UAB „Orinote“ teisiniai dokumentai
Subtvarkytojai
Šis priedas yra neatskiriama Paslaugų teikimo sutarties (MSA) ir Duomenų tvarkymo sutarties (DPA) dalis.
1. BENDROSIOS NUOSTATOS
1.1. Teikėjas, teikdamas Platformos paslaugas, gali pasitelkti trečiuosius asmenis (subtvarkytojus), kurie Teikėjo vardu tvarko asmens duomenis arba dalyvauja Paslaugų teikimo procese.
1.2. Visi subtvarkytojai parenkami atsižvelgiant į jų technines, organizacines ir duomenų apsaugos priemones.
1.3. Teikėjas užtikrina, kad kiekvienam subtvarkytojui būtų taikomi ne mažesni duomenų apsaugos reikalavimai nei nustatyti DPA.
1.4. Klientas suteikia bendrą išankstinį sutikimą naudoti šiame Priede nurodytus subtvarkytojus.
2. SUBTVARKYTOJŲ SĄRAŠAS
3. DIRBTINIO INTELEKTO PASLAUGŲ TIEKĖJAI
3.1. Teikėjas naudoja Google Gemini API kaip dirbtinio intelekto paslaugų tiekėją Platformos funkcionalumui užtikrinti.
3.2. Šie tiekėjai gali būti naudojami:
- a) kalbos atpažinimui;
- b) garso transkripcijai;
- c) AI analizei;
- d) odontologinės dokumentacijos generavimui;
- e) teksto apdorojimui.
3.3. Konkretūs AI modelių variantai ir vidiniai technologiniai maršrutai gali būti neviešinami dėl saugumo ir komercinių paslapčių apsaugos, tačiau paslaugų teikėjai ir jų duomenų tvarkymo apimtis nurodomi šiame Priede.
3.4. Teikėjas užtikrina, kad naudojami AI paslaugų tiekėjai būtų parinkti atsižvelgiant į saugumo, patikimumo ir duomenų apsaugos kriterijus.
4. DEBESIJOS PASLAUGŲ TIEKĖJAI
4.1. Teikėjas gali naudoti vieną ar daugiau debesijos infrastruktūros tiekėjų Platformos veikimui užtikrinti.
4.2. Debesijos tiekėjai gali būti naudojami:
- a) duomenų apdorojimui;
- b) sistemų veikimui;
- c) atsarginių kopijų saugojimui;
- d) saugumo užtikrinimui.
4.3. Jeigu debesijos infrastruktūros tiekėjo pakeitimas reiškia naujo subtvarkytojo įtraukimą, taikomas šiame Priede nustatytas išankstinio pranešimo ir prieštaravimo procesas.
5. SUBTVARKYTOJŲ KEITIMAS
5.1. Teikėjas turi teisę:
- a) pridėti naujus subtvarkytojus;
- b) pašalinti subtvarkytojus;
- c) pakeisti subtvarkytojus;
jeigu tai būtina Paslaugų teikimui, Platformos vystymui arba saugumo užtikrinimui.
5.2. Aktuali šio Priedo versija visada pateikiama Platformoje arba pateikiama Klientui jo prašymu.
5.3. Naujas neįvardytas subtvarkytojas neaktyvuojamas, kol nepasibaigia 14 dienų pranešimo laikotarpis ir neišsprendžiami pagrįsti prieštaravimai pagal DPA.
6. DUOMENŲ PERDAVIMAS
6.1. Kai subtvarkytojai tvarko duomenis už Europos ekonominės erdvės ribų, Teikėjas užtikrina, kad būtų taikomos BDAR numatytos tinkamos apsaugos priemonės.
6.2. Tokios priemonės gali apimti:
- a) Europos Komisijos patvirtintas standartines sutarčių sąlygas (SCC);
- b) sprendimus dėl tinkamumo;
- c) kitas BDAR leidžiamas apsaugos priemones.
7. BAIGIAMOSIOS NUOSTATOS
7.1. Šis Priedas yra neatskiriama MSA ir DPA dalis.
7.2. Esant prieštaravimui tarp šio Priedo ir DPA nuostatų dėl subtvarkytojų naudojimo, pirmenybė teikiama DPA nuostatoms.
