Data processing addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between Clinia Health Inc. or the applicable Clinia contracting entity (“Clinia”) and the customer identified in the applicable Order Form or other ordering document (“Customer”) and applies where Clinia processes Personal Information in Customer Data on behalf of Customer in connection with the Services. It supplements the Agreement and, where it conflicts with the Agreement, controls solely as to the processing of Personal Information within its scope; the Agreement governs all other matters. Depending on the applicable law and context, Clinia may act as a processor, subprocessor, service provider, Business Associate, or similar role, and Customer determines the purposes and means of processing Customer Data. Capitalized terms not defined here have the meanings given in the Agreement.
- 1. Roles and Instructions
Customer determines the purposes and means of processing Customer Data and may act as a controller, processor, business, Covered Entity, Business Associate, or similar role; Clinia acts as a processor, service provider, Business Associate, or similar role when processing Personal Information on Customer’s behalf. Customer instructs Clinia to process Personal Information to provide, secure, support, maintain, and improve the Services in accordance with Section 11 and as otherwise set out in the Agreement, this DPA, and Customer’s documented instructions. Customer’s documented instructions comprise the Agreement, Order Forms, Product Schedules, this DPA, Customer’s configuration and use of the Services, support requests, Authorized User activity, and other written instructions accepted by Clinia.
Clinia will process Personal Information only on Customer’s documented instructions unless applicable law requires otherwise, in which case Clinia will notify Customer beforehand subject to applicable law. Clinia will inform Customer if, in its reasonable view, an instruction violates Data Protection Laws and may suspend or decline an instruction to the extent necessary to comply with law, protect the security or integrity of the Services, or avoid processing outside its operational scope. The subject matter, duration, nature, and purpose of processing and the categories of Data Subjects and Personal Information are described in Schedule A. Where the Services are deployed in a Customer-Managed Deployment, processing and security responsibilities are allocated as described in this DPA, Schedule B, and the applicable Product Schedule.
- 2. Customer Responsibilities
Customer is responsible for its own compliance with Data Protection Laws in connection with Customer Data and its use of the Services, including determining whether the Services are appropriate for its use cases, workflows, users, and regulatory obligations, and the purposes, means, categories, individuals, and legal bases for the Personal Information it submits. Customer represents that it has the rights, consents, authorizations, notices, and legal bases required to provide Customer Data to Clinia for processing under the Agreement and this DPA. Where Customer Data includes Personal Information, Health Information, or Protected Health Information, Customer is responsible for ensuring that its submission is permitted by applicable law and supported by any required notices, consents, or authorizations.
Customer is responsible for how it configures, accesses, and uses the Services—including its workflows, data sources, integrations, prompts, Outputs, permissions, access controls, and Customer-Managed Deployments—and for managing its Authorized Users. In a Customer-Managed Deployment, Customer is responsible for the infrastructure and settings within its control, including the cloud account, network configuration, identity and access management, deployment region, data residency, monitoring, logging, backups, and retention; Clinia is not responsible for Customer systems, environments, or controls outside Clinia’s scope of control. Customer is responsible for providing privacy notices to, and handling requests from, individuals relating to Customer Data, with reasonable assistance from Clinia as described in this DPA.
- 3. Clinia’s Processing Obligations
Clinia will process Personal Information only in accordance with Customer’s documented instructions, the Agreement, this DPA, and applicable law, and will not sell Personal Information or use it for any purpose outside those sources. Clinia will ensure that personnel authorized to process Personal Information are bound by appropriate confidentiality obligations and will limit access to those who need it to perform Clinia’s obligations, support or operate the Services, maintain security, or comply with law. Clinia will access Personal Information, including in a Customer-Managed Deployment, only as reasonably necessary for those purposes and in accordance with the applicable Product Schedule, support process, and Customer authorization.
Taking into account the nature of processing and the information available to it, Clinia will provide reasonable assistance to Customer where required by Data Protection Laws and where Customer cannot reasonably meet the obligation without that assistance, including in connection with data protection, security, and transfer assessments, individual rights requests, and regulatory consultations relating to Clinia’s processing under this DPA. Clinia will comply with Data Protection Laws applicable to its processing; Customer remains responsible for its own compliance.
