Legal

Data Processing Addendum

The processor terms that attach to the Terms of Service whenever Healthplex processes personal data on a customer's behalf — covering GDPR Article 28, HIPAA Business Associate obligations, and India's DPDP Act.

Read Section 2 first. In a self-hosted deployment Healthplex does not process your patient data at all, and most of this document is dormant by design. It becomes operative only where processing genuinely occurs — a Healthplex-operated deployment, a support session you initiate, or a cloud AI provider you have explicitly enabled.

This addendum forms part of the Terms of Service. If you need a countersigned copy, or your regulator requires a specific form, email legal@healthplex.app.

1. Definitions

Data protection terms carry their statutory meanings; everything else is defined in the Terms.

Capitalised terms not defined here have the meaning given in the Terms of Service. "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Supervisory Authority" have the meanings given in the GDPR. "Business Associate", "Covered Entity", "PHI" and "Required by Law" have the meanings given in HIPAA and its implementing regulations. "Data Fiduciary", "Data Processor" and "Data Principal" have the meanings given in India's Digital Personal Data Protection Act, 2023 ("DPDP").

"Applicable Data Protection Law" means all privacy and data protection law applicable to a party's processing under this addendum, including the GDPR, the UK GDPR and Data Protection Act 2018, HIPAA/HITECH, DPDP, the CCPA/CPRA, and Australia's Privacy Act 1988.

2. When this addendum applies

Only when Healthplex actually processes personal data on your behalf. In the default self-hosted model, it does not.

2.1 Self-hosted deployments — no processing by Healthplex. Where Customer operates the Software on infrastructure it owns or controls, Customer is the sole Controller and sole custodian of the Personal Data within it. Healthplex neither stores, accesses nor otherwise processes that Personal Data, and is therefore not a Processor or Business Associate in respect of it. Sections 4 to 12 do not engage.

2.2 Where this addendum does engage. The obligations below apply to each of the following, and only to the Personal Data actually involved:

  • (a) Healthplex-operated deployments — where an Order places hosting or managed operation with Healthplex.
  • (b) Support and diagnostic access — where Customer requests assistance that requires Healthplex personnel to view a Customer environment (Terms, Section 3.3).
  • (c) Customer-enabled cloud AI — where Customer configures the BYOK gateway to route prompts to a third-party model provider instead of the default on-premises model.
  • (d) Implementation and migration services — where Customer supplies data extracts to Healthplex for loading or conversion.

2.3 Roles. In each engaging scenario Customer is the Controller / Covered Entity / Data Fiduciary and Healthplex is the Processor / Business Associate / Data Processor. Healthplex does not sell Personal Data and does not process it for its own purposes.

3. Subject matter, duration, nature and purpose

The Article 28(3) particulars — what is processed, why, for how long, and about whom.

The particulars required by GDPR Article 28(3) are set out in Annex A. Processing continues for the duration of the Term and for the limited post-termination period described in Section 10.

4. Healthplex's obligations as processor

We process only on your documented instructions, keep it confidential, secure it, and tell you if we think an instruction is unlawful.

4.1 Documented instructions. Healthplex processes Personal Data only on Customer's documented instructions, which comprise the Terms, this addendum, the applicable Order, and Customer's configuration of the platform. Healthplex will not process Personal Data for any other purpose, and will not sell, share for cross-context behavioural advertising, or retain it outside the scope of the direct business relationship.

4.2 Unlawful instruction. If Healthplex forms the view that an instruction infringes Applicable Data Protection Law, it will inform Customer without undue delay and may suspend the affected processing until the instruction is confirmed, amended or withdrawn.

4.3 Confidentiality. Healthplex ensures that every person authorised to process Personal Data is bound by a written confidentiality obligation surviving termination of their engagement, and receives role-appropriate privacy and security training.

4.4 Least privilege. Access to Personal Data is restricted to personnel with a demonstrable need, granted for the shortest practicable duration, individually attributable, and logged.

4.5 Security. Healthplex implements and maintains the technical and organisational measures set out in Annex B, appropriate to the risk under GDPR Article 32 and the HIPAA Security Rule.

