Data Processing Agreement

Data Processing Agreement (DPA) — Annex to the Service Agreement
Last updated: June 23, 2026  |  Version 1.0

This Data Processing Agreement ("DPA" or "Agreement") forms an integral part of the Terms of Service entered into between the following parties:

Data controller:
Max Antonio Méndez Gómez (Pequeño Contribuyente), domiciled in Guatemala City, Guatemala ("Customer" or "Controller").

Data processor:
MedicIA (clinical management SaaS platform) ("MedicIA" or "Processor").

The parties hereby agree on the conditions under which MedicIA processes personal data of data subjects (patients, staff) on behalf of the Customer. The primary and governing legal framework of this Agreement is that of the Republic of Guatemala, as set out in clause 12. By way of comparative reference —and not as the governing regime— the parties acknowledge regional personal-data protection standards (Law 25.326 — Argentina; LFPDPPP — Mexico; Law 1581/2012 — Colombia; Law 19.628 — Chile; and their regulations), whose principles MedicIA observes in good faith as industry best practices.

1. Definitions

2. Subject matter and scope of processing

MedicIA shall process the Personal Data solely for the provision of the Service described in the Terms of Service and according to the documented instructions of the Customer. The processing comprises:

MedicIA shall not process the data for its own purposes, marketing or commercial analysis. In the event of any instruction from the Customer that, in MedicIA's judgment, could infringe data protection regulations, MedicIA shall inform the Customer without delay.

3. MedicIA's obligations (Processor)

MedicIA undertakes to:

  1. Process the data only according to the documented instructions of the Customer.
  2. Ensure that persons authorized to process the data are subject to a duty of confidentiality.
  3. Implement the technical and organizational security measures described in clause 6.
  4. Assist the Customer in fulfilling data subject rights requests (access, rectification, erasure, etc.).
  5. Delete or return all data at the end of the contract, as the Customer chooses.
  6. Make available to the Customer the information necessary to demonstrate compliance with its obligations.
  7. Not disclose data to third parties without the Customer's instruction, except where legally required.

4. Customer's obligations (Controller)

The Customer undertakes to:

  1. Have obtained the necessary legal authorization (consent, contract, legal mandate) to collect and submit its patients' data for processing.
  2. Ensure that the data provided to MedicIA is accurate and up to date.
  3. Notify MedicIA of any change in the processing instructions.
  4. Be solely responsible toward the data subjects and supervisory authorities.

5. Sub-processors

The Customer authorizes MedicIA to engage the following sub-processors for the provision of the Service. MedicIA shall notify the Customer at least 30 days in advance of any change to this list.

Sub-processor Service Country/region Data involved
Anthropic, PBC Claude AI API — intent detection in WhatsApp messages USA WhatsApp message text (without patient name or clinical record)
Recurrente Payment and subscription processing Guatemala Clinic billing data (email, tax name)
Resend, Inc. Sending transactional emails USA Recipient's email address and name
Railway Corp. Cloud infrastructure (server, PostgreSQL database) USA All data stored on the platform
Meta Platforms, Inc. (WhatsApp Business Cloud API) Sending and receiving WhatsApp messages per clinic USA / variable Incoming and outgoing WhatsApp messages
Google LLC Google Calendar + Gmail (calendar synchronization and email sending when the clinic connects its Google Workspace account) USA Calendar events (appointments) and, where applicable, emails sent from the connected Gmail account

MedicIA requires all of its sub-processors to undertake data protection obligations equivalent to those of this DPA.

Data concentration at Railway (US infrastructure): all platform data —including health data— is stored on the infrastructure of Railway Corp., located in the United States of America. As a result, such data is subject to US jurisdiction and the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) may apply, which in certain circumstances allows US authorities to compel access to data held by providers subject to their jurisdiction. As of the date of this Agreement, MedicIA has not entered into a health-data-specific data processing agreement (DPA) with Railway; the execution of such an agreement is pending. The Customer, in its capacity as Controller, should weigh this circumstance when instructing the processing of its patients' health data.

6. Technical and organizational security measures

MedicIA implements the following measures:

7. Security breach notification

MedicIA shall notify the Customer within 72 hours of becoming aware of a security breach affecting personal data. The notification shall include: a description of the breach, the categories and approximate number of affected data subjects, the likely consequence and the measures taken or proposed.

The Customer is responsible for notifying the affected data subjects and the supervisory authorities according to the applicable legislation in its country.

8. International transfers

Data transfers to sub-processors in the USA or other jurisdictions are carried out under appropriate safeguards: European Union Standard Contractual Clauses (where applicable), Data Privacy Framework (where the sub-processor is certified) or equivalent contractual terms. Additional information available upon request at privacidad@medicia.app.

9. Audit rights

The Customer has the right to audit compliance with this DPA. The audit shall be carried out through:

Security-breach exception: the annual audit cap shall not apply where a security breach affecting the Customer's data has occurred. In such a case, the Customer shall have the right to request an immediate audit —in addition to the annual one— to verify the corrective measures adopted, without prejudice to the duty of confidentiality and reasonably coordinating the date and scope with MedicIA.

10. Return and deletion of data at the end of the contract or upon account closure

When the clinic's administrator deletes the account (the DELETE /account/clinic action) or when the contractual relationship ends, access is suspended and, within the following 30 days, the Customer may:

After those 30 days, MedicIA permanently deletes ALL data associated with the clinic — including the clinic's data, its doctors and users, and all of its patients (clinical records, appointments, conversations and documents). The retention periods for the clinical record required by health regulations (for example, a minimum of 10 years) are an obligation that rests on the clinic as the data controller while the account is active; voluntary closure of the account triggers this total deletion.

MedicIA shall retain only the data that it is legally obligated to keep (for example, billing records).

11. Term

This DPA enters into force on the date of acceptance of the Terms of Service and remains in effect for as long as the main contract is in force. The confidentiality and data deletion obligations survive termination.

12. Applicable law and alignment with Guatemalan law

This DPA is governed primarily and principally by the laws of the Republic of Guatemala. In the absence of a general personal-data protection statute in Guatemala as of the date of this Agreement, the Processor's obligations are construed and supplemented in accordance with the following Guatemalan legal framework:

The legislation of other Latin American countries cited in this Agreement (Argentina, Mexico, Colombia, Chile, among others) constitutes comparative reference and represents industry best practices that MedicIA observes in good faith, but does not constitute the legal regime governing this DPA. Notwithstanding the foregoing, where the Controller operates in a country that has personal-data protection rules binding upon it, such rules shall apply with respect to the obligations falling on the Controller itself.

13. DPO contact

For inquiries about this Agreement or to exercise rights:
Max Antonio Méndez Gómez (Pequeño Contribuyente)
privacidad@medicia.app
Guatemala City, Guatemala