Data Processing Addendum
This page summarises how MB Labelis processes personal data on behalf of business
customers ("you") under Art. 28 GDPR. It supplements our
Terms of Service. If your organisation requires a countersigned copy,
email support@labelis.app and we will provide one.
1. Roles
For the records your team enters into Labelis (patient/client records, label photos, scan data, notes), you are the data controller and MB Labelis is your data processor. We process this data only to provide the service described in the Terms of Service and never for our own purposes. For your account data (emails, billing), we are an independent controller as described in the Privacy Policy.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: data entered into the Labelis app and portal by your team
- Duration: the term of your subscription plus the retention windows in the Privacy Policy (90 days after a paid plan ends; deletion on request)
- Nature and purpose: hosting, synchronisation across your team's devices, backup, and display within the app — nothing else
- Categories of data subjects: your patients, clients, or animals' owners; your team members
- Categories of data: names, dates of birth, identification codes, label photographs, scanned barcode data, notes. Labelis is not marketed as a medical-records system; you decide what you enter.
3. Our Obligations as Processor
- Process the data only on your documented instructions (your use of the app is the instruction)
- Ensure persons authorised to process the data are bound by confidentiality
- Apply the security measures described in the Privacy Policy: TLS 1.2+ in transit, AES-256 at rest, access control via security rules, EU data residency (
eur3, Belgium) - Engage sub-processors only as listed below and inform you of changes via this page and email notice
- Assist you, insofar as possible, with data-subject requests and Art. 32–36 obligations
- Notify you without undue delay after becoming aware of a personal data breach affecting your data
- Delete your data at the end of the service per the retention windows, or earlier on request
- Make available information reasonably necessary to demonstrate compliance with Art. 28
4. Sub-Processors
| Sub-processor | Purpose | Location / transfer basis |
|---|---|---|
| Google Cloud EMEA Ltd (Firebase) | Cloud infrastructure: database, file storage, authentication | EU (Belgium, eur3); Google Cloud DPA with EU SCCs |
| Resend Inc. | Transactional email (team invitations, service notices) — receives team member email addresses only, never patient data | USA; DPA with EU SCCs |
Paddle (payments) is not a sub-processor of your records: it acts as merchant of record for billing and never receives data your team enters into the app.
5. Contact
Data protection questions, signed DPA copies, audits, or sub-processor objections: support@labelis.app.