1. Parties and nature of the Agreement
1.1. This Data Processing Agreement (the "Agreement") is an annex to, and an integral part of, the Kusties Terms of Service for specialists (the "Terms"; https://kusties.com/en/terms). The parties to the Agreement are:
- SIA "Kusties.com", registration number 50203259371, legal address Ābolu iela 14C, Mārupe, Mārupes nov., LV-2167, VAT number LV50203259371 ("Kusties"), acting as processor; and
- the specialist who uses the Kusties service in their professional practice and has accepted the Terms ("you" or the "Specialist"), acting as controller.
1.2. The Agreement sets out how Kusties processes the personal data of your patients and clients on your behalf, and meets the requirements of Article 28(3) of the General Data Protection Regulation.
1.3. The Agreement takes effect when you accept it together with the Terms. Kusties keeps a record of the acceptance: the document version, the time and the method.
1.4. If you use the Service as an employee or on behalf of another person (for example a practice or a clinic), you confirm that you are entitled to accept this Agreement on behalf of the controller.
1.5. The Agreement covers only the personal data that Kusties processes on your behalf ("Patient Data", see sections 2 and 4). Data for which Kusties itself is the controller is described in the Kusties Privacy Policy (https://kusties.com/en/privacy). That data is your account and sign-in data, sessions and devices, consent records, the security audit log, billing data, the Kusties service e-mails sent to you, the data from the kusties.com enquiry forms, Patients' IP addresses that Kusties uses for rate limiting, the security of the Service and the delivery of exercise videos and images (point 4.2), and (when switched on) client cabinet accounts and their links to your records.
2. Definitions
2.1. GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
2.2. The terms "personal data", "processing", "controller", "processor", "personal data breach" and "data concerning health" have the meaning given in GDPR Article 4. A data subject is the natural person to whom the personal data relates. Special categories of personal data are the data listed in GDPR Article 9(1).
2.3. Service means the Kusties web application kusties.app and its API, the patient programme links, the public forms, the Android player app, and the e-mails and text messages (SMS) that the Service sends on your behalf.
2.4. Patient means a natural person for whom you create a client record in the Service (a patient or a client), including a minor.
2.5. Patient Data means personal data that you or Patients enter into the Service on your behalf, and data that the Service generates in that context, for example the programme completion log and the log of messages sent to Patients.
2.6. Sub-processor means another processor engaged by Kusties to process Patient Data (GDPR Article 28(2) and (4)).
2.7. In writing includes electronically, for example by e-mail.
2.8. Working day means a day that is not a Saturday, a Sunday or a public holiday set in the Republic of Latvia.
3. Subject matter, purpose, nature and duration of the processing
3.1. Subject matter. Processing of Patient Data to provide the Service to you under the Terms.
3.2. Purpose. Kusties processes Patient Data only for the following purposes:
- a) to provide the functions of the Service: client records, exercise programmes and sending them to Patients by personal links, the completion log, notes, alerts, clinical documents and forms, the appointment calendar, and reminders and notices to Patients;
- b) to maintain the security and operation of the Service, fix errors and provide support at your request;
- c) to count the use of the Service where this is needed for its limits and billing, for example the number of text messages sent.
3.3. Nature. Storage, structuring, encryption, retrieval and display to you; display to a Patient when you send them a link; sending by e-mail and SMS when you instruct it; backup; export; correction and deletion.
3.4. Duration. For the whole term of the Terms and afterwards until the Patient Data is returned or deleted under section 13.
3.5. Functions not yet switched on. Some functions of the Service are built but not yet switched on, for example the client cabinet, specialists uploading their own exercise videos, and the self-service data export. This Agreement applies to them from the moment they are switched on for your account.
4. Categories of data subjects and types of personal data
4.1. Data subjects:
- a) Patients, including minors;
- b) Patients' legal representatives (parents, guardians) and contact persons;
- c) other persons you mention in records, for example the Patient's family doctor;
- d) once this function is switched on, persons shown in the videos of private exercises you upload.