- 4. Security
Clinia will maintain reasonable administrative, technical, physical, and organizational safeguards designed to protect Personal Information within its scope of control against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access, as described in Schedule B. These safeguards are designed taking into account the nature, scope, and purposes of processing, the sensitivity of the information, the risks involved, the state of the art, and the cost of implementation, and Clinia may update them provided it does not materially reduce their overall level of protection during the term. Clinia restricts access to authorized personnel on a least-privilege, role-based basis and maintains processes to monitor, review, and improve its safeguards.
In a Customer-Managed Deployment, security is a shared responsibility: Customer is responsible for controls within its environment (including cloud account governance, network configuration, identity and access management, monitoring, logging, backups, endpoint security, and deployment region), and Clinia remains responsible for the application components and Clinia Technology within its scope of control. Customer will configure and use the Services in a manner that supports the security of Customer Data, manage its Authorized Users and credentials, and notify Clinia without undue delay of any actual or suspected compromise affecting the Services or Personal Information.
- 5. Subprocessors
Customer authorizes Clinia to engage Subprocessors to process Personal Information in connection with the Services. Clinia’s current Subprocessors are identified in the Subprocessor List; Clinia will impose on each Subprocessor written data protection obligations materially consistent with this DPA and remains responsible for its Subprocessors’ processing of Personal Information to the same extent as for its own.
Clinia will make the Subprocessor List available and provide a mechanism for notice of new Subprocessors at least thirty (30) days before authorizing them, unless a shorter period is reasonably necessary to maintain the security, availability, or operation of the Services. Customer may object on reasonable data-protection grounds by written notice within fifteen (15) days of notice, describing its specific, good-faith concerns, and the parties will work in good faith to resolve the objection, including through additional safeguards or an alternative Subprocessor where reasonably available. If the objection cannot be resolved and Clinia cannot provide the affected Services without the Subprocessor, either party may terminate the affected portion of the Services, and Clinia will refund any prepaid, unused fees for that portion as required under the Agreement. If Customer does not object within the notice period, the Subprocessor is deemed authorized. Subprocessors do not include third-party services, integrations, or environments selected or controlled by Customer, for which Customer is responsible.
- 6. Individual Rights Requests
Customer is responsible for receiving, assessing, and responding to requests from individuals to exercise rights in Personal Information in Customer Data, including determining validity, exceptions, and identity verification. If Clinia receives such a request, it will, where legally permitted, notify Customer or direct the individual to Customer, and will not respond except on Customer’s documented instructions or as required by law (in which case it will notify Customer unless prohibited). Taking into account the nature of processing and the information available to it, Clinia will provide reasonable assistance where Customer cannot fulfill a request through available Service functionality, and may charge reasonable professional-services fees for assistance that is not available through standard functionality or requires material additional effort, unless prohibited by law.
- 7. International Transfers and Data Residency
Customer authorizes Clinia, its Affiliates, and its Subprocessors to process Personal Information in the jurisdictions where they operate or provide services, subject to this DPA, applicable Data Protection Laws, and any data residency or location restriction in the Agreement, Order Form, or Product Schedule. Where a Restricted Transfer occurs, Clinia will apply the transfer mechanism required by applicable Data Protection Laws; where standard contractual clauses or similar transfer terms apply, they are incorporated by reference and completed as described in the applicable jurisdiction-specific schedule (see Schedule D for EEA, UK, and Swiss transfers). Clinia will make Restricted Transfers to Subprocessors subject to written obligations materially consistent with this DPA.
For Clinia-managed Services, Customer Data containing patient information, Health Information, or Protected Health Information is stored and processed in the Canadian or United States region selected for the applicable workspace. Customer is responsible for selecting the workspace region appropriate to its legal, regulatory, contractual, and operational requirements. Workspace metadata and other non-sensitive control-plane information may be processed through Clinia’s centralized Canadian infrastructure. Any additional hosting, residency, or transfer requirements supported by the applicable Service may be specified in the applicable Order Form or Product Schedule. In a Customer-Managed Deployment, Customer controls the deployment environment, region, and data residency, and Customer Data may remain within that environment unless Customer configures the Services otherwise or authorizes Clinia access.
