Relvema가 GDPR, UK GDPR, CCPA 및 해당 미국 주 개인정보 보호법에 따라 치료사와 개업의를 대신하여 개인 데이터를 처리하는 방법입니다.
DPA 읽기
Effective June 10, 2026
This Data Processing Agreement (“DPA”) governs how Relvema processes personal data on behalf of therapists and practices using the Relvema platform (“Controller”). It satisfies the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable U.S. state privacy laws including the California Consumer Privacy Act (CCPA/CPRA) and the Florida Digital Bill of Rights.
This DPA is incorporated by reference into the Relvema Terms of Service and supplements the Business Associate Agreement (BAA) for health-related personal data processed under HIPAA. Where health information is involved, the BAA governs; this DPA governs all other personal data processing.
In providing the Services, Relvema processes the following categories of personal data on behalf of the Controller:
| Category | Data elements |
|---|---|
| Patient identity | Full name, email address |
| Clinical content | Session audio recordings, AI-generated transcripts, SOAP/DAP/BIRP clinical notes, session summaries and insights |
| Patient app data | Mood scores, journaling entries, homework assignments and completion data, push notification interactions |
| Scheduling data | Appointment dates and times, modality, session-specific notes |
| Therapist profile | Name, email, phone, professional credentials (license type/number/state), specializations, practice information |
| Usage data | Session counts, note generation activity, platform engagement metrics (aggregated, not sold or shared) |
Special category data (health data) is processed under both this DPA and the HIPAA BAA. The BAA governs in case of conflict for data subject to HIPAA.
Relvema processes personal data solely to provide the Services described in the Terms of Service and as instructed by the Controller through the platform interface. Relvema will not process personal data for any other purpose, including but not limited to:
If Relvema is required by applicable law to process personal data in a manner inconsistent with these instructions, Relvema will notify the Controller before processing unless prohibited by law.
Relvema implements the technical and organizational measures described in the HIPAA Security Policy for all personal data, including:
The Controller authorizes Relvema to engage the following sub-processors to process personal data as part of providing the Services:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google LLC (Google Cloud) | Cloud infrastructure (Firestore, Cloud Storage, Cloud Functions, Vertex AI, Firebase Authentication, Secret Manager, App Hosting) | United States (primary); GDPR-compliant EU regions available on request |
| Stripe, Inc. | Payment processing (subscription billing only; does not process health data or patient data) | United States |
Relvema will notify Controllers of any intended changes to this sub-processor list (additions or replacements) with at least 30 days’ advance notice, giving Controllers the opportunity to object. If a Controller objects and Relvema cannot accommodate the objection, the Controller may terminate the Services agreement without penalty.
Relvema ensures that all sub-processors are bound by data protection obligations no less protective than those in this DPA, including appropriate agreements under GDPR Article 28 or equivalent frameworks.
Relvema will assist the Controller in responding to data subject rights requests to the extent technically feasible, including:
Personal data is processed primarily in Google Cloud’s United States regions. For Controllers in the European Economic Area (EEA) or United Kingdom, the transfer of personal data to Relvema (located in the United States) is governed by:
Controllers in the EEA or UK who require data to be processed within the EEA should contact compliance@relvema.com to discuss Google Cloud regional configuration options.
Relvema retains personal data for the duration of the Controller’s active subscription plus any applicable legal retention requirement. Upon termination of the Services agreement:
Controllers may request earlier deletion by emailing support@relvema.com. Deletion requests will be confirmed in writing.
Relvema will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA. Upon at least 30 days’ written notice, Relvema will allow for audits or inspections by the Controller or an authorized third-party auditor, subject to reasonable confidentiality protections. Alternatively, Relvema may satisfy this obligation by providing relevant third-party audit reports (SOC 2 or equivalent) covering the systems used to process Controller data.
For questions about data processing, to exercise rights under this DPA, or to request signed SCCs, contact Relvema’s Privacy Officer at compliance@relvema.com.