4.2. Types of personal data:
| Type of data | Examples | Health data |
|---|---|---|
| Identity and contact details | first name, last name, e-mail, phone, contact language, birthday (optional) | no |
| Notes | title, content, type, confidentiality flag | yes |
| Clinical documents and forms | the whole content of the form, including the personal identity code, date of birth, gender, address, family doctor, occupation, examination findings, diagnoses, plans and signatures; the answers submitted by the Patient, the typed name, the consent tick and the submission time; the legal representative's and contact person's details in the consent form | yes |
| Alerts | for example "pacemaker", with a severity level | yes |
| Programmes | exercises, start date and planned end date, end reason, private note, the day the programme was last opened | yes (a programme can indicate a health condition) |
| Programme completions | time, duration, difficulty and length rating, free-text feedback, completed exercises | yes |
| Appointments | title, description, time, status, type, recurring series | may contain (the title and description are your free text) |
| Reminders | channel, time, status | no |
| Message log | for each e-mail and SMS sent to a Patient: the recipient (e-mail address or phone number), the content (without one-time links), language, purpose, status, cost | may contain |
| Client cabinet (when switched on) | a mark in your record that it is linked; Kusties processes the account itself and the link as controller (client cabinet terms) | yes (reveals a care relationship) |
| Exercise videos in private exercises (when switched on) | image and possibly voice of the persons shown | may contain |
Kusties processes Patients' IP addresses for rate limiting, the security of the Service and the delivery of exercise videos and images as controller (Privacy Policy subsection 4.13). Showing published exercises to other specialists is processing by Kusties as controller (Privacy Policy subsection 4.14).
4.3. Patient Data includes special categories of personal data (data concerning health, GDPR Article 9) and the personal identity code where you enter it in clinical documents.
4.4. You decide what data you enter. Enter only the data needed for your purpose (data minimisation).
5. Your obligations and instructions as controller
5.1. You are the controller of Patient Data and determine the purposes and means of its processing. You ensure that:
- a) the processing has a legal basis under GDPR Article 6 and, for data concerning health, one of the exceptions in GDPR Article 9(2) applies, for example point (h) for health professionals or point (a) (the Patient's explicit consent);
- b) Patients receive the information required by GDPR Articles 13 and 14; you may use the template in Annex 3 for this;
- c) where needed, the processing of a minor Patient's data has the consent of the legal representative;
- d) Patients' contact details are correct, and you send personal links and forms only to the Patient concerned or their legal representative;
- e) you comply with the retention periods for medical records that apply to you under the law (see point 13.5).
5.2. Free-text fields that are sent to the Patient. The appointment title and description are not encrypted at field level. They are included in the e-mail that the Service sends to the Patient when an appointment is created, changed or cancelled, and in the message log. A calendar file (.ics) with the appointment title, description, and the specialist's and the Patient's first and last names may be attached to the created and changed e-mails. This e-mail is sent when "Send an e-mail notification to the client" is ticked in the appointment dialog, and it is ticked by default. Therefore, do not write diagnoses or other health data in the appointment title or description when this e-mail is sent. The programme name and description are visible to anyone who has the programme link.
5.3. Instructions. Your documented instructions to Kusties are:
- a) the Terms and this Agreement;
- b) your actions in the Service, for example creating or editing a record, sending a programme or a form, switching on an SMS reminder or an e-mail notification, and deleting a record;
- c) other written instructions that you agree with Kusties.
If an additional instruction cannot be carried out with the existing functions of the Service, Kusties informs you, and the parties agree on a solution.
5.4. Account security. You use a secure password, do not disclose your access credentials to others, protect the devices on which you use the Service, and inform Kusties without delay if you suspect unauthorised access to your account. Kusties recommends switching on two-step sign-in.
6. Kusties' obligations as processor
6.1. Kusties processes Patient Data only on your documented instructions, including with regard to transfers to third countries, unless required to do so by European Union or Latvian law. In that case Kusties informs you before the processing, unless the law prohibits this (GDPR Article 28(3)(a)).
