This Hello Patient Data Processing Addendum (the “DPA”) is entered into between Patient Engagement Technologies Inc., a Delaware corporation, doing business as Hello Patient and Hello Fido (“Hello Patient”), with offices at 2025 Guadalupe St, Suite 260, Austin, TX 78705, and the customer identified in the Order Form (“Customer”). This DPA forms part of the Master Subscription Agreement or other written agreement between the parties for the provision of services (the “Agreement”), and is effective as of the effective date of the Agreement. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
1.1. “Account Data” has the meaning given in the Agreement or, if not defined in the Agreement, means Personal Data that relates to Hello Patient’s relationship with Customer, including the names and contact information of individuals authorized by Customer to access Customer’s account, support communications, and billing and administrative information relating to Customer. Account Data does not include Customer Data or Customer Personal Data submitted to or processed through the Services.
1.2. “Aggregated and De-identified Data” has the meaning given in the Agreement or, if not defined in the Agreement, means data derived from Customer Personal Data, Customer Data, or use of the Services that has been aggregated or de-identified such that it does not identify, and could not reasonably be used to identify, Customer or any natural person.
1.3. “Applicable Privacy Law” means any applicable law, regulation, or binding regulatory guidance governing the privacy, protection, or Processing of Personal Data, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA”), the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, the Swiss Federal Act on Data Protection (“Swiss FADP”), and any US state privacy law listed in Annex C (US State Privacy Law Addendum), each as amended, superseded, or replaced from time to time.
1.4. “Controller” means the entity that determines the purposes and means of Processing Personal Data, including any “business” as defined in the CCPA.
1.5. “Customer Personal Data” means the Personal Data within Customer Data (as defined in the Agreement) that Customer or its Users provide, transmit, or make available to Hello Patient in connection with Customer’s use of the Services, as further described in Annex A, Part 1 (Description of Processing Activities). Customer Personal Data does not include Usage Data, Account Data, or Aggregated and De-identified Data.
1.6. “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
1.7. “Outputs” has the meaning given in the Agreement or, if not defined in the Agreement, means the content and results generated or returned by the Services.
1.8. “Personal Data” means any information that identifies, relates to, describes, or could reasonably be used to identify a natural person, as defined under Applicable Privacy Law.
1.9. “Processing” (and “Process” and “Processes”) means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, combination, erasure, or destruction.
1.10. “Processor” means the entity that Processes Personal Data on behalf of the Controller, including any “service provider” or “contractor” as those terms are defined under the CCPA or other US state privacy laws.
1.11. “SCCs” means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914.
1.12. “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Hello Patient or its Sub-processors. Security Incident does not include unsuccessful attempts that do not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, or denial-of-service attacks.
1.13. “Sub-processor” means any third party engaged by Hello Patient to Process Customer Personal Data on Hello Patient’s behalf.
1.14. “Trust Center” means Hello Patient’s security and compliance portal or webpage identified in the applicable ordering document or on Hello Patient’s website.
1.15. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office (version B1.0, in force 21 March 2022), as updated.
1.16. “Usage Data” has the meaning given in the Agreement or, if not defined in the Agreement, means technical logs, events, and usage and performance information generated by or collected in connection with the Services, excluding the content of Customer Personal Data.
2.1. Processor Role and Instructions. With respect to Customer Personal Data, Customer is the Controller and Hello Patient is the Processor. Where Customer acts as a Processor on behalf of another Controller, Customer appoints Hello Patient as a Sub-processor, and Customer represents and warrants that its instructions to Hello Patient are authorized by the relevant Controller. In that case, references in this DPA to Customer’s instructions, obligations, or rights as Controller will be deemed to include Customer acting on behalf of the relevant Controller, as applicable. Hello Patient will Process Customer Personal Data only: (a) in accordance with Customer’s documented instructions as set forth in this DPA and the Agreement; (b) as necessary to provide, maintain, secure, and support the Services; (c) as required by Applicable Privacy Law (in which case Hello Patient will inform Customer of the requirement before Processing unless prohibited by law); and (d) as set forth in Annex A, Part 1. The Agreement, this DPA, the applicable Order Forms, and Customer’s documented configuration and use of the Services constitute Customer’s complete documented instructions as of the effective date of this DPA; any additional instructions require the parties’ written agreement. If Hello Patient reasonably believes that an instruction infringes Applicable Privacy Law or is technically infeasible or outside the scope of the Services, Hello Patient will promptly notify Customer and will not be required to follow it. Hello Patient’s restrictions on using Customer Personal Data to train, develop, or improve artificial intelligence or machine learning models are set forth in Section 10 (AI and Machine Learning Restrictions) of this DPA and the applicable model-training or data-use provisions of the Agreement.
