Our commitment to protecting your data and ensuring compliance with GDPR, HIPAA, and PIPEDA.
Effective Date: January 15, 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller" or "Customer") and Radiology Pro AI Corp., an Ontario corporation doing business as RadPro AI ("Processor" or "RadPro AI"). This DPA governs the processing of Personal Data and Protected Health Information (PHI) by RadPro AI on behalf of Controller when using the RadPro AI radiology reporting assistant platform ("Service").
This DPA ensures compliance with applicable data protection laws including GDPR (EU General Data Protection Regulation), PIPEDA (Canadian Personal Information Protection and Electronic Documents Act), and HIPAA (US Health Insurance Portability and Accountability Act) where applicable.
By using the Service to process Personal Data or PHI, Controller agrees to the terms of this DPA and represents that it has the legal authority to enter into this agreement and to instruct RadPro AI to process Personal Data on its behalf.
For the purposes of this DPA, the following definitions apply:
"Controller" means the entity that determines the purposes and means of processing Personal Data. In the context of RadPro AI, this is typically the healthcare organization or individual healthcare professional using the Service.
"Processor" means RadPro AI, the entity that processes Personal Data on behalf of the Controller according to the Controller's instructions.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed. In healthcare contexts, this includes patients whose information appears in radiology reports.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws including GDPR, PIPEDA, and similar regulations.
"Protected Health Information (PHI)" means individually identifiable health information as defined under HIPAA, including the 18 HIPAA Safe Harbor identifiers that RadPro AI automatically detects and protects.
"Processing" means any operation performed on Personal Data or PHI, including collection, storage, use, transmission, analysis, and deletion.
Subject Matter: Processing of radiology report text and associated metadata to provide AI-powered report structuring, clinical impression generation, quality assurance, and differential diagnosis assistance.
Duration: Processing occurs for the duration of the Service agreement and continues through the data retention period specified in Section 11.
Nature and Purpose: RadPro AI processes Personal Data and PHI solely for the purpose of providing the radiology reporting assistance Service as described in the Terms of Service, including:
• Report text analysis and structuring
• Clinical impression generation from findings
• Quality assurance review
• Advanced differential diagnosis generation
• OCR text extraction from medical images
• Template management and macro expansion
Types of Personal Data: The Service may process the following categories of Personal Data and PHI:
• Patient demographic information (names, dates, medical record numbers)
• Clinical findings and imaging observations
• Medical diagnoses and impressions
• Physician names and credentials
• Facility and department information
• Any other information contained in radiology reports
Categories of Data Subjects: Patients undergoing radiological imaging studies, healthcare providers creating or reviewing radiology reports.
RadPro AI implements comprehensive technical and organizational security measures to protect Personal Data and PHI:
Encryption in Transit: All data transmitted to and from RadPro AI servers is encrypted using TLS 1.3 protocol with strong cipher suites. This ensures that Personal Data and PHI cannot be intercepted during transmission.
Encryption at Rest: All PHI and sensitive Personal Data stored in our databases is encrypted using AES-256-GCM (Advanced Encryption Standard with 256-bit keys in Galois/Counter Mode), a military-grade encryption standard.
Access Controls and Multi-Factor Authentication (MFA): Access to the Service requires user authentication. RadPro AI supports time-based one-time password (TOTP) multi-factor authentication to prevent unauthorized access. Role-based access controls ensure users can only access data appropriate to their role.
Session Management: automatic session timeout after 24 hours of inactivity for all users, administrators included (the NIST SP 800-63B AAL2 maximum), to prevent unauthorized access from unattended workstations. Users receive 5-minute advance warning before timeout.
PHI Detection and Protection: RadPro AI automatically detects all 18 HIPAA Safe Harbor identifiers in report text before AI processing. Detected PHI is visually highlighted and can be automatically scrubbed before transmission to AI models. PHI metadata is stored in encrypted format.
Audit Logging: Comprehensive audit logging of all user activities, PHI access, and system events. Audit logs are retained for 6 years to meet HIPAA requirements and are tamper-evident. Logs can be exported for compliance reviews.
