Legal & Trust
Data Processing Agreement
Preamble & Execution
This Data Processing Agreement ("DPA") governs the processing of personal data by Dicomly on behalf of the Customer in connection with the Dicomly service. This agreement satisfies the requirements of Article 28(3) and Article 28(4) of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR").
How to execute this DPA:
The terms below are the agreement in full. To put a signed copy in your compliance files, email info@dicomly.io and we will send you this agreement as a signable PDF. Return it signed and we will send back a countersigned copy within one business day.
1. Parties
This DPA is entered into between:
- The Customer ("Data Controller"): The entity or organization that registers for an account and configures endpoints on Dicomly to receive DICOM imaging data.
- Dicomly ("Data Processor"):
Ing. Martin Höger
IČO: 76263428
Svestkova 2337
412 01 Litoměřice
Czech Republic
Contact: info@dicomly.io
2. Scope, Subject Matter, and Duration
2.1 Subject matter: The Processor provides stateless, real-time protocol conversion and forwarding of medical imaging data (DICOM DIMSE C-STORE to DICOMweb STOW-RS over HTTPS) to the Controller's designated destination URL.
2.2 Duration: This DPA remains in effect for the duration of the Principal Agreement (Terms of Service) and terminates automatically upon closure of the Controller's account and cessation of all data transmission activities.
3. Nature and Purpose of Processing (Stateless Transit)
3.1 Real-time conduit: The Processor operates exclusively as a real-time data conduit. Processing consists strictly of receiving incoming TLS-encrypted DICOM streams, translating wire protocols in flight, and streaming the resulting payload directly to the Controller's specified STOW-RS webhook endpoint.
3.2 Zero persistence: No payload data is stored, cached, buffered on disk, or queued on Processor infrastructure; zero retention of medical image files, DICOM datasets, or patient records. Bytes exist in volatile memory only for as long as the transfer itself takes. When a transmission completes or aborts, all in-flight buffers are immediately released.
4. Categories of Data and Data Subjects
4.1 Data subjects: Patients whose diagnostic or therapeutic medical imaging studies are transmitted by hospitals, imaging centers, or medical devices to the Controller's Dicomly endpoint.
4.2 Categories of personal data: Special category health data under GDPR Article 9(1), specifically diagnostic medical imaging datasets in DICOM format.
4.3 Processing modality: In-transit protocol translation only. Zero storage or data mining.
5. Obligations of the Processor
The Processor agrees and commits to:
- Documented instructions: Process personal data solely on documented instructions from the Controller, as established by the Controller's endpoint routing configuration, unless required to do so by applicable European Union or Member State law.
- Confidentiality: Ensure that all personnel authorized to operate the infrastructure have committed themselves to strict statutory or contractual confidentiality.
- Security of processing: Implement technical and organizational security measures compliant with GDPR Article 32, as detailed in Dicomly Security and Annex II.
- Sub-processor controls: Adhere to the conditions for engaging sub-processors as stipulated in Section 6 and GDPR Article 28(2) and (4).
- Assistance to Controller: Assist the Controller, taking into account the stateless nature of processing, in responding to data subjects exercising their rights under Chapter III GDPR.
- Breach notification: Notify the Controller without undue delay, and in any event within 24 hours of becoming aware of any confirmed personal data breach affecting infrastructure through which Controller data transits.
- Deletion and return: Due to the stateless architecture, no customer imaging data is retained. Upon termination of service, all routing endpoints and cryptographic credentials are revoked and permanently deleted.
- Audits and verification: Make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 obligations, and allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller.
6. Sub-processors
6.1 Authorized sub-processors: The Controller grants general authorization to the Processor to engage the sub-processors listed on our public directory at Dicomly Sub-processors.
6.2 Notification of changes: The Processor shall notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance by email to the Controller's registered administrative contact address.