- 8. Audits
On Customer’s reasonable request, Clinia will make available information reasonably necessary to demonstrate its compliance with this DPA, such as security documentation, third-party audit reports, and certifications available through its trust center or other customer-facing process; such materials are Clinia’s Confidential Information. Where Data Protection Laws require and compliance cannot reasonably be demonstrated through those materials, Customer may audit Clinia’s compliance, provided the audit protects the confidentiality, security, and integrity of Clinia’s systems, personnel, other customers, and Subprocessors.
Customer must give reasonable advance written notice and agree with Clinia on the audit’s scope, timing, and process; audits occur during business hours, remotely where practicable, no more than once in any twelve-month period (unless required by Data Protection Laws or a regulator), and without unreasonably interfering with Clinia’s operations. Customer and any auditor are subject to confidentiality obligations reasonably acceptable to Clinia. Customer bears its audit costs, and Clinia may charge reasonable fees for audit support requiring material time or resources. Customer will promptly share audit findings, which are Confidential Information, and the parties will work in good faith to address any confirmed material non-compliance.
- 9. Security Incidents
Clinia will notify Customer without undue delay after becoming aware of a Data Security Incident and will include the information reasonably available at the time, including the nature of the incident, the categories of Personal Information and individuals affected (where known), the measures taken or planned to investigate, contain, and remediate it, any recommended Customer measures, and a Clinia contact; Clinia will supplement its notice as further information becomes available. Clinia will take reasonable steps to investigate, contain, mitigate, and remediate Data Security Incidents within its scope of control and will reasonably cooperate to help Customer meet its legal obligations, taking into account the information available and applicable security and confidentiality requirements.
Customer is responsible for incidents involving its own systems, accounts, credentials, or Customer-Managed Deployments, and for determining whether notification to individuals or authorities is required unless law requires Clinia to notify directly. Where a public or regulatory notice refers to Clinia, Customer will, where permitted and practicable, give Clinia an opportunity to review the relevant portions first. Clinia’s notification of or response to a Data Security Incident is not an admission of fault or liability.
- 10. Return and Deletion
Following termination or expiry of the Agreement, Clinia will return or delete Personal Information in accordance with the Agreement, applicable Product Schedule, Customer’s written instructions, and applicable law, and Customer is responsible for exporting Customer Data through available Service functionality before termination. On Customer’s written request, Clinia will initiate deletion of Personal Information in Clinia-controlled production systems within thirty (30) days of termination or expiry, unless a different period is stated in the Agreement or Product Schedule. Clinia may retain Personal Information where required by law or for backup, audit, security, or recordkeeping purposes permitted by law; retained Personal Information remains subject to this DPA, and information retained in backups is protected from further active processing and deleted in the ordinary course. In a Customer-Managed Deployment, Customer is responsible for return, deletion, and retention within its environment.
- 11. Usage Data and Aggregated Data; Service Improvement and Model Training
Clinia may collect and process Usage Data to operate, secure, monitor, support, troubleshoot, and improve the Services. Usage Data does not include Customer Data or other customer content. It excludes the content of queries, prompts, Outputs, search terms, document or retrieval paths, patient information, and any log entry or telemetry containing that information. If Usage Data is Personal Information because it relates to an Authorized User or another individual, Clinia will process it in accordance with this DPA.
Customer instructs and authorizes Clinia to create De-identified Data from Customer Data and to create Aggregated Data by combining or summarizing De-identified Data with other De-identified Data or data from other sources, in each case in accordance with the Agreement, this DPA, and Applicable Laws. Where the source data includes Protected Health Information, creation of De-identified Data is governed by the BAA and applicable HIPAA de-identification requirements.
Clinia may use De-identified Data and Aggregated Data to operate, secure, analyze, evaluate, improve, train, and maintain the Services and Clinia’s underlying models and technology, perform analytics, and develop new products and services, subject to the Agreement, this DPA, the BAA where applicable, and Applicable Laws. No separate case-by-case Customer instruction or written consent is required for those uses.
Clinia will not attempt to re-identify De-identified Data or Aggregated Data, use either to identify Customer or any individual, or use either to reconstruct Customer Data.
