If the Controller objects on reasonable grounds and the parties cannot agree on a resolution, the Controller may terminate the subscription without penalty.

5. Technical and organisational measures

  • Encryption in transit: all traffic is protected with TLS.
  • Encryption at rest: session notes, treatment plans, diagnoses, telehealth credentials and assessment answers are encrypted with AES-256-GCM using a random nonce per record.
  • Search privacy: client phone numbers are converted to an HMAC-SHA256 blind index for uniqueness checks, so the plaintext never sits in a searchable column.
  • Access control: owner, admin, therapist, front desk and supervisor roles are governed by a central permission matrix. Front desk cannot see clinical notes; a supervisor reads notes read-only.
  • Tenant isolation: every request compares the clinic on the session against the clinic that owns the resource; in the client portal, each access is additionally checked to be the client’s own.
  • Authentication: staff passwords are stored with bcrypt; the client portal works through single-use links.
  • Logging discipline: system logs carry no client name, phone number, note or transcript text, assessment answer, portal message or AI request/response body; the rule is enforced in continuous integration and logs are deleted after 14 days.
  • Audit log: create, edit and delete actions are recorded. View logging does not exist yet.
  • Session audio: not retained once transcribed.

The current list is on the Security page. Data is not end-to-end encrypted; search, reporting and AI features require the server to read it.

6. Audit and information

On the Controller’s request we provide, within a reasonable time, the information needed to demonstrate compliance with this agreement. We hold no independent audit report (SOC 2, ISO 27001); if we obtain one it will be published on the Security page. We will accommodate reasonable audit requests made on prior written notice, no more than once a year and without disrupting operations.

7. Transfers

Data is hosted in the EU (Alkmaar, Netherlands), which constitutes a transfer abroad under KVKK art. 9. Transfers to the US-based sub-processors are limited to the scope in clause 4. The Controller is responsible for informing its clients about these transfers; the KVKK Disclosure Notice contains information that can be used in such a notice.

8. Termination and deletion

When the subscription ends, the Controller may export its data for 30 days. At the end of that period, or on the Controller’s earlier request, the data is deleted. Copies in backups fall away when the backup retention period expires; until then backups are protected by the same measures.

Cases where law requires retention are reserved.

9. Contact

[email protected]