Medinformics

Data Processing Agreement

Last updated: March 2026

1. Scope

This Data Processing Agreement (DPA) applies to the processing of personal data by Medinformics, operated by Roi Shternin-Martini ("Processor") on behalf of institutional customers ("Controller") under the General Data Protection Regulation (GDPR).

2. Nature of Processing

  • Purpose: Providing AI literacy and software development education services
  • Duration: Duration of the service agreement
  • Types of data: Account data, learning progress, exercise submissions
  • Data subjects: Employees or members of the Controller organization

3. Sub-processors

We use the following sub-processors:

  • Stripe Inc. — Payment processing (EU)
  • Resend Inc. — Email delivery (EU)
  • PostHog Inc. — Analytics (EU cloud)
  • Vercel Inc. — Hosting (US, SOC 2, SCCs in place)
  • Neon Inc. — Database hosting (US, SOC 2, SCCs in place)
  • Anthropic PBC — AI feedback (US, SCCs in place)

4. Security Measures

  • Encryption in transit (TLS 1.3)
  • Encryption at rest (database)
  • Access control and authentication
  • Regular security audits
  • Audit logging with 3-year retention
  • Breach notification within 72 hours

5. Contact

For DPA inquiries or to request a signed copy: legal@medinformics.com

We use essential cookies to keep you logged in. Analytics cookies are optional. Learn more