DATA PROCESSING AGREEMENT – MEDICAL DEVICE HQ AB

Last update: 2026-02-04

By creating a Group Account in accordance with TERMS OF SERVICE – ONLINE SERVICE AND COURSES – MEDICAL DEVICE HQ AB (“TOS”) Medical Device HQ (“the Data Processor”) and the Customer (“the Data Controller”) enter into this Data Processing Agreement on the date the Group Account is created.

The Data Processor and the Data Controller are hereinafter referred to jointly as “the Parties” and/or each of them separately as “the Party”

All capitalized terms shall have the meaning included in the TOS unless the Parties decided otherwise.

WHEREAS:

The Data Controller has provided the Data Processor with Participants’ personal data which allows the Data Processor to perform the Service in accordance with the description on the Product Page and TOS. Once the Service is ordered, the Data Controller shall entrust the Data Processor with processing activities concerning the personal data required for that Service within the scope described herein;

The purpose of this Data Processing Addendum is to establish terms and conditions for processing the personal data by the Data Processor on behalf of the Data Controller;

By entering into this Data Processing Addendum, the Parties aim to establish terms and conditions for processing personal data in compliance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)

Therefore, the Parties agree as follows:

1 REPRESENTATIONS OF THE PARTIES

1.1    The Data Controller acknowledges that it acts as a data controller within the meaning of the GDPR in respect of the personal data entrusted to the Data Processor.

1.2    The Parties acknowledge that, with respect to personal data relating to the other Party’s representatives, employees, or contact persons exchanged or processed in connection with the negotiation, execution, administration, compliance, or termination of the TOS and this Data Processing Addendum (including names, business contact details, and correspondence), each Party acts as an independent data controller within the meaning of the GDPR. Such personal data does not constitute personal data processed by the Data Processor on behalf of the Data Controller under this Data Processing Addendum and is therefore excluded from the scope of the processing activities described herein, including the deletion and return obligations set out in section 8.3, and shall be retained only in accordance with applicable data protection law and each Party’s own retention obligations

1.3    The Data Processor acknowledges that it shall process personal data only on documented instructions from the Data Controller as further described in section 2.2, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by applicable law.

1.4    Where the Data Processor is required by Union or Member State law to process personal data other than on the instructions of the Data Controller, the Data Processor shall inform the Data Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

1.5    Where the Data Processor is unable to comply with its obligations under this Data Processing Addendum or applicable data protection law, it shall inform the Data Controller without undue delay.

2 SUBJECT MATTER, PURPOSE, AND CATEGORIES OF PERSONAL DATA

2.1    The Data Processor shall process personal data solely for the purpose of providing the Services under the TOS. For clarification, this may include:

  • communicating course-related information to Participants, Group Leaders, and Single Point of Contact;
  • verifying the authenticity of course certificates;
  • surveying Participants’ results and feedback regarding the Services; and
  • recommending future courses related to the Services.

2.2    Details of the processing:

  • Subject matter: Provision of the Services under the TOS.
  • Duration: For the term of the contractual relationship between the Parties, unless otherwise required by applicable law.
  • Nature of the processing: Collection, recording, organisation, structuring, storage, consultation, use, transmission, and deletion of personal data in connection with hosting, administration, communication, assessment, certification, and reporting.
  • Purpose of the processing: To enable the delivery, operation, administration, and improvement of the Services under the TOS.

2.3    The Data Processor may process personal data relating to the following categories of data subjects: employees, workers, and consultants of the Data Controller.

2.4    The Data Processor may process only the following types of personal data: first name, last name, email, phone number, IP address, signature, title, username, nickname, password, image and any other data resulting from the usage of the Services. The data will be subject to the following processing operations: storage in data retrieval systems, communication, emailing, and statistical processing and reporting.

2.5    The Parties acknowledge that the personal data processed under this Data Processing Addendum do not include special categories of personal data pursuant to Article 9 of GDPR, or personal data relating to criminal convictions and offences pursuant to Article 10 of GDPR.

3 AUDITING RIGHTS

3.1    The Parties shall be able to demonstrate compliance with this Data Processing Addendum.

3.2    The Data Processor shall deal promptly and adequately with inquiries from the Data Controller about the data processing in accordance with this Data Processing Addendum.

3.3    The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations that are set out in this Data Processing Addendum and stem directly from GDPR.

