DPA
Version: 2026-09-19 · Processor terms for RehabPilot clinics worldwide
This DPA is a contractual offer under Art. 28 GDPR (and equivalent processor terms for non-EU clinics). US clinics that process HIPAA-covered PHI also accept the Business Associate Agreement (BAA).
1. Parties and roles
Controller: the physiotherapy clinic / practice that creates a RehabPilot clinic account (“Clinic”).
Processor: Rosenheinrich Software Solutions (Phillip Rosenheinrich), Destouchesstr. 3, 80803 München, Germany (“RehabPilot”, “we”).
By accepting this DPA (including via clickwrap at trial signup or checkout), the Clinic instructs us to process personal data as described below to provide the RehabPilot cloud service.
2. Subject matter, duration, nature and purpose (Annex A)
- Subject: hosting and operation of RehabPilot clinic/patient cloud features (accounts, plans, media, messaging, invites, push tokens where enabled).
- Duration: for the term of the Clinic’s RehabPilot subscription/trial and until deletion/return under §8.
- Nature: storage, transmission, display, backup, and related IT operations.
- Purpose: provide the contracted RehabPilot service to the Clinic and its patients on the Clinic’s instructions.
- Data subjects: Clinic staff; patients of the Clinic (and guardians where applicable).
- Data categories: identity and contact data; therapy plans, exercises, session notes, progress; in-app messages; media (photos/videos); authentication data; device/push tokens; technical logs.
- Special categories: health-related data may be included (Art. 9 GDPR). The Clinic is responsible for its Art. 9 legal basis.
3. Instructions
We process personal data only on documented instructions from the Clinic, including this DPA, product configuration, and support requests from verified Clinic admins — unless required by EU/Member State law (we will inform the Clinic unless legally prohibited).
4. Confidentiality
Persons authorized to process personal data are bound to confidentiality and receive appropriate training.
5. Security — technical and organisational measures (Annex B)
- Access control: least-privilege admin access; hashed passwords; session tokens in HTTP-only cookies where applicable.
- Encryption in transit (TLS) for public endpoints; media via signed/presigned URLs where configured.
- Logical separation of practice data by practice_id.
- Application and server logging for security/operations; retention limits where documented in the Privacy Policy.
- Backups and restore procedures for disaster recovery (availability).
- Dependency and security updates on a best-effort schedule.
6. Sub-processors (Annex C)
The Clinic authorises the sub-processors listed below. We will publish material changes by bumping this DPA version on the website. Continued use of the service after publication constitutes authorisation. The Clinic may object on reasonable data-protection grounds within 14 days of publication by emailing [email protected].
- Application hosting (dedicated servers) — Rosenheinrich-operated dedicated servers at Hetzner Online GmbH, data centre Nuremberg, Germany. Processes application data and databases.
- Cloudflare, Inc. — R2 object storage for exercise/media assets; CDN/DNS/security as configured. May involve processing outside the EEA with SCCs/appropriate safeguards.
- Amazon Web Services EMEA SARL (Amazon SES) — transactional email (SMTP) for invites, magic links, plan PDFs; EU sending region as configured in production.
- Google LLC — Firebase Cloud Messaging (push); Firebase Analytics (optional, anonymised app telemetry where enabled); Google Sign-In when used.
- Apple Inc. — Sign in with Apple when used.
- Stripe, Inc. — payment/billing for Clinic subscriptions (typically Controller data for billing, not therapy content). Listed for transparency.
7. International transfers (Annex D)
Application hosting (dedicated servers) is in Germany (Hetzner, Nuremberg). Where other sub-processors process data outside the EEA/UK/Switzerland (e.g. Stripe, Cloudflare, Google/Apple), transfers rely on appropriate safeguards (e.g. EU Standard Contractual Clauses and the vendor’s DPA), plus the measures in Annex B.
8. Assistance, breaches, deletion
- We assist the Clinic with data-subject requests, DPIAs, and consultations insofar as feasible for a SaaS processor.
- We notify the Clinic without undue delay after becoming aware of a personal-data breach affecting Clinic data.
- End of contract: on Clinic request or account deletion, we delete or return Clinic personal data from production systems within 30 days, and from backups within a further 90 days, except where retention is required by law. Admin deletion of a practice removes associated clinical records and legal-acceptance audit rows for that practice.
9. Audits
Upon written request (max. once per 12 months, unless a supervisory authority requires more), we provide information reasonably necessary to demonstrate Art. 28 compliance (e.g. this DPA, TOM summary, sub-processor list). On-site audits are replaced by documentation unless a supervisory authority mandates otherwise.
10. UK and Switzerland
Clinics in the United Kingdom must also accept the UK GDPR Addendum. Clinics in Switzerland must also accept the Swiss nDSG Addendum. EU/EEA clinics accept this DPA alone (German version: AVV).
11. Liability
Liability is as set out in the Terms of Service / AGB, without limiting mandatory GDPR processor liability where applicable.
12. Contact
Phillip Rosenheinrich · Rosenheinrich Software Solutions · Destouchesstr. 3 · 80803 München · Germany · [email protected]
