Skip to content
Muveya

Muveya Data Processing Agreement

Effective date: · Version: 1.0

This DPA is written in English. The Spanish and Portuguese versions are translations; if they differ, the English version governs.

Last updated: September 20, 2026.

This Data Processing Agreement (the "DPA") forms part of the Muveya Terms of Service or of another written agreement that incorporates this DPA (the "Main Agreement") between the Customer and Woku SpA, a company incorporated in Chile, domiciled at Calle 120 39 Dp 14 B, Hualpén, Chile 4600150 ("Woku"). Muveya is a product of Woku operated by Woku SpA.

The DPA takes effect when the Customer accepts the Main Agreement or when both parties sign it, and it applies when Woku processes Customer Personal Data on the Customer's behalf in providing Muveya.

1. Definitions

The terms "personal data", "processing", "controller", "processor", "subprocessor", "data subject" and "personal data breach" shall have the meaning given in the applicable Data Protection Legislation.

For this DPA:

  • Customer is the person or entity that accepts the Main Agreement and determines the essential purposes and means of the processing of Customer Personal Data.
  • Customer Data has the meaning given in the Terms.
  • Customer Personal Data is the personal data included in Customer Data that Woku processes on the Customer's behalf, including the identification of Users and staff in operational records (who recorded, approved, dispatched, delivered, or received, with dates, comments, and notes), the email addresses of invited people, Patient References and care references, imported files, and free-text fields. It does not include data for which Woku acts as an independent controller to administer accounts, authentication, security, support, or the business relationship.
  • Data Protection Legislation comprises the laws applicable to the processing, including Chile's Law No. 19.628 and, from its entry into force, its amendments by Law No. 21.719; Regulation (EU) 2016/679 ("GDPR"); the UK GDPR; and other applicable mandatory rules.
  • SCCs are the European Commission's standard contractual clauses approved by Implementing Decision (EU) 2021/914, as updated or replaced.
  • Services are the Muveya features described in the Main Agreement (the "Service" as defined in the Terms).
  • Subprocessor is a third party engaged by Woku to process Customer Personal Data on the Customer's behalf.

2. Roles and Scope

The Customer acts as controller and Woku as processor with respect to Customer Personal Data. If the Customer acts as a processor for a third party, the Customer is the processor and Woku is the subprocessor; the Customer represents that it has authority to give instructions and to incorporate this DPA.

Woku acts as an independent controller with respect to data necessary to:

  • administer accounts, Users, authentication, and the business relationship;
  • protect the security and integrity of the Service;
  • comply with its own legal obligations;
  • generate aggregated or de-identified metrics that do not allow identifying a person.

The Privacy Policy governs those own activities.

3. Documented Instructions

Woku will process Customer Personal Data only:

  1. to provide, protect, and maintain the Services in accordance with the Main Agreement, this DPA, and the Customer's configuration;
  2. according to other documented and lawful instructions agreed by the parties;
  3. when an applicable law requires it, in which case Woku will inform the Customer before the processing, unless legally prohibited.

The Main Agreement, the use and configuration of the Service, authorized support requests, and the Customer's written instructions constitute documented instructions.

Woku will inform the Customer if, in its reasonable opinion, an instruction infringes the Data Protection Legislation. It may suspend the affected instruction while the parties review it, without being obligated to provide legal advice to the Customer.

4. Customer Obligations

The Customer warrants that it:

  • has a legal basis to collect, use, and entrust the processing;
  • provides transparent notices to Users, staff, and patients;
  • obtains consents when necessary;
  • limits the data to what is necessary and keeps it accurate;
  • does not instruct processing that is unlawful or incompatible with the Terms;
  • responds to data subject requests and forwards to Woku only those that require assistance;
  • has authority over the systems, files, and integrations it connects;
  • assesses the suitability of the Service for its industry, territory, and risk.

The Service is designed to store Patient References and care references only as opaque, encrypted codes taken from the Customer's own systems. The Customer must not use Muveya to deliberately solicit or process health or clinical data, diagnoses, clinical histories, patient names, biometric or genetic data, trade union membership, political opinions, beliefs, sex life or sexual orientation, criminal records, government identifiers (such as the Chilean RUT), data of minors, or other sensitive categories, unless there is a specific written addendum with Woku, a valid legal basis, and appropriate controls. Even with an addendum, the Customer must never enter passwords, secrets, authentication codes, or full payment card numbers into the Service.