7.3. Atnaujinta šio Priedo versija įsigalioja joje nurodytą dieną, tačiau naujas neįvardytas subtvarkytojas neaktyvuojamas anksčiau, nei užbaigiamas 14 dienų pranešimo ir prieštaravimo procesas.
Patikrintas paslaugų teikėjų ir gavėjų sąrašas
Šiame sąraše atskiriami Orinote pasitelkti duomenų tvarkytojai, jų infrastruktūros dalyviai ir atskirai atskleidžiami gavėjai ar kliento nurodymu naudojamos integracijos.
| Teikėjas ir juridinis asmuo | Vaidmuo | Tikslas | Duomenų kategorijos | Tvarkymo vietos | Perdavimo apsaugos priemonės |
|---|---|---|---|---|---|
| Laravel Cloud and Laravel Cloud Object Storage Laravel Holdings Inc. |
Processor and infrastructure service provider | Application hosting, managed database and cache services, backups, logs, and object storage | Account and organization data; Patient and clinical data; Reports and final transcript content; Transient audio and transcript artifacts; Application logs and technical metadata | Frankfurt, Germany (application region); European Union (object storage jurisdiction) | EU-region configuration, EU-jurisdiction object storage, Laravel DPA, and applicable Standard Contractual Clauses for restricted transfers Teisinė informacija |
| Cloudflare Cloudflare, Inc. |
Processor and network, security, and browser-rendering service provider | DNS, content delivery, edge security, traffic protection, and server-side PDF rendering | IP addresses and request metadata; Device and security signals; Application content submitted for PDF rendering; Technical logs | Cloudflare global network, including the European Economic Area and United States | Cloudflare DPA, EU-U.S. Data Privacy Framework where applicable, and EU Standard Contractual Clauses for restricted transfers Teisinė informacija |
| Google Gemini API Google Ireland Limited |
Processor for paid Gemini API services | Speech recognition, transcription, clinical text analysis, and generation of dental documentation | Audio recordings; Transcripts and transcript versions; Patient and clinical context; Prompts and generated report content; Technical request metadata | Google and approved subprocessor facilities globally, including the EEA and United States | Google processor terms, adequacy mechanisms where available, and applicable EU Standard Contractual Clauses with supplementary measures Teisinė informacija |
| Crisp Crisp IM SAS |
Processor for customer-support workspace data | User-initiated customer support chat and support-request administration | User name and email address; Support correspondence; Account and organization context; App, device, and technical metadata | France; Netherlands; Limited approved subprocessor locations outside the EEA | Crisp DPA, EEA-focused hosting, and applicable Standard Contractual Clauses for restricted transfers Teisinė informacija |
| Stripe Stripe Payments Europe, Limited |
Independent controller and processor, depending on the payment-processing activity | Subscription billing, credit purchases, payment authentication, invoicing, and fraud prevention | Customer and billing contact details; Payment customer and transaction identifiers; Subscription and invoice data; Fraud and device signals | European Economic Area; United States and other approved service-provider locations | Stripe DPA, EU-U.S. Data Privacy Framework where applicable, and EU Standard Contractual Clauses Teisinė informacija |
| Klaviyo Klaviyo, Inc. |
Processor for customer profile and communication data | Post-registration SaaS usage instructions and other transactional onboarding communications, not marketing campaigns | User name and email address; Account and organization identifiers; Registration and product-usage events; Communication delivery and interaction metadata | United States and approved subprocessor locations | Klaviyo DPA, EU-U.S. Data Privacy Framework where applicable, EU Standard Contractual Clauses, and supplementary measures Teisinė informacija |
| Sentry Functional Software, Inc. d/b/a Sentry |
Processor for mobile application diagnostics | Mobiliosios programėlės strigčių ir našumo metaduomenys | Klaidų, įrenginio ir operacinės sistemos metaduomenys; pseudoniminiai identifikatoriai; numatytasis PII rinkimas išjungtas; paciento ar klinikinis turinys tyčia nesiunčiamas | Germany when the EU data-storage region is enabled; Approved global subprocessor locations | Sentry DPA, EU data-region configuration when enabled, and EU Standard Contractual Clauses for restricted transfers Teisinė informacija |
| Expo Application Services 650 Industries, Inc. |