Infrastructure Security: Hosted on secure cloud infrastructure with regular security updates, intrusion detection systems, and network-level protections. Production systems are isolated from development environments.
Personnel Security: All RadPro AI personnel with potential access to Personal Data undergo background checks and receive regular privacy and security training. Access to production data is restricted on a need-to-know basis.
For Controllers subject to the European Union General Data Protection Regulation (GDPR), RadPro AI agrees to comply with the Standard Contractual Clauses (SCCs) adopted by the European Commission Decision 2021/914 for the transfer of personal data to processors established in third countries.
RadPro AI, as data processor, agrees to:
• Process Personal Data only on documented instructions from the Controller
• Ensure that persons authorized to process Personal Data are under confidentiality obligations
• Implement appropriate technical and organizational measures as described in Section 4
• Respect the conditions for engaging sub-processors as described in Section 7
• Assist the Controller in responding to Data Subject requests
• Assist the Controller in ensuring compliance with security obligations
• Delete or return all Personal Data upon termination, as described in Section 11
• Make available to the Controller all information necessary to demonstrate compliance
The full text of the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) is incorporated by reference into this DPA and is available upon request at admin@radpro.ai.
For data transfers from the EU/EEA to Canada, RadPro AI relies on Canada's adequacy decision for commercial organizations subject to PIPEDA. For transfers to other jurisdictions, the SCCs provide appropriate safeguards.
For Controllers that are HIPAA Covered Entities or Business Associates, this section constitutes the required Business Associate Agreement (BAA).
RadPro AI agrees to:
• Use and disclose PHI only as permitted by this DPA or as required by law
• Use appropriate safeguards to prevent unauthorized use or disclosure of PHI as described in Section 4
• Report to Controller any use or disclosure of PHI not permitted by this DPA within 72 hours of discovery, as described in Section 10
• Ensure that any subcontractors or agents that handle PHI agree to the same restrictions and conditions
• Make PHI available to Data Subjects as required by 45 CFR § 164.524 upon Controller's request
• Make PHI available for amendment and incorporate amendments as directed by Controller
• Make available information required to provide an accounting of disclosures per 45 CFR § 164.528
• Make internal practices, books, and records relating to PHI available to HHS for compliance investigation
• Return or destroy all PHI upon termination as described in Section 11
Permitted Uses and Disclosures:
• RadPro AI may use and disclose PHI only to provide the Service as described in the Terms of Service
• RadPro AI may use PHI for proper management and administration if required by law
• RadPro AI may aggregate de-identified data for research and service improvement, provided the data cannot be re-identified
The Controller represents that it has obtained all necessary patient authorizations and consents required under HIPAA for the processing of PHI through the Service.
RadPro AI may engage third-party subprocessors to assist in providing the Service. All subprocessors are subject to data protection obligations equivalent to those in this DPA.
Current Subprocessors:
A complete and current list of all subprocessors is maintained on our website at radpro.ai/subprocessors and includes:
• Cloud infrastructure providers (server hosting, database hosting)
• AI model providers (OpenRouter)
• Payment processors (Stripe)
• Email service providers
• Monitoring and analytics tools
Subprocessor Notification:
RadPro AI will provide Controller with at least 30 days' advance notice before:
• Engaging a new subprocessor that will process Personal Data or PHI
• Making material changes to an existing subprocessor arrangement
Objection Rights:
Controller may object to RadPro AI's appointment or replacement of a subprocessor on reasonable grounds relating to data protection. Such objection must be raised in writing within 15 days of notification. If Controller objects, RadPro AI will either:
• Not appoint or use the subprocessor, or
• Provide Controller with the option to suspend or terminate the Service without penalty
Subprocessor Obligations:
RadPro AI ensures all subprocessors enter into written agreements requiring them to:
• Process Personal Data only according to RadPro AI's instructions
• Implement appropriate security measures
• Comply with applicable data protection laws
• Allow for audits and inspections
RadPro AI remains fully liable to Controller for any subprocessor's failure to fulfill its data protection obligations.