2.2. Independent Controller Activities. Except as set forth below, with respect to Usage Data and Account Data, and any Aggregated and De-identified Data that constitutes Personal Data, Hello Patient is an independent Controller (and not a joint Controller with Customer). To the extent such data constitutes Personal Data, Hello Patient Processes it as an independent Controller solely for purposes related to managing its relationship with Customer (including account administration, billing, and communications, subject to applicable law and opt-out rights), operating, securing, supporting, and improving the Services, preventing fraud and abuse, and complying with law. Hello Patient will not Process such data for advertising, sale, sharing, model training, or unrelated product development except with Customer’s express written authorization. Aggregated and De-identified Data that no longer constitutes Personal Data is not subject to this DPA except as provided in Section 11 (Aggregated and De-identified Data). Hello Patient’s Processing as an independent Controller is governed by Hello Patient’s applicable privacy notices and Applicable Privacy Law and is not subject to the Processor obligations in Sections 3 through 9 of this DPA. To the extent Usage Data constitutes Customer Personal Data and is Processed solely to provide the Services on Customer’s behalf, Hello Patient Processes it as a Processor under this DPA. Subject to the restrictions expressly set forth in this DPA and Applicable Privacy Law, nothing in this DPA limits Hello Patient’s rights with respect to Aggregated and De-identified Data, Usage Data, or Account Data.
2.3. Inability to Comply. Hello Patient will notify Customer promptly if Hello Patient determines that it can no longer meet its obligations under Applicable Privacy Law with respect to Customer Personal Data. In that case, Customer may, as Customer’s sole contractual remedy for such prospective inability to continue the affected Processing, suspend the affected Processing or terminate the affected Order Form. Nothing in this Section limits any rights or remedies that cannot be limited under Applicable Privacy Law or the SCCs.
2.4. Customer Affiliates. Customer enters into this DPA for itself and, where required by Applicable Privacy Law, on behalf of its Affiliates that use the Services, thereby establishing a separate DPA between Hello Patient and each such Customer Affiliate. Customer remains responsible for coordinating all instructions and communications with Hello Patient under this DPA and for its Affiliates’ compliance, and any right or claim under this DPA on behalf of a Customer Affiliate must be exercised or brought by Customer and not by the Affiliate directly, except to the extent such a restriction is not permitted under Applicable Privacy Law or the SCCs.
2.5. Customer-Directed Services. The Services may permit Customer to configure the Services to transmit Customer Data, including Customer Personal Data, to a third-party product or service selected by Customer, including an AI or large language model provider accessed using Customer’s own account, API key, or other credentials (each, a “Customer-Directed Service”). Customer’s configuration of the Services to route Customer Personal Data to a Customer-Directed Service constitutes Customer’s documented instruction to transmit that data. A Customer-Directed Service is not a Sub-processor, and Sections 5 (Sub-processors) and 10 (AI and Machine Learning Restrictions) do not apply to its Processing of Customer Personal Data. As between the parties, Customer is solely responsible for its selection of, and terms with, each Customer-Directed Service; for the lawfulness of the disclosure, including any required legal basis, notices, consents, and transfer mechanisms; for evaluating the Customer-Directed Service’s security, retention, and data-use practices, including any use of data to train or improve models; and for ensuring that no Restricted Data is transmitted except as permitted under Customer’s agreement with that provider and Applicable Privacy Law. Hello Patient’s obligations under this DPA do not apply to Customer Personal Data once it has been delivered to a Customer-Directed Service, and Hello Patient is not responsible for the acts, omissions, or security of any Customer-Directed Service. Hello Patient will protect credentials Customer submits to configure a Customer-Directed Service as Customer’s Confidential Information and will use them solely to provide the Services as configured by Customer.