Unless Customer expressly agrees in writing and Applicable Laws permit, Clinia will not use identifiable Customer Data, or data derived from Customer Data that does not qualify as De-identified Data or Aggregated Data, to train or fine-tune models made available to other customers. Clinia may use Usage Data, Aggregated Data, and synthetic, internal, public, or customer-approved evaluation datasets to evaluate and improve the Services. For Aggregated Data, this may include analytics and improvements to product functionality and system behaviour, including deterministic ingestion, matching, merging, and relationship logic. This permission does not extend to the model training or fine-tuning described above.
Any customer-specific configuration, troubleshooting, or improvement involving Customer Data or Customer-specific information will be limited to the authorized purpose and will not be reused outside Customer’s environment without written agreement. Clinia will not sell Customer Data or Personal Information or disclose it for cross-context behavioral or targeted advertising. Disclosures Customer directs through its own integrations or third-party services are governed by Customer’s instructions and are not a sale or sharing by Clinia.
- 12. Jurisdiction-Specific Terms
The following schedules form part of this DPA and apply only where, and to the extent, the relevant law applies to Clinia’s processing of Personal Information under this DPA: Schedule C (U.S. State Privacy Addendum); Schedule D (EEA, UK, and Swiss Transfer Addendum); Schedule E (Canadian Privacy Addendum); and Schedule F (Québec Law 25 Addendum). Where more than one applies to the same processing, Clinia will handle Personal Information in accordance with the most stringent applicable requirement. If a schedule conflicts with the main body, the schedule controls to the extent required by the applicable law, and the main body otherwise continues to apply. The jurisdiction-specific schedules do not require Clinia to provide services, features, deployment models, support, data residency, retention, or security commitments not included in the Agreement, applicable Product Schedule, Documentation, or this DPA.
- 13. General
Business Associate Agreement. Where Personal Information includes Protected Health Information and Clinia acts as a Business Associate, the Business Associate Agreement also forms part of the Agreement and governs Clinia’s use and disclosure of that Protected Health Information. If the Business Associate Agreement conflicts with this DPA or another document forming the Agreement regarding the treatment of Protected Health Information, the Business Associate Agreement controls. This DPA continues to govern Personal Information within its scope.
Order of Precedence. If this DPA conflicts with the Agreement, this DPA controls solely as to Clinia’s processing of Personal Information on behalf of Customer.
Liability. Each party’s liability under this DPA is subject to the limitation-of-liability provisions of the Agreement, unless otherwise required by applicable law.
Customer Affiliates. Customer enters into this DPA for itself and, where required by Data Protection Laws, its Affiliates for whose Personal Information Clinia processes, and is responsible for coordinating their instructions, requests, and communications.
Notices and Amendments. Notices are given as provided in the Agreement, except that operational notices (including on Subprocessors, security, support, or privacy) may be provided through the Services, a trust center, customer portal, or email. Amendments follow the Agreement’s amendment provisions; Clinia may update customer-facing security, Subprocessor, and similar operational materials from time to time as permitted by this DPA and the Agreement.
Governing Law. Except as otherwise required by a jurisdiction-specific schedule, the SCCs, applicable Data Protection Laws, or a Business Associate Agreement between the parties, the governing-law, forum, and dispute-resolution provisions of the Agreement apply to this DPA.
Execution and Survival. This DPA is effective when the Agreement or a document incorporating it becomes effective, may be executed in counterparts and by electronic signature, and survives termination of the Agreement for as long as Clinia processes Personal Information on behalf of Customer.
- 14. Definitions
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. In this DPA:
“Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
“Agreement” means the agreement between Clinia and Customer governing the Services, including the applicable Order Form, Product Schedule, general terms, this DPA, and any document incorporated by reference.
“Aggregated Data” means data created by combining or summarizing De-identified Data with other De-identified Data or data from other sources so that it does not identify and is not reasonably capable of being used to identify Customer or any individual and is not reasonably capable of being used to reconstruct Customer Data.
“Applicable Laws” means laws, regulations, rules, orders, and binding governmental requirements applicable to a party’s performance under the Agreement or use of the Services.
