Data Processing Agreement
Data Processing Agreement
Data Processing Agreement
Last updated: July 2026.
This Data Processing Agreement (“DPA”) establishes the terms for processing personal data between Summit AI Limited (“Summit AI”, “Processor”, “we”, “us”, or “our”) and the subscribing healthcare clinic (“Client”, “Controller”, or “you”).
This DPA forms an integral part of the Summit AI Terms of Service. By accessing or using the Summit AI inbound phone receptionist service, you agree to the terms of this DPA on behalf of yourself and your authorized End Users.
Roles and Statutory Legal Grounds
Capitalized terms used in this DPA shall have the meanings set forth below or as defined in the main Agreement:
1.1 Legal Role AlignmentController / Principal Agency: The Client acts as the Data Controller (or Principal Agency under New Zealand law) and retains primary regulatory responsibility for establishing the legal basis for processing patient data.
Processor / Secondary Agency: Summit AI acts strictly as a Data Processor (or Secondary Agency under Sections 11 and 12 of the New Zealand Privacy Act 2020). Personal data held by Summit AI is legally treated as being held by the primary clinic agency.
1.2 Statutory Legal Grounds
The Client warrants that it has established a valid statutory legal basis for Summit AI to process health and interaction data under applicable laws:New Zealand: Rules 10, 11, and 12 of the Health Information Privacy Code 2020 (HIPC).
Australia: Section 16B and APP 6.1 of the Privacy Act 1988 (Cth) (collection and use of information necessary to provide a health service).
UK / EU / EEA: Article 6(1)(b)/(f) and Article 9(2)(h) of the UK/EU GDPR (provision and management of healthcare systems under professional secrecy obligations).
Scope and Processing Details
Core Purpose: Providing automated inbound AI phone reception, managing appointment bookings into connected Practice Management Systems (PMS), taking caller messages, and routing call summaries to clinic staff.
Categories of Data Subjects: Patients, callers, and clinic administrative staff.
Personal Data Processed:
Caller Identifiers: Full names, contact telephone numbers, dates of birth, and email addresses.
Interaction Data: Call audio streams, speech-to-text transcripts, call duration, timestamps, and caller intent classifications.
Health Context: Appointment booking reasons, practitioner preferences, clinical front-desk triage notes, and health details voluntarily disclosed by callers during interactions.
Technical Data: Staff credentials, encrypted PMS API access keys, IP addresses, system logs, and integration telemetry.
Technical & Organizational Security Measures
Summit AI shall maintain the following security safeguards to protect Client Personal Data:Encryption Standards: All network data in transit is encrypted using TLS 1.3 / HTTPS. All persistent data at rest is encrypted using AES-256 bit encryption. PMS API integration tokens are encrypted via AES-256 prior to storage.
Access Controls: Staff access to production environments is strictly limited under least-privilege principles and protected by Multi-Factor Authentication (MFA) and Single Sign-On (SSO).
System Testing: Summit AI maintains periodic vulnerability scanning and testing on web properties and application infrastructure.
Personnel Confidentiality: All employees and contractors authorized to process Client data are bound by strict confidentiality agreements and privacy training.
Sub-processors and Data Handling
4.1 General Authorization
Client grants general written authorization for Summit AI to engage vetted sub-processors (e.g., cloud hosts, LLMs, telephony providers). An up-to-date directory is maintained in the Summit AI Trust Centre.
4.2 Sub-processors & Data Handling
Summit AI utilizes third-party sub-processors (including workflow orchestrators, and telecommunications networks) to deliver the Service.Client acknowledges that data processed through third-party sub-processors is subject to the technical capabilities, operational logging schedules, and standard enterprise terms of those providers. Summit AI configures its integrations using commercial enterprise API endpoints intended to restrict data usage to service delivery and prevent Client Personal Data from being used to train public AI models.
4.3 Sub-processor Notice & Objections
Summit AI will provide reasonable advance notice via the Trust Centre or admin portal before adding or replacing a sub-processor handling patient data. Client may object on reasonable privacy grounds within twenty (20) days. If the parties cannot resolve the objection in good faith, Client may terminate the Service.
4.4 Operational Emergency Protocol
In an Operational Emergency (such as a critical cyber threat, infrastructure outage, or sudden vendor termination), Summit AI may temporarily engage or replace a sub-processor without advance notice to preserve service continuity and data security, provided the vendor meets equivalent security standards. Summit AI will notify Client within twenty-four (24) hours of engagement.Data Subject Rights & Incident Management
5.1 Patient Privacy RequestsBecause Summit AI is a Data Processor, direct patient requests regarding access, correction, or erasure must be managed by the Client:
Forwarding: Summit AI will log and forward any direct patient requests to the Client within two (2) business days.
