Data Processing Agreement
Effective since 7 September 2026 · Version 2.1
Agreement governing the processing of personal data entrusted to Delta Labs in connection with the Delta Service.
Preamble and parties
This Data Processing Agreement, hereinafter the “DPA”, is entered into between:
The Controller: the User of the Delta Service or the organisation on whose behalf the User is authorised to act, where that party determines the purposes and means of the processing of Patient Data. Where that party itself acts as a processor on behalf of a third party, references to the Controller include that initial processor to the applicable extent;
and
The Processor: Delta Labs SAS, a French simplified joint-stock company with share capital of EUR 1,000, registered with the Niort Trade and Companies Register under number 102 094 448, SIRET number 102 094 448 00010, whose registered office is located at 11 BIS Allée du Muguet, 79200 Parthenay, France, represented by its President, Grégory Ilan Muschel, hereinafter “Delta Labs”.
This DPA supplements the Terms of Use and, where applicable, the Terms of Sale of the Delta Service. It forms part of the agreement entered into between the parties.
It applies where Delta Labs processes personal data on behalf of the Controller in connection with the Service. It does not govern processing for which Delta Labs itself determines the purposes and means, including certain processing relating to account management, billing, security, support and communications. Such processing is described in the Privacy Policy.
Article 1 — Definitions
For the purposes of this DPA:
- “Patient Data” means personal data entrusted to Delta Labs by the Controller in connection with the care, support or follow-up of a Patient, including identification data, notes, session information, audio recordings, transcripts and reports;
- “Entrusted Personal Data” means Patient Data and any other personal data contained in content transmitted to Delta Labs and processed on behalf of the Controller;
- “Applicable Data Protection Law” means any data protection law applicable to the relevant processing, including, where applicable, Regulation (EU) 2016/679, hereinafter the “GDPR”;
- “Data Subject” means any natural person to whom Entrusted Personal Data relates;
- “Controller”, “Processor”, “processing”, “personal data” and “personal data breach” have the meanings assigned to them by Applicable Data Protection Law;
- “Subprocessor” means a third party to which Delta Labs entrusts part of the processing of Entrusted Personal Data;
- “Service” means the Delta software and the features provided through its web and desktop applications.
Article 2 — Purpose and scope
This DPA defines the conditions under which Delta Labs processes Entrusted Personal Data to provide, secure, maintain and administer the Service in accordance with the Controller’s documented instructions.
The main characteristics of the processing are detailed in Appendix 1.
This DPA applies throughout the period during which Delta Labs processes Entrusted Personal Data on behalf of the Controller, including, where applicable, during return, deletion or technical retention operations following the end of use of the Service.
If supplementary provisions applicable to a particular jurisdiction or profession are presented to the Controller, they supplement this DPA and prevail in respect of their specific subject matter in the event of a conflict.
Article 3 — Instructions from the Controller
Delta Labs processes Entrusted Personal Data only on documented instructions from the Controller, unless applicable law requires otherwise.
Documented instructions include:
- this DPA, the Terms of Use and, where applicable, the Terms of Sale;
- the actions, settings and choices made by the Controller within the Service;
- additional written requests accepted by Delta Labs as instructions under this DPA.
Where Delta Labs is legally required to process data outside the Controller’s instructions, it informs the Controller before the processing takes place, unless applicable law prohibits such information on important grounds of public interest.
Delta Labs informs the Controller if it considers that an instruction infringes Applicable Data Protection Law. It may suspend the performance of that instruction for the time required to clarify or amend it.
This DPA does not grant Delta Labs the right to use Entrusted Personal Data for its own advertising or commercial purposes or for the general training of artificial intelligence models.
Article 4 — Obligations of the Controller
The Controller remains responsible for the lawfulness of the collection and processing of Entrusted Personal Data.
In particular, the Controller is responsible for:
- having a valid legal basis for each processing operation carried out through the Service;
- providing Data Subjects with the information required by Applicable Data Protection Law;
- obtaining the required consent or authorisation, including before any audio recording where required by applicable law or professional rules;
- complying with the principles of purpose limitation, proportionality, accuracy and data minimisation;
- transmitting only the data necessary for its professional use of the Service;
- determining retention periods appropriate to its activities and carrying out the necessary deletion operations;
- responding to requests from Data Subjects and competent authorities;
- securing its devices, credentials, access and any copies of data retained outside the Service;
- ensuring that persons using the Account are authorised to process the relevant data.