“Business Associate, Covered Entity, and Protected Health Information (or PHI)” have the meanings given under HIPAA and, as between the parties, are addressed under the Business Associate Agreement.
“Business Associate Agreement” means a business associate agreement entered into between the parties in connection with Protected Health Information under HIPAA.
“Canadian Data Protection Laws” means Data Protection Laws applicable in Canada, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”), and excluding Québec Data Protection Laws, which are addressed separately.
“Customer Data” means data, content, records, files, prompts, queries, instructions, inputs, materials, configurations, and other information submitted to, uploaded to, transmitted through, stored in, or otherwise made available to the Services by or on behalf of Customer, Authorized Users, or End Users. Customer Data includes Personal Information and Health Information where such information is included in the foregoing. Customer Data does not include Usage Data, De-identified Data, Aggregated Data, Feedback, or Clinia Technology.
“Customer-Managed Deployment” means a deployment of the Services in a cloud account, infrastructure, network, or other environment owned, operated, configured, or controlled by or on behalf of Customer.
“Data Protection Laws” means Applicable Laws relating to privacy, data protection, data security, breach notification, or the processing of Personal Information or Health Information, including, where applicable, HIPAA, U.S. state privacy laws (“U.S. State Privacy Laws”), the GDPR, the UK GDPR, Swiss data protection law, and Canadian Data Protection Laws (including Québec Data Protection Laws).
“Data Security Incident” means a confirmed or reasonably suspected breach of security resulting in the unauthorized access to, acquisition, disclosure, loss, alteration, or destruction of Personal Information processed by Clinia on behalf of Customer. It does not include unsuccessful access attempts or routine security events (such as pings, scans, or denial-of-service attempts) that do not result in unauthorized access to Personal Information.
“Data Subject” means the identified or identifiable individual to whom Personal Information relates, which may include a patient, consumer, or user.
“De-identified Data” means data derived from Customer Data that has been processed so that it does not identify and is not reasonably capable of being used to identify Customer, an Authorized User, an End User, a patient, or any other individual, and is not reasonably capable of being used to reconstruct Customer Data. Where the source data includes Protected Health Information, De-identified Data must satisfy the de-identification requirements of HIPAA, including 45 C.F.R. § 164.514(b), through either the Safe Harbor method or Expert Determination.
“Documentation” means the user guides, technical and product documentation, support materials, and policies made available by Clinia for the Services, as updated from time to time.
“EEA” means the European Economic Area.
“GDPR” means Regulation (EU) 2016/679 (the General Data Protection Regulation) and, where the context requires, the UK GDPR and Swiss data protection law.
“Health Information” means information relating to the physical or mental health, healthcare, diagnosis, treatment, or health-related status of an individual, including Protected Health Information and similar information protected under Data Protection Laws.
“HIPAA” means the U.S. Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations.
“Order Form” means an order form, statement of work, or other ordering document identifying the Services purchased or accessed by Customer.
“Outputs” means responses, results, summaries, classifications, extractions, retrieved information, or other outputs generated through the Services based on inputs provided by or on behalf of Customer.
“Personal Information” means information relating to an identified or identifiable individual, including personal data, personally identifiable information, Protected Health Information, and similar information protected under Data Protection Laws.
“Product Schedule” means a product- or deployment-specific schedule, addendum, or set of terms applicable to a particular Service, deployment model, feature, or offering.
“Québec Data Protection Laws” means Data Protection Laws applicable in Québec, including the Act respecting the protection of personal information in the private sector, as amended (“Québec Law 25”).
“Restricted Transfer” means a transfer of Personal Information that requires additional safeguards under applicable Data Protection Laws because it is transferred to, or accessed from, a jurisdiction not recognized as providing an adequate level of protection.
“SCCs” means the standard contractual clauses approved for Restricted Transfers under applicable Data Protection Laws, including the EU standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914 and the UK International Data Transfer Addendum.
“Services” means the products, software, platform, APIs, AI features, tools, support, and related offerings provided by Clinia to Customer under the Agreement.
“Subprocessor” means a third party engaged by Clinia to process Personal Information on behalf of Customer in connection with the Services.
