Data Processing Agreement
Last updated 11 June 2026.
This Data Processing Agreement (DPA) forms part of the Terms of Use for Linea and applies whenever the customer uses Linea to process personal data relating to the customer's clients.
1. Parties
Controller: the psychologist, psychotherapist, professional practice or other business customer that accepts this DPA and uses Linea to process client personal data (Controller).
Processor: the Linea Platform, email [email protected] (Processor or Linea).
Controller and Processor are each a Party and together the Parties.
2. Status and scope
This DPA is intended to satisfy Article 28 GDPR. It supplements the Terms of Use. If this DPA conflicts with the Terms concerning the processing of Controller Personal Data, this DPA prevails.
The DPA begins when the Controller accepts it electronically or otherwise starts processing client personal data through Linea and continues for as long as Processor processes Controller Personal Data.
3. Definitions
Terms including personal data, processing, controller, processor, data subject, personal-data breach, special categories of personal data and supervisory authority have the meanings in GDPR.
Controller Personal Data means personal data processed by Processor on behalf of Controller through Linea, including client data described in Annex I.
Clinical Vault Data means the categories encrypted in the therapist's browser under the browser-held master key and stored by Processor as ciphertext.
Operational Client Data means client data required for service operation that is protected by server-side encryption and can be decrypted by Processor where necessary to provide the service and follow Controller's instructions.
4. Controller instructions and responsibilities
Processor will process Controller Personal Data only on Controller's documented instructions, including the Terms, account configuration, use of product features and additional written instructions agreed by the Parties, unless EU or Member State law requires otherwise. Where permitted, Processor will inform Controller before processing required by law.
Controller is responsible for:
- determining the purposes and legal basis for processing;
- identifying any applicable Article 9 condition for special-category data;
- providing required notices and obtaining any required consent;
- deciding whether data concerning minors may lawfully be processed;
- ensuring instructions are lawful;
- using Linea consistently with professional confidentiality and retention obligations;
- responding to data-subject requests, with Processor's assistance where required; and
- instructing users not to place clinical information in plaintext tags or unnecessary free-text fields.
Controller acknowledges the vault recovery trade-off: if Controller loses both the vault passphrase and every valid recovery method, Clinical Vault Data becomes permanently inaccessible and Processor cannot recover it.
5. Processor obligations
Processor will:
- process Controller Personal Data only on documented instructions;
- ensure persons authorised to process Controller Personal Data are subject to confidentiality obligations;
- implement appropriate technical and organisational measures;
- engage sub-processors only in accordance with Section 7;
- assist Controller, taking into account the nature of processing, with appropriate technical and organisational measures for data-subject requests;
- assist Controller with obligations under Articles 32–36 GDPR, taking into account the nature of processing and information available to Processor;
- notify Controller without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data;
- at Controller's choice and subject to applicable law, delete or return Controller Personal Data after service termination as described in Section 9; and
- make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and permit audits in accordance with Section 10.
6. Security and encryption model
Processor implements appropriate technical and organisational measures. The Parties acknowledge two distinct encryption models.
6.1 Clinical Vault Data
Clinical Vault Data is encrypted in the therapist's browser before transmission. Processor stores ciphertext and wrapped key material but does not receive the plaintext master key, vault passphrase or recovery words and cannot decrypt Clinical Vault Data.
6.2 Operational Client Data
Operational Client Data, including contact details and intake answers where enabled, is processed by the API and protected using server-side field encryption and access controls. Processor can decrypt such data where necessary to provide the service, follow documented instructions, maintain security or comply with law.
The existence of browser-only vault encryption does not remove the Parties' GDPR obligations for Controller Personal Data.
7. Sub-processors
Controller grants Processor a general written authorisation to use sub-processors listed in the current sub-processor register made available by Processor.
Processor will provide at least 14 days' prior notice of an intended addition or replacement of a sub-processor that may process Controller Personal Data, unless urgent security or legal circumstances require a shorter period. Controller may object on reasonable data-protection grounds during the notice period. The Parties will work in good faith to resolve the objection. If no reasonable solution is available, Controller may stop using the affected feature or terminate the service.