2.6. Deployment Model. The Services are provided as Hello Patient-hosted cloud services as specified in the applicable Order Form. The Processor obligations in Sections 3 through 9 apply to Customer Personal Data that Hello Patient Processes in providing the Services. Hello Patient Processes Account Data and Usage Data, including support and product usage data, as an independent Controller in accordance with Section 2.2 and Hello Patient’s privacy notices.
Hello Patient will ensure that persons authorized to Process Customer Personal Data are subject to binding confidentiality obligations or professional duties of confidentiality, and access to Customer Personal Data will be limited to Hello Patient personnel and Sub-processors who require access to perform the Services.
Hello Patient will implement and maintain technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or unauthorized disclosure, as further described in Annex A, Part 2 (Technical and Organizational Measures). Hello Patient may update such measures from time to time, provided that the updated measures do not materially reduce the overall level of security provided to Customer Personal Data. Hello Patient’s audit reports and certifications are available as set forth in Section 12 (Audit Rights). Where Hello Patient maintains a Trust Center, Hello Patient’s then-current security controls are described there.
Customer authorizes Hello Patient to engage Sub-processors to Process Customer Personal Data in accordance with this Section 5. Hello Patient will maintain a current list of Sub-processors at the Trust Center (currently available at https://www.hellopatient.com/subprocessors) or as otherwise identified by Hello Patient, and Customer may subscribe to notifications of changes on Hello Patient’s website or as otherwise directed by Hello Patient. Hello Patient will provide Customer with at least thirty (30) days’ advance notice of any material addition, replacement, or removal of a Sub-processor that will Process Customer Personal Data, except where a shorter notice period is reasonably necessary for urgent security or legal reasons. Hello Patient will impose on Sub-processors the same data protection obligations required under Applicable Privacy Law and obligations no less protective than Hello Patient’s obligations under this DPA with respect to Customer Personal Data, in each case to the extent applicable to the services provided by the Sub-processor. Hello Patient remains liable for its compliance with this DPA, including for the acts and omissions of Sub-processors that breach this DPA in connection with their Processing of Customer Personal Data. If Customer objects to a new or replacement Sub-processor on reasonable data protection grounds, Customer must notify Hello Patient in writing within fifteen (15) days of the applicable notice. The parties will cooperate in good faith to resolve the objection. If the parties cannot resolve the objection within a reasonable time, Customer may, as Customer’s sole contractual remedy for such objection, terminate the affected Order Form upon written notice and pay Hello Patient all amounts due and owing under the Agreement as of the date of such termination. Nothing in this Section limits any rights or remedies that cannot be limited under Applicable Privacy Law or the SCCs.
Taking into account the nature of the Processing and the information available to Hello Patient, Hello Patient will provide Customer with reasonable assistance to fulfill Customer’s obligation to respond to Data Subject rights requests under Applicable Privacy Law. Hello Patient will promptly notify Customer if Hello Patient receives a Data Subject request and will not respond on Customer’s behalf without Customer’s prior written authorization, except as required by Applicable Privacy Law. To the extent assistance under this Section 6 requires work beyond the Services, Customer will compensate Hello Patient at Hello Patient’s then-current professional services rates. Hello Patient’s obligations under this Section are limited to information reasonably available to Hello Patient and do not require Hello Patient to disclose confidential information of other customers, compromise the security of Hello Patient systems, or take actions not required by Applicable Privacy Law.
To the extent required by Applicable Privacy Law and upon Customer’s reasonable written request, Hello Patient will provide reasonable cooperation and assistance with the conduct of data protection impact assessments and any required prior consultations with supervisory authorities, in each case solely to the extent relating to Hello Patient’s Processing of Customer Personal Data. Customer is responsible for conducting the assessment and reaching any legal determinations required under Applicable Privacy Law. The cost and limitation provisions in Section 6 (Data Subject Rights) apply equally to assistance under this Section 7.