4.6 No independent PHI use. Healthplex will not use or disclose PHI other than as permitted by this addendum or Required by Law, and will not use PHI to train, fine-tune or evaluate any machine-learning model except where Customer has given specific, separate written instruction to do so.

5. Subprocessors

General authorisation with 30 days' notice and a right to object. The current list is public.

5.1 Authorisation. Customer grants general written authorisation for Healthplex to engage subprocessors, subject to this Section. The current list is published in the Trust Center.

5.2 Flow-down. Healthplex imposes on each subprocessor, by written contract, data protection obligations no less protective than those in this addendum, and remains fully liable to Customer for the subprocessor's performance.

5.3 Notice and objection. Healthplex gives at least 30 days' notice before engaging a new subprocessor that will process Customer's Personal Data. Customer may object in writing within 15 days on reasonable data protection grounds. If the parties cannot resolve the objection within a further 15 days, Customer may terminate the affected Services for cause without penalty and with a pro-rata refund of prepaid fees.

5.4 Cloud AI providers. A third-party model provider becomes a subprocessor only if Customer enables it. The platform default is an on-premises model, and PHI is redacted from outbound prompts unless Customer has explicitly instructed otherwise in writing.

6. Assistance with data subject rights

The platform gives you the tools to answer requests yourself; where it can't, we help.

6.1 The platform provides Customer with functionality to access, correct, export and erase records, enabling Customer to respond to Data Subject requests directly.

6.2 Where a request cannot be satisfied through that functionality, Healthplex will provide reasonable assistance, taking into account the nature of the processing, at no additional charge for requests proportionate in volume to Customer's deployment.

6.3 If a Data Subject contacts Healthplex directly regarding data Healthplex processes on Customer's behalf, Healthplex will not respond substantively but will redirect the Data Subject to Customer and notify Customer without undue delay, unless Required by Law to act otherwise.

7. Personal data breach

We notify you without undue delay and in any case within 48 hours of confirming a breach affecting your data.

7.1 Notification. Healthplex notifies Customer without undue delay, and in any event within 48 hours of confirming a Personal Data Breach affecting Personal Data it processes for Customer. Notification is not an admission of fault or liability.

7.2 Content. The notification will describe, to the extent known: the nature of the breach and categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the full picture is not available at once, information is provided in phases without undue further delay.

7.3 Cooperation. Healthplex will reasonably assist Customer with its own notification obligations to Supervisory Authorities, the HHS Office for Civil Rights, the Data Protection Board of India, and affected individuals — including HIPAA breach notification under 45 C.F.R. §§164.400–414 where applicable.

7.4 Self-hosted deployments. Healthplex has no visibility into a Customer-operated environment and cannot detect or notify breaches occurring within it. Detection, assessment and notification for such environments rest with Customer. Healthplex will support Customer's investigation on request.

8. International transfers

Where data crosses a border, the EU Standard Contractual Clauses apply — and in a self-hosted deployment, nothing crosses at all.

8.1 Residency by deployment. Data residency is a property of where the deployment runs. In a self-hosted deployment Customer determines residency entirely, and no cross-border transfer to Healthplex occurs.

8.2 Standard Contractual Clauses. Where Healthplex processes Personal Data originating in the EEA, the United Kingdom or Switzerland and transfers it to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), with: Clause 7 (docking) included; Clause 9 option 2 (general authorisation, 30 days' notice); Clause 11 optional independent dispute resolution excluded; Clause 17 governed by Irish law; and Clause 18(b) courts of Ireland. Annexes I, II and III of the SCCs are populated by Annex A, Annex B and the published subprocessor list respectively.

8.3 UK and Switzerland. Transfers from the UK are governed by the UK International Data Transfer Addendum to the SCCs. Transfers from Switzerland apply the SCCs with references to the GDPR read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as competent authority.

8.4 Government access requests. Healthplex will, unless legally prohibited, notify Customer of any binding request from a public authority for Personal Data it processes for Customer, challenge requests that appear unlawful or overbroad, and disclose only the minimum lawfully required.

