Data Processing Agreement (DPA) — Annex to the Service Agreement
Last updated: June 23, 2026 | Version 1.0
This Data Processing Agreement ("DPA" or "Agreement") forms an integral part of the Terms of Service entered into between the following parties:
Data controller:
Max Antonio Méndez Gómez (Pequeño Contribuyente), domiciled in Guatemala City, Guatemala ("Customer" or "Controller").
Data processor:
MedicIA (clinical management SaaS platform) ("MedicIA" or "Processor").
The parties hereby agree on the conditions under which MedicIA processes personal data of data subjects (patients, staff) on behalf of the Customer. The primary and governing legal framework of this Agreement is that of the Republic of Guatemala, as set out in clause 12. By way of comparative reference —and not as the governing regime— the parties acknowledge regional personal-data protection standards (Law 25.326 — Argentina; LFPDPPP — Mexico; Law 1581/2012 — Colombia; Law 19.628 — Chile; and their regulations), whose principles MedicIA observes in good faith as industry best practices.
1. Definitions
Personal Data: Any information that allows a natural person to be identified or made identifiable.
Health Data: A special category of personal data relating to a person's physical or mental condition.
Processing: Any operation or set of operations on personal data (collection, storage, use, transmission, deletion, etc.).
Security breach: A breach of security leading to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data.
Sub-processor: A third party that MedicIA engages to process data on its behalf.
2. Subject matter and scope of processing
MedicIA shall process the Personal Data solely for the provision of the Service described in the Terms of Service and according to the documented instructions of the Customer. The processing comprises:
Storage of clinical records and patient data.
Processing of WhatsApp messages for appointment coordination.
Analysis through artificial intelligence (intent detection).
Generation of reports and statistics for the Customer's internal use.
Backup and disaster recovery.
MedicIA shall not process the data for its own purposes, marketing or commercial analysis. In the event of any instruction from the Customer that, in MedicIA's judgment, could infringe data protection regulations, MedicIA shall inform the Customer without delay.
3. MedicIA's obligations (Processor)
MedicIA undertakes to:
Process the data only according to the documented instructions of the Customer.
Ensure that persons authorized to process the data are subject to a duty of confidentiality.
Implement the technical and organizational security measures described in clause 6.
Assist the Customer in fulfilling data subject rights requests (access, rectification, erasure, etc.).
Delete or return all data at the end of the contract, as the Customer chooses.
Make available to the Customer the information necessary to demonstrate compliance with its obligations.
Not disclose data to third parties without the Customer's instruction, except where legally required.
4. Customer's obligations (Controller)
The Customer undertakes to:
Have obtained the necessary legal authorization (consent, contract, legal mandate) to collect and submit its patients' data for processing.
Ensure that the data provided to MedicIA is accurate and up to date.
Notify MedicIA of any change in the processing instructions.
Be solely responsible toward the data subjects and supervisory authorities.
5. Sub-processors
The Customer authorizes MedicIA to engage the following sub-processors for the provision of the Service. MedicIA shall notify the Customer at least 30 days in advance of any change to this list.
Sub-processor
Service
Country/region
Data involved
Anthropic, PBC
Claude AI API — intent detection in WhatsApp messages
USA
WhatsApp message text (without patient name or clinical record)
Meta Platforms, Inc. (WhatsApp Business Cloud API)
Sending and receiving WhatsApp messages per clinic
USA / variable
Incoming and outgoing WhatsApp messages
Google LLC
Google Calendar + Gmail (calendar synchronization and email sending when the clinic connects its Google Workspace account)
USA
Calendar events (appointments) and, where applicable, emails sent from the connected Gmail account
MedicIA requires all of its sub-processors to undertake data protection obligations equivalent to those of this DPA.
Data concentration at Railway (US infrastructure): all platform data —including health data— is stored on the infrastructure of Railway Corp., located in the United States of America. As a result, such data is subject to US jurisdiction and the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) may apply, which in certain circumstances allows US authorities to compel access to data held by providers subject to their jurisdiction. As of the date of this Agreement, MedicIA has not entered into a health-data-specific data processing agreement (DPA) with Railway; the execution of such an agreement is pending. The Customer, in its capacity as Controller, should weigh this circumstance when instructing the processing of its patients' health data.
6. Technical and organizational security measures
MedicIA implements the following measures:
Encryption in transit: TLS 1.2 or higher on all network communications.
Encryption at rest: The production PostgreSQL database (hosted on Railway) is encrypted at rest at the infrastructure level, in accordance with the security posture published by the managed-infrastructure provider. In addition, backups are encrypted with an AES-256 key.
