Data Processing Agreement — Carewell Pool

Data processing agreement applicable to the use of Carewell Pool services by institutions.

Last updated · Version · 2026-07-09
Applies to: Carewell Pool

1. Parties

This data processing agreement (the “DPA”) is entered into between:

  • Carewell SA, Rue du Grand-Pré 4, 1007 Lausanne, Switzerland (“Carewell” or the “Processor”), and
  • the Institution identified in the main agreement (the “Controller” or “You”).

Carewell and the Institution are collectively referred to as the “Parties”.

2. Subject matter and scope

This DPA governs the processing of personal data carried out by Carewell on behalf of the Institution in connection with the provision of the Carewell Pool services (management by the Institution of its internal pool of professionals: scheduling, availability, document management).

The DPA forms an integral part of the main agreement entered into between the Parties. In the event of a conflict, the DPA prevails over the provisions of the main agreement with respect to data protection matters.

3. Definitions

The terms “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject” and “Data Breach” have the meaning given to them by the Swiss Federal Act on Data Protection (FADP/revFADP) and, where applicable, Regulation (EU) 2016/679 (GDPR).

4. Term

The DPA takes effect on the date of signature of the main agreement and remains in force for as long as Carewell processes Personal Data on behalf of the Institution.

5. Nature and purposes of the processing

Carewell processes Personal Data solely for the following purposes:

  • management of the Institution’s internal pool of professionals (scheduling, availability, documents);
  • creation and management of the accounts of the Institution’s professionals and staff;
  • documentation of schedules and services performed;
  • service communications (notifications, reminders);
  • user support;
  • any other purpose expressly documented by the Institution.

6. Categories of data and data subjects

Category of data subjectsCategories of data
Professionals in the Institution’s poolIdentity, contact details, login credentials, availability, schedules, usage data
Institution staffIdentity, business contact details, login credentials
Patients (where applicable)No patient data is processed by Carewell.

7. Retention period

In general, personal data is retained for a period proportionate to the purposes pursued by its processing and not exceeding what is necessary to achieve those purposes. At the end of the applicable retention periods, the data is archived and then deleted or anonymised in accordance with applicable legal obligations or overriding interests justifying extended retention.

As an indication, data related to the user account is retained for the entire duration of the contractual relationship, then archived in accordance with applicable legal and regulatory obligations, in particular in accounting, tax and evidentiary matters.

8. Carewell’s obligations

Carewell undertakes to:

  1. process Personal Data only on the documented instructions of the Institution;
  2. ensure that persons authorised to process Personal Data have committed themselves to confidentiality;
  3. implement the technical and organizational measures described in the Security Policy;
  4. assist the Institution in handling requests from Data Subjects (rights of access, rectification, erasure, portability, objection) and forward to it without delay any request that a Data Subject addresses directly to Carewell;
  5. notify the Institution of any Data Breach as soon as possible and, in any event, no later than within 48 hours;
  6. make available to the Institution all information necessary to demonstrate compliance with these obligations;
  7. delete or return the Personal Data at the end of the main agreement, at the Institution’s choice.

9. Sub-processors

Carewell is authorised to engage sub-processors in connection with the provision of Carewell Pool. The up-to-date list is published at: Sub-processors — Carewell Pool.

Carewell informs the Institution of any change to this list with reasonable prior notice. The Institution has a right to object on justified grounds.

10. International transfers

Carewell hosts Personal Data in Switzerland. Where a transfer outside Switzerland or the EEA is necessary, Carewell implements appropriate safeguards (standard contractual clauses, adequacy decision, etc.) as documented in the sub-processor list.

11. Audit

The Institution may request, once a year and with reasonable prior notice, an audit of Carewell’s compliance with its obligations under the DPA. Carewell may, at its option, provide an existing independent audit report (for example ISO 27001) in place of an on-site audit.

12. Liability

The Parties’ liability under the DPA is limited in accordance with the provisions of the main agreement.

13. Governing law and jurisdiction

This DPA is governed by Swiss law. Any dispute is subject to the exclusive jurisdiction of the ordinary courts of Lausanne.


Signatures and entry into force

This DPA is accepted electronically upon signature of the main agreement.