6.2. Kusties immediately informs you if, in its opinion, an instruction infringes the GDPR or other data protection law.
6.3. Kusties does not use Patient Data for its own purposes: it does not sell it, use it for advertising or profiling, or disclose it to third parties. The exceptions are Sub-processors (section 9), recipients to whom you instruct the data to be sent (for example the Patient, to whom data is sent by e-mail or SMS), and cases where the law requires disclosure.
6.4. No analytics or tracking tools are used in the Service. If Kusties ever introduced them, it would do so only after amending the Privacy Policy and with a consent mechanism, and they would not be loaded on the Patient programme, form and sign-in pages.
6.5. Checks on copies of the data. Before releasing updates to the Service, Kusties may restore a copy of the production database in a temporary, isolated environment on the computer of a person authorised by Kusties, to check that the update works correctly with real data. The environment is deleted after the check. Kusties does not pass Patient Data to development tools, including artificial-intelligence tools; release checks use pseudonymised copies or are carried out so that Patient Data does not leave the EU and Kusties' control.
6.6. Kusties maintains a record of the processing activities it carries out on behalf of controllers (GDPR Article 30(2)).
6.7. Kusties has not appointed a data protection officer. For data protection questions, write to [email protected].
7. Confidentiality and access to Patient Data
7.1. Kusties gives access to Patient Data only to persons who need it to operate, support or secure the Service or to meet legal obligations. Kusties ensures that these persons have committed themselves to confidentiality or are under a statutory obligation of confidentiality (GDPR Article 28(3)(b)).
7.2. Who can access Patient Data:
- a) you: all of your records;
- b) notes, clinical documents, alerts and the programme's private note can be opened in the Service only by their author; Kusties administrators have no such option in the Service;
- c) Kusties staff with the administrator role can open in the Service your client records (first and last name, contact details, birthday), programmes, programme completion marks and feedback, and appointments, as well as the log of e-mails and text messages sent to Patients, including their content. Kusties uses this access only to provide support at your request, investigate security incidents or fix errors;
- d) persons with access to the Service's infrastructure (the database, backups and the encryption key) are technically able to access all Patient Data. Infrastructure access is held only by persons authorised by Kusties who need it to maintain the Service and who are bound by confidentiality (point 7.1).
7.3. If an authority requests Kusties to disclose Patient Data, Kusties assesses the lawfulness of the request, discloses only what the law requires, and informs you unless this is prohibited.
8. Security measures
8.1. Kusties implements appropriate technical and organisational measures under GDPR Article 32, taking into account the state of the art, the costs of implementation, the nature of the processing and the risks to Patients. The current measures, known limitations and planned improvements are described in Annex 1.
8.2. Kusties may change the measures provided that the overall level of protection is not reduced. Kusties reflects material changes in Annex 1.
8.3. You are responsible for security on your side (devices, password, sending links to the right recipient) (points 5.1 and 5.4).
9. Sub-processors
9.1. You give Kusties a general written authorisation to engage Sub-processors (GDPR Article 28(2)). The current Sub-processors are listed in Annex 2.
9.2. Kusties concludes a contract with each Sub-processor that imposes on it, in substance, the same data protection obligations as this Agreement, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures (GDPR Article 28(4)).
9.3. Prior notice. Kusties informs you at least 30 days in advance of engaging a new Sub-processor or replacing an existing one, by sending an e-mail to your account's e-mail address and updating Annex 2.
9.4. Right to object. You may object in writing within 14 days of receiving the notice if you have reasonable grounds relating to data protection. The parties seek a solution in good faith. If none is found, you may end the agreement under the Terms before the change takes effect, and Kusties refunds the fees for the unused period (clause 6.9(c) of the Terms).
9.5. Urgent replacement. If a Sub-processor must be replaced urgently for reasons of security or availability of the Service, Kusties may do so without prior notice and informs you as soon as possible. The right to object in point 9.4 also applies to such a replacement.