Where the Controller itself acts as a processor on behalf of a third party, it warrants that it is authorised to transmit the relevant instructions, to engage Delta Labs as a further processor and to authorise the Subprocessors identified in this DPA.
The Controller must not use the Service for processing that is incompatible with its documentary purpose or prohibited by the Terms of Use.
Article 5 — General obligations of Delta Labs
Delta Labs undertakes to:
- process Entrusted Personal Data in accordance with the Controller’s documented instructions;
- ensure that persons authorised to process it are subject to an appropriate duty of confidentiality;
- restrict access to the data to what is necessary to provide, maintain, secure or support the Service;
- implement the technical and organisational measures described in Appendix 2;
- assist the Controller under the conditions set out in this DPA;
- make available the information necessary to demonstrate compliance with its obligations;
- inform the Controller if an instruction appears to infringe Applicable Data Protection Law;
- impose data protection obligations appropriate to the relevant services on its Subprocessors.
Where required by Applicable Data Protection Law, Delta Labs maintains a record of the categories of processing activities carried out on behalf of its customers.
Article 6 — Confidentiality and access to data
Delta Labs restricts access to Entrusted Personal Data to members of its personnel, contractors and Subprocessors who require access to perform their duties.
These persons are subject to a contractual, statutory or professional duty of confidentiality.
Access rights are granted according to the principle of least privilege and are revoked or adjusted when their justification no longer exists.
Delta Labs does not intentionally access clinical content for purposes unrelated to the provision of the Service. Occasional access may nevertheless be necessary to process a support request, prevent or investigate a security incident, comply with an instruction from the Controller or meet a legal obligation.
Article 7 — Security of processing
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing and the risks to Data Subjects, Delta Labs implements technical and organisational measures designed to ensure a level of security appropriate to the risk.
The main measures currently implemented are described in Appendix 2.
Delta Labs may update these measures to reflect technical changes, risks and developments to the Service, provided that such updates do not materially reduce the overall level of protection afforded to Entrusted Personal Data.
The Controller acknowledges that security also depends on its own use of the Service, the security of its devices, the confidentiality of its credentials and compliance with the security recommendations communicated to it.
Article 8 — Subprocessors
The Controller grants Delta Labs general authorisation to engage the Subprocessors required to provide the Service.
The Subprocessors used as of the effective date of this DPA are listed in Appendix 3.
Delta Labs ensures that each Subprocessor is bound by a written agreement imposing data protection obligations that are appropriate and at least equivalent, for the processing entrusted to it, to the relevant obligations set out in this DPA.
Delta Labs remains responsible to the Controller for the performance of the obligations entrusted to its Subprocessors, within the limits provided by Applicable Data Protection Law and the agreement between the parties.
Delta Labs informs the Controller, by an appropriate means, of the intended addition or replacement of a Subprocessor that will process Entrusted Personal Data. Except in an emergency justified by security, continuity of the Service or a legal obligation, this information is provided at least thirty days before the relevant processing begins.
During that period, the Controller may submit a written objection based on serious data protection grounds.
The parties will then seek a reasonable solution in good faith. If no solution can be found without disproportionate burden, Delta Labs may refrain from using the relevant Subprocessor, restrict the affected feature or allow the Controller to terminate the part of the Service that requires that Subprocessor, depending on the circumstances.
Changes made by a provider to its own list of subprocessors are governed by that provider’s contractual commitments.
Article 9 — Location and international transfers
Delta’s main production infrastructure is configured in an AWS region located in France. Certain specialised processing operations are configured in European Google Cloud regions or locations.
These configuration choices do not mean that all support, security or subprocessing operations performed by the providers take place exclusively in France or within the European Economic Area.
Where Entrusted Personal Data is transferred to a country that does not benefit from an applicable adequacy decision, Delta Labs ensures that the transfer is based on a mechanism recognised under Applicable Data Protection Law, including the standard contractual clauses adopted by the European Commission, accompanied where necessary by appropriate supplementary measures.
Delta Labs may rely on the transfer mechanisms, contractual commitments and security measures implemented by its Subprocessors after assessing their relevance to the processing concerned.
Upon reasonable request, Delta Labs provides the Controller with available information concerning the principal processing locations and applicable transfer mechanisms, subject to confidentiality obligations and the information made available by the relevant providers.
