Privacy, compliance & data governance
PosturalCheck
ResourcesPrivacy, compliance & data governance

DPA checklist when contracting SaaS for posture and imaging workflows

About 1 min read

A signed DPA nobody reads is theatre. Use this list during actual negotiation.

At a glance

  • Require prior approval or notice for new subprocessors.
  • Define measurable security annexes, not vague “industry standard.”
  • Spell deletion timelines after contract end.

Scope and instructions must match reality

If staff use features you did not list, you have a gap. Update DPAs when enabling exports to new countries or tools.

International transfers need explicit mechanisms

Map where data is processed and stored. Attach appropriate transfer tools your counsel approves. Do not assume “cloud” equals your country.

How many credits does each analysis type use?

Fast, Standard, Advanced, and Dynamic analyses use different credit amounts—there’s a dedicated guide in this hub; Pricing also has plans and FAQs on monthly renewal.

Explore pricing

Processor assistance for data subjects

Require reasonable support timelines for access, rectification, and erasure requests. Test the process once before an urgent patient email arrives.

Including PosturalCheck in your vendor register

Record purposes, categories, and link to their security documentation. Align internal ROPA entries with features you actually toggled on.

PosturalCheck

From reading to the product: plans and credits at a glance

On Pricing you can compare subscriptions, monthly credits included, operator seats, and features (PDF reports, comparisons, stats, roles).

Go to pricing