9.6. Kusties remains fully liable to you for the performance of its Sub-processors' obligations (GDPR Article 28(4)).
10. Assistance to you
10.1. Data subject requests. Taking into account the nature of the processing, Kusties assists you in responding to Patients' requests under Chapter III of the GDPR (GDPR Article 28(3)(e)):
- a) access and rectification: you can view and correct your records in the Service;
- b) copy and portability: the self-service data export is not yet switched on in the Service. Until then, at your written request, Kusties prepares an export of your account's data in a machine-readable format (JSON and CSV; the export's content is set out in point 13.1) within the period set in point 15.1 of the Terms. If the export is needed to fulfil a Patient's request, Kusties prepares, by agreement, that Patient's data only within 10 working days;
- c) erasure: a client record deleted in the Service is hidden but remains in the database; a finalised clinical document cannot be deleted; alerts are deleted permanently. If you need to fulfil a Patient's erasure request, Kusties permanently deletes the specified Patient Data within 30 days of your written instruction. The exceptions are backups (point 13.4) and data that the law requires to be kept;
- d) restriction and objection: Kusties provides the assistance that is technically possible on your instruction.
10.2. If Kusties receives a request directly from a Patient, it forwards the request to you without undue delay and no later than within 5 working days, if it can determine which specialist the request concerns. Kusties does not answer the request on the merits unless you instruct it to. Kusties may tell the requester that the request has been forwarded to the controller.
10.3. Security, impact assessment and consultation. Kusties assists you in meeting the obligations in GDPR Articles 32 to 36 (security, breach notification, data protection impact assessment and prior consultation). Kusties provides the information available to it: this Agreement with its annexes, a description of the Service, and answers to reasonable written questions within 30 days.
10.4. Assistance under this section is free of charge unless the request is manifestly unfounded or excessive. For substantial additional work, the parties may agree on reasonable compensation in advance.
11. Personal data breaches
11.1. Kusties informs you of a personal data breach affecting Patient Data without undue delay and no later than 48 hours after Kusties becomes aware of it (GDPR Article 33(2)).
11.2. Kusties sends the notification to your account's e-mail address.
11.3. To the extent the information is available, the notification states (GDPR Article 33(3)):
- a) the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- b) a contact person from whom more information can be obtained;
- c) the likely consequences;
- d) the measures taken or proposed to address the breach and mitigate its effects.
Where not all information can be provided at once, Kusties provides it in phases without undue delay (GDPR Article 33(4)).
11.4. Kusties promptly takes reasonable measures to contain the breach and mitigate its effects, documents the breach and cooperates with you. Kusties does not notify the supervisory authority or Patients on your behalf of a breach affecting Patient Data unless you instruct it in writing or the law requires it.
11.5. A breach notification is not an admission of fault by Kusties.
11.6. You inform Kusties without delay if you suspect a breach in the Service or unauthorised access to your account.
12. Transfers outside the EEA
12.1. The Service's database is located in the European Union, in the DigitalOcean data centre in Frankfurt (Germany). Session and rate-limiting data is stored in Redis Cloud (an AWS data centre in Frankfurt, Germany). Text messages and e-mails are sent by Brevo (EU).
12.2. DigitalOcean and Cloudflare are companies registered in the United States of America, and Cloudflare uses a global network. It therefore cannot be ruled out that Patient Data is transferred or becomes accessible outside the European Economic Area (EEA), for example during maintenance or content delivery.
12.3. Kusties transfers Patient Data outside the EEA, or allows it to be transferred, only if the conditions of Chapter V of the GDPR are met, for example:
- a) the European Commission has adopted an adequacy decision for the recipient's country or the recipient (GDPR Article 45); or
- b) standard data protection clauses adopted by the European Commission have been concluded with the recipient (GDPR Article 46(2)(c)) and, where needed, supplementary measures have been taken.
12.4. The safeguard for each Sub-processor is stated in Annex 2.
12.5. Kusties' manual backups are kept in the EU, on the computer of a person authorised by Kusties.
13. End of the Agreement: return and deletion of data
13.1. Export. After the Terms end or your account is closed, you may request, within 30 days, an export of your Patient Data in a machine-readable format (JSON and CSV). Once the self-service export "Download my data" is switched on in the Service, you may also use it. Notes, clinical documents and programme private notes are included in the export in decrypted form. The export does not include patient alerts, the log of messages sent to Patients, appointment types and recurring appointment series, or deleted (hidden) records; at your written request, Kusties prepares them separately within 30 days.