Processor will impose data-protection obligations on each sub-processor that are no less protective than the relevant obligations in this DPA and remains responsible for the sub-processor's performance to the extent required by GDPR.
8. International transfers
Processor will not transfer Controller Personal Data outside the European Economic Area unless a lawful mechanism under Chapter V GDPR applies. Where required, Processor will use an adequacy decision, standard contractual clauses or another lawful mechanism and apply supplementary measures where appropriate.
Controller authorises transfers described in the verified sub-processor register, subject to the safeguards stated there.
9. Return, export and deletion
During the account term, Controller may use available export functions. Clinical Vault Data must be exported through the browser-side vault export because Processor cannot decrypt it.
Following account deletion or termination:
- account access is deactivated promptly;
- sessions are revoked and the public profile is unpublished;
- wrapped vault-key material is cryptographically destroyed within 24 hours, making Clinical Vault Data inaccessible;
- Operational Client Data is deleted, zeroed or anonymised through the erasure workflow;
- storage objects and integration links are removed where applicable;
- backup copies expire under the configured backup-retention window; and
- limited structural, audit, billing or legal records may be retained where required or permitted by law.
Processor uses a tombstone mechanism designed to prevent deleted vault-key material from being revived by restoration of an older database backup.
For an individual client's erasure request, Controller may contact [email protected]. During beta, Processor may execute per-client deletion through an operator-assisted tool.
10. Audit and demonstration of compliance
Processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Controller should first use available documentation, security descriptions, certifications, vendor reports and written responses.
If that information is insufficient, Controller may request an audit on reasonable written notice, limited to matters relevant to Controller Personal Data and conducted in a way that avoids unreasonable disruption, security risk or disclosure of other customers' confidential information. On-site audits are a last resort unless required by a supervisory authority or a substantiated material-risk concern.
11. Personal-data breaches
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data. The notice will include available information reasonably required for Controller to meet Articles 33 and 34 GDPR, such as:
- the nature of the breach;
- categories and approximate number of affected data subjects and records where known;
- likely consequences;
- measures taken or proposed; and
- a contact point for follow-up.
Information may be provided in phases where it is not available at once.
12. Data-subject requests
Taking into account the nature of processing, Processor will assist Controller with requests to access, rectify, erase, restrict or export Controller Personal Data. If Processor receives a request directly from Controller's client, Processor will route the request to Controller where appropriate and may acknowledge receipt to the requester.
Because Processor cannot decrypt Clinical Vault Data, Controller is responsible for using the browser-side vault export and therapist-side functionality where plaintext access is required.
13. DPIA and prior-consultation assistance
Taking into account the nature of processing and information available, Processor will reasonably assist Controller with data-protection impact assessments and any prior consultation required under Articles 35 and 36 GDPR.
14. Liability and governing law
Liability is governed by the Terms and applicable law. This DPA is governed by Polish law, without limiting mandatory data-protection rights or supervisory-authority powers.
Annex I — Processing description
A. Subject matter and duration
Provision of Linea practice-management software for the term of Controller's account and the limited post-termination deletion and retention periods described in this DPA and the Privacy Policy.
B. Nature and purpose
Storage, organisation, encryption, transmission, retrieval, deletion and other processing required to provide public booking, client portal, calendar, client-record, clinical-vault, export, retention and security features on Controller's instructions.
C. Data subjects
- Controller's prospective, current and former clients;
- client representatives, guardians or emergency contacts where entered;
- legacy recovery contacts where enabled; and
- Controller's authorised users if future team features are enabled.
D. Categories of personal data
- identity and contact data;
- appointment, booking, calendar and service data;
- client-portal authentication and consent evidence;
- therapist-entered session-payment metadata;
- intake answers where enabled;
- clinical-vault content, including session notes, note title, risk level, therapy-goal descriptions, client core profiles and formulations;
- tags and structural metadata;
- audit and security metadata; and
- optional integration metadata.
E. Special-category data
Mental-health and healthcare-related information may be contained in intake answers and clinical-vault content.
F. Frequency
Continuous for as long as Controller uses Linea for client records.