Free-text fields, such as the justification of an order, approval comments, and delivery and receipt notes, may receive sensitive data that neither the Customer nor Woku solicited. Only the justification of an order is automatically checked against common identifier patterns. The Customer must instruct its Users to avoid such disclosure, minimize collection, and communicate to Woku any special instructions needed.

5. Woku Obligations

Woku shall:

  • process the data only under documented instructions and to provide the Services;
  • ensure that authorized persons are bound by confidentiality;
  • implement the security measures in Annex II;
  • reasonably assist with rights, incidents, assessments, and regulatory consultations;
  • maintain records required by the Data Protection Legislation;
  • allow audits in accordance with section 12;
  • return or delete data in accordance with section 10;
  • impose substantially equivalent protection obligations on its Subprocessors;
  • not sell Customer Personal Data or use it for its own behavioral advertising;
  • not use Customer Data to train or fine-tune artificial intelligence models, nor send it to model providers without first following section 8.2.

6. Authorized Personnel and Confidentiality

Woku will limit access to personnel and contractors who need the data to provide, secure, or support the Service. Such personnel will be subject to contractual or legal confidentiality obligations and will receive instructions appropriate to their role.

Human administrative access to Customer Data will be limited to authorized support, incident investigation, legal compliance, or maintenance that cannot reasonably be performed otherwise, and is subject to Woku's internal access controls and confidentiality obligations.

7. Security

Woku will maintain technical and organizational measures proportionate to the nature, scope, context, and risk of the processing. Annex II describes the technical and organizational measures Woku maintains.

The Customer acknowledges that no measure eliminates all risk and that it is responsible for configuring Users, roles, permissions, API keys, integrations, and content securely.

Woku may update the measures to respond to threats or improve the Service, provided that it does not materially reduce the overall level of protection during the term.

8. Subprocessors

8.1 Initial Specific Authorization

By accepting this DPA, the Customer specifically authorizes the Subprocessors named in Annex III for the purposes described there. Woku will not enable a provider to process Customer Personal Data until appropriate data protection conditions are in place.

8.2 Authorization for New Subprocessors

Where the Data Protection Legislation permits a general written authorization, the Customer authorizes the addition or replacement of Subprocessors subject to this procedure. Woku will notify the account contact at least 30 days before the new Subprocessor processes Customer Personal Data. The notice will describe the name, purpose, and relevant location.

Where applicable law requires specific authorization, Woku will obtain an affirmative acceptance, written or electronic, before enabling the new Subprocessor. If a legal or security emergency prevents prior notice, Woku will limit the processing to what is strictly necessary and will inform the Customer as soon as it is legally and reasonably possible.

The Customer may object on reasonable data protection grounds within the following 15 days. The parties will try to agree on a solution, such as disabling the feature or applying additional measures. If there is no reasonable solution, the Customer may terminate the affected part of the Service before the change takes effect.

8.3 Responsibility for Subprocessors

Woku will enter into a written contract with each Subprocessor that imposes substantially equivalent obligations for the delegated processing. Woku will remain responsible to the Customer for the Subprocessor's compliance to the extent required by law and the Main Agreement.

9. Data Subject Rights

Taking into account the nature of the processing, Woku will assist the Customer through appropriate technical and organizational measures to respond to requests for access, correction, erasure, objection, blocking, restriction, portability, or rights relating to automated decisions.

If Woku receives a request related to Customer Personal Data:

  • it will forward it to the Customer without responding substantively, unless authorized or legally required;
  • it will not identify or disclose data from another Tenant;
  • it will provide reasonable assistance without undue delay and with enough time for the Customer to meet the applicable legal deadline.

Muveya has no rights-management feature: it offers no self-service tool to export, correct, or delete personal data, so a person at Woku locates and handles each record by hand, through the privacy contact in section 18. On receiving a request, Woku will confirm receipt to the Customer and agree with it the scope and the timing of that manual work, so that the Customer can meet its own deadline.

Extraordinary, repetitive, or technically complex assistance may be subject to reasonable costs disclosed in advance, unless the need arises from Woku's breach.