13.2. Deletion. After the period in point 13.1 ends, Kusties permanently deletes the Patient Data within 60 days, unless European Union or Latvian law requires it to be kept (GDPR Article 28(3)(g)) or you instruct in writing that it be returned otherwise. At your request, Kusties confirms the deletion in writing.
13.3. Current procedure. The Service does not yet have an automatic account closure and data deletion function. An account is closed by a Kusties administrator by deactivating it, and the data is kept until the deletion in point 13.2, which Kusties performs manually.
13.4. Backups. Patient Data may remain in backups until they are deleted in the ordinary course. During that time the backups are used only for restoring data and are protected by the measures in Annex 1.
13.5. Retention of medical records. If the law requires you to keep medical records for a certain period, you export them and keep them yourself before the deletion. After the Terms end, Kusties continues to store Patient Data only under a separate agreement.
13.6. Kusties keeps the data for which it is the controller (for example your account's consent records and the security audit log) in accordance with the Privacy Policy.
14. Audits and information
14.1. Kusties makes available to you all information necessary to demonstrate compliance with the obligations in GDPR Article 28 (GDPR Article 28(3)(h)): this Agreement with its annexes, and answers to written questions within 30 days.
14.2. If the information in point 14.1 is not sufficient, you or an independent auditor mandated by you who is bound by confidentiality may carry out an audit, including an inspection, under the following conditions:
- a) the audit is announced in writing at least 30 days in advance;
- b) audits are carried out no more than once every 12 months, except after a personal data breach or at the request of a supervisory authority;
- c) the audit is carried out during working hours and in a way that does not disrupt the Service or reveal other customers' data or Sub-processors' trade secrets;
- d) you bear the costs of the audit unless it reveals a material breach of Kusties' obligations.
14.3. Kusties demonstrates the compliance of the Sub-processors' infrastructure with the audit reports or certificates published by the Sub-processors, where available.
14.4. If an audit reveals non-compliance with this Agreement, Kusties remedies it without undue delay.
15. Liability
15.1. The limitations and exclusions of liability set out in section 13 of the Terms apply to the parties' liability in connection with this Agreement. This Agreement does not create a separate or higher liability cap.
15.2. This Agreement does not limit the parties' liability towards data subjects under GDPR Article 82, nor any liability that cannot be limited under the law.
15.3. Kusties is liable for its Sub-processors as for its own acts (point 9.6).
16. Term, amendments and precedence
16.1. The Agreement remains in force while the Terms are in force and afterwards until section 13 has been carried out.
16.2. Kusties may amend this Agreement, for example if the law, the functions of the Service or the Sub-processors change. Kusties informs you of amendments by e-mail at least 30 days in advance; section 9 applies to changes of Sub-processors. If you do not agree to the amendments, you may end the agreement under the Terms before the day they take effect. Amendments required by law may take effect sooner.
16.3. In matters of the processing of Patient Data, this Agreement takes precedence over the Terms.
16.4. If any provision of the Agreement becomes invalid, the other provisions remain in force.
16.5. The Agreement is drawn up in Latvian, and translations are for information. In case of discrepancy, the Latvian version prevails.
17. Governing law and disputes
17.1. The Agreement is governed by the laws of the Republic of Latvia and the GDPR.
17.2. Disputes are resolved in the manner set out in section 17 of the Terms.
17.3. This Agreement does not limit the right of Patients to apply to the Data State Inspectorate (Datu valsts inspekcija) or to a court.
18. Contact details
18.1. Kusties: SIA "Kusties.com", Ābolu iela 14C, Mārupe, Mārupes nov., LV-2167, e-mail [email protected].
18.2. You: the e-mail address of your Service account. Keep it up to date, because Kusties sends the notices provided for in this Agreement to it.
Annex 1. Technical and organisational measures
Status as of 1 October 2026. This annex describes only the measures that are in place. Known limitations and planned improvements are listed in point 12.