9. Audit and demonstration of compliance

We give you the documentation to verify compliance, and accept on-site audit where documentation is genuinely insufficient.

9.1 Healthplex makes available the information reasonably necessary to demonstrate compliance with GDPR Article 28, including architecture documentation, security-measure descriptions and the results of independent assessments once available.

9.2 Where that documentation is genuinely insufficient for Customer's regulatory obligations, Customer may conduct an audit no more than once per year — on 30 days' written notice, during business hours, scoped to systems processing Customer's Personal Data, subject to confidentiality undertakings, and without access to other customers' data. A Supervisory Authority may audit at any time as its powers require.

9.3 Reasonable costs of an audit beyond the annual allowance are borne by Customer, unless the audit identifies a material breach by Healthplex.

10. Return and deletion

At the end, you choose return or deletion. Self-hosted data was always yours and stays put.

10.1 Self-hosted deployments. Personal Data remains on Customer infrastructure throughout. Healthplex holds no copy and so has nothing to return or delete.

10.2 Where Healthplex holds data. On termination, and at Customer's election, Healthplex will return the Personal Data in a structured, commonly used, machine-readable format, or delete it. Absent an election, Healthplex provides export access for 30 days, then deletes within a further 30 days.

10.3 Backups and legal holds. Personal Data persisting in encrypted backup media is deleted on the ordinary backup expiry cycle, during which it remains subject to this addendum. Healthplex may retain Personal Data where Required by Law, for the period required and for that purpose alone.

10.4 Certification. Healthplex will certify deletion in writing on request.

11. HIPAA business associate provisions

Where PHI is involved, these terms operate as the Business Associate Agreement.

11.1 Where Healthplex processes PHI on behalf of a Covered Entity or another Business Associate, this Section, together with Sections 4, 5, 7 and 10, constitutes the Business Associate Agreement required by 45 C.F.R. §164.504(e).

11.2 Healthplex will: use and disclose PHI only as permitted by this addendum or Required by Law; use appropriate safeguards and comply with the Security Rule at 45 C.F.R. Part 164 Subpart C; report to Customer any use or disclosure not permitted here, including any Security Incident and any Breach of Unsecured PHI; ensure subcontractors that create, receive, maintain or transmit PHI agree to the same restrictions; make PHI available for access, amendment and accounting of disclosures under §§164.524, 164.526 and 164.528; make its internal practices and records available to the Secretary of HHS for compliance determination; and, at termination, return or destroy all PHI where feasible, extending protections to any PHI whose return or destruction is infeasible.

11.3 Minimum necessary. Healthplex will request, use and disclose only the minimum PHI necessary for the permitted purpose.

11.4 Self-hosted deployments. Where Healthplex does not receive, maintain or transmit PHI, no Business Associate relationship arises under 45 C.F.R. §160.103. Healthplex will nonetheless execute a BAA on request to cover support scenarios under Section 2.2(b).

12. India — DPDP Act provisions

Where Healthplex acts as a Data Processor under DPDP, it processes only on your instruction and assists with your obligations.

12.1 Where DPDP applies, Customer is the Data Fiduciary and Healthplex the Data Processor. Healthplex processes Personal Data only under Customer's instruction and under this addendum, which constitutes the valid contract required by Section 8(2) of the DPDP Act.

12.2 Healthplex will implement reasonable security safeguards under Section 8(5), assist Customer with Data Principal requests and grievance redressal, notify Customer of any personal data breach so Customer can notify the Data Protection Board and affected Data Principals under Section 8(6), and erase Personal Data on Customer's instruction under Section 8(7).

12.3 Healthplex's grievance contact for DPDP matters is privacy@healthplex.app.

13. General

This addendum wins over the Terms on data protection. Liability follows the Terms.

13.1 Order of precedence. In the event of conflict, the following order applies: (a) the SCCs; (b) this addendum; (c) the Terms of Service; (d) the applicable Order — except that an Order may vary this addendum where it expressly says so.

13.2 Liability. Each party's liability under this addendum is subject to the limitations in Section 9 of the Terms, save that nothing limits liability that cannot be limited under Applicable Data Protection Law, including a Data Subject's rights under GDPR Article 82 and the SCCs.

