Data processing agreement
Last updated
This is the agreement that will govern how Yumee handles patient information on a clinic's behalf. It is published now, before launch, so a clinic can read it without asking. Accepting it will be part of signing up; there is no signup yet, so nothing on this page has been accepted by anyone.
The two roles
The clinic decides what patient information is collected and why. Yumee handles that information only to provide the service and only on the clinic's instructions. Every market names the two sides differently and means the same thing by them: the clinic is the APP entity in Australia, the agency in New Zealand and the controller in the United Kingdom, and we act for the clinic — its processor, in UK GDPR terms.
Each clinic remains responsible for telling its own patients how their information is handled, and for having the right to give it to us in the first place.
What is processed, and for how long
Subject matter: answering inbound calls to the clinic and booking, rescheduling and cancelling appointments in the clinic's practice management system.
People involved: patients and prospective patients who call the clinic, and the clinic's own staff.
Information involved: phone numbers, what is said on a call, appointment details, and the name, date of birth and phone number of patients in the clinic's practice management system.
Duration: for as long as the clinic uses Yumee, subject to the retention windows in the privacy policy.
What we undertake
To process patient information only on the clinic's documented instructions, and to tell the clinic if an instruction appears to breach the privacy law that applies to it.
To keep it secure, to restrict access to people who need it, and to bind them to confidentiality.
Not to record calls. Recording is off, there is no storage for it, and it could not be enabled for a clinic without that clinic's agreement and a disclosure to the caller at the start of the call.
To help the clinic respond to a patient asking for access, correction or deletion, and to help it meet its breach-notification obligations — the Notifiable Data Breaches scheme in Australia, the notifiable privacy breach duty under the Privacy Act 2020 in New Zealand, and the 72-hour duty under Article 33 of the UK GDPR.
To tell the clinic without undue delay if we become aware of a data breach affecting its information, with what we know at the time rather than waiting until we know everything.
To delete or return the clinic's information when it stops using Yumee, on request.
Other processors
We use the companies listed on the subprocessors page, and the clinic authorises them by accepting this agreement. As each one's own data processing agreement is signed, it is bound to obligations no weaker than these; that paperwork is in progress and none of it is complete yet, which is why no clinic is taking real patient calls.
We will give notice before adding or replacing one, and a clinic that objects may stop using the service.
Information crossing borders
Some of it does in every market, and the subprocessors page says exactly which parts and where. The voice service that answers calls runs in the United States and Canada; background processing runs in Singapore; records at rest are in Sydney.
For an Australian clinic, the disclosures to the United States, Canada and Singapore are the cross-border ones. We take reasonable steps to ensure each recipient handles the information consistently with the Australian Privacy Principles, as APP 8 requires.
For a New Zealand clinic, IPP 12 applies to those same disclosures — and records at rest in Sydney are a disclosure too, not a domestic arrangement.
For a UK clinic the analysis inverts. Every leg is a restricted transfer out of the United Kingdom, Sydney at rest included, and each one needs its own basis — the transfer clauses in that subprocessor's own agreement with us. That paperwork is in progress and none of it is complete, which is why no clinic is taking real patient calls.
Checking for yourself
A clinic may ask us for the information reasonably needed to confirm we are meeting this agreement, once a year or after a breach affecting its information. We will answer in writing.
We hold no SOC 2, ISO 27001 or HIPAA certification and do not claim any.
Precedence
Where this agreement and the customer agreement conflict on the handling of patient information, this one wins. Questions go to hello@getyumee.com.