1. Hosting and data location
- The web application, the API and the database run on DigitalOcean App Platform in region fra1 (Frankfurt, Germany).
- The session and rate-limiting store (Redis) runs on Redis Cloud in AWS region eu-central-1 (Frankfurt, Germany).
- The API is reachable only under the path
/api, and diagnostic tools are switched off. - The test environment has a separate database.
2. Encryption
- The connection between the browser or app and the Service is encrypted (HTTPS). E-mails are handed to the sending server over SMTP with STARTTLS.
- Field-level encryption (AES-256-GCM) with a separately stored encryption key:
- the title and content of notes;
- the whole content of clinical documents (bound to the document identifier);
- the programme's private note (bound to the programme and the client);
- alerts (bound to the client);
- two-step sign-in secrets (bound to the user).
- The API does not start without the encryption key unless an unencrypted mode is explicitly allowed, which is used only in local development.
- Not encrypted at field level: client names and contact details, birthdays, appointment titles and descriptions, programme names and descriptions, completion feedback and the message log.
- The connection to Redis is currently not encrypted (see point 12). Redis does not store health data. Tokens and e-mail addresses are stored there only as hashes. IP addresses are stored there in rate-limit counters (for the duration of the limit, no longer than 24 hours) and in two-step sign-in challenges (5 minutes).
3. Access control
- Roles: super administrator (galvenais administrators), administrator, specialist and client (client cabinet, switched off).
- A specialist sees only their own records. The Service answers requests for other specialists' records with "not found".
- Notes, clinical documents, alerts and the programme's private note can be opened in the Service only by their author.
- In the Service, administrators can open client records, programmes, completion marks and feedback, appointments and the message log (point 7.2 of the Agreement).
- Switched-off functions answer "not found" before sign-in is checked.
- Two-step sign-in (an authenticator-app code and 10 recovery codes) is mandatory for administrators and optional for specialists.
- Sensitive administrator actions and the data export require a sign-in within the last 10 minutes (with the second step if two-step sign-in is on or the role requires it); the export also requires the password to be entered again and, if two-step sign-in is on, a code.
- Sessions: the access token is valid for 15 minutes; the refresh token changes on every use, only its hash is stored, and reuse is detected; a session ends no later than 30 days after sign-in. In "My devices" a user can see their devices and sign them out; an administrator can also do this. All sessions end after a change of password, role or e-mail address, or when the account is blocked.
4. Passwords and one-time links
- Passwords are stored as bcrypt hashes. A sign-in with an unknown e-mail address runs the same password check, so the response time does not reveal which addresses are registered.
- One-time links (password reset, password setup, forms, invitations) contain 32 random bytes, and only their SHA-256 hash is stored. Validity: password reset 1 hour, password setup 72 hours, form 14 days. Password links are deleted 7 days after use or expiry.
- Recovery codes are stored as HMAC-SHA-256 hashes.
5. Patient links and forms
- The programme link contains two unguessable identifiers and acts as an access key: anyone who has the link can see the programme and record completions without signing in.
- Notes, clinical documents and alerts are never shown on a public link or in an e-mail or SMS.
- A form link shows only that form, and the prefilled part does not contain the personal identity code. The link is valid for 14 days.
- A Patient's unsent form answers are kept in the Patient's browser (localStorage) until the link expires, so that they are not lost if the page is reloaded.
- Exercise video playback addresses are not signed: anyone who has a video's identifier can play it. When an administrator takes a video down, the video is blocked. Videos in the Kusties platform library are never blocked or deleted.
6. Rate limits
- Sign-in: per IP address, per e-mail address and per combination of both.
- Two-step sign-in.
- E-mails to one recipient: 5 per hour.
- Public forms, invitations and unsubscribing: 60 per hour per IP address.
- Public completions: 600 per hour per IP address.
- SMS: 100 per specialist in 24 hours, a reminder re-send 3 times in 24 hours, 500 per day in total on the platform.
- Data export (when switched on): 3 times in 24 hours.