“Subprocessor List” means Clinia’s list of Subprocessors made available through its trust center, Documentation, website, or another customer-facing location.
“UK GDPR” means the GDPR as incorporated into the law of the United Kingdom.
“Usage Data” means technical, operational, telemetry, metadata, usage, diagnostic, performance, error, and log data relating to the operation, security, monitoring, support, troubleshooting, or use of the Services, such as the number and type of calls, response size, latency, errors, and performance metrics. Usage Data does not include Customer Data or other customer content. It excludes the content of queries, prompts, Outputs, search terms, document or retrieval paths, patient information, and any log entry or telemetry containing that information.
The terms “controller,” “processor,” “processing,” “business,” “service provider,” “contractor,” “consumer,” “sell,” and “share” have the meanings given under applicable Data Protection Laws.
- Schedule A: Details of Processing
This Schedule A describes the general processing activities under this DPA. Additional or different details may be set out in the applicable Order Form, Product Schedule, Documentation, or written instructions agreed between the parties.
Subject matter and Services. Clinia processes Personal Information in Customer Data to provide the Services, which may include healthcare data search, retrieval, summarization, classification, matching, ranking, workflow support, API and AI-supported features, and related implementation, support, monitoring, and security services.
Duration. For the term of the Agreement, after which Personal Information is returned, deleted, or retained in accordance with this DPA.
Nature and purpose. To provide, operate, secure, and support the Services; enable search, retrieval, ranking, matching, summarization, and classification and generate Outputs; monitor performance, reliability, and security; troubleshoot and provide support; prevent, detect, and respond to security, fraud, and service-integrity issues; comply with law; and create and use Usage Data and Aggregated Data, including De-identified Data, in accordance with Section 11.
Processing operations. Collection, access, use, storage, hosting, organization, retrieval, analysis, transformation, classification, matching, ranking, summarization, generation, transmission, disclosure to authorized Subprocessors, restriction, deletion, and return.
Categories of Data Subjects. Patients, members, and other individuals whose information is included in Customer Data; healthcare providers and professionals; Authorized Users, End Users, and administrators who operate the Services for Customer; and Customer representatives and business contacts.
Categories of Personal Information. Identifiers and contact details; demographic information; Health Information and, where HIPAA applies, Protected Health Information; provider and professional information; account, access, and user-administration information; prompts, queries, retrieval context, Outputs, and related content; technical, usage, and log data; support and configuration information; and other Personal Information included in Customer Data.
Sensitive information. May include Health Information, Protected Health Information, special categories of personal data, government identifiers, information about vulnerable individuals, or similar regulated information. Customer is responsible for ensuring its submission is lawful and supported by any required notices, consents, or authorizations.
Frequency. Continuous, periodic, or event-driven during the term, depending on Customer’s use of the Services.
Processing locations. As described in Section 7 and the Subprocessor List.
Subprocessors. As described in Section 5 and the Subprocessor List.
- Schedule B: Security Measures
Clinia maintains an information security program with administrative, technical, physical, and organizational safeguards appropriate to the Services, the sensitivity of the Personal Information, the deployment model, and Clinia’s scope of control. Product- or deployment-specific responsibilities may be described in the applicable Product Schedule or security documentation. The program includes:
Governance. Security policies, risk assessments, control reviews, vendor review, and personnel security and privacy training.
Access control. Least-privilege, role-based access with approval, periodic review, and timely deprovisioning.
Authentication. Single sign-on, multi-factor authentication, and administrative access controls appropriate to system and risk.
Encryption. Encryption of Personal Information in transit and at rest where appropriate to the Service and deployment model.
Logging and monitoring. Logging of authentication, system, administrative, and security events, applied to limit unnecessary exposure of Personal Information.
Vulnerability and secure development. Vulnerability scanning, dependency and code review, security testing, change management, and separation of development, testing, and production environments.
Subprocessor security. Written security obligations materially consistent with this DPA.
Incident response. Processes to detect, investigate, contain, remediate, and communicate incidents, handled in accordance with Section 9.
Resilience. Backup, recovery, and availability measures for Clinia-managed environments.
Physical security. Reliance on cloud-infrastructure provider controls for data-center facilities, plus reasonable controls for Clinia offices.
