Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Order and Terms between an organizational customer (“Customer”) and the independent company identified in that Order: Virtuosis Artificial Intelligence SA or its affiliates, including but not limited to Virtuosis Health SAS (“Virtuosis”). It applies only when Virtuosis processes personal data for Customer, not to direct consumer use.

1. Roles and scope

Customer is controller and Virtuosis is processor of personal data processed on Customer’s behalf (“Customer Personal Data”). If Customer is a processor, Virtuosis is its subprocessor and Customer confirms it may give the instructions in the agreement. Each party complies with the EU GDPR, Swiss FADP or other data-protection law applicable to it. Virtuosis is an independent controller for its own business contacts, billing, security, legal compliance and regulatory or vigilance records; the Privacy Policy covers that processing.

2. Processing details

3. Instructions and Customer duties

Virtuosis processes Customer Personal Data only on documented instructions in the agreement, settings and agreed written requests, including for transfers, unless law requires otherwise. It will first inform Customer of that requirement unless prohibited and promptly warn if it reasonably believes an instruction violates applicable data-protection law.

Customer is responsible for lawful instructions, transparency, legal bases and sensitive-data conditions, permissions, data accuracy, Service configuration, and required professional, clinical, employment, research or ethics approvals. For a study, Customer provides the study-specific participant notice and obtains each distinct consent or authorization required.

Virtuosis will not use identifiable Customer Personal Data to train or develop models without Customer’s written authorization and a lawful basis. Properly anonymized data is outside this DPA; pseudonymized data is not.

4. Confidentiality and security

Virtuosis limits access to personnel and subprocessors who need it and are bound to confidentiality. Taking account of risk, state of the art and cost, it maintains appropriate measures, including least-privilege access and strong authentication; encryption in transit and at rest where appropriate; separation and minimization or pseudonymization; logging, monitoring, incident response, backup and recovery; and secure development, testing, patching and provider review. Measures may change without materially reducing overall protection.

5. Breaches and assistance

Virtuosis will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide available information reasonably needed for Customer’s duties. Notification is not an admission of fault. Taking account of the processing and information available, Virtuosis will reasonably assist with data-subject requests, security, breach notices, impact assessments, prior consultations and regulator inquiries. Reasonable agreed fees may apply to exceptional assistance not caused by Virtuosis, where law permits.

6. Subprocessors

Customer gives general authorization for the following providers only to the extent the listed service is used. Virtuosis imposes equivalent data-protection duties as applicable and remains responsible under the agreement. Where Virtuosis Health SAS is the contracting entity, Virtuosis Artificial Intelligence SA (Switzerland; adequacy) is also authorized as its subprocessor for operating and supporting the Services.

Virtuosis will give reasonable prior email or in-Service notice before adding or replacing a subprocessor. Customer may promptly object on reasonable data-protection grounds. The parties will seek a practical solution; if none is available, Virtuosis may change or stop the affected feature, or Customer may terminate only that affected Service.

7. Hosting, HDS and transfers

Customer Personal Data is hosted as stated above unless the Order states another region. Another transfer requires Customer’s documented instruction and a lawful safeguard. For French health data subject to Article L.1111-8 of the Public Health Code, the Order or HDS terms identify the certified host, activities and services; eligible Azure services must remain within Microsoft’s applicable HDS certification scope.

Switzerland provides adequate protection for EU transfers, so no Standard Contractual Clauses are required solely because the contracting entity is Virtuosis Artificial Intelligence SA or Virtuosis Health SAS or other affiliates in the EU. Any onward transfer to a destination without adequate protection uses the applicable provider or party Standard Contractual Clauses, with Swiss adaptations where required, or another lawful safeguard. Unless prohibited, Virtuosis will notify Customer of a binding government request, assess it and disclose only what is legally required.

8. Return and deletion

At the end of the Services and at Customer’s choice, Virtuosis will return or make Customer Personal Data available for export, then delete it and existing copies unless law requires retention. Unless the Order states otherwise or the Terms provide a longer period, Customer must export within 30 days after termination. Retained data remains protected and unused for another purpose and is deleted through the documented backup or retention cycle. Where HDS rules apply, health data is destroyed upon the controller’s request and without retaining a copy, other than protected backup copies pending their normal deletion cycle. Except where law requires deletion, this Section does not apply to Customer Personal Data that Customer has instructed Virtuosis to retain for a purpose documented in the Order or applicable agreement, which Virtuosis may retain and process for that purpose and for the period instructed, subject to a lawful basis. The rest of this DPA continues to apply to that data.

9. Information and audits

Virtuosis will provide information reasonably necessary to demonstrate compliance and may first provide security documentation, certifications or audit reports. Customer may audit at reasonable intervals where it reasonably suspects material non-compliance, after a breach, where an authority requires it, or where necessary for Customer's own compliance. Audits require reasonable notice, confidentiality, security, protection of other customers and minimal disruption. Customer bears reasonable costs unless the audit identifies a material Virtuosis breach.

10. Priority, liability and law

This DPA prevails over conflicting agreement terms for Customer Personal Data; mandatory transfer clauses and applicable HDS terms prevail for their subject. Liability is governed by the agreement unless mandatory law or transfer clauses prohibit the limitation. The law and courts stated in the Order or Terms apply, based on the contracting entity. The version incorporated into the Order governs that Order; an online update applies only to a renewal, new Order, or express acceptance unless law requires earlier effect.

Privacy contact: privacy@virtuosis.ch. Virtuosis Artificial Intelligence SA: EPFL Innovation Park, Bâtiment C, CH-1015 Lausanne, Switzerland, UID CHE-174.048.997. Virtuosis Health SAS: 14 rue Federico Garcia Lorca, 76320 Saint-Pierre-lès-Elbeuf, France, SIREN 939 667 812.

 

Last updated: 18 September 2026

We use optional cookies to measure site usage and load YouTube videos. You can change your choice anytime in Cookie preferences. Read our Cookie Policy.