Article 10 — Rights of Data Subjects
Taking into account the nature of the processing, Delta Labs assists the Controller, insofar as possible and through appropriate technical or organisational measures, in responding to requests from Data Subjects exercising their rights.
Where Delta Labs directly receives a request relating to Entrusted Personal Data and can identify the relevant Controller, it forwards the request to the Controller or directs the Data Subject to contact the Controller, unless otherwise required by law.
Delta Labs does not respond to the substance of such a request without instructions from the Controller unless Applicable Data Protection Law requires it to do so.
The Controller remains responsible for assessing the request, verifying the requester’s identity, determining the appropriate response and meeting applicable statutory deadlines.
If the assistance requested exceeds the ordinary features of the Service and requires substantial specific work, the parties may agree in advance on reasonable arrangements, including financial arrangements, unless Applicable Data Protection Law requires such assistance to be provided free of charge.
Article 11 — Compliance assistance
Taking into account the nature of the processing and the information available to it, Delta Labs reasonably assists the Controller in complying with its obligations relating to:
- the security of processing;
- the notification of personal data breaches;
- the provision of information to Data Subjects;
- data protection impact assessments;
- prior consultations with a supervisory authority;
- documentation of the measures and processing carried out through the Service.
This assistance is provided through the features of the Service, the information available in the documentation and, where necessary, reasonable additional cooperation.
The Controller remains responsible for determining whether a data protection impact assessment, authorisation, consultation, local formality or specific measure is required for its activities or use of the Service.
Article 12 — Personal data breaches
Delta Labs notifies the Controller without undue delay after becoming aware of any personal data breach affecting Entrusted Personal Data processed on the Controller’s behalf.
To the extent available, the notification includes:
- the nature of the breach;
- the categories and approximate number of Data Subjects concerned;
- the categories and approximate number of records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its consequences;
- the contact details of the point from which further information may be obtained.
Where all information cannot be provided at the same time, it may be supplied in phases without further undue delay.
Delta Labs takes reasonable measures within its scope to contain the breach, limit its consequences and contribute to its investigation.
Notification of a breach does not, in itself, constitute an acknowledgement of fault or liability by Delta Labs.
The Controller remains responsible for determining whether the breach must be notified to a supervisory authority or to the affected Data Subjects.
Article 13 — Information, reviews and audits
Delta Labs makes available to the Controller the information reasonably necessary to demonstrate compliance with the obligations set out in this DPA and Applicable Data Protection Law.
Where the documents, written responses, reports or information already provided are insufficient, the Controller may request an audit of the processing carried out on its behalf.
Except in the event of a breach, a request from a competent authority or reasonable grounds to suspect a material breach, such an audit may not be requested more than once in any twelve-month period.
The audit must:
- be conducted during business hours;
- be subject to reasonable prior notice;
- be limited to relevant systems, information and processing;
- not compromise the security, confidentiality or rights of other customers;
- be carried out by the Controller or by a competent independent auditor that is not a competitor of Delta Labs and is subject to a duty of confidentiality;
- avoid any disproportionate disruption to the Service.
The Controller bears the costs of the audit and the time specifically incurred by Delta Labs, unless the audit reveals a material breach attributable to Delta Labs or Applicable Data Protection Law requires a different allocation.
Delta Labs cooperates with competent supervisory authorities under the conditions provided by law.
Article 14 — Return and deletion of data
While using the Service, the Controller may access, rectify or delete certain data through the available features.
Where the ordinary features do not enable the complete performance of an instruction to return or delete data, the Controller may submit a documented request to Delta Labs.
At the end of the processing carried out on behalf of the Controller, Delta Labs deletes or returns the Entrusted Personal Data, at the Controller’s choice and in accordance with its instructions, and then deletes the remaining copies unless applicable law requires their retention.
Data is returned in a reasonably available and technically usable format. Delta Labs is not required to develop a specific format or tool that does not exist within the Service unless separately agreed by the parties or required by law.
Deletion is performed without undue delay, taking into account the nature of the data, the systems concerned and the technical cycles reasonably required.
Data may temporarily remain in backups, technical logs or disaster recovery systems until it is overwritten or expires under the applicable cycles. During that period, it remains protected, is not returned to ordinary use and is processed only where necessary for security, restoration or compliance with a legal obligation.
The end of a paid subscription does not necessarily end the processing where the Account continues to exist under a free plan. Processing ends when the data is deleted upon instruction, when the Account is permanently deleted or when another event effectively ends the relevant processing.