Access control: Role-based system (admin, specialist, receptionist, auditor); principle of least privilege.
Auditing: Immutable log of all sensitive operations (audit_log) with traceability of user, action and timestamp.
Vulnerability management: Dependency updates and periodic security reviews.
Continuity: Automated backups with a minimum retention of 30 days.
Security reviews: MedicIA conducts internal security reviews of its code and configuration, in particular following significant architecture changes. MedicIA does not represent that it carries out third-party certified penetration testing on a fixed schedule; any external security review will be documented and made available to the Customer upon request.
7. Security breach notification
MedicIA shall notify the Customer within 72 hours of becoming aware of a security breach affecting personal data. The notification shall include: a description of the breach, the categories and approximate number of affected data subjects, the likely consequence and the measures taken or proposed.
The Customer is responsible for notifying the affected data subjects and the supervisory authorities according to the applicable legislation in its country.
8. International transfers
Data transfers to sub-processors in the USA or other jurisdictions are carried out under appropriate safeguards: European Union Standard Contractual Clauses (where applicable), Data Privacy Framework (where the sub-processor is certified) or equivalent contractual terms. Additional information available upon request at privacidad@medicia.app.
9. Audit rights
The Customer has the right to audit compliance with this DPA. The audit shall be carried out through:
Written questionnaires answered by MedicIA within 15 business days.
Documentary review of security policies and certifications.
On-site audit or audit by an auditor designated by the Customer, with 30 days' prior notice and at most once per year, subject to a confidentiality agreement.
Security-breach exception: the annual audit cap shall not apply where a security breach affecting the Customer's data has occurred. In such a case, the Customer shall have the right to request an immediate audit —in addition to the annual one— to verify the corrective measures adopted, without prejudice to the duty of confidentiality and reasonably coordinating the date and scope with MedicIA.
10. Return and deletion of data at the end of the contract or upon account closure
When the clinic's administrator deletes the account (the DELETE /account/clinic action) or when the contractual relationship ends, access is suspended and, within the following 30 days, the Customer may:
Export: Delivery of all data in structured JSON format through the GET /api/account/export endpoint.
Deletion: Secure erasure of all of the Customer's personal data from MedicIA's systems, including active backups (tape or cold-archive copies are deleted in the normal rotation cycle, a maximum of 90 additional days).
After those 30 days, MedicIA permanently deletes ALL data associated with the clinic — including the clinic's data, its doctors and users, and all of its patients (clinical records, appointments, conversations and documents). The retention periods for the clinical record required by health regulations (for example, a minimum of 10 years) are an obligation that rests on the clinic as the data controller while the account is active; voluntary closure of the account triggers this total deletion.
MedicIA shall retain only the data that it is legally obligated to keep (for example, billing records).
11. Term
This DPA enters into force on the date of acceptance of the Terms of Service and remains in effect for as long as the main contract is in force. The confidentiality and data deletion obligations survive termination.
12. Applicable law and alignment with Guatemalan law
This DPA is governed primarily and principally by the laws of the Republic of Guatemala. In the absence of a general personal-data protection statute in Guatemala as of the date of this Agreement, the Processor's obligations are construed and supplemented in accordance with the following Guatemalan legal framework:
Political Constitution of the Republic of Guatemala — Art. 24 (inviolability of correspondence, documents and communications) and Art. 31 (right of access to records and archives, and to the correction or rectification of one's personal data).
Health Code (Decree 90-97), Art. 195 — confidentiality of the information contained in the clinical record and the duty of secrecy regarding the patient's health data.
Civil Code (Decree-Law 106), Arts. 26 to 35 — protection of personality rights, including the individual's privacy and image.
Law for the Recognition of Electronic Communications and Signatures (Decree 47-2008) — validity of consent and of records in electronic form.
Commercial Code (Decree 2-70) — as regards the commercial relationship between the parties and the retention of records.
The legislation of other Latin American countries cited in this Agreement (Argentina, Mexico, Colombia, Chile, among others) constitutes comparative reference and represents industry best practices that MedicIA observes in good faith, but does not constitute the legal regime governing this DPA. Notwithstanding the foregoing, where the Controller operates in a country that has personal-data protection rules binding upon it, such rules shall apply with respect to the obligations falling on the Controller itself.
13. DPO contact
For inquiries about this Agreement or to exercise rights:
Max Antonio Méndez Gómez (Pequeño Contribuyente)
privacidad@medicia.app
Guatemala City, Guatemala