10. Return, Retention, and Deletion

10.1 During the Service

The Customer can update catalog, Clinic, Warehouse, and membership data, and deactivate or remove it where the features allow. Stock movements, approval decisions, and custody confirmations are not edited or deleted during the Service: they are corrected with new compensating records. For the records that contain Customer Personal Data processed on the Customer's behalf, the following retention applies:

  • Customer Data, including operational records: while the Tenant exists or until a valid deletion instruction, subject to section 10.2;
  • analytics export records: 7 days, with download links that expire after 5 minutes;
  • application logs that incidentally contain this data: the period will be published in the Privacy Policy before the production environment starts processing data.

Account, security, and business-relationship data that Woku processes as controller are governed by the retention table in the Privacy Policy, not by the instructions in this DPA.

10.2 Termination or Deletion Instruction

Following a valid return or deletion instruction, or upon termination of the Main Agreement when Woku ceases to provide the Service and process the data, Woku will, at the Customer's documented choice, return a copy of the Customer Personal Data in a reasonably portable format prepared by Woku, such as CSV or JSON, or delete it in active systems without undue delay, unless the law requires retaining a limited copy. Both actions are manual: Muveya has no Tenant export or deletion feature, so a person at Woku extracts or removes the records by hand in the underlying database and object storage, and the parties agree the scope and the date in writing. Woku will only anonymize as a substitute for deletion when the Customer expressly instructs or agrees to it, for example to preserve the traceability of stock records. On request, Woku will provide written confirmation of the completed actions and of any legal exceptions or pending backups. Woku deletes data under its direct control through its providers' interfaces and forwards deletion instructions where provider action is needed, subject to applicable legal retention and the provider's data controls.

Production backups, when enabled, are isolated from serving traffic and expire according to the active backup configuration. Contact Woku for the applicable schedule, rotation period, and recovery coverage described in Annex II, section 7.

Ending the Pilot or ceasing to use the Service does not, by itself, constitute a deletion instruction.

10.3 Legal Retention

If Woku must retain data for legal reasons, security, fraud, or defense of claims, it will isolate it from ordinary use, limit access, and delete it when the obligation ends.

11. Security Incidents

Woku will notify the Customer without undue delay after becoming aware of a security breach affecting Customer Personal Data, unless legally prevented. The notice will be sent to the Tenant's account contact and coordinated through the privacy, security, and incident address in section 18. Annex II, section 7, states the status of Woku's written incident response procedure, which will be added to that Annex before the production environment starts processing Customer Personal Data.

The initial notification will include, to the extent known:

  • the nature and approximate scope;
  • the categories of data and data subjects affected;
  • the estimated date or period;
  • the likely consequences;
  • the measures taken or proposed;
  • a contact for coordination.

If the information is not available in the first notice, Woku will provide it in phases without unjustified delay. Woku will cooperate reasonably so that the Customer can assess and meet its notification duties. A notification does not constitute an admission of fault or liability.

The Customer is responsible for notifying authorities and data subjects when it is required to as controller, unless otherwise agreed or legally required.

12. Audits and Compliance Information

Woku will make available information reasonably necessary to demonstrate compliance with this DPA. The process will follow this order:

  1. questionnaire, documentation, or available evidence;
  2. a remote meeting with relevant personnel;
  3. an independent or on-site audit only when the prior evidence is insufficient, an authority requires it, or there is a material incident reasonably connected to Woku.

Except in cases of urgency or an authority's mandate, the Customer will give 30 days' notice, conduct at most one audit per 12 months, use an independent auditor bound by confidentiality, not access other customers' data, and avoid affecting operations. The Customer will bear its own costs, unless the audit reveals a material breach by Woku.

Woku does not claim to hold certifications, audits, or reports that are not current and available.

13. Assessments and Authorities

Woku will provide reasonable assistance with impact assessments, prior consultations, and requests from authorities when the processing through the Service makes it necessary and the Customer provides sufficient information.

Each party will inform the other, when legally possible, of a binding request that affects Customer Personal Data. Woku will review the legality of the request and will limit disclosure to what is required.

14. International Transfers

The Customer authorizes processing in Chile, the United States, and the locations of the Subprocessors in Annex III, subject to valid mechanisms.

