Data processing agreement
Your patients’ records are the most sensitive thing you entrust to us. This document sets out what we may and may not do with them. It is not a formality: the GDPR requires both of us to have these arrangements in black and white, and you can hold us to them at any time.
On this page
- Why this document exists
- What exactly we process for you
- We act only on your instructions
- Confidentiality and who has access
- How we secure your records
- Sub-processors we use
- If something does go wrong
- Help with requests from patients
- Your right to audit us
- Where your data is physically stored
- What happens at the end
- Relationship to our other agreements
Why this document exists
As soon as you work with Nollie, your patients’ personal data ends up on our systems. The GDPR calls this processing on behalf of a controller, and requires a written agreement between the controller and the processor. This is that agreement. It applies automatically from the moment your subscription starts, together with the terms and conditions and the privacy policy.
The division of roles is not negotiable, because it follows from the law and from your profession:
Your practice decides
You decide which patients get a record, what goes into it, who may view it and how long it is kept. You are also the point of contact for your patients and, where necessary, for the supervisory authority.
Nollie carries it out
We build and maintain the system in which those records live. We process them solely to provide the service to you, and never for our own purposes.
We are Soluxion BV, Steenbruggestraat 11, 8570 Anzegem, Belgium, company number 0607.888.607. Anything relating to this agreement can be sent to [email protected].
What exactly we process for you
The law requires this section to state concretely what happens, and not merely “processing data”. Hence this table: it describes the full assignment you give us.
| Nature of the processing | Storing, consulting, structuring, modifying, transmitting to the healthcare network, backing up and erasing, always within the software. |
| Purpose | Running your practice: calendar, patient records, prescriptions, reports, certificates via eAttest, invoicing via eFact and your financial follow-up. |
| Data subjects | Your patients and any contact persons they have, plus the therapists and staff to whom you grant access. |
| Ordinary data | Name, date of birth, national register number, address, telephone, e-mail, health insurance fund and insurability, appointments and invoicing data. |
| Special category data | Health data: pathology, prescriptions, medical history, treatment reports, progress and attachments such as imaging. This category enjoys extra protection under the GDPR, which is reflected in chapter 05. |
| Duration | For as long as your subscription runs, plus the wind-down period in chapter 11. |
If this assignment changes materially, for example because a new module is added that processes other data, we update this table and notify you as described in chapter 12.
We act only on your instructions
We process your patients’ data only as you instruct. In concrete terms, that means three things.
- Your use is your instruction. What you do in the software, together with what is set out in this agreement and the terms, forms the assignment. If you also have a specific instruction, send it to us in writing.
- Never for ourselves. We do not use your patient data for our own analyses, for advertising, to develop products or to train models. We compile statistics on the use of the software exclusively on an anonymised basis, without any data that can be traced back to individuals.
- We tell you if your instruction is not possible. If an instruction asks us to do something that we believe infringes the GDPR or other legislation, we do not carry it out blindly: we inform you and explain why.
If, exceptionally, a law nevertheless obliges us to process data outside your instructions, for example by order of a court, we notify you of this in advance, unless that same law prohibits us from doing so.
Confidentiality and who has access
At Nollie, access to medical records is not a convenience, but an exception that has to be justified.
- Everyone at Nollie who may come into contact with personal data is contractually bound to confidentiality, including after the collaboration or employment contract ends.
- Access is granted on a need-to-know basis. Anyone who does not need a record for their work has no access to it.
- In the event of a technical problem, we only look at your data after you ask us to or give permission, only as far as necessary, and that access is logged.
- Our people are trained in how to handle health data and what is expected of them.
How we secure your records
Article 32 of the GDPR calls for measures appropriate to the risk. With health data, that bar is high. This is what we do:
- ✓Encryption in transit and at rest. All traffic runs over TLS; stored data and backups are encrypted.
- ✓Role-based access control. Within your practice, you decide who sees what. On our side, the same principle applies, with strong authentication for administrator access.
- ✓Logging of sensitive actions. Who accessed or modified which record remains traceable and verifiable.
- ✓Tested backups. We make them automatically and restore them regularly, so we know they work when it matters.
