qEEG Annex & Data Processing Agreement
Version 1.0 · Last updated 17 August 2026 · Annex to the Terms
This Annex applies to use of the qEEG Platform (qeeg.neurologic.fr / qeeg.neurologic.academy). It governs the processing, by NeuroLogic on the professional’s behalf, of data relating to Patients. By creating a qEEG account, the professional User accepts this Annex. It forms an integral part of the Terms.
Part A — Data Processing Agreement (art. 28 GDPR)
A.1 Roles of the parties
- Controller: the professional User (the “Controller”).
- Processor: SARL NeuroLogic.
The Controller determines the purposes and means of processing Patient data. NeuroLogic processes it only on the Controller’s documented instructions, as evidenced by use of the Platform and by this Annex.
A.2 Subject-matter, nature and purpose
Processing of personal data, including health data (art. 9 GDPR), for the purposes of: upload and storage of qEEG recordings; administration of psychometric questionnaires (NeuroMETRIC); production, storage and delivery of interpretive reports; associated features (longitudinal follow-up, comparisons, notifications).
A.3 Duration
Processing continues for as long as the Controller’s account is active, unless the Controller instructs otherwise.
A.4 Categories of persons and data
- Data subjects: the Controller’s Patients / End clients; where applicable, questionnaire respondents (parent, relative).
- Categories of data: identity and contact details, date of birth, language, reason for consultation, history and anamnesis, symptoms and diagnoses recorded, qEEG recordings and images, psychometric questionnaire responses, generated reports.
A.5 NeuroLogic’s obligations (processor)
NeuroLogic undertakes to:
- process Patient data only on the Controller’s documented instructions, including as regards transfers outside the EU;
- ensure confidentiality (authorised staff bound by confidentiality);
- implement appropriate security measures (art. 32 GDPR) — see Part B;
- comply with the conditions for engaging sub-processors (A.6);
- assist the Controller in: responding to data-subject rights requests; ensuring security, breach notifications, data protection impact assessments (DPIAs) and prior consultation of the CNIL;
- notify the Controller of any breach concerning Patient data without undue delay after becoming aware of it;
- at the Controller’s choice, delete or return Patient data at the end of the service, and destroy existing copies unless legally required to retain them;
- make available the information needed to demonstrate compliance with art. 28 and allow audits under reasonable conditions.
A.6 Sub-processors
The Controller authorises NeuroLogic to engage the sub-processors listed in the Privacy Policy (notably Supabase, Google/Firebase, AWS, Resend, Stripe, Pennylane, TidyCal). NeuroLogic imposes equivalent data-protection obligations on them. NeuroLogic informs the Controller of any addition or replacement of a sub-processor, and the Controller may object on legitimate grounds.
A.7 International transfers
See Privacy Policy, § International transfers. Any transfers are governed by appropriate safeguards (standard contractual clauses, Data Privacy Framework).
A.8 Health-data hosting
This Annex does not claim certified health-data hosting (HDS, art. L1111-8 of the French Public Health Code). The qEEG database, authentication and file storage are hosted in Frankfurt, Germany (EU).
A.9 Security and incidents
NeuroLogic implements the measures in Part B. In the event of a breach, NeuroLogic assists the Controller with its notification obligations to the CNIL (72 h) and, where applicable, to data subjects.
A.10 Production of anonymised statistics
The Controller authorises NeuroLogic to produce, from the processed data, aggregated and anonymised statistics (a “cohort” dashboard), with no additional collection, under the conditions described in the Privacy Policy (§7). These statistics are designed to allow no re-identification (percentages, a minimum cohort threshold of ten individuals for practitioner-facing views, no cross-tabulation of dimensions, age in brackets, free-text excluded). Once anonymised, they contain no identifying data and may be retained and used by NeuroLogic for analysis and improvement of the service and the network, including after the end of the service.
Part B — Technical and organisational measures
- Encryption of data in transit (TLS).
- Access control: authentication, role management (User / Admin), manual approval of new accounts.
- Database-level data isolation (row-level security) and least-privilege principle.
- Anonymous mode masking Patient names on screen during sessions.
- Logging of access and sensitive operations.
Part C — Retention and erasure of Patient data
Patient data is retained for the account’s period of use and per the Controller’s instructions. The Controller may at any time export, rectify, or delete a Patient’s data. On account closure, Patient data is deleted or returned at the Controller’s choice, unless otherwise legally required.
Part D — Information notice for Patients
The notice below is displayed, in short and readable form, on the questionnaire screens accessible to Patients via a secure link, and may be provided by the professional to their Patient. The professional remains responsible for informing their Patient beforehand and for establishing the lawful basis (including consent where required).
Your data and the NeuroLogic questionnaire
Your practitioner uses the NeuroLogic platform to prepare and follow up your assessment. The answers you enter here, and where applicable your brain-activity recording (qEEG), are used solely to produce the report for your practitioner.
- Who is responsible? Your practitioner decides how your data is used; NeuroLogic acts as a technical provider on their behalf.
- Who has access? Your practitioner and the authorised NeuroLogic team who prepares the report. Your data is neither sold nor used for advertising.
- For how long? As long as needed for your follow-up, per your practitioner’s rules.
- Your rights: access, rectification, erasure, objection. Contact your practitioner first. You may also contact NeuroLogic (brendan@neurologic.academy) or the CNIL (cnil.fr).
Questions about these documents or about data protection: brendan@neurologic.academy.