Delta Labs may retain the information necessary to demonstrate that a deletion request was performed, provided that such information does not unnecessarily contain the data whose deletion was requested.
Article 15 — Liability
Each party is responsible for compliance with the obligations imposed on it by Applicable Data Protection Law.
Delta Labs is liable for damage caused by processing where it has failed to comply with obligations specifically imposed on it as a processor or where it has acted outside or contrary to the Controller’s lawful instructions.
The contractual allocation of liability between the parties is governed by the Terms of Use and, where applicable, the Terms of Sale, without limiting the rights of Data Subjects or any liability that cannot lawfully be excluded or restricted.
Nothing in this DPA deprives a Data Subject of any right granted by Applicable Data Protection Law.
Article 16 — Term and termination
This DPA takes effect upon its acceptance or on the date on which Delta Labs begins processing Entrusted Personal Data on behalf of the Controller.
It remains applicable for as long as Delta Labs retains or processes such data, including during return, deletion or permitted technical retention operations.
Obligations which by their nature must survive termination of the agreement, including obligations relating to confidentiality, security, deletion and cooperation, remain applicable until they have been fully performed.
Article 17 — Amendments to the DPA
Any amendment to this DPA results in a new identifiable and dated version.
In accordance with its legal document management policy, Delta Labs determines whether an amendment:
- may be published without specific notification;
- must be notified to the Controller;
- requires new express acceptance before use of the Service may continue.
Changes to purely operational information, such as a provider’s contact details or clarification of a processing location, may be made without renewed acceptance where they do not materially reduce the Controller’s rights or safeguards, subject to the information obligations applicable to Subprocessors.
No amendment applies retroactively in a manner that would make lawful any processing that was not lawful when it took place.
Article 18 — Contractual hierarchy
In the event of a conflict concerning the protection of Entrusted Personal Data:
- mandatory provisions of Applicable Data Protection Law prevail;
- supplementary provisions applicable to a particular jurisdiction or processing activity prevail in respect of their specific subject matter;
- this DPA prevails over the Terms of Use and Terms of Sale for matters specifically relating to the processing of personal data on behalf of the Controller;
- the other contractual documents apply to matters not governed by this DPA.
Article 19 — Governing law, language and contact
This DPA is governed by French law, without prejudice to mandatory provisions of Applicable Data Protection Law.
The French version is the authoritative version. A translation may be provided to facilitate understanding. Where applicable law prohibits the French version from prevailing or imposes another rule of interpretation, that mandatory rule remains applicable.
For any question, instruction or request relating to this DPA, the Controller may contact:
Delta Labs SAS
11 BIS Allée du Muguet
79200 Parthenay, France
07 66 80 89 66
Appendix 1 — Description of the processing
1. Subject matter of the processing
Provision, security, maintenance and support of the Service features that allow the Controller to organise its professional activities and manage documentation relating to its Patients and sessions.
2. Nature of the operations
Depending on the features used, the operations may include:
- collecting and receiving data entered, imported or recorded by the Controller;
- recording, organising, structuring and storing data;
- consulting data and making it available to the Controller;
- transmitting data to the necessary Subprocessors;
- optionally capturing and storing audio recordings;
- converting, transcribing and automatically analysing content;
- generating draft reports, summaries or other documents;
- rectifying, restricting, exporting, archiving or deleting data according to the applicable features and instructions;
- carrying out technical processing necessary for the security, diagnosis and continuity of the Service.
3. Purposes
The purposes of the processing are:
- to allow the Controller to create and manage Patient records and sessions;
- to enable note-taking and the organisation of information;
- to transcribe audio recordings made at the Controller’s initiative;
- to generate draft reports or documents from the information provided;
- to allow the Controller to review, correct, validate, consult and delete content;
- to secure, maintain and troubleshoot the Service.
4. Categories of Data Subjects
Data Subjects may include:
- Patients cared for or supported by the Controller;
- relatives, representatives, professionals or other third parties mentioned in the content;
- the Controller and authorised persons where their data is included in the information processed on the Controller’s behalf.
5. Categories of data
The data may include:
- the identity, contact details and administrative information of Patients;
- information relating to appointments, sessions and follow-up;
- free-text notes and observations made by the Controller;
- optional audio recordings;
- transcripts;
- draft reports, summaries and generated documents;
- information relating to health, personal life or other sensitive matters mentioned in the content;
- technical identifiers, dates, durations, statuses and metadata necessary for the operation of the Service.