Confidentiality. Confidentiality obligations for personnel authorized to access Personal Information.
Shared responsibility. In a Customer-Managed Deployment, Customer secures its environment and Clinia secures the application layer and Clinia Technology within its scope of control.
Clinia may update these measures but will not materially reduce their overall level of protection during the term.
- Schedule C: U.S. State Privacy Addendum
This Schedule C applies where, and only to the extent, U.S. State Privacy Laws apply to Clinia’s processing of Personal Information under this DPA. Where it applies, Customer is the business or controller that determines the purposes and means of processing, and Clinia acts as a service provider, processor, or contractor processing Personal Information on Customer’s behalf for the business purposes described in the Agreement, this DPA, and Customer’s documented instructions.
Restrictions on Use. Clinia will not: (a) sell Personal Information; (b) share Personal Information for cross-context behavioral or targeted advertising; (c) retain, use, or disclose Personal Information for any purpose other than the permitted business purposes or as otherwise allowed by U.S. State Privacy Laws; (d) retain, use, or disclose Personal Information outside the direct business relationship between the parties, except as permitted by law; or (e) combine Personal Information with information from other sources, except as permitted by U.S. State Privacy Laws.
Permitted Processing. Clinia may process Personal Information as reasonably necessary to provide, secure, support, and improve the Services in accordance with Section 11; perform the Agreement and Customer’s instructions; detect and respond to security and service-integrity issues; comply with law; engage Subprocessors under Section 5; and create and use Usage Data and Aggregated Data, including De-identified Data, in accordance with Section 11.
Consumer Requests and Assistance. Customer is responsible for responding to consumer requests. Clinia will provide reasonable assistance as required by U.S. State Privacy Laws where Customer cannot fulfill a request without it, and will notify Customer or direct the individual to Customer if it receives a request. Each party is responsible for meeting the obligations that apply to it.
De-identified Data. Clinia will maintain reasonable measures to prevent re-identification of De-identified Data and will not attempt to re-identify it or use it to reconstruct Customer Data.
Sensitive Personal Information. Customer is responsible for determining whether Customer Data includes sensitive Personal Information and for providing any required notices and obtaining any required consents; Clinia processes it only in accordance with Customer’s documented instructions and applicable law.
Certification. Clinia certifies that it understands and will comply with the restrictions and obligations applicable to it under this Schedule C. If this Schedule C conflicts with the main body of the DPA, this Schedule C controls to the extent required by U.S. State Privacy Laws.
- Schedule D: EEA, UK, and Swiss Transfer Addendum
This Schedule D applies where, and only to the extent, a Restricted Transfer of Personal Information from the European Economic Area, the United Kingdom, or Switzerland is subject to the GDPR, the UK GDPR, or Swiss data protection law. Customer is the data exporter and Clinia the data importer.
EU Standard Contractual Clauses. Where the GDPR applies to a Restricted Transfer, the EU SCCs are incorporated into this DPA by reference. Module Two applies where Customer is a controller and Clinia is a processor, and Module Three applies where Customer is a processor and Clinia is a subprocessor. The parties select: Clause 7 (docking clause) applies; Clause 9, Option 2 (general written authorization), applies, with the notice period stated in Section 5; the Clause 11 optional redress language does not apply; and under Clause 17 (Option 1) and Clause 18 the SCCs are governed by, and disputes resolved in the courts of, France.
SCC Annexes. Annex I (list of parties and description of the transfer) is completed by the Agreement, the applicable Order Form, and Schedule A; Annex II (technical and organizational measures) by Schedule B and the applicable Product Schedule; and Annex III (subprocessors) by the Subprocessor List and Section 5.
UK Transfers. Where the UK GDPR applies, the UK International Data Transfer Addendum to the EU SCCs is incorporated by reference and completed by this Schedule, the Agreement, Schedule A, and Schedule B, and the EU SCCs are modified as required by the UK Addendum.
Swiss Transfers. Where Swiss data protection law applies, the EU SCCs apply with the amendments necessary under Swiss law, including references to the Swiss Federal Act on Data Protection and to the Swiss Federal Data Protection and Information Commissioner as a supervisory authority.