3.4    Should the information provided under section 3.3 be insufficient to confirm the compliance with the obligations that are set out in this Data Processing Addendum and stem directly from GDPR, at the Data Controller’s request, the Data Processor shall also permit and contribute to audits of the processing activities covered by this Data Processing Addendum, at reasonable intervals or if there are indications of non-compliance. The audit may be conducted on condition that a relevant non-disclosure agreement is signed between the Parties and/or an independent auditor indicated in section 3.5. In deciding on a review or an audit, the Data Controller may consider relevant certifications held by the Data Processor.

3.5    The Data Controller may conduct the audit or mandate an independent auditor. Should the information and documents provided during a virtual audit be insufficient, the audits may also include inspections of the premises or physical facilities of the Data Processor. Any audit shall be carried out with a notice of at least 45 (forty-five) calendar days before the audit. The Data Processor may charge a fee (based on the Data Processor’s reasonable costs) for any such audit. The Data Processor will provide the Data Controller with further details of any applicable fee and the basis for its calculations before any such audit. The Data Controller will be responsible for any fee charged by any auditor appointed by the Data Controller to execute such control.

3.6    The Data Processor may object in writing to an auditor appointed by the Data Controller if the auditor is, in the Data Processor’s reasonable opinion, not suitably qualified or independent, or a competitor of the Data Processor. The Data Controller shall respond to any objection to an auditor within 10 business days. Any such objection by the Data Processor will require the Data Controller to appoint another auditor or conduct the control on its own.

3.7    The Data Controller shall have the above-stipulated rights in respect of the Sub-processors listed in section 7. Where direct audits of such Subprocessors are not reasonably practicable, the Data Processor may satisfy these obligations by providing appropriate third-party audit reports, certifications, or other independent assurance documentation relating to the relevant Subprocessors.

3.8    The Parties shall make the information referred to in this Section, including the results of any audits, available to the competent supervisory authority/ies on request.

3.9    The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction issued by the Data Controller infringes the GDPR or other applicable data protection law.

4 TECHNICAL AND ORGANISATIONAL MEASURES

4.1    The Data Processor shall implement appropriate technical and organisational measures to ensure an appropriate level of security, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons.

4.2    Such measures include, inter alia: 

  1. the pseudonymisation and encryption of personal data;
  2. ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems;
  3. timely restoration of availability and access to personal data;
  4. regular testing and evaluation of security measures.

5 ASSISTANCE TO THE DATA CONTROLLER

5.1    Taking into account the nature of the processing, the Data Processor shall assist the Data Controller, by appropriate technical and organisational measures, in fulfilling its obligations to respond to requests for exercising data subject rights pursuant to Articles 12–23 of GDPR. The Data Controller hereby authorizes the Data Processor to delete the Participant’s account on their demand in accordance with TOS, including but not limited to the situation when the Participant is enrolled in the Service ordered by the Data Controller. Any dispute between the Data Controller and the Participant relating to the account deletion shall be settled exclusively between the Data Controller and the Participant. 

5.2    Taking into account the nature of the processing and the information available to it, the Data Processor shall assist the Data Controller in ensuring compliance with Articles 32 to 36 of the GDPR, to the extent reasonably possible, including with respect to:

a) implementation of appropriate technical and organisational measures,
b) notification of personal data breaches to the supervisory authority and to data subjects,
c) Data Protection Impact Assessments (DPIAs) and prior consultation,
d) Provision of information necessary to demonstrate GDPR compliance in a timely manner

5.3    The Data Processor may charge reasonable fees for assistance provided under section 5, taking into account the nature of the request.

6 RECORD OF PROCESSING ACTIVITIES

6.1  The Data Processor shall maintain a record of processing activities in accordance with Article 30 (2) of GDPR.

6.2  Such Record shall include:

  1. names and contact details of the Parties and, where applicable, the data protection officer;
  2. categories of processing activities; 
  3. a general description of technical and organisational security measures;
  4. details of international transfers and safeguards;
  5. categories of recipients.

7 SUB-PROCESSING

7.1    The Data Controller hereby grants the Data Processor a general authorisation to engage other processors (“Subprocessors”) for the performance of the Services.

7.2    The Data Processor shall inform the Data Controller of any intended changes concerning the addition or replacement of Subprocessors, thereby giving the Data Controller the opportunity to object on reasonable grounds relating to data protection within ten (10) business days following such notification:

7.3    The Data Processor shall ensure that each Subprocessor is bound by a written agreement imposing data protection obligations equivalent to those set out in this Data Processing Addendum and Article 28 GDPR. The Data Processor shall remain fully liable to the Data Controller for the performance of the Subprocessor’s obligations.

