You are currently offline. Changes are not saved in this version.
Mesora Health

Data Processing Agreement

MohaX Digital – Mesora Health

Last Updated: 05 June 2026

1. Parties

This Data Processing Agreement is entered into between the Clinic or Healthcare Provider as Data Controller and MohaX Digital, provider of Mesora Health, as Data Processor.

2. Purpose

MohaX Digital processes personal and medical information solely for the purpose of providing clinic management services through Mesora Health.

3. Types of Data Processed

Data processed may include:

  • Patient identification data
  • Patient contact information
  • Appointment records
  • Medical notes
  • Clinical records
  • Uploaded documents
  • User account information
  • Technical logs and security events

4. Categories of Data Subjects

The data subjects may include patients, clinic staff, healthcare professionals, and administrative users.

5. Ownership of Data

All data remains the property of the Clinic. MohaX Digital acquires no ownership rights in customer or patient data.

6. Processing Instructions

MohaX Digital shall process personal data only:

  • According to documented instructions from the Clinic
  • For the purpose of providing the contracted services
  • To maintain security, reliability, and functionality of the platform
  • Where required by applicable law

7. Confidentiality

MohaX Digital shall ensure that persons authorized to process personal data are subject to confidentiality obligations.

8. Security Measures

MohaX Digital shall implement reasonable technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

These measures may include:

  • Encrypted communication
  • Authentication controls
  • Role-based access management
  • Logging and monitoring
  • Backup procedures
  • Infrastructure security measures

9. Subprocessors

MohaX Digital may engage subprocessors for hosting, email delivery, monitoring, backup, or infrastructure services. Subprocessors shall only process personal data to the extent necessary to provide their services.

10. Assistance to the Controller

Where reasonably possible, MohaX Digital shall assist the Clinic in fulfilling its data protection obligations, including responding to data subject requests and investigating security incidents.

11. Data Breach Notification

MohaX Digital shall notify affected Customers without undue delay after becoming aware of a confirmed security incident affecting customer data.

12. Data Return and Deletion

Upon termination of services and where technically feasible, customer data may be exported and returned to the Clinic.

MohaX Digital may delete customer data after a reasonable retention period, subject to backup, operational, contractual, or legal requirements.

13. International Transfers

Where personal data is transferred internationally, MohaX Digital shall take reasonable steps to ensure appropriate safeguards are applied.

14. Liability

Each party remains responsible for its own acts, omissions, and legal obligations.

MohaX Digital is not responsible for security incidents caused by customer negligence, insecure devices, unauthorized credential sharing, or unlawful use of the platform.

15. Governing Law

This agreement shall be governed by the laws of the Federal Republic of Germany, unless otherwise agreed in writing.

16. Contact Information

MohaX Digital
Email: info@mohax.de
Product: Mesora Health

Login About us Privacy Policy Terms of Service DPA
© 2026 MohaX Digital – Mesora Health · v1.0.0