14.1 Data Subject to the GDPR

When the GDPR applies and a transfer requires safeguards:

  • for a transfer from the Customer as controller to Woku as processor, the parties will incorporate the SCCs of Decision 2021/914, Module 2;
  • when the Customer is a processor and Woku a subprocessor, Module 3 will be used;
  • Annex I of this DPA will complete the description of the parties and the processing, and Annex II will describe the technical measures;
  • the authority and law chosen in the SCCs will be those of a Member State that allows third-party beneficiary rights, as agreed by the parties or the applicable addendum;
  • Woku will apply the SCCs or equivalent mechanisms with Subprocessors where applicable.

If there is a conflict between the SCCs and this DPA, the SCCs prevail with respect to the covered transfer.

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs applies. Unless an order states otherwise, the governing law of the SCCs is that of Ireland and the competent supervisory authority is the Irish Data Protection Commission. Woku applies the SCCs or an equivalent recognized mechanism with each Subprocessor in Annex III where a transfer requires it.

14.2 Chile and Other Jurisdictions

Woku will apply the transfer and subcontracting rules of the Chilean Data Protection Legislation from its entry into force, in addition to any mandatory safeguard of the Customer's jurisdiction agreed in writing.

15. Liability

Each party's liability under this DPA is subject to the exclusions and limits of the Main Agreement, except to the extent that the Data Protection Legislation or the SCCs prohibit limiting them. This DPA does not duplicate indemnities for the same event.

16. Term, Changes, and Termination

This DPA remains in force for as long as Woku processes Customer Personal Data. Obligations that by their nature must survive will continue until deletion or anonymization is complete.

We may update the DPA to reflect legal or Service changes. We will notify material changes at least 30 days in advance, except in cases of legal or security urgency. A change of Subprocessor also follows the process in section 8.

We will not materially reduce the protection of Customer Personal Data during the Pilot or a paid period without offering a reasonable solution or right of termination where the law requires it.

17. Precedence and Governing Law

If there is a conflict regarding data processing:

  1. the SCCs prevail for the transfer they cover;
  2. then this DPA;
  3. then the Main Agreement.

Outside the mandatory scope of the SCCs or a mandatory foreign law, this DPA is governed by the law of Chile and the dispute clause of the Main Agreement.

18. Contact

Annex I: Processing Details

A. Parties

Exporter or initial controller/processor

The Customer identified in the account, written agreement, or signature of the Main Agreement.

Importer or processor/subprocessor

Woku SpA, operator of the Muveya product, with the contact details in section 18.

B. Subject Matter, Nature, and Purpose

ElementDescription
Subject matterProvision of Muveya's catalog, stock ledger, receipts and consumption, internal orders and approvals, custody of deliveries, counts, reports, CSV imports and exports, read-only API and MCP access, and support
DurationTerm of the Main Agreement and applicable deletion/retention periods
NatureCollecting, receiving, recording, organizing, structuring, storing, querying, encrypting, displaying, exporting, backing up, restricting, and deleting
PurposeProviding the features configured by the Customer, recording and tracing its operations, maintaining security, diagnosing, and carrying out instructions
FrequencyContinuous or as determined by the use of the Customer and its Users

C. Categories of Data Subjects

  • Users, members, and staff of the Customer only when their data forms part of Customer Data or Woku processes it following the Customer's instructions; account, authentication, security, and business-relationship data processed for Woku's own purposes are governed by the Privacy Policy;
  • people invited by the Customer to join its Tenant;
  • patients, only through opaque, encrypted Patient References and care references;
  • suppliers, contacts, and other individuals whose data the Customer is authorized to process.

D. Categories of Data

  • photos of supply packaging that Users choose to send for assisted catalog entry, and the proposed fields they review;
  • identity and contact data included in Customer Data: name and email address of Users and invited people;
  • operational attribution: who recorded, approved, dispatched, delivered, or received, with dates, comments, and notes;
  • pseudonymous references: Patient References and care references;
  • business data: catalog, costs, lots, serial numbers, expiry dates, quantities, and consumption destinations;
  • any data a person enters in free text, which could incidentally and unsolicited include sensitive categories.

E. Sensitive Data

Deliberate processing of sensitive data is not contemplated as a standard purpose. The Service stores Patient References and care references only as opaque, encrypted codes, and the Customer must not enter identifying or clinical data about patients without a written addendum. If such data appears incidentally in free text, Woku will process it under the same instructions and measures, and the Customer may instruct its deletion.

