A data processing agreement (DPA) is required by Article 28(3) GDPR whenever a controller uses a processor. Heltio is that processor for the practice, and the providers listed below are processors for Heltio.
Where to find it
Three pages, all public and all carrying a Draft banner — the documents are awaiting review by Polish counsel:
/podprocesorzy— the list of providers with region, data category, retention period and a link to the provider's own agreement./dpa— the model processing agreement between the practice and Heltio./processor-agreement— the short summary of that agreement, accepted when the practice signs up.
Accepting the agreement at sign-up is recorded as a separate practice-consent record: the document type, its version, the moment of acceptance, the IP address and the browser identifier.
The provider list
Read from the register in the source of the /podprocesorzy page.
Active (10):
| Provider | For what | Region | Data |
|---|---|---|---|
| Supabase | Database, files, sync | Frankfurt | personal, health |
| Clerk | Sign-in, sessions, two-factor authentication | EU (to be confirmed) | personal |
| AWS KMS | Key management | Frankfurt | none |
| PowerSync | Offline work in the mobile app | EU | personal, health |
| MailerSend | Transactional and marketing e-mail | EU | personal |
| SMSAPI (LINK Mobility) | SMS | Poland | personal |
| Przelewy24 (PayPro) | Patient payments and the Heltio subscription | Poland | personal, financial |
| Better Stack | Uptime monitoring | EU | operational |
| Polish e-Health Centre (P1) | Medical events, EDM | Poland | personal, health |
| DeepL | Message translation | Germany | personal |
Planned (1): Sentry — error monitoring; the entry is waiting for the EU region to be switched on.
Listed as disabled (3): Anthropic, OpenAI, Google Calendar.
The e-Health Centre is not a classic processor — it is a separate public controller, acting under the Health Information System Act. The practice does not entrust data to it under Article 28; it hands the data over because the law says so.
A discrepancy you need to know about
AWS KMS is listed the same way, as an active key-management provider, while in the code the master key comes from an environment variable — the KMS layer is prepared but not in use. Details: Encryption and data residency.
Changing the list
Changing a provider means changing the register in the source of the /podprocesorzy page and deploying. There is no mechanism in the app today that automatically notifies practices of a change to the list or counts an objection period — the previous version of this page described such a mechanism together with a change register; the database schema has no matching table. The notification has to be sent by hand.
After the relationship ends
A practice can export its data from the panel — see Clinic data export. The deadlines for deleting data after termination are governed by the text of the processing agreement at /dpa, not by a separate mechanism in the app.
Related
- GDPR at Heltio — the division of roles and the four gates before anything is sent to AI.
- Patient consent for AI processing — what accepting the disclosure looks like in practice.
- P1 and EDM — the one recipient the practice cannot switch off.
- Encryption and data residency