Skip to content
Audience: DPO / Compliance

Processors and data processing agreements

Who outside Heltio touches the practice's data, where the current list lives, and where that list parts company with what the product actually does.

Last reviewed:

A data processing agreement (DPA) is required by Article 28(3) GDPR whenever a controller uses a processor. Heltio is that processor for the practice, and the providers listed below are processors for Heltio.

Where to find it

Three pages, all public and all carrying a Draft banner — the documents are awaiting review by Polish counsel:

  • /podprocesorzy — the list of providers with region, data category, retention period and a link to the provider's own agreement.
  • /dpa — the model processing agreement between the practice and Heltio.
  • /processor-agreement — the short summary of that agreement, accepted when the practice signs up.

Accepting the agreement at sign-up is recorded as a separate practice-consent record: the document type, its version, the moment of acceptance, the IP address and the browser identifier.

The provider list

Read from the register in the source of the /podprocesorzy page.

Active (10):

ProviderFor whatRegionData
SupabaseDatabase, files, syncFrankfurtpersonal, health
ClerkSign-in, sessions, two-factor authenticationEU (to be confirmed)personal
AWS KMSKey managementFrankfurtnone
PowerSyncOffline work in the mobile appEUpersonal, health
MailerSendTransactional and marketing e-mailEUpersonal
SMSAPI (LINK Mobility)SMSPolandpersonal
Przelewy24 (PayPro)Patient payments and the Heltio subscriptionPolandpersonal, financial
Better StackUptime monitoringEUoperational
Polish e-Health Centre (P1)Medical events, EDMPolandpersonal, health
DeepLMessage translationGermanypersonal

Planned (1): Sentry — error monitoring; the entry is waiting for the EU region to be switched on.

Listed as disabled (3): Anthropic, OpenAI, Google Calendar.

The e-Health Centre is not a classic processor — it is a separate public controller, acting under the Health Information System Act. The practice does not entrust data to it under Article 28; it hands the data over because the law says so.

A discrepancy you need to know about

AWS KMS is listed the same way, as an active key-management provider, while in the code the master key comes from an environment variable — the KMS layer is prepared but not in use. Details: Encryption and data residency.

Changing the list

Changing a provider means changing the register in the source of the /podprocesorzy page and deploying. There is no mechanism in the app today that automatically notifies practices of a change to the list or counts an objection period — the previous version of this page described such a mechanism together with a change register; the database schema has no matching table. The notification has to be sent by hand.

After the relationship ends

A practice can export its data from the panel — see Clinic data export. The deadlines for deleting data after termination are governed by the text of the processing agreement at /dpa, not by a separate mechanism in the app.

Was this article helpful?