RadPro AI will assist Controller in fulfilling its obligations to respond to Data Subject requests exercising their rights under applicable data protection laws, including:
Right of Access: Data Subjects have the right to obtain confirmation of whether their Personal Data is being processed and to access that data. RadPro AI will provide Controller with the necessary information within 10 business days of request.
Right to Rectification: Data Subjects may request correction of inaccurate Personal Data. Controllers can update report data directly through the Service interface, or RadPro AI will assist upon request.
Right to Erasure ("Right to be Forgotten"): Data Subjects may request deletion of their Personal Data in certain circumstances. RadPro AI will permanently delete requested data within 30 days of Controller's instruction, except where retention is required by law.
Right to Restriction of Processing: Data Subjects may request limitation of processing in certain circumstances. RadPro AI will mark such data and process it only for limited purposes as instructed by Controller.
Right to Data Portability: Data Subjects have the right to receive their Personal Data in a structured, commonly used, and machine-readable format. RadPro AI provides export functionality in JSON and PDF formats.
Right to Object: Data Subjects may object to processing based on legitimate interests. RadPro AI will cease processing upon Controller's instruction unless there are compelling legitimate grounds.
Response Timeline:
RadPro AI will respond to Controller requests for assistance with Data Subject rights within 10 business days. RadPro AI may charge reasonable fees for extensive or repetitive requests that require disproportionate effort.
Controller Responsibilities:
Controller is responsible for verifying the identity of Data Subjects making requests and determining the validity and scope of such requests under applicable law. RadPro AI processes requests only upon documented instructions from Controller.
Controller has the right to audit RadPro AI's compliance with this DPA and applicable data protection laws, subject to the following terms:
Audit Reports:
RadPro AI will make available to Controller, upon written request, an annual summary audit report demonstrating compliance with the security measures described in Section 4 and the obligations set forth in this DPA. Such reports will be made available within 30 days of request.
Third-Party Certifications:
RadPro AI will obtain and maintain industry-standard security certifications and assessments, and will provide copies or summaries of relevant certifications upon request. Currently available documentation includes:
• HIPAA compliance architecture documentation
• PIPEDA compliance statement
• GDPR compliance documentation
• Security practices and infrastructure documentation
On-Site Audits:
Upon reasonable advance written notice of at least 30 days, and no more than once per year (unless required by a Data Protection Authority), Controller may conduct an on-site audit or inspection of RadPro AI's facilities and systems that process Personal Data. Such audits:
• Must be conducted during regular business hours
• Must not unreasonably interfere with RadPro AI's operations
• May be conducted by Controller or an independent third-party auditor bound by confidentiality
• Must be at Controller's expense unless the audit reveals material non-compliance
Audit Findings:
If an audit reveals non-compliance with this DPA, RadPro AI will:
• Work with Controller to develop a remediation plan within 15 days
• Implement corrective measures within a reasonable timeframe based on the severity of the finding
• Provide Controller with regular updates on remediation progress
Cost Allocation:
RadPro AI may charge reasonable fees to cover the cost of extensive audits that require significant time and resources. Standard annual audit reports are provided at no charge.
RadPro AI maintains a comprehensive data breach response plan and will notify Controller of any Personal Data breach without undue delay.
Internal Assessment (72 Hours):
Upon discovering a suspected Personal Data or PHI breach, RadPro AI will:
• Conduct an immediate internal investigation to determine the scope and impact
• Contain the breach and implement measures to prevent further unauthorized access
• Complete initial assessment within 72 hours of discovery
• Document all findings and remediation steps taken
Notification to Controller (72 Hours):
RadPro AI will notify Controller within 72 hours of discovering a Personal Data breach. The notification will include:
• Description of the nature of the breach, including categories and approximate number of Data Subjects affected
• Name and contact information of RadPro AI's data protection point of contact
• Description of likely consequences of the breach
• Description of measures taken or proposed to address the breach and mitigate harm
• Timeline of discovery and response actions
Notification to Individuals (60 Days):
For breaches involving PHI subject to HIPAA, RadPro AI will support Controller in providing notification to affected individuals within 60 days as required by HIPAA Breach Notification Rule. For GDPR breaches likely to result in high risk to individuals, RadPro AI will assist Controller in providing notification without undue delay.