Processor for mobile build, update, and push-token infrastructure; controller for limited service telemetry | Mobile application build and delivery services, update infrastructure, and Expo push-token routing | App build and release metadata; Device push tokens; Pseudonymous device and project identifiers; Technical service telemetry | United States and approved subprocessor locations | Expo terms incorporating the relevant EU Standard Contractual Clause modules Teisinė informacija |
| Apple Push Notification service and Google Firebase Cloud Messaging through Expo Apple Distribution International Limited; Google Ireland Limited |
Mobile push-notification delivery service providers | Delivery of generic report-status and price-list-status notifications to registered devices | Device push tokens; App and device identifiers; Generic notification title and status text; No patient or clinical content | European Economic Area; United States and global delivery infrastructure | Applicable Apple and Google data-protection terms, adequacy mechanisms, and Standard Contractual Clauses for restricted transfers Teisinė informacija |
| Google Sign-In Google Ireland Limited |
Independent controller and authentication-data recipient | Optional user authentication and account linking | Google account identifier; Name and email address; Profile image when supplied; Authentication and technical metadata | European Economic Area and Google global infrastructure | Google controller terms, adequacy mechanisms, and applicable Standard Contractual Clauses Teisinė informacija |
| Sign in with Apple Apple Distribution International Limited |
Independent controller and authentication-data recipient | Optional user authentication and account linking | Apple account relay identifier; Name and email or private relay address when supplied; Authentication and technical metadata | European Economic Area, United States, and Apple global infrastructure | Apple privacy and developer terms, adequacy mechanisms, and applicable Standard Contractual Clauses Teisinė informacija |
| Google Analytics Google Ireland Limited |
Processor or independent controller as specified by Google measurement terms | Consent-gated website and product usage measurement | Cookie and online identifiers; IP-derived and device information; Page, referral, and interaction events; No intentionally submitted patient or clinical content | European Economic Area, United States, and Google global infrastructure | Google Ads Data Processing Terms, EU-U.S. Data Privacy Framework where applicable, and Standard Contractual Clauses Teisinė informacija |
| Meta Pixel Meta Platforms Ireland Limited |
Joint or independent controller, and processor where applicable under Meta Business Tools terms | Consent-gated campaign measurement and conversion attribution | Cookie and online identifiers; IP address, browser, and device information; Page and conversion events; No intentionally submitted patient or clinical content | European Economic Area, United States, and Meta global infrastructure | Meta Data Processing Terms, European Data Transfer Addendum, and applicable Standard Contractual Clauses Teisinė informacija |
| YouTube Google Ireland Limited |
Independent controller for embedded-video interaction data | Consent-gated display and playback of embedded product videos | IP address and device information; Cookie and online identifiers; Video viewing and interaction data; Referring page information | European Economic Area, United States, and Google global infrastructure | Google privacy and controller terms, adequacy mechanisms, and applicable Standard Contractual Clauses Teisinė informacija |
| Clinic Cards “Cliniccards” TOV |
Downstream processor acting through the clinic-owned Clinic Cards account on clinic instructions | Exchange of patient identity, appointment, treatment, and Orinote report data through the clinic-connected Clinic Cards account | Patient identifiers and contact details; Appointments and clinic account identifiers; Health and clinical data; Treatment history and Orinote report content; Integration delivery and audit metadata | Ukraine; Germany; United States and other published subprocessor locations | Signed or incorporated Clinic Cards DPA, 2021 EU Standard Contractual Clauses Module 2, and published technical and organizational measures Teisinė informacija |
Dirbtinio intelekto teikėjai
Google Gemini yra vienintelis konkrečiai autorizuotas dirbtinio intelekto paslaugų teikėjas nuo pirminio DPA priėmimo. Jam gali būti perduodami neapdoroti garso įrašai, įkelti failai, transkripcijos ir ataskaitos tekstas tik tiek, kiek būtina Paslaugoms suteikti.
Naujo subtvarkytojo įtraukimas
Apie būsimą šiame sąraše neįvardytą subtvarkytoją paveikti duomenų valdytojai informuojami el. paštu ir Platformoje ne vėliau kaip prieš 14 dienų iki jo aktyvavimo. Per šį laiką Klientas gali pateikti pagrįstą prieštaravimą pagal DPA.