Hello Patient will notify Customer in writing without undue delay, and in any event within seventy-two (72) hours, after Hello Patient becomes aware of a Security Incident. Hello Patient may provide initial notice based on information then available and supplement it as additional information is confirmed. To the extent then known, the notification will include a description of the Security Incident, the likely consequences, and the measures taken or proposed to address it. Hello Patient will cooperate with Customer and take reasonable steps within Hello Patient’s control to investigate, mitigate, and remediate the Security Incident. As between the parties, Customer is solely responsible for fulfilling any third-party notification obligations relating to a Security Incident, except to the extent Applicable Privacy Law requires Hello Patient to provide such notices. Hello Patient’s notification of, or response to, a Security Incident does not constitute an acknowledgment of any fault or liability.
Upon termination or expiration of the Agreement, or upon Customer’s earlier written request to the extent Customer Personal Data is no longer required for the Services and deletion or return is technically feasible, Hello Patient will, at Customer’s election, return Customer Personal Data to Customer in an industry-standard, machine-readable format or securely delete it. In either case, Hello Patient will use commercially reasonable efforts to complete the action within thirty (30) days. Upon Customer’s written request, Hello Patient will provide a written certification confirming such return or deletion. Notwithstanding the foregoing, Hello Patient may retain Customer Personal Data (a) in routine system backups until they are overwritten or expire in the ordinary course of Hello Patient’s backup cycle; (b) to comply with a legal hold or any order or request from a court, regulator, or other governmental authority; and (c) to the extent and for the period required by Applicable Privacy Law. Customer Personal Data so retained remains subject to this DPA. Customer acknowledges that fulfilling a return or deletion request before the end of the Term may limit or prevent Hello Patient’s ability to continue providing the affected Services.
Hello Patient will not use Customer Personal Data, or any data derived from Customer Personal Data, to train, fine-tune, develop, or improve any artificial intelligence or machine learning model (including any such model operated by a Sub-processor or third-party provider engaged by Hello Patient), except with Customer’s express written authorization. With respect to AI/ML Sub-processors, Hello Patient will contractually require each such Sub-processor not to use Customer Personal Data to train, fine-tune, develop, or improve its models except as expressly authorized under the Agreement and, where the Sub-processor offers configurable training or retention settings, Hello Patient will use commercially reasonable efforts to configure those settings consistently with this restriction. Hello Patient will also require that each such Sub-processor: (i) Processes Customer Personal Data only as necessary to provide inference or other Services to Hello Patient; (ii) does not retain Customer Personal Data except as necessary to provide, secure, debug, or comply with legal obligations for the applicable service; and (iii) does not permit human review of Customer Personal Data except for abuse, security, support, or legal-compliance purposes and only under confidentiality obligations. Hello Patient’s use of Outputs for model training or improvement is subject to the Agreement. Nothing in this Section 10 restricts Hello Patient’s Processing of Customer Personal Data as otherwise authorized under this DPA or the Agreement, or as necessary to provide, maintain, secure, or support the Services.
Customer authorizes Hello Patient to aggregate and de-identify Customer Personal Data. To the extent any resulting data no longer constitutes Personal Data under Applicable Privacy Law, such data will be considered outside the scope of this DPA. With respect to any such data that constitutes Aggregated and De-identified Data: (a) Hello Patient will implement and maintain reasonable technical and organizational measures designed to ensure that the data cannot reasonably be associated with, or used to re-identify, any Data Subject; (b) Hello Patient will not attempt to re-identify the data except to test the effectiveness of its de-identification processes; (c) Hello Patient will Process the data solely in aggregated or de-identified form (as applicable); and (d) Hello Patient will contractually require any recipients of Aggregated and De-identified Data to maintain the data in aggregated or de-identified form and not to attempt re-identification, in each case to the extent required by Applicable Privacy Law. Hello Patient applies de-identification and aggregation measures intended to align with the standards for deidentified information and aggregate consumer information under California Civil Code Section 1798.140 and comparable de-identification, aggregation, or anonymization requirements under Applicable Privacy Law. Subject to the foregoing, Hello Patient may use Aggregated and De-identified Data for the purposes permitted under the Agreement or, where the Agreement does not address such use, to operate, secure, analyze, improve, benchmark, and develop the Services.