13.3 Changes. Healthplex may update this addendum to reflect changes in Applicable Data Protection Law or its processing, provided no update materially reduces the protections afforded to Customer. Material changes are notified at least 30 days in advance.

13.4 Term. This addendum takes effect on the Effective Date of the Order and continues while Healthplex processes Personal Data for Customer.


Annex A — Particulars of processing

Populates Annex I of the Standard Contractual Clauses.

ItemDetail
Controller / exporterCustomer — the healthcare organisation identified in the Order
Processor / importerHealthplex, Inc., Delaware, USA
Subject matterProvision of the Healthplex EHR platform and related support, implementation and optional managed-hosting services
DurationThe Term of the Order, plus the post-termination period in Section 10
Nature of processingStorage, retrieval, structuring, transmission, backup, diagnostic inspection and — where enabled by Customer — model inference
PurposeDelivering clinical, administrative and revenue functionality to Customer, and supporting Customer's operation of it
Categories of data subjectPatients and their related persons; clinicians and staff of Customer; contacts at Customer's suppliers and payers
Categories of personal dataIdentifiers and demographics; contact details; national/health identifiers; insurance and billing data; employment records for Customer's workforce; authentication and audit metadata
Special category dataHealth and medical records, diagnoses, medication, laboratory and imaging results, genetic and biometric data where Customer records it, and data revealing racial or ethnic origin where captured for clinical or statutory reporting
Children's dataPaediatric records, where Customer provides paediatric care
FrequencyContinuous for the duration of the Term
RetentionAs configured by Customer under its own retention policy and applicable medical-records law
Competent supervisory authorityDetermined under Clause 13 of the SCCs by the Controller's place of establishment or EU representative

Annex B — Technical and organisational measures

Populates Annex II of the SCCs. These are the controls built into the platform and into how we operate.

Control areaMeasure
Access controlRole-based and attribute-based access control; permission-level enforcement on every endpoint; documented break-glass procedure that is time-limited and alerts on use
Tenant isolationEvery query is scoped by org_id; isolation is asserted by automated tests in the build pipeline
AuthenticationOIDC-based sign-in; tokens issued in HttpOnly cookies, never browser-accessible storage; MFA supported and configurable as mandatory
Encryption in transitTLS 1.2+ for all network communication, internal and external
Encryption at restDatabase and object-storage encryption; tenant AI credentials protected by envelope encryption
Audit loggingEvery read of patient data is audit-logged with actor, subject, purpose and timestamp; logs are append-only and independently retained
PseudonymisationAutomatic redaction of identifiers from outbound AI prompts unless Customer explicitly instructs otherwise in writing
Segregation of dutiesSeparate development, staging and production environments; production data is not used for development or testing
Secure developmentMandatory peer review; static analysis, dependency and secret scanning in CI; null-safety and module-boundary verification enforced at build time
Vulnerability managementContinuous dependency scanning; risk-ranked remediation targets; responsible disclosure channel published in the Trust Center
Availability & resilienceBackup and restore procedures with periodic restore testing; forward-only, reversible-by-design database migrations
PersonnelBackground checks where lawful; confidentiality undertakings; onboarding and annual privacy and security training
Incident responseDocumented response plan with defined severities, notification paths and post-incident review
AI governanceEvery model call logged with prompt, response, model, cost, latency, user and tenant; feature-flag kill switches on every AI capability; clinical outputs labelled advisory in the interface
Self-hosted deploymentsInfrastructure, network, physical and backup controls are operated by Customer. Healthplex publishes hardening guidance and secure default configuration.

Healthplex may update these measures over time provided the level of protection is not reduced. The current version is always the one published on this page.

Annex C — Subprocessors

Maintained as a live list rather than frozen into this document.

The authoritative subprocessor list is published in the Trust Center and forms Annex III of the SCCs. To subscribe to change notifications, email privacy@healthplex.app with the subject "Subscribe: subprocessor notifications".

Healthplex, Inc. — legal@healthplex.app

Back to top ↑