Data Processing Agreement
Last updated: March 2026
1. Scope
This Data Processing Agreement (DPA) applies to the processing of personal data by Medinformics, operated by Roi Shternin-Martini ("Processor") on behalf of institutional customers ("Controller") under the General Data Protection Regulation (GDPR).
2. Nature of Processing
- Purpose: Providing AI literacy and software development education services
- Duration: Duration of the service agreement
- Types of data: Account data, learning progress, exercise submissions
- Data subjects: Employees or members of the Controller organization
3. Sub-processors
We use the following sub-processors:
- Stripe Inc. — Payment processing (EU)
- Resend Inc. — Email delivery (EU)
- PostHog Inc. — Analytics (EU cloud)
- Vercel Inc. — Hosting (US, SOC 2, SCCs in place)
- Neon Inc. — Database hosting (US, SOC 2, SCCs in place)
- Anthropic PBC — AI feedback (US, SCCs in place)
4. Security Measures
- Encryption in transit (TLS 1.3)
- Encryption at rest (database)
- Access control and authentication
- Regular security audits
- Audit logging with 3-year retention
- Breach notification within 72 hours
5. Contact
For DPA inquiries or to request a signed copy: legal@medinformics.com