Institutional DPA
This Institutional Data Processing Addendum (DPA) is entered into by [Institution legal name] (Customer) and Surgeon AI LLC, trading as SurgeonAI (Processor), and forms part of the agreement under which Processor provides the Service to Customer (Agreement).
If this DPA conflicts with the Agreement on the processing of Personal Data, this DPA prevails. Capitalised terms not defined here have the meaning given in the Agreement or applicable Data Protection Law.
Customer is Controller and Processor acts as Processor when processing Customer Personal Data to provide the Service. Processor will process Customer Personal Data only on Customer’s documented instructions, including those in the Agreement, this DPA, and the configured use of the Service, unless required by applicable law. If legally permitted, Processor will inform Customer before processing required by law.
Customer warrants that it has a lawful basis for the processing and for its instructions, has provided all required notices, and will not instruct Processor to process patient-identifying data or PHI unless the parties have separately agreed in writing to an appropriate healthcare-data arrangement.
Processor will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory duty of confidentiality, and will limit access to those with a legitimate need to know.
Processor will implement appropriate technical and organisational measures considering the nature, scope, context, purposes, and risks of processing. These measures will include, as appropriate, encryption in transit, role-based access, logical segregation, least privilege, logging, secure-development practices, vulnerability management, backup and recovery controls, incident response, and supplier due diligence.
Customer gives Processor general authorisation to appoint subprocessors necessary to provide the Service. Processor will impose written data-protection obligations on subprocessors that are no less protective than those in this DPA for the relevant processing.
Processor will maintain a current sub-processor list at https://surgeon.ai/subprocessors and will provide Customer at least 30 days’ advance notice of a material new subprocessor where reasonably practicable. Customer may object on reasonable, data-protection grounds during that period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Service on reasonable written notice without penalty for the unused affected portion.
Taking account of the nature of processing, Processor will provide reasonable assistance to Customer, through appropriate technical and organisational measures, to fulfil verified requests from data subjects to exercise rights under Data Protection Law. If Processor receives a request directly relating to Customer Personal Data, it will promptly forward it to Customer unless legally prohibited or able to respond under Customer’s documented instructions.
Processor will provide reasonable information and assistance to help Customer meet obligations concerning security, data protection impact assessments, prior consultation, breach notification, and regulatory enquiries, to the extent required by Data Protection Law and proportionate to the Service.
Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide available information reasonably needed for Customer to meet its reporting obligations. Processor will take reasonable steps to contain, investigate, mitigate, and remediate the breach. Processor will not notify affected data subjects on Customer’s behalf unless required by law or expressly authorised by Customer.
Where Customer Personal Data is transferred from the UK or EEA to a country not recognised as adequate under applicable Data Protection Law, the parties will implement a valid transfer mechanism, including the UK International Data Transfer Agreement/Addendum and/or the European Commission’s Standard Contractual Clauses, as applicable, together with supplementary measures where appropriate. The parties will cooperate in good faith to complete the relevant modules and annexes.
At the end of the Agreement, Processor will, at Customer’s choice, return or delete Customer Personal Data within 90 days, unless retention is required by law or the data remains in a secure backup cycle. If retained by law, Processor will protect it and stop active processing except as required by law. De-identified, aggregated information that does not identify Customer or any individual may be retained where permitted by law.
On reasonable written request not more than once annually, Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Where available, Processor may satisfy this obligation through independent audit reports, certifications, penetration-test summaries, or other appropriate third-party assurances.
If those materials are insufficient and a material compliance concern remains, Customer may conduct or appoint an independent auditor to conduct a remote or on-site audit on at least 30 days’ notice, during normal business hours, subject to confidentiality, security, safety, and reasonable cost-allocation safeguards. Audits must not unreasonably disrupt Processor’s operations or expose other customers’ confidential information.
| Item | Details |
|---|---|
| Subject matter | provision of AI-supported surgical education, learning analytics, simulations, logbook/portfolio tools, educator oversight, and associated support |
| Duration | term of the Agreement plus permitted deletion/backup period |
| Nature of processing | collection, recording, organisation, structuring, storage, retrieval, consultation, analysis, transmission to authorised users/subprocessors, restriction, deletion, and destruction |
| Purpose | provide, secure, support, maintain, and improve the contracted Service; meet legal obligations; prevent abuse |
| Categories of data subjects | authorised trainees, medical students, surgeons, educators, programme administrators, and support contacts |
| Categories of personal data | account/contact details; professional/training data; learning and assessment outputs; logbook and portfolio information; communications; technical logs; optional voice/video/transcripts where enabled |
| Special categories | not intended. Customer must not provide patient data, PHI, or special-category data unless expressly agreed in writing with appropriate safeguards |
| Frequency | continuous for authorised use of the Service |
| Retention | as specified in the Agreement, Customer configuration, Privacy Notice, and this DPA |
Customer will not use AI-generated feedback, scores, safety labels, competency profiles, readiness bands, or other Service outputs as the sole basis for a high-impact decision concerning an individual. Customer will provide meaningful human review, context, transparency, and a fair opportunity to correct or challenge material errors before relying on such information for consequential action.
| For Customer | For SurgeonAI |
|---|---|
| Name: [name] | Name: [name] |
| Title: [title] | Title: [title] |
| Date: [date] | Date: [date] |
| Signature: [signature] | Signature: [signature] |