Because notes and recordings may contain free-form information, other categories of data may also be processed under the Controller’s responsibility.
6. Frequency and duration
Processing takes place continuously or occasionally, depending on the Controller’s use of the Service.
It continues for the duration of the Account and for as long as the data remains stored on the Controller’s instructions, under an authorised technical cycle or pursuant to a legal obligation.
Appendix 2 — Technical and organisational measures
Delta Labs implements the following measures, among others, depending on the components concerned:
1. Access management
- individual authentication of Users;
- enhanced authentication mechanisms available or required depending on the context;
- server-side authorisation controls;
- logical isolation of data between Users;
- restriction of internal access according to the principle of least privilege;
- secure management of secrets and technical credentials.
2. Protection of communications and storage
- encryption of exposed network communications using secure protocols;
- encryption at rest of the main production databases, cache and object storage;
- storage of audio files in a private bucket with public access blocked;
- use of technical roles and access policies restricted to the resources required.
3. Hosting and segmentation
- main production infrastructure configured in the AWS
eu-west-3region, located in Paris; - database and cache placed in private subnets and not directly exposed to the Internet;
- separation of environments and technical responsibilities;
- restriction of network traffic through dedicated security rules.
4. Backup and continuity
- automatic backups of the production database with a recovery window currently configured for thirty days;
- protection of the production database against accidental deletion;
- monitoring of the status of key components and recovery mechanisms appropriate to the architecture;
- deployment and operational procedures designed to limit uncontrolled changes.
The technical cache is not used as the durable system of record and does not currently benefit from persistent retention in production.
5. Logs, diagnostics and monitoring
- centralisation of technical logs with a limited retention period;
- current retention of the main cloud execution logs for ninety days;
- monitoring of technical errors and incidents;
- configuration of diagnostic tools designed to exclude known clinical content and sensitive fields;
- no intentional transmission of audio recordings, transcripts, notes or reports to observability tools.
Technical or pseudonymous identifiers strictly necessary for diagnostics may nevertheless be processed.
6. Audio file lifecycle
- deletion of temporary audio segments that are no longer required after finalisation and transcription, according to the relevant technical workflow;
- temporary storage of copies required for Google Cloud transcription, with application-level deletion after processing and automatic expiration configured as a safeguard;
- versioning of the main audio storage;
- expiration of non-current versions according to the configured lifecycle;
- deletion of data according to the Controller’s instructions and applicable technical procedures.
7. Incident and change management
- restriction and traceability of administrative access;
- management of technical errors and alerts;
- version-controlled deployment procedures;
- storage of code and infrastructure configuration in controlled repositories;
- review and adaptation of measures based on risks and changes to the Service.
Appendix 3 — Subprocessors
Amazon Web Services EMEA SARL
Services concerned: application hosting, object storage, database, cache, networking, logging, monitoring and related cloud services.
Data concerned: all categories of Entrusted Personal Data necessary for the operation of the Service.
Main configured location: AWS eu-west-3 region, Paris, France.
Additional information: AWS may engage its own subprocessors and support services in accordance with its data processing agreement and subprocessor list. Recognised transfer mechanisms are used where required.
Google Cloud France
Services concerned: temporary storage required for transcription, speech recognition, artificial intelligence processing and content generation.
Data concerned: audio recordings transmitted for transcription, transcripts, instructions, context strictly necessary for generation and generated content.
Configured locations: temporary European multi-region bucket, speech recognition configured in a European location and artificial intelligence services configured in compatible European locations.
Additional information: data may be processed by Google or its own subprocessors under the Google Cloud DPA, applicable service-specific terms and relevant transfer mechanisms. Temporary audio copies are deleted after processing and are covered by a technical expiration rule as a safeguard.
Functional Software, Inc., doing business as Sentry
Services concerned: detection, centralisation and analysis of technical errors.
Data concerned: diagnostic information, technical context and technical or pseudonymous identifiers required to investigate a malfunction.
Location: United States and other locations declared by the provider.
Additional information: Delta configures Sentry to exclude known clinical content and sensitive fields. Notes, transcripts, audio recordings and reports are not intentionally transmitted to Sentry. Transfers are governed by the mechanisms provided in the provider’s DPA.