Regulatory Notification:
RadPro AI will assist Controller in notifying relevant Data Protection Authorities and regulatory bodies (such as HHS Office for Civil Rights for HIPAA breaches) as required by applicable law.
Cooperation:
RadPro AI will fully cooperate with Controller's investigation of any breach and will provide all reasonably requested information and assistance. RadPro AI will not publicly disclose any breach without Controller's prior written consent, except as required by law.
Prevention Measures:
Following any breach, RadPro AI will conduct a root cause analysis and implement additional safeguards to prevent similar incidents in the future.
Upon termination or expiration of the Service agreement, Controller may instruct RadPro AI regarding the disposition of Personal Data and PHI.
Data Return Option:
Controller may request return of all Personal Data and PHI within 30 days of termination. RadPro AI will provide the data in a structured, commonly used, machine-readable format (JSON or CSV) via secure encrypted transfer. Data return services may be subject to reasonable fees based on data volume and complexity.
Data Deletion Option:
Controller may request secure deletion of all Personal Data and PHI. RadPro AI will:
• Permanently delete all Personal Data and PHI from production systems within 30 days
• Delete all backup copies within 90 days (or upon next backup rotation cycle)
• Use secure deletion methods that render data unrecoverable
• Provide written certification of deletion upon request
Retention for Legal Requirements:
Notwithstanding the above, RadPro AI may retain Personal Data to the extent and for such period as required by applicable law, regulation, or court order. Any such retained data will continue to be subject to the confidentiality and security provisions of this DPA.
Audit Logs:
Audit logs containing references to Personal Data or PHI may be retained for 6 years to meet regulatory requirements (including HIPAA). Such logs are encrypted and access-restricted.
Subprocessor Data:
RadPro AI will ensure that all subprocessors return or delete Personal Data and PHI in accordance with this section, and will obtain written confirmation of such deletion from subprocessors.
Automatic Deletion:
If Controller does not provide deletion or return instructions within 90 days of termination, RadPro AI will automatically and securely delete all Personal Data and PHI, except as required by law.
Execution of Data Processing Agreement:
This DPA is incorporated by reference into the RadPro AI Terms of Service and becomes effective when Controller begins using the Service to process Personal Data or PHI.
For organizations requiring a separately executed DPA (including those subject to specific regulatory requirements or corporate policies), RadPro AI offers a formal DPA execution process.
To Request Formal DPA Execution:
Please contact our compliance team at admin@radpro.ai with the following information:
• Organization name and legal entity details
• Contact person name, title, and email address
• Regulatory framework(s) applicable to your organization (GDPR, HIPAA, PIPEDA, etc.)
• Any specific DPA requirements or addendums needed
• Estimated volume of Personal Data to be processed
Response Timeline:
Our legal and compliance team will respond to DPA execution requests within 5 business days with:
• DPA review and any necessary clarifications
• Execution process and timeline
• Any additional documentation required
• Signature authority and execution method (electronic or wet signature)
Business Associate Agreements (HIPAA):
HIPAA Covered Entities should specifically request BAA execution. The HIPAA Business Associate provisions in Section 6 of this DPA constitute the required BAA, and can be executed as a standalone document upon request.
Amendment and Updates:
RadPro AI may update this DPA from time to time to reflect changes in applicable law, regulatory guidance, or service capabilities. Material changes will be communicated to Controllers with 30 days' advance notice. Continued use of the Service after changes become effective constitutes acceptance of the updated DPA.
If you have any questions about this Data Processing Agreement or need to execute a formal DPA, please contact us:
Company: Radiology Pro AI Corp. (RadPro AI)
Email: admin@radpro.ai
Mail: RadPro AI Legal & Compliance
Canada
This Data Processing Agreement is incorporated by reference into the RadPro AI Terms of Service and becomes effective when you begin using the Service to process Personal Data or PHI. For formal DPA execution, please contact admin@radpro.ai.