Hello Patient’s most recent independent security audit report or assessment (such as a SOC 2 Type II audit report or ISO 27001 certification), together with Hello Patient’s security documentation at the Trust Center, serves as the primary means of demonstrating compliance with this DPA. Hello Patient will, upon reasonable request, make its then-current SOC 2 Type II audit report (or an equivalent report or certification, such as ISO 27001) available to Customer, subject to reasonable confidentiality obligations. If additional information is reasonably required, Hello Patient will respond to reasonable written security questionnaires no more than once in any twelve (12) month period. If compliance still cannot reasonably be demonstrated, Customer may, no more than once annually and upon at least sixty (60) days’ prior notice, engage an independent third-party auditor subject to confidentiality obligations to conduct an audit at Customer’s expense during normal business hours and in a manner that minimizes disruption to Hello Patient. Hello Patient may reasonably object to any auditor that is a competitor, lacks independence, or is otherwise unsuitable. No audit or inspection will provide Customer or its auditor with access to other customers’ data, Hello Patient’s source code, information that would compromise the security of Hello Patient’s systems or other customers, or facilities where access would pose a security risk, and Hello Patient may require Customer and its auditor to agree to reasonable confidentiality protections in connection with any audit or inspection.
To the extent legally permitted and reasonably practicable, Hello Patient will use commercially reasonable efforts to notify Customer of any legally binding governmental request for Customer Personal Data prior to disclosure. Hello Patient may challenge or seek to narrow any request that Hello Patient reasonably believes is overbroad, unlawful, or otherwise inappropriate and will disclose only the Customer Personal Data required by law.
To the extent Hello Patient Processes or transfers Customer Personal Data to a jurisdiction for which Applicable Privacy Law requires a lawful transfer mechanism, Hello Patient will comply using a recognized mechanism, including the SCCs, the UK Addendum, the Swiss modifications to the SCCs, or any other lawful transfer mechanism recognized under Applicable Privacy Law. The terms set forth in Annex B (International Data Transfer Addendum) are incorporated by reference into this DPA and apply to the extent Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that the applicable supervisory authority has not recognized as providing an adequate level of protection.
15.1. Restricted Data. Customer represents and warrants that Customer will not submit, and will not permit any User to submit, the following categories of data to the Services without the parties’ express prior written agreement (including an executed business associate agreement, which constitutes such agreement with respect to Protected Health Information) (collectively, “Restricted Data”): (a) social security numbers or other government-issued identification numbers; (b) protected health information subject to HIPAA, or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis; (c) health insurance information; (d) biometric or genetic information; (e) passwords or credentials for third-party online accounts (other than credentials created for and used solely to access the Services or submitted to configure a Customer-Directed Service); (f) credentials for any financial accounts; (g) tax return data; (h) payment card information subject to PCI DSS; (i) Personal Data of children under sixteen (16) years of age; (j) precise geolocation data; or (k) any other information that falls within any special categories of Personal Data as defined under Applicable Privacy Law. Health-related Personal Data and Personal Data of minors, in each case submitted by or for Customer in connection with the Services (including Personal Data of patients and prospective patients and pet owners’ pet health information), are not Restricted Data and are subject to Customer’s consent and lawful-basis warranties in the Agreement and this DPA; all other categories listed above, including precise geolocation data, remain Restricted Data unless the parties expressly agree otherwise in writing. Restricted Data also includes API keys, private keys, access tokens, passwords, secrets, and production credentials, in each case unless the parties specifically agree otherwise in writing, and in each case excluding credentials Customer submits to configure the Services to connect to a Customer-Directed Service (as defined in Section 2.5). If Customer Personal Data submitted to the Services incidentally contains Restricted Data, Customer remains solely responsible for ensuring such submission complies with Applicable Privacy Law, and Hello Patient’s obligations under this DPA apply to such data as Customer Personal Data.