- ✓Separate environments. Development and testing never run on real patient data.
- ✓Updates and vulnerabilities. Security updates are tracked and rolled out quickly.
Security is never finished. We adapt these measures when technology or risk calls for it, and we may change them as long as the level of protection does not decrease.
Sub-processors we use
We do not build everything ourselves. For hosting, backups, e-mail and payments, we work with specialist providers. By entering into this agreement, you give us permission to engage them, under strict conditions.
| Purpose | Provider | Location |
|---|---|---|
| Hosting & storage | AWS Europe | European Union |
Every sub-processor is assessed in advance and has the same obligations as those set out here imposed on it through a written agreement. Towards you, we remain fully liable for what they do: you never have to turn to them.
What if one is added or removed
If we want to replace or add a sub-processor, we notify you at least 30 days in advance. If you have reasonable grounds, you can object within that period. If we cannot reach agreement, you may end your subscription free of charge with effect from the date the change takes effect, while retaining your export right under chapter 11.
If something does go wrong
A data breach is not a theoretical scenario, so we agree in advance how we respond. If we discover a breach of the security of your data, we notify you without undue delay and in principle within 48 hours of becoming aware of it, by e-mail and, if necessary, by telephone.
That notification contains everything you need to make your own assessment:
- What happened, when, and how we discovered it.
- Which categories of data and approximately how many data subjects are affected.
- The likely consequences and whether the data was encrypted.
- The measures we have taken to contain the breach and recover from it.
If we do not yet know everything, we do not wait: we report what we have and add to it as the investigation progresses. We keep a register of every incident.
Help with requests from patients
Does a patient ask for access to their record, correction of an error or erasure of data? Then you are the right recipient: it is your record and your decision. We help you technically to answer that request.
You can do most of it yourself in the software: viewing, exporting, correcting and deleting records. If that is not enough, we respond to your request for assistance within five working days. If we receive a request directly from one of your patients, we do not handle it ourselves but forward it to you.
In addition, to the extent of what we can know as a processor, we also help you with your other obligations: with a data protection impact assessment (DPIA), with a prior consultation of the supervisory authority, and with demonstrating that security is in order.
Your right to audit us
You do not have to take our word for it. On simple request, we provide you with the information you need to verify that we are meeting our obligations: a description of the measures, the current list of sub-processors, and any audit reports or certificates we hold.
If that is not sufficient, you may have an audit carried out, yourself or by an independent expert who is not our competitor. The ground rules keep it workable for both of us: you announce the audit at least 30 days in advance, it takes place during office hours, it does not disrupt our service, and the auditor is bound to confidentiality. Save where there are serious indications of a shortcoming, this happens at most once a year, at your expense.
If the audit brings a shortcoming to light, we address it at our expense, and without delay.
Where your data is physically stored
Your patient records are stored and processed on servers within the European Economic Area. The same applies to the backups.
We do not transfer any personal data to countries outside the EEA, unless that were to become unavoidable and a valid legal basis exists for it: an adequacy decision of the European Commission or the standard contractual clauses, with the necessary supplementary safeguards. Should such a situation ever arise, we will notify you in advance, as with a change of sub-processors.
What happens at the end
This agreement runs for as long as we process data for you, and therefore for as long as your subscription lasts. When it ends, the process is as follows:
Mind your own side of the arrangement: as the controller, you remain subject to the statutory retention periods for physiotherapists’ patient records. So make sure your export is secured in time and in full before the end of those 60 days.
Relationship to our other agreements
This agreement does not stand alone. It supplements the terms and conditions, and in the event of a conflict concerning the processing of personal data, this document takes precedence. For anything not governed here, the terms apply: this includes the liability provisions.
If the legislation or the way we work changes, we may amend this agreement. If it concerns a material change, we notify you at least one month in advance, and you can cancel as described in the terms. This agreement is governed by Belgian law; disputes follow the same route as set out in the terms.
This version dates from August 2026 and supersedes all previous versions.
Contact for this agreement
Soluxion BV · Steenbruggestraat 11, 8570 Anzegem, Belgium
Company number 0607.888.607