F. Retention

Section 10 and the table in the Privacy Policy describe the periods. When a written agreement sets a shorter period and the product supports it, that period will prevail.

Annex II: Technical and Organizational Measures

The following measures apply to the operating production service. Woku applies authorization, Tenant isolation, field-level encryption, redaction, limits, and audit records. Hosting controls depend on the active configuration of the providers identified in Annex III; database backup arrangements are described in section 10 of the Privacy Policy.

1. Governance and Access

  • access on a need-to-know basis, by role and permission within the Tenant, with access that can be limited to specific Clinics;
  • personnel bound by confidentiality;
  • individual accounts and access revocation;
  • console sessions that are opaque, revocable, and stored as a hash;
  • account authentication through an identity provider, with an optional second factor using an authenticator app that is not required for every account; no availability of passkeys is asserted;
  • secrets managed outside the repository.

2. Isolation and Authorization

  • a Tenant context that denies access by default during each request;
  • repositories and database controls scoped to the Tenant;
  • automated cross-Tenant access tests;
  • private objects and short-lived signed download links.

3. Encryption and Transmission

  • TLS on the public interfaces controlled by Woku;
  • encryption at rest managed by AWS, MongoDB Atlas, and the relevant providers, under each provider's configuration for the production environment;
  • field-level encryption of Patient References and care references with AES-256-GCM before they are stored;
  • Customer API keys stored as a hash;
  • session-authority cookie with the __Host- prefix, set Secure, HttpOnly, and SameSite=Strict; CSRF cookie deliberately readable by JavaScript, with no authority of its own, also Secure and SameSite=Strict.

4. Sensitive Values

  • costs, order values, and Patient References omitted server-side for Users without the corresponding permission;
  • Patient References and care references excluded from application logs, exports, the public API, and MCP access;
  • automated check of order justifications against common identifier patterns;
  • CSV exports that neutralize spreadsheet formulas;
  • no training of artificial intelligence models on Customer Data.

5. Availability and Abuse

  • limits on sign-in attempts by email address and network range;
  • limits on the rate of requests to the public API;
  • access that is denied by default when a validation or security control fails;
  • limits on the size of imported files.

6. Logging and Monitoring

  • Tenant-scoped audit records for the sensitive actions the system covers;
  • application logs with redaction of secrets, cookies, authorization headers, request bodies, costs, and Patient References.

Pattern-based checks reduce exposure but do not guarantee the detection of all personal data present in free text.

7. Incidents and Continuity

  • notification of incidents to the Customer in accordance with section 11;
  • storage with the durability and redundancy provided by the database and object storage providers;
  • incident response and recovery arrangements depend on the active production services; contact Woku for the applicable procedures, database backup schedule, and recovery coverage;

8. Deletion

  • automatic expiration of sessions, sign-in attempt records, Google sign-in continuations, and export records;
  • deletion of Customer Personal Data, or its anonymization when the Customer instructs it, in accordance with section 10.

Annex III: Authorized Subprocessors

Provider / entityService and purposePotential dataKnown relevant location
Amazon Web Services, Inc.Account email, private file and packaging-photo storage, compute, caching, logs, and secrets managementEmails, files, packaging photos, logs, identifiers, and communicationsUnited States (us-east-1)
MongoDB, Inc. (MongoDB Atlas)Operational databaseTenant data, operational records, encrypted references, and metadataLocation follows the production cluster configuration; details are available from our privacy contact
Cloudflare, Inc.DNS for muveya.com and, when enabled, edge network and securityIP, headers, host, and technical trafficGlobal network
OpenAIReading packaging photos to propose catalog fields for human reviewSubmitted photos, scanned barcode when present, interface language, and proposed fieldsInternational processing under standard API terms; no country-specific residency is promised

The providers listed above support the operating Service. OpenAI processes the packaging photos described in section 6 of the Privacy Policy under its standard API data controls; this does not imply zero retention, dedicated regional processing, or a separately negotiated agreement.

Stytch, Google for sign-in and Android scanner diagnostics, and the mailbox provider process data for which Woku acts as controller for authentication, technical operation, security, support, or the business relationship. This listing does not enable model tracing or operational messaging providers. Any new provider processing Customer Personal Data on the Customer's behalf must follow section 8.2.