Opens in a new tab

Data processing agreement (DPA)

How Autoderm processes End User images on your behalf, with separate terms for images you choose to share for AI model training.

This DPA contains two parts. Part A governs Inference Processing carried out by Autoderm or iDoc24 AB as processor on behalf of Customer. Part B governs Training Processing carried out by iDoc24 AB or the applicable Autoderm entity as independent controller where a valid Consent Signal exists. If the Consent Signal is disabled, Part B does not apply and no images may be retained for training under this Agreement.


Part A - Processor agreement for diagnostic inference

Customer is controller and Autoderm inc. or iDoc24 AB is processor for the processing of Personal Data from receipt of an image at the API gateway until return of the Output to Customer, and any transient processing required to provide, secure and evidence that service.


A.1 Processing details

Field Detail
Subject matter Automated analysis of skin images submitted by End Users through Customer’s platform.
Duration Subscription Term and any Bridge Period, plus any post-termination period necessary for deletion, security logs or legal retention.
Nature Image receipt, metadata stripping, automated filters, AI inference, Output generation, technical logging, security controls and return of results.
Purpose Delivery of skin disease analytics as an informational layperson tool according to the Order Form and IFU.
Data subjects End Users whose images are submitted via Customer’s platform.
Personal data Skin images and optional non-identifying metadata, to the extent such data constitutes Personal Data or health data.
Customer legal basis [Customer to confirm Article 6 basis and Article 9 exception.]


A.2 Processor obligations

Process Personal Data only on Customer’s documented instructions and this Agreement, unless required by Law.

Ensure authorised personnel are bound by confidentiality.

Maintain appropriate security measures, including encryption in transit, API key authentication, rate limiting, role-based access controls, logging, EU hosting and metadata stripping.

Notify Customer without undue delay of Personal Data Breaches affecting data processed under Part A.

Assist Customer, taking into account the nature of processing and information available, with data subject rights, security, breach notification, DPIAs and prior consultation.

Delete or return Personal Data processed under Part A on termination or Customer request, unless retention is required by Law or another part of this Agreement.


A.3 Sub-processors

Approved sub-processors include Google Cloud Europe for cloud processing and Hetzner Online GmbH in Germany for hosting and storage, together with any additional sub-processors listed in the Order Form or Autoderm’s sub-processor list. Autoderm remains liable for sub-processor performance as required by GDPR Article 28.


A.4 International transfers

Processing is intended to occur within the EEA. Where any transfer outside the EEA occurs, Autoderm shall ensure appropriate safeguards under Chapter V GDPR, including Standard Contractual Clauses and transfer impact assessments where required.


Part B - Independent controller framework for AI training retention

Part B applies only to images for which Customer transmits a valid Consent Signal confirming End User explicit consent for retention and use by Autoderm or iDoc24 AB for AI model research, development, validation, improvement and training.


B.1 Roles and legal basis

For Training Processing, the applicable Autoderm entity acts as independent controller. Customer acts as the source of the End User relationship and consent record. This is not a processor arrangement and does not create joint controllership unless expressly agreed in a separate Article 26 arrangement.

The legal basis is consent under Article 6(1)(a) GDPR and explicit consent under Article 9(2)(a) GDPR, obtained by Customer from the End User on Autoderm’s behalf or for Autoderm’s benefit. Autoderm’s processing is further governed by its Training DPIA and anonymisation documentation.


B.2 Consent signal

A Consent Signal means the boolean parameter or equivalent auditable confirmation transmitted with the API Call, for example: training_consent: true. Absence of the parameter, or a false or null value, means the image is not eligible for training retention. Autoderm shall log the Consent Signal value for audit purposes.


B.3 Customer obligations

Obtain freely given, specific, informed and explicit consent from the End User before transmitting a Consent Signal.

Use only Autoderm-approved privacy and consent wording, unless otherwise approved in writing.

Maintain consent records, including date, wording, mechanism and withdrawal status, for the retention period plus three years.

Notify Autoderm within five business days of withdrawal or data subject requests relating to Training Data.

Provide API key, approximate date range and other lawful non-excessive information required to identify relevant source images.

Not transmit a Consent Signal where consent is absent, withdrawn, defective or outside scope.


B.4 Autoderm obligations

Use retained images only for AI model research, development, validation, improvement, training, bias monitoring, regulatory submissions and post-market surveillance.

Apply relevant EXIF and metadata stripping before or at the point of retention to ensure anonymity of the end user.

Store retained images without End User identifiers and with no link to user account, IP address, device identifier, email, phone number or name.

Apply logical segregation, role-based access, encryption at rest and in transit, access logging and periodic security review.

Retain images only for the period stated in the Order Form, Training DPIA or Record of Processing Activities.

Delete source images following valid withdrawal to the extent technically feasible, without obligation to retrain or modify completed model weights.


B.5 Residual re-identification risk

The Parties acknowledge that retained images are intended not to be re-identifiable. Autoderm applies EXIF stripping, anonymous filter rejection and no End User linking data. Autoderm nonetheless applies GDPR safeguards to retained images as a precautionary measure because a small residual subset may not be guaranteed to fall outside Article 4(1) GDPR in every conceivable circumstance.

Alexander Borve
Autoderm Exploration Call
30 min
Web conferencing details provided upon confirmation.
You will not meet a dermatologist. It's a business call.
1
Your details
2
Select time
3
Confirm

Tell us about your use case

A few quick questions before we find a time.