Technical Execution: Summit AI will technically execute extractions or hard purges across production systems within five (5) business days of receiving written instructions from the Client.
5.2 Security Incident Notification
In the event of a confirmed Security Incident compromising Client Personal Data, Summit AI shall:Notify the Client within twenty-four (24) hours of confirmation.
Provide details regarding the nature of the incident, affected data types, and remedial actions taken.
Assist the Client in fulfilling mandatory notification duties under the Australian Notifiable Data Breaches (NDB) scheme, or the New Zealand Privacy Act 2020.
Data Retention and Deletion
30-Day Rolling Purge: During an active subscription, all call audio recordings and speech-to-text transcripts are automatically deleted on a rolling 30-day schedule post-call.
Immediate Cancellation Purge: Upon subscription cancellation, active call audio recordings and transcripts are immediately deleted from production environments.
30-Day Export Window: Client may request a structured export of remaining administrative account records within thirty (30) days of subscription termination. After 30 days, all remaining data across production systems and historical backups will be permanently erased
Governing Law
This DPA is governed by the laws of New Zealand, regardless of conflict of laws principles, govern all matters arising out of or relating to this Agreement, including its interpretation, construction, performance, and enforcement. The parties consent to the exclusive jurisdiction and venue of the courts of New Zealand. If you are acting as a consumer under this Agreement and are domiciled in a Member State of the European Union or the European Economic Area, or in the United Kingdom, the foregoing choice of governing law will not deprive you of the protection afforded to you by provisions that cannot be derogated from by agreement by virtue of the Laws applicable to you where you habitually reside.Contact Us
For data protection inquiries, please contact Summit at:Email: contact@usesummitai.com
Website: www.usesummitai.com
By using the Service, you acknowledge that you have read, understood, and agree to be bound by this Data Processing Agreement.
This Data Processing Agreement (“DPA”) establishes the terms for processing personal data between Summit AI Limited (“Summit AI”, “Processor”, “we”, “us”, or “our”) and the subscribing healthcare clinic (“Client”, “Controller”, or “you”).
This DPA forms an integral part of the Summit AI Terms of Service. By accessing or using the Summit AI inbound phone receptionist service, you agree to the terms of this DPA on behalf of yourself and your authorized End Users.
Roles and Statutory Legal Grounds
Capitalized terms used in this DPA shall have the meanings set forth below or as defined in the main Agreement:
1.1 Legal Role AlignmentController / Principal Agency: The Client acts as the Data Controller (or Principal Agency under New Zealand law) and retains primary regulatory responsibility for establishing the legal basis for processing patient data.
Processor / Secondary Agency: Summit AI acts strictly as a Data Processor (or Secondary Agency under Sections 11 and 12 of the New Zealand Privacy Act 2020). Personal data held by Summit AI is legally treated as being held by the primary clinic agency.
1.2 Statutory Legal Grounds
The Client warrants that it has established a valid statutory legal basis for Summit AI to process health and interaction data under applicable laws:New Zealand: Rules 10, 11, and 12 of the Health Information Privacy Code 2020 (HIPC).
Australia: Section 16B and APP 6.1 of the Privacy Act 1988 (Cth) (collection and use of information necessary to provide a health service).
UK / EU / EEA: Article 6(1)(b)/(f) and Article 9(2)(h) of the UK/EU GDPR (provision and management of healthcare systems under professional secrecy obligations).
Scope and Processing Details
Core Purpose: Providing automated inbound AI phone reception, managing appointment bookings into connected Practice Management Systems (PMS), taking caller messages, and routing call summaries to clinic staff.
Categories of Data Subjects: Patients, callers, and clinic administrative staff.
Personal Data Processed:
Caller Identifiers: Full names, contact telephone numbers, dates of birth, and email addresses.
Interaction Data: Call audio streams, speech-to-text transcripts, call duration, timestamps, and caller intent classifications.
Health Context: Appointment booking reasons, practitioner preferences, clinical front-desk triage notes, and health details voluntarily disclosed by callers during interactions.
Technical Data: Staff credentials, encrypted PMS API access keys, IP addresses, system logs, and integration telemetry.
Technical & Organizational Security Measures
Summit AI shall maintain the following security safeguards to protect Client Personal Data:Encryption Standards: All network data in transit is encrypted using TLS 1.3 / HTTPS. All persistent data at rest is encrypted using AES-256 bit encryption. PMS API integration tokens are encrypted via AES-256 prior to storage.