If the rate-limit store is unavailable, sign-in, two-step sign-in, e-mail and data export requests are refused.
7. Logs and audit
- Application logs do not record IP addresses, browser and device descriptions (user agents), e-mail addresses, phone numbers, tokens or message content.
- The security audit log can only be appended to. It records the actor, the action and the identifiers of the object. For security events (failed sign-ins, reused tokens, password events and administrator actions) it also records the request's IP address. This log is data for which Kusties is the controller.
- Session records with the IP address and device details are deleted 90 days after the session ends.
8. Messages to Patients
- Text messages do not contain the appointment title, the Patient's name or health data.
- E-mail reminders (when switched on) and recurring-series e-mails do not contain the appointment title or description.
- Exception: the e-mails about an appointment being created, changed or cancelled contain the appointment title and description; if a calendar file (.ics) is attached to a created or changed e-mail, it also contains the Patient's first and last name (point 5.2 of the Agreement).
- One-time links are not stored in the message log.
- The Service's e-mails have a DKIM signature and a DMARC policy set up.
9. Backups and availability
- There are currently no automatic database backups.
- Before every deployment of a database structure change, a full manual copy of the database is made, and it is verified by a full restore.
- The copies are kept on the computer of a person authorised by Kusties, and only that user has access to the copy files.
- In the copies, data encrypted at field level (point 2) stays encrypted. The encryption key is not stored in the copy.
10. Development, testing and secrets
- Checks on copies of the data: see point 6.5 of the Agreement.
- Secrets (keys and passwords) are stored as secret environment variables of the hosting platform. They are not stored in the code repository and are not written to logs. They were last rotated on 26 September 2026, except the database password, which will be changed when moving to a managed database.
11. Organisational measures
- Only the persons listed in section 7 of the Agreement have access to Patient Data.
- No analytics or tracking tools are loaded in the Service (point 6.4 of the Agreement).
- Persons with access to Patient Data are bound by confidentiality (point 7.1 of the Agreement).
- Kusties assesses and remedies personal data breaches and notifies them under section 11 of the Agreement.
- No data protection officer has been appointed, and no data protection impact assessment has been carried out.
12. Known limitations and planned improvements
| Limitation | Plan |
|---|---|
| There are no automatic database backups. | A managed PostgreSQL database with daily backups, 7-day point-in-time recovery, encryption at rest and access only from a private network. Approved in principle, not yet implemented. |
| The database is not isolated in a private network (VPC). | The same solution. |
| The connection to Redis is not encrypted (TLS). | To be assessed when Redis stores more than session data. |
| The access token is stored in the browser's localStorage, where a malicious script could read it. | Under assessment. |
| Exercise video addresses are not signed. | Signed addresses are provided for as an option; until then, video takedown applies. |
| The programme link is an access key without sign-in. | The client cabinet (built, switched off) will let the Patient sign in. |
| There is no automatic account closure and data deletion function. | Until then, manual deletion (point 10.1 and section 13 of the Agreement). |
| In the Service, administrators can open client records, completion feedback and the message log. | Access is used only for the purposes in point 7.2 of the Agreement. |
| The kusties.com domain has no SPF record. | Planned to be added. |
Annex 2. Sub-processors
Status as of 1 October 2026.