Assessments, Safeguards, and Execution. Clinia will maintain the safeguards described in Schedule B and, as described in Section 3, provide reasonable assistance with transfer impact assessments. Execution or acceptance of the Agreement or a document incorporating this DPA constitutes execution of the SCCs and the UK Addendum to the extent applicable. On any conflict between this Schedule and the SCCs or another mandatory transfer mechanism, the SCCs or mandatory mechanism control to the extent required by applicable Data Protection Laws.
- Schedule E: Canadian Privacy Addendum
This Schedule E applies where, and only to the extent, Canadian Data Protection Laws (including PIPEDA) apply to Clinia’s processing of Personal Information under this DPA. Québec-specific requirements are addressed in Schedule F.
Roles and Accountability. Customer is accountable for Personal Information under its control and determines the purposes for which it is processed through the Services; Clinia processes Personal Information on Customer’s behalf in accordance with the Agreement, this DPA, and applicable law.
Comparable Protection. Clinia protects Personal Information using contractual, administrative, technical, physical, and organizational safeguards designed to provide a level of protection appropriate to its sensitivity, as described in Schedule B, and requires Subprocessors to provide comparable protection.
Limiting Processing and Retention. Clinia processes, retains, and deletes Personal Information only for the purposes and periods described in the Agreement, this DPA, and Customer’s documented instructions; Customer is responsible for limiting the Personal Information it submits to what is appropriate for its use of the Services.
Consent and Notices. Customer is responsible for providing required notices and obtaining any required consents, authorizations, or other legal bases; Clinia is not responsible for determining whether Customer has done so, except where it has expressly agreed in writing to support a specific obligation.
Access, Correction, and Incidents. Customer handles individual access and correction requests, with reasonable assistance from Clinia; Clinia notifies Customer of Data Security Incidents under Section 9 and assists Customer’s assessment of breach-notification obligations under Canadian Data Protection Laws.
Cross-Border Processing. Customer authorizes processing of Personal Information outside the jurisdiction of collection subject to this DPA. Each party is responsible for meeting its own obligations for such processing within its scope of control, and Clinia maintains the safeguards required for transfers it performs.
- Schedule F: Québec Law 25 Addendum
This Schedule F applies where, and only to the extent, Québec Data Protection Laws (including Québec Law 25) apply to Clinia’s processing of Personal Information under this DPA.
Roles and Responsibility. Each party is responsible for meeting the obligations that apply to it under Québec Data Protection Laws. Customer determines the purposes for which Personal Information is processed through the Services and whether its use requires a privacy impact assessment, transfer assessment, notice, or consent; Clinia processes Personal Information on Customer’s behalf and is responsible for compliance steps required for its own systems and processing within its scope of control.
Service-Provider Processing. Clinia processes Personal Information only for the purposes described in the Agreement, this DPA, and Customer’s documented instructions, including the processing authorized under Section 11; will not otherwise use it for its own purposes except as permitted by Québec Data Protection Laws; and ensures that authorized personnel are subject to confidentiality obligations.
Confidentiality Incidents. Clinia notifies Customer without undue delay of a Data Security Incident (which, for this Schedule, includes a confidentiality incident under Québec Data Protection Laws) and provides reasonable information to support Customer’s assessment of whether the incident presents a risk of serious injury and whether notification to individuals, the Commission d’accès à l’information, or others is required. Customer determines whether notification is required unless applicable law requires Clinia to notify directly.
Privacy Impact and Transfer Assessments. Taking into account the nature of processing and the information available to it, Clinia provides reasonable information to support Customer’s privacy impact assessments and assessments of transfers outside Québec where required and where Customer cannot reasonably complete them without Clinia’s support; Customer is responsible for the conclusions, mitigations, and decisions arising from those assessments.
Transfers Outside Québec. Customer authorizes processing of Personal Information outside Québec subject to this DPA, and Clinia maintains the safeguards and contractual measures required for transfers it performs within its scope of control.
Individual Rights and Retention. Customer handles requests to access or correct Personal Information and to withdraw consent, with reasonable assistance from Clinia; retention and deletion follow the Agreement, this DPA, and Customer’s documented instructions.