7.4    Approved categories of Subprocessors may include, without limitations:

  • data storage and hosting services;
  • CRM systems;
  • customer surveying tools;
  • email delivery services;
  • certificate issuance services;
  • invoicing and accounting services;
  • learning management systems;
  • document sending and printing services.

The list of the Sub-Processors currently engaged by the Data Processor is available to the Data Controller upon request.

7.5    Where the engagement of a Subprocessor involves a transfer of personal data to a third country or an international organisation, the Data Processor shall ensure that such transfer is carried out in compliance with Chapter V of the GDPR. Such transfers shall take place only where:

  1. the third country is subject to an adequacy decision adopted by the European Commission pursuant to Article 45 GDPR; or
  2. appropriate safeguards pursuant to Article 46 GDPR are in place, in particular the European Commission’s Standard Contractual Clauses, together with any supplementary measures required under applicable data protection law.

The Data Processor shall, upon request, make available information to the Data Controller regarding the applicable transfer mechanism.

8 CONFIDENTIALITY AND DATA RETURN

8.1    The Data Processor shall grant access to personal data only to personnel who require such access strictly for implementing, managing, or monitoring the Services. The Data Processor shall ensure that all personnel authorised to process personal data have committed themselves to confidentiality, whether by contractual obligation or statutory duty. This confidentiality obligation extends to information about the personal data itself and the technical and organisational measures implemented to ensure the security of the personal data. 

8.2    The Data Processor acknowledges that every person with access to the personal data shall process them only on the Data Processor’s instruction unless otherwise stipulated by law.

8.3    Upon termination or expiry of this Data Processing Addendum, the Data Processor shall, at the choice of the Data Controller, delete or return all personal data and delete existing copies thereof. Where deletion or return is not technically or operationally feasible, the Data Processor may instead irreversibly anonymise the personal data so that it no longer constitutes personal data. Union or Member State law requiring storage of the personal data shall remain unaffected.

8.4    The provisions shall apply equally to all Subprocessors, provided that the Data Processor shall not be required to impose identical contractual obligations on Subprocessors engaged under standard, non-negotiable terms, so long as such Subprocessors comply with applicable data protection laws and maintain appropriate confidentiality and security measures consistent with generally accepted industry standards.

8.5    For the avoidance of doubt, the obligations set out in this section 8 apply solely to personal data processed by the Data Processor on behalf of the Data Controller within the scope of this Data Processing Addendum. They do not apply to personal data processed by the Parties as independent data controllers, including personal data relating to the other Party’s representatives or contact persons processed for contractual, legal, compliance, or administrative purposes.

9 PERSONAL DATA BREACH

9.1    As soon as the Data Processor becomes aware of a personal data breach, it shall notify the Data Controller without undue delay.

9.2    The notification referred to in section 9.1 shall at least:

  1. describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned,
  2. communicate the name and contact details of the data protection officer or another contact point where more information can be obtained,
  3. describe the likely consequences of the personal data breach
  4. describe the measures taken or proposed by the Data Processor to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

9.3    To perform the obligations stipulated hereinabove, the Data Processor shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects, and the remedial action taken.

9.4    Where, and insofar as it is impossible to provide all this information at the same time, the initial notification shall contain the information then available, and further information shall, as it becomes available, subsequently be provided without undue delay.

10 FINAL PROVISIONS

10.1    This Data Processing Addendum is entered into for a limited period and shall terminate on the day the Data Processor stops rendering Services for the benefit of the Data Controller under the TOS.

10.2    All amendments made hereto shall be in writing otherwise shall be null and void.

10.3    Upon termination, the Data Processor shall comply with section 8.3 regarding return, deletion, or anonymisation of personal data and all copies, including those held by Subprocessors. Notwithstanding the foregoing, where personal data is held by Subprocessors engaged under standard, non-negotiable terms, the Data Processor shall not be required to procure actions beyond those made available under such Subprocessors’ standard data protection terms, provided that such Subprocessors comply with applicable data protection laws and maintain appropriate confidentiality and security measures consistent with generally accepted industry standards.

Get in touch to receive proposal for customised training

When you submit this form, your personal data will be processed in accordance with our privacy policy.