SOSCHAIN Professional Terms of Service
Version: 1.1.0 Effective date: 26 August 2026
1. Parties and scope
SOSCHAIN Professional is provided by Fundación UNID, tax ID G02793479, registered in the Castilla y León Register of Foundations by resolution dated 23 February 2021 and published on 4 March 2021 (the “Provider”), with published statutory address at Calle Condes de Gómara 6, 5C, Apartado 80, Soria, Spain. The general privacy and rights channel is contact@unid.es; it is not represented as a data-protection-officer contact unless a DPO is formally appointed.
These terms bind the member organisation and each authorised professional user. A person accepting for an organisation represents that they can bind it; other users accept individual security, confidentiality and permitted-use duties. Acceptance does not itself prove profession, office, membership, licence, representation, sector or access to a subject.
2. Service and responsibilities
SOSCHAIN supports capability identification, authorised-card selection, minimum emergency data, location and auditable communications. It does not replace 112, official care systems, a health record, professional decisions or internal protocols. The organisation remains responsible for its acts, personnel, devices, legal bases, data-subject information and sector compliance.
Fundación UNID is controller for processing purposes it determines. The organisation is an independent controller for its access and acts unless a written agreement defines a specific processor or joint-controller arrangement. Required processing, security, support, retention, incident and exit agreements must be signed before production.
3. Users, authority and least privilege
The organisation grants named access only while identity, profession, role, membership and need remain current. It must immediately revoke leavers and role changes, review permissions, protect devices and cooperate in audits and incidents. Shared accounts, impersonation, curiosity, indiscriminate search, unauthorised export and purpose substitution are forbidden.
Every access requires a backend-issued or verified capability for the exact subject, sector, purpose and operation. Caregiver is a function in relation to the subject, not a family relationship or employment category. A caregiver may be on this organisation's payroll, paid by the individual, family or a third party, or unpaid; the payment source remains separate and never grants access. A browser role, invitation, municipal membership or known identifier likewise grants no authority.
4. Consent and individual rights
This organisational contract does not replace a person’s consent, informed care consent, representation or a public-law basis. EHDS-governed secondary use relies on a permit and opt-out right, not contract acceptance; where another rule or project requires research consent, it must be obtained separately. The organisation must honour portal opt-outs and withdrawals.
Organisations as legal persons do not exercise a data subject’s GDPR withdrawal right. They may terminate the contract, remove users or capabilities and change organisational choices under the agreement. Natural-person users and data subjects retain their rights. Termination does not erase audit evidence, duties or lawful past access.
5. Break-glass
Break-glass is a last-resort exception, not general authority or a feature obtained by contracting SOSCHAIN. Only a separate technical policy may enable it for an immediate serious risk to life or integrity, inability to obtain timely authorisation and legal and professional qualification for the intervention.
It requires strong identity; verified profession and membership; strict subject, sector and purpose match; justification; minimum data; short duration and one incident; tamper-evident audit; post-event review; and notice to the person or representative when safe and lawful. Bulk use, export, research, analytics, training, marketing, surveillance and convenience access are forbidden.
6. Mandatory sector separation
health-care: healthcare professionals, people and human care; the only domain potentially eligible for human break-glass.animal-care: veterinary professionals, animals and animal care; the only domain potentially eligible for animal break-glass.- every
animal-*: absolute technical bar on break-glass over people. health-research: secondary use and research; no break-glass or direct operational access to people.onehealth-research: joint human-animal research/analysis using minimisation, pseudonymisation or anonymisation; no break-glass or direct operational access to people or animals.
A multi-service organisation must keep capabilities, memberships, policies and audit separate. A municipality may operate animal-care for its veterinarian and health-care for a municipal emergency physician; those care functions need not be classified as onehealth-research. Municipal police may use current consent or a specific statutory-authority ordinary flow, but never gain break-glass through office or municipal membership. An invited veterinarian can operate only on animals and a physician only on people.
7. Secondary use and research
Contract acceptance requires the organisation to apply the relevant secondary-use profile but is not itself a project permit. In the EU, covered data are included by default once EHDS applies and a permitted purpose, legal basis, health-data access permit, governance, minimisation and secure environment exist. Individuals can opt out simply, reversibly and without a reason through the personal portal. Where another rule requires consent, consent remains separate and withdrawable.
The opt-out prevents new identifiable inclusion under later permits, without retroactive effect on lawful prior use, anonymised results or statutory exceptions with safeguards. Pseudonymisation is not anonymisation. EHDS secondary-use rules apply mainly from March 2029 and to remaining categories from March 2031; they do not currently authorise automatic reuse or police access. Animal data are included by default under policy and authority over the animal while linked personal data remain protected. The United States and Canada use separate profiles and do not automatically inherit the European model.
8. Security, incidents and retention
The organisation applies least privilege, strong authentication, device inventory and protection, training, confidentiality, log review and incident response. Suspected incidents must be reported to the Provider without delay and the parties cooperate on statutory deadlines. Data and audit are retained according to category, duty and agreement, then returned, erased or anonymised where applicable.
9. Availability, suspension and liability
The Provider may suspend unsafe, unauthorised or cross-sector access. It does not guarantee uninterrupted availability or accept responsibility for professional decisions, inaccurate third-party data, external systems or force majeure, without excluding non-waivable liability. Service levels, support, price and financial liability belong in the order or specific contract.
10. Versions, evidence and termination
Material changes create a new version and require renewed acceptance. The document, digest, language, date, account, organisation and declared authority are archived and a reproducible confirmation is provided. The organisation may terminate under its specific contract; the Provider may terminate for material breach while confidentiality, audit, retention and cooperation duties survive.
11. Law and jurisdiction
Spanish and European Union law applies. The organisational contract validly defines venue or dispute resolution without affecting regulatory powers or mandatory individual rights.