RITAJA PRACTICE

Data Processing Agreement (DPA)

Summary for UK and European Economic Area customers where your practice is the data controller and Ritaja Practice processes personal data (including health data) on your behalf under GDPR / UK GDPR Article 28.

Not a substitute for counsel. This page summarizes standard DPA topics. Your executed DPA and Standard Contractual Clauses (if applicable) are provided during onboarding.

Last updated: August 2026

Roles

You determine purposes and means of processing patient and staff personal data in your practice. Ritaja Practice processes that data only on your documented instructions as set out in the DPA and Terms of Service.

Processing instructions

  • Process personal data only to deliver the subscribed service and support.
  • Inform you if we believe an instruction infringes GDPR, where legally permitted.
  • Not engage another processor without your authorization (subprocessors listed below).

Security measures

We implement appropriate technical and organizational measures, including access control, encryption in transit, logging, and confidentiality commitments for personnel. See Trust & security.

Subprocessors

We use the following categories of subprocessors depending on features you enable. Your service agreement identifies which apply to your deployment.

Subprocessors that may process clinic or client data depending on deployment configuration
ProviderPurposeWhat they may handle
Cloud hostingApplication hosting, database, and backupsAll clinic and patient data stored in your deployed region

Our hosting provider offers a BAA for covered services when configured for HIPAA workloads.

Email deliveryTransactional email (activation, portal verification, notifications)Email addresses, message content you send via the platform
Video telehealthSecure video visits between clinician and patientVideo session connection details; video/audio per your setup

Your practice confirms agreements cover telehealth if required.

Microsoft Azure OpenAIOptional AI writing assist and clinical documentation drafting (when your practice enables it)Clinical text submitted for that task only, with identifying details removed first. Microsoft’s Azure OpenAI service terms provide that prompts are not retained for model training.

Runs inside our own Azure tenant under a Microsoft Business Associate Agreement — not the public OpenAI API and not a third-party AI vendor. No client or clinician name, date of birth, phone number, email or address is sent to the model in any AI feature: chart assistants and note drafters carry no identifying fields, report drafting substitutes placeholders that are restored afterwards, group notes are pseudonymised, and free-text note excerpts pass through a PHI scrubber first. Our AI request logs record token counts only, never prompt or completion text. Opt-in; requires BAA on file and practice administrator enablement.

Microsoft Azure Speech (optional)Optional clinician dictation — speech-to-text for the clinician composing a noteThe clinician’s own dictated audio; no client audio is captured. Audio is discarded once text is returned.

Same Azure tenant and Business Associate Agreement as above — no third-party scribe or transcription vendor. Only the clinician speaks; sessions are not recorded and clients are not captured, so no client recording consent arises. The clinician reviews and edits the text before signing any note.

E-prescribing partner (US, optional)Optional US e-prescribing when platform and clinic enable eRx add-onPrescriber credentials, patient demographics, allergies, medication orders (via partner UI)

Enabled per clinic; requires prescriber identity proofing (EPCS) through the partner.

Payment processor (not currently in use)Card payment processing for optional patient-portal premium subscriptions. Built but not enabled for any clinic — no card payments are processed today.If enabled: cardholder payment details entered directly with the processor — never sent to or stored by Ritaja Practice — plus billing name and email. Nothing is shared while the integration is off.

We will confirm a Business Associate Agreement is in place with the processor before enabling it for any clinic handling PHI.

International transfers

Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses and supplementary measures described in your DPA.

Data subject rights

We assist you in responding to requests from individuals (access, rectification, erasure, restriction, portability) using product tools or support, within reasonable timeframes and as required by Article 28(3).

Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data in our systems, and provide information needed for your regulatory notifications.

Deletion & return

Stopping payment does not wipe records that day. If the account is suspended or cancelled, we keep personal data for 90 calendar days so you can export or email us for a copy (include your practice name and “data export”). After that window we delete or return personal data per your instructions and this DPA, subject to legal retention, rolling backups, and copies you already received. Operational detail matches the US BAA data-after-termination section and the Terms of Service.

Audits

We make available information necessary to demonstrate compliance and allow audits described in the DPA, typically via documentation and questionnaires rather than on-site visits except where required by law.

How to obtain the DPA

Register at /signup. The countersigned DPA is provided with activation. US HIPAA practices should also review the BAA. UK and EU customers should read our GDPR & DPA guide.

Contact

Privacy and data protection inquiries:

See the Privacy Policy for general privacy practices.

← Plans & pricing · Trust center · BAA · DPA