Access Controls: Staff access to production environments is strictly limited under least-privilege principles and protected by Multi-Factor Authentication (MFA) and Single Sign-On (SSO).
System Testing: Summit AI maintains periodic vulnerability scanning and testing on web properties and application infrastructure.
Personnel Confidentiality: All employees and contractors authorized to process Client data are bound by strict confidentiality agreements and privacy training.
Sub-processors and Data Handling
4.1 General Authorization
Client grants general written authorization for Summit AI to engage vetted sub-processors (e.g., cloud hosts, LLMs, telephony providers). An up-to-date directory is maintained in the Summit AI Trust Centre.
4.2 Sub-processors & Data Handling
Summit AI utilizes third-party sub-processors (including workflow orchestrators, and telecommunications networks) to deliver the Service.Client acknowledges that data processed through third-party sub-processors is subject to the technical capabilities, operational logging schedules, and standard enterprise terms of those providers. Summit AI configures its integrations using commercial enterprise API endpoints intended to restrict data usage to service delivery and prevent Client Personal Data from being used to train public AI models.
4.3 Sub-processor Notice & Objections
Summit AI will provide reasonable advance notice via the Trust Centre or admin portal before adding or replacing a sub-processor handling patient data. Client may object on reasonable privacy grounds within twenty (20) days. If the parties cannot resolve the objection in good faith, Client may terminate the Service.
4.4 Operational Emergency Protocol
In an Operational Emergency (such as a critical cyber threat, infrastructure outage, or sudden vendor termination), Summit AI may temporarily engage or replace a sub-processor without advance notice to preserve service continuity and data security, provided the vendor meets equivalent security standards. Summit AI will notify Client within twenty-four (24) hours of engagement.Data Subject Rights & Incident Management
5.1 Patient Privacy RequestsBecause Summit AI is a Data Processor, direct patient requests regarding access, correction, or erasure must be managed by the Client:
Forwarding: Summit AI will log and forward any direct patient requests to the Client within two (2) business days.
Technical Execution: Summit AI will technically execute extractions or hard purges across production systems within five (5) business days of receiving written instructions from the Client.
5.2 Security Incident Notification
In the event of a confirmed Security Incident compromising Client Personal Data, Summit AI shall:Notify the Client within twenty-four (24) hours of confirmation.
Provide details regarding the nature of the incident, affected data types, and remedial actions taken.
Assist the Client in fulfilling mandatory notification duties under the Australian Notifiable Data Breaches (NDB) scheme, or the New Zealand Privacy Act 2020.
Data Retention and Deletion
30-Day Rolling Purge: During an active subscription, all call audio recordings and speech-to-text transcripts are automatically deleted on a rolling 30-day schedule post-call.
Immediate Cancellation Purge: Upon subscription cancellation, active call audio recordings and transcripts are immediately deleted from production environments.
30-Day Export Window: Client may request a structured export of remaining administrative account records within thirty (30) days of subscription termination. After 30 days, all remaining data across production systems and historical backups will be permanently erased
Governing Law
This DPA is governed by the laws of New Zealand, regardless of conflict of laws principles, govern all matters arising out of or relating to this Agreement, including its interpretation, construction, performance, and enforcement. The parties consent to the exclusive jurisdiction and venue of the courts of New Zealand. If you are acting as a consumer under this Agreement and are domiciled in a Member State of the European Union or the European Economic Area, or in the United Kingdom, the foregoing choice of governing law will not deprive you of the protection afforded to you by provisions that cannot be derogated from by agreement by virtue of the Laws applicable to you where you habitually reside.Contact Us
For data protection inquiries, please contact Summit at:Email: contact@usesummitai.com
Website: www.usesummitai.com
By using the Service, you acknowledge that you have read, understood, and agree to be bound by this Data Processing Agreement.

Summit is built for:
Physiotherapists - Podiatrists - Chiropractors - Osteopaths - Psychologists - Naturopaths - Occupational Therapists - Speech Pathologists - Massage Therapists - Exercise Physiologists - Allied Health Clinics - NDIS Service Providers
© 2026 Summit AI Limited. All rights reserved.
Summit is built for:
Physiotherapists - Podiatrists - Chiropractors - Osteopaths - Psychologists - Naturopaths - Occupational Therapists - Speech Pathologists - Massage Therapists - Exercise Physiologists - Allied Health Clinics - NDIS Service Providers
© 2026 Summit AI Limited. All rights reserved.