Last Updated: August 31, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the Clinic and Juxano, Inc., operating as PatientBack ("PatientBack"), created by the Clinic's acceptance of the Terms of Service. It applies whenever PatientBack processes personal data of the Clinic's patients on the Clinic's behalf. In case of conflict between this DPA and the Terms regarding the processing of patient data, this DPA prevails.
The Clinic is the controller of its patients' personal data; PatientBack is the processor. Where local law uses different names for these roles — such as "Data Fiduciary" and "Data Processor" under India's DPDP Act — the same allocation applies.
PatientBack processes patient data only on the Clinic's documented instructions. The Terms, this DPA, and the Clinic's configuration and use of the service — adding patients, enabling reminders, choosing channels, uploading images — constitute those instructions. PatientBack will inform the Clinic if, in its opinion, an instruction infringes applicable data protection law.
Persons authorised to process patient data are bound by confidentiality obligations. PatientBack implements appropriate technical and organizational measures, including: encryption of data in transit; encryption at rest of the most sensitive patient fields (identity documents, tax numbers, dates of birth, home addresses); storage of X-ray images under random identifiers with original file names and technical metadata removed; logging of access and of changes to patient records; and hosting in the European Union. A detailed description of current measures is available to the Clinic on request.
The Clinic gives general authorisation for PatientBack to engage sub-processors for hosting, storage, message delivery, email delivery and payment processing. PatientBack imposes data protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. A current list of sub-processors, with the role of each, is available on request at info@patientback.com. PatientBack will give the Clinic prior notice of intended additions or replacements; if the Clinic reasonably objects, it may terminate the affected service.
Application servers and databases are located in the European Union. Where a sub-processor processes personal data outside the European Economic Area, the transfer is made under safeguards required by applicable law, such as the European Commission's Standard Contractual Clauses.
Taking into account the nature of the processing, PatientBack will assist the Clinic with appropriate technical and organizational measures in fulfilling data subject requests (access, correction, deletion, objection), and in the Clinic's obligations regarding security, breach notification and data protection impact assessments.
PatientBack will notify the Clinic without undue delay after becoming aware of a personal data breach affecting the Clinic's patient data, and will provide information reasonably needed for the Clinic to meet its own notification obligations.
PatientBack may use de-identified X-ray images — stripped of names, identifiers and metadata — to improve its own analysis models. The Clinic may opt out at any time by writing to info@patientback.com, with no effect on the service.
When the Clinic deletes a patient, the records are removed and stored images are erased within 30 days. On termination of the service, PatientBack will, at the Clinic's choice, return the Clinic's patient data in a commonly used format or delete it, unless law requires further storage. Rolling backups are overwritten in turn.
PatientBack will make available to the Clinic information reasonably necessary to demonstrate compliance with this DPA, and will allow audits — normally satisfied by written responses, documentation and third-party attestations, and conducted no more than once per year on reasonable notice unless a supervisory authority requires otherwise.
Liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by applicable data protection law. This DPA applies for as long as PatientBack processes patient data on the Clinic's behalf.
Juxano, Inc., Cheyenne, Wyoming, USA — info@patientback.com