6.3 Right to object: The Controller has the right to object to any new sub-processor on reasonable data protection grounds within 14 days of receiving notice. If the parties cannot resolve the objection, the Controller may terminate the affected endpoints without penalty.
6.4 Flow-down of obligations: The Processor enters into written data processing agreements with all sub-processors imposing data protection obligations no less protective than those in this DPA.
7. International Data Transfers
7.1 Primary processing location: All Dicomly gateway processing and transmission infrastructure is hosted within the European Economic Area (specifically Germany, EU).
7.2 Third-country transfers: Any transfer of personal data to a third country or international organization shall only take place on the basis of an adequacy decision pursuant to GDPR Article 45, or standard contractual clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c).
8. Liability and Governing Law
8.1 Liability: Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement (Terms of Service). Nothing in this DPA limits either party's liability towards data subjects under applicable data protection law.
8.2 Governing law and jurisdiction: This DPA is governed by the law of theCzech Republic, without regard to its conflict-of-law provisions, and the parties submit to the exclusive jurisdiction of the competent courts of the Czech Republic. Where the GDPR or Member State data protection law of the Controller's establishment imposes stricter requirements, those requirements prevail.
8.3 Order of precedence: In the event of a conflict between this DPA and the Principal Agreement in relation to the processing of personal data, this DPA prevails.
9. Annex I — Description of Transfer and Processing
A. List of Parties:
- Controller: Customer organization using Dicomly to receive clinical imaging.
- Processor: Ing. Martin Höger (Dicomly), Svestkova 2337, 412 01 Litoměřice, Czech Republic.
B. Categories of Data Subjects: Patients undergoing medical imaging procedures.
C. Categories of Personal Data: Diagnostic imaging datasets (DICOM format), which may contain embedded patient demographic data (name, ID, birth date) and clinical image data.
D. Nature of Processing: Ephemeral, in-transit protocol conversion from DICOM DIMSE C-STORE over mutual TLS to DICOMweb STOW-RS over HTTPS.
E. Retention Period: Payload data is not retained. DICOM bytes are never written to non-volatile storage; they exist in volatile memory only for as long as the transfer itself takes, and are released as soon as the transfer completes or aborts.
10. Annex II — Technical and Organizational Security Measures (TOMs)
The Processor maintains security measures designed to protect personal data during transit:
- Mutual TLS (mTLS): All inbound DICOM transmissions require client certificates verified against dedicated customer credentials. Inbound associations without valid certificates are rejected at the TLS handshake.
- HTTPS Encryption: All outbound STOW-RS requests are encrypted using TLS 1.3 or TLS 1.2 with forward secrecy cipher suites.
- Zero Local Persistence: Core gateway workers are configured with read-only filesystems. No imaging data is written to disk, scratch spaces, swap files, or local storage.
- Separation of Control and Data: Account credentials, routing configurations, and audit telemetry are strictly separated from data transit paths. Account and configuration systems never store or process DICOM imaging files.
- Access Controls: Administrative access to production infrastructure is restricted to named operators, authenticated by SSH key. There are no shared administrative accounts and no password-based administrative login.
- Reproducible Deployment: Production runs from version-controlled infrastructure code. Services are redeployed from that code rather than modified in place, and the same code path is used to restore service during recovery.
For additional details regarding technical controls, visit the Dicomly Security Hub.
11. Annex III — Authorized Sub-processors
The current list of sub-processors engaged by Dicomly, including their processing role, corporate location, and data center regions, is maintained at https://dicomly.io/subprocessors.
Key infrastructure providers include European cloud hosting facilities (Amazon Web Services EMEA SARL in Frankfurt, Germany) for routing and control plane compute, and payment processing services (Stripe, Inc.) for administrative billing.
12. Signatures & Countersignature Process
To execute this agreement, email us and we will send it to you as a signable PDF. Add your organisation's details and authorised signature, return the document, and we will send back a countersigned copy:
Email: info@dicomly.io
Turnaround time: Countersigned within 1 business day.