15.2. Lawful Basis, Security, and Assessment. Customer represents and warrants that: (a) Customer has established and will maintain a valid legal basis under Applicable Privacy Law (including, where applicable, Articles 6, 9, and 10 of the EU GDPR or the equivalent provisions of the UK GDPR) for Hello Patient’s Processing of Customer Personal Data as contemplated by the Agreement and this DPA; and (b) Customer has provided all required notices and obtained all required consents (including, where applicable, under Articles 12 through 14 of the EU GDPR or the equivalent provisions of the UK GDPR). Customer is solely responsible for making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of Customer Personal Data, for securing the account credentials, systems, and devices Customer uses to access the Services, and for backing up Customer Personal Data as applicable. Customer acknowledges that it has had the opportunity to evaluate the Services, the technical and organizational measures described in Annex A, Part 2, and Hello Patient’s commitments under this DPA in determining whether the Services are appropriate for Customer’s intended use.
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, which are incorporated herein by reference. Those limitations and exclusions apply to any costs of responding to or remediating a Security Incident for which Hello Patient is responsible. Nothing in this Section 16 limits the rights of Data Subjects or supervisory authorities under Applicable Privacy Law, or limits either party’s liability to such persons or authorities (or to Data Subjects under the third-party beneficiary provisions of the SCCs) to the extent such liability cannot be limited by contract under Applicable Privacy Law.
This DPA is effective as of the effective date of the Agreement and will remain in force for the duration of the Agreement and for as long as Hello Patient Processes Customer Personal Data. Upon termination or expiration of the Agreement, this DPA will continue in effect until all Customer Personal Data has been returned or deleted in accordance with Section 9 (Data Return; Deletion). Any provision that, by its nature, is intended to survive will survive termination or expiration of this DPA and the Agreement.
This DPA supplements the Agreement; in any conflict between the Agreement and this DPA with respect to the Processing of Customer Personal Data, this DPA controls, unless amended by Special Terms that expressly reference the provision amended, except that any business associate agreement between the parties controls with respect to Protected Health Information and compliance with HIPAA, and in all other respects the Agreement governs. This DPA, together with the Agreement, the Annexes hereto, and any applicable Order Forms, constitutes the entire agreement between the parties with respect to the Processing of Customer Personal Data. Except as expressly set forth in this DPA, this DPA may be amended or modified only by a written instrument signed by authorized representatives of both parties. Hello Patient may, however, modify this DPA (including replacing the SCCs, UK Addendum, or Swiss modifications to the SCCs with any successor or replacement transfer mechanism) on written notice to Customer solely to the extent necessary to maintain compliance with Applicable Privacy Law, so long as any such modification does not materially reduce the protections afforded to Customer Personal Data or materially increase Customer’s obligations under this DPA. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable and the remaining provisions will remain in full force and effect. This DPA will be governed by, and the parties submit to, the governing law and jurisdiction specified in the Agreement. Notices under this DPA will be given in accordance with the notice provisions of the Agreement; Security Incident notices may also be sent by email to Customer’s designated notice or security contact.
Hello Patient will ensure that persons authorized to Process Customer Personal Data are subject to binding confidentiality obligations or professional duties of confidentiality, and access to Customer Personal Data will be limited to Hello Patient personnel and Sub-processors who require access to perform the Services.
Hello Patient will implement and maintain technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or unauthorized disclosure, as further described in Annex A, Part 2 (Technical and Organizational Measures). Hello Patient may update such measures from time to time, provided that the updated measures do not materially reduce the overall level of security provided to Customer Personal Data. Hello Patient’s audit reports and certifications are available as set forth in Section 12 (Audit Rights). Where Hello Patient maintains a Trust Center, Hello Patient’s then-current security controls are described there.
A.1 Parties. Data Exporter: Customer, acting as Controller or Processor, as applicable. Data Importer: Hello Patient, acting as Processor or Sub-processor, as applicable. The parties’ details are as set forth in the Agreement or applicable Order Form.