| Sub-processor | Service | Patient Data | Location | Safeguard |
|---|---|---|---|---|
| DigitalOcean | hosting of the application and API, PostgreSQL database, application logs | all data listed in section 4 | data centre fra1, Frankfurt (Germany); US company | data stored in the EU; for access from outside the EEA: standard data protection clauses in the provider's data processing terms (point 12.3(b)) |
| Redis Cloud (Redis) | session and rate-limiting store | none (IP addresses in the counters are processing by Kusties as controller); no health data is stored | AWS eu-central-1, Frankfurt (Germany) | data stored in the EU; for access from outside the EEA: standard data protection clauses in the provider's data processing terms (point 12.3(b)) |
| Brevo | sending text messages; sending e-mails (SMTP) | Patients' phone numbers and SMS text; Patients' e-mail addresses and e-mail content, including calendar files where attached | EU (France); some of Brevo's sub-processors may be outside the EEA | EU company; for Brevo's sub-processors outside the EEA: standard data protection clauses (point 12.3(b)) |
| Cloudflare | Stream (exercise videos) and Images (exercise images) | when switched on, the videos of private exercises you upload (Cloudflare receives the Patient's IP address and browser and device description, when the Patient's device loads a video or image, in processing by Kusties as controller, point 4.2) | global network; US company | standard data protection clauses in the provider's data processing terms (point 12.3(b)) |
Recipients that are not Sub-processors. Kusties does not pass Patient Data to these recipients for processing on its behalf, or they receive data on your instruction:
- mobile network operators and e-mail providers through which a message reaches the Patient;
- Mailchimp (Intuit): only for the kusties.com enquiry forms, for which Kusties is the controller;
- hosting of the kusties.com marketing website: no Patient Data is processed there;
- VIES (European Commission): VAT number check for billing;
- sign-in providers (Google, Microsoft, Apple, GitHub, LinkedIn): not currently used.
Annex 3. Information for patients (template)
As controller, you may use this text to inform Patients (GDPR Article 13). Fill in the parts in curly brackets { } and adapt the text to your practice. The template does not replace your obligation to provide complete information.
Full version
How {name of the practice or specialist} processes your personal data
Controller. {first and last name or name of the practice}, {registration number, if any}, {address}, {e-mail}, {phone}.
What data we process. Your first and last name, contact details and date of birth; information about your health that we record during your care (notes, examination findings, forms {and your personal identity code, if it is needed in the medical records}); your exercise programmes, the completions you record and your feedback; appointment times; the reminders and notices we send.
Why. To provide you with {physiotherapy / massage / training} services, prepare and send exercise programmes, schedule appointments and remind you of them, and keep {medical} records.
Legal basis. {choose the one that applies: a contract for the provision of services (GDPR Article 6(1)(b)) and the provision of health care (GDPR Article 9(2)(h)) / your explicit consent (GDPR Article 9(2)(a))}.
Who processes data on our behalf. We keep your data in the Kusties system. SIA "Kusties.com" is our data processor and processes the data only on our instructions. The database is located in the European Union (Frankfurt, Germany). Text messages and e-mails are sent by Kusties' service providers, and exercise videos are loaded from Cloudflare. Some of Kusties' service providers are US companies. If data is transferred outside the European Economic Area, it is protected by the mechanisms provided for in Chapter V of the GDPR. List of service providers: https://kusties.com/en/dpa.
Other recipients. {for example: your family doctor or another specialist, only with your consent or where the law provides for it.}
How long we keep the data. {retention period, for example the retention period for medical records set by law.}
Your personal link. We send you your exercise programme by a personal link. Anyone who has this link can see the programme and record completions, so please do not forward the link to others. If the link has reached another person, let us know.
Forms. Before an appointment we may ask you to fill in a form by sending you a link by e-mail or text message (SMS). The link is valid for 14 days. Until the form is submitted, the answers you enter are kept in your browser on that device until the link expires. If you use a shared computer, we recommend filling in and submitting the form in one go.
Messages. SMS reminders contain no information about your health. An e-mail about an appointment being booked, changed or cancelled may include the appointment title and description.
Your rights. You have the right to access your data and receive a copy, to have it corrected, to request its erasure (to the extent the law does not require it to be kept), to restrict processing, to object to processing and to receive your data in a portable format. If processing is based on your consent, you may withdraw it at any time; this does not affect the lawfulness of the processing before the withdrawal. To exercise these rights, contact us: {contact details}. You also have the right to lodge a complaint with the Data State Inspectorate (Datu valsts inspekcija). {if applicable: as a patient, you also have the rights set out in the Patients' Rights Law (Pacientu tiesību likums).}
Minors. If the patient is a minor, we provide this information to their legal representative.
Short version
For example, for your website, an e-mail or a printed form:
Your data is processed by {name of the practice or specialist} using the Kusties system (SIA "Kusties.com" as processor). More information: {link to the full information}.