What is a Data Processing Addendum?
A Data Processing Addendum (DPA) is a contract that governs how a service provider processes personal data on behalf of a customer in compliance with privacy laws — most notably the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar frameworks.
Our DPA supplements the main subscription agreement and the Terms of Use. It covers the processing of personal data of EU and UK individuals and any other personal data covered by applicable privacy law.
What our DPA covers
The NexiumCare DPA addresses, at minimum:
- The subject matter, duration, nature, and purpose of processing.
- Categories of data subjects and personal data processed.
- Customer's instructions and the obligations of NexiumCare as a processor.
- Confidentiality obligations of personnel with access to personal data.
- Technical and organizational measures (TOMs) to ensure appropriate security.
- Use of subprocessors, prior authorization, and the customer's right to object.
- Data subject rights — access, rectification, erasure, restriction, portability, objection.
- Personal data breach notification timelines and content.
- Data Protection Impact Assessment (DPIA) cooperation.
- Audit rights, including audit reports and on-site audits where required.
- Return or deletion of personal data on termination.
Standard Contractual Clauses (SCCs)
For data transfers outside the EEA, the UK, or Switzerland, our DPA incorporates the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor and Module 3: Processor to Processor, where applicable), as adopted in 2021 (Commission Decision (EU) 2021/914).
For UK transfers, we use the UK International Data Transfer Addendum (IDTA) issued by the ICO. For Swiss transfers, the SCCs are amended to address the Federal Data Protection Act (FADP).
Subprocessors and authorization
NexiumCare maintains a current list of subprocessors that process personal data on our behalf. The customer provides general written authorization for the engagement of subprocessors, subject to written notice of any intended additions or replacements at least 30 days in advance. The customer may object to a new subprocessor on reasonable grounds.
Technical and organizational measures
The technical and organizational measures NexiumCare implements to protect personal data are described on our Security & Compliance page and incorporated by reference into the DPA. Measures include encryption in transit and at rest, role-based access control, multi-factor authentication, audit logging, continuous monitoring, vulnerability management, and incident response procedures.
Data subject rights and assistance
NexiumCare provides functionality within the platform to help customers respond to data subject requests — including export, deletion, and rectification. Where additional assistance is required, NexiumCare will cooperate with the customer at no additional charge for assistance reasonable in scope and frequency.
Personal data breach notification
NexiumCare will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. The notification will describe the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it.
How to request the DPA
To execute the DPA:
- Email [email protected] with your organization's legal entity name, registered address, and authorized signatory.
- NexiumCare will return a counter-signed DPA within two business days.
- For enterprise customers with their own DPA template, our legal team reviews and either accepts or proposes redlines within five business days.
Common questions
Do I need a DPA if I'm a US-only practice? Generally, no. The DPA is required when your practice processes personal data of EU, UK, or Swiss individuals, or when other privacy laws (e.g., CCPA/CPRA, PIPEDA) require equivalent processor terms. Many US practices request the DPA as a best practice.
Is the DPA enough on its own? No — the DPA supplements your subscription agreement and the Terms of Use. Healthcare practices with PHI also need our Business Associate Agreement.
What about CCPA / CPRA? Our DPA includes service provider terms compliant with the California Consumer Privacy Act / California Privacy Rights Act. Equivalent terms are included for Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA).