A.2 Data Subjects and Personal Data. Customer Personal Data may relate to (a) Customer’s employees and contractors (Users) who access or use the Services; (b) individuals whose Personal Data Customer or its Users submit to the Services; and (c) any other individuals identified in the applicable Order Form, and may include professional and organizational data (job title, employer, business contact information), content data submitted by Customer or its Users in connection with the Services, and any other categories specified in the applicable Order Form. For clarity, Account Data and Usage Data, including, where applicable, User names, email addresses, employee identifiers, authentication identifiers and account-access metadata (excluding passwords, access tokens, private keys, and other authentication secrets), log records, session data, feature usage statistics, device identifiers, and IP addresses generated by use of the Services, are Processed by Hello Patient as an independent Controller in accordance with Section 2.2 (Independent Controller Activities) of this DPA, except to the extent Section 2.2 provides that Hello Patient Processes such data as a Processor. The categories of Data Subjects and Customer Personal Data Processed for the human health and veterinary offerings are further described in the following table:
Human health offerings (Hello Patient brand)
Data Subjects: Customer’s staff, administrators, and authorized users; marketing and outreach contacts; and patients and prospective patients, solely to the extent their contact and scheduling information does not constitute PHI governed by the BAA.
Personal Data: contact information (name, phone number, email address); appointment and scheduling data (visit dates, appointment types, provider or clinic); call and message content that does not constitute PHI; and user account credentials and access logs.
Veterinary offerings (Hello Fido brand)
Data Subjects: pet owners and prospective clients of Customer; and Customer’s clinic staff, administrators, and authorized users.
Personal Data: contact information (name, phone number, email address); appointment and scheduling data (visit dates, appointment types, provider or clinic, and pet name and species); call and message content, including audio recordings and transcripts generated as a core part of the services’ work product, which may contain incidental references to pet health information; and user account credentials and access logs.
A.3 Special Categories of Personal Data. Hello Patient does not intentionally collect or Process special categories of Personal Data or other Restricted Data, and Customer must not submit them to the Services unless the parties have specifically agreed in writing in the applicable Order Form or other written agreement (including, with respect to Protected Health Information, an executed business associate agreement). Health-related Personal Data and Personal Data of minors that are not Restricted Data under Section 15.1 (Restricted Data) may be submitted to the Services as contemplated by the Agreement.
A.4 Nature, Purpose, Frequency, and Duration of Processing. Hello Patient will Process Customer Personal Data as necessary to provide, maintain, secure, and support the Services, to fulfill its obligations under this DPA, and to comply with Applicable Privacy Law. Processing is continuous for the duration of the Agreement (as initiated by Customer through its use of the Services) and for such additional period as is necessary to return or delete Customer Personal Data in accordance with Section 9 (Data Return; Deletion).
Hello Patient implements and maintains an industry-standard information security program designed to protect the confidentiality, integrity, and availability of Customer Personal Data, evidenced by Hello Patient’s then-current independent audit report or assessment (such as a SOC 2 Type II audit report or ISO 27001 certification), available to Customer in accordance with Section 12 (Audit Rights). Hello Patient’s measures include, as applicable to the Services and the nature of the Processing, role-based access controls and least-privilege principles, multi-factor authentication for privileged access, periodic access reviews, industry-standard encryption in transit and at rest, a security incident response plan, logging and monitoring to detect and alert on anomalous activity, physical and environmental security for facilities used to host Customer Personal Data, including those of Hello Patient’s cloud infrastructure providers (badge access, surveillance, fire suppression, power redundancy, climate control), backup and business continuity / disaster recovery procedures with periodic recoverability testing, vulnerability scanning, periodic penetration testing or equivalent technical security assessments, risk-based patch management, appropriate due diligence of Sub-processors consistent with applicable law and contractual security obligations, security awareness training for personnel who Process Customer Personal Data, and appropriate background screening to the extent permitted by applicable law. Hello Patient also maintains logical access controls that associate Customer Personal Data with unique customer identifiers and keys and are designed to limit access to Customer Personal Data to authorized users and systems. Hello Patient also maintains written information security policies and procedures governing access control, change management, vulnerability management, secure development practices, and incident response.
Customer authorizes Hello Patient to engage the Sub-processors identified at Hello Patient’s Trust Center or otherwise on Hello Patient’s website, in accordance with Section 5 (Sub-processors). The current Sub-processor list at the Trust Center constitutes the then-current list of authorized Sub-processors. Hello Patient’s Sub-processors may include providers of cloud infrastructure and hosting, artificial intelligence and machine learning model inference and API services, security, monitoring, and logging services, customer relationship management and support tooling, analytics and performance monitoring services, and authentication and identity management. Hello Patient will notify Customer of changes to the Sub-processor list in accordance with Section 5 (Sub-processors).