Data Processing Agreement
(Schedule B to the Master Service Agreement, or, where the parties so elect, executed as a standalone agreement)
Effective Date: the date recorded in the Customer acceptance receipt
This Data Processing Agreement (the “DPA”) forms part of the Master Service Agreement between The Health Aisle Inc. (the “Company”) and the Customer named in the applicable Order Form (the “Customer”) (as amended from time to time, the “MSA”). Where the parties have not entered into an MSA, or have agreed to execute this DPA separately, this DPA forms a binding standalone agreement between them governing the Company’s Processing (as defined below) of Personal Health Information and Personal Data on the Customer’s behalf in connection with the Services.
In the event of a conflict between this DPA and the MSA (or any other agreement between the parties) with respect to the Processing of Personal Health Information or Personal Data, this DPA prevails to the extent of the conflict.
Capitalized terms used but not defined in this DPA have the meanings given to them in the MSA. If no MSA is in effect, capitalized terms have the meanings given to them in this DPA or, where the context requires, in PHIPA (as defined below).
1. Definitions
“Agent” has the meaning given in section 2 of PHIPA.
“Authorized Personnel” means the Company’s employees, contractors, and other personnel who require access to Personal Health Information or Personal Data to perform the Services and who are bound by written obligations of confidentiality.
“Health Information Custodian” or “HIC” has the meaning given in section 3 of PHIPA. The parties acknowledge that the Customer is, or acts on behalf of, the HIC in respect of the Personal Health Information Processed under the MSA.
“Personal Data” means information about an identifiable individual that is not Personal Health Information, including account, registration, and contact information collected by the Company in connection with providing the Services.
“Personal Health Information” or “PHI” has the meaning given in section 4 of PHIPA.
“PHIPA” means Ontario’s Personal Health Information Protection Act, 2004 and its companion regulation O. Reg. 329/04, each as amended from time to time.
“Process” or “Processing” means any operation or set of operations performed on Personal Health Information or Personal Data, including collection, recording, organization, structuring, storage, alteration, retrieval, use, disclosure, transmission, restriction, erasure, or destruction.
“Security Incident” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Health Information or Personal Data Processed by or on behalf of the Company.
“Services” has the meaning given in the MSA, or where no MSA is in effect, means the platform, software, and related services provided by the Company to the Customer.
“Subprocessor” means any third party engaged by the Company to Process Personal Health Information or Personal Data on the Company’s behalf in connection with the Services.
2. Roles of the Parties and Scope of Processing
The Customer is the Health Information Custodian (or acts on behalf of a Health Information Custodian) with respect to the Personal Health Information Processed under this DPA. The Company is an Agent of the Customer for the purposes of PHIPA and Processes Personal Health Information and Personal Data only on behalf of, and on the documented instructions of, the Customer, except as required by applicable law.
The Customer’s instructions to the Company are: (a) those set out in the MSA, the Order Form, and this DPA; (b) the configurations the Customer makes through the Services; and (c) any further written instructions issued by the Customer to the Company. The Company shall promptly notify the Customer if, in its opinion, an instruction infringes PHIPA or other applicable law.
Details of the Processing — including subject matter, duration, nature and purpose, categories of data subjects, and categories of data — are set out in Schedule 1 to this DPA.
3. PHIPA Agent Obligations
Without limiting any other provision of this DPA, the Company shall, in its capacity as Agent of the Customer under PHIPA:
Process Personal Health Information only for the purposes of providing the Services and only as permitted or required under PHIPA;
not collect, use, or disclose Personal Health Information if other information will serve the purpose, and not collect, use, or disclose more Personal Health Information than is reasonably necessary to meet the purpose;
not Process Personal Health Information for marketing, fundraising, market research, or commercial purposes, except as expressly authorized in writing by the Customer in advance;
not disclose Personal Health Information except as expressly permitted by the Customer’s instructions, this DPA, the MSA, or as required by law (and where required by law, notify the Customer in advance unless legally prohibited from doing so);
notify the Customer at the first reasonable opportunity if the Company believes it has Processed Personal Health Information other than as permitted under this DPA or PHIPA;
comply with the additional duties of Agents prescribed by section 17 of PHIPA.
De-identified data. Once Personal Health Information or Personal Data has been irreversibly de-identified in accordance with applicable law and guidance from the Information and Privacy Commissioner of Ontario, such data is no longer Personal Health Information or Personal Data for the purposes of this DPA, and the Company may collect, use, disclose, and retain such de-identified data to maintain, improve, and develop the Services, for statistical and research purposes, and for any other lawful purpose.
PIPEDA acknowledgment. To the extent that any Personal Data Processed under this DPA is subject to the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”), the Company shall comply with the requirements of PIPEDA applicable to its Processing of such Personal Data on behalf of the Customer.
4. Personnel and Confidentiality
The Company shall limit access to Personal Health Information and Personal Data to Authorized Personnel on a need-to-know basis. The Company shall ensure that Authorized Personnel: (a) are subject to written obligations of confidentiality no less protective than those in this DPA and the MSA; (b) receive training in respect of their obligations relating to the protection of Personal Health Information; and (c) are bound by appropriate sanctions for breach of those obligations.
5. Security Measures
The Company shall implement and maintain appropriate administrative, technical, and physical safeguards to protect Personal Health Information and Personal Data against loss, theft, unauthorized access, use, disclosure, copying, modification, or destruction, in accordance with industry standards and the requirements of PHIPA. The Company’s minimum security measures are set out in Schedule 2 to this DPA. The Company may update its security measures from time to time, provided that the updated measures provide a level of protection no less than that set out in Schedule 2.
6. Subprocessors
The Customer provides general authorization for the Company to engage Subprocessors to Process Personal Health Information and Personal Data in connection with the Services, subject to this Section.
The Company maintains a current list of Subprocessors at https://www.healthaislelearn.ca/legal/dpa#schedule-3-list-of-subprocessors and in Schedule 3 below. The Company shall provide the Customer with at least thirty (30) days’ prior written notice (which may be by email to the Customer’s designated contact, or by an update to the Subprocessor list with a corresponding notification mechanism) of any new Subprocessor that will Process Personal Health Information.
If the Customer has a reasonable, good-faith objection to the addition of a new Subprocessor on data protection grounds, the Customer may notify the Company within fifteen (15) days of the notice. The parties shall work together in good faith to resolve the objection. If no resolution is reached, the Customer may, as its sole and exclusive remedy, terminate the Services that cannot be provided without the proposed Subprocessor by providing written notice to the Company.
The Company shall enter into a written agreement with each Subprocessor that imposes obligations on the Subprocessor with respect to Personal Health Information and Personal Data that are no less protective than those imposed on the Company under this DPA. The Company shall remain liable to the Customer for the acts and omissions of its Subprocessors as if such acts or omissions were those of the Company.
7. Patient and Data Subject Rights
The Customer, as Health Information Custodian, is responsible for responding to requests from individuals (including patients) to exercise rights under PHIPA in respect of their Personal Health Information, including rights of access, correction, withdrawal of consent, and complaint.
The Company shall, taking into account the nature of the Processing, provide reasonable assistance to the Customer (through appropriate technical and organizational measures, including making functionality available within the Services) to enable the Customer to respond to such requests. The Company shall not respond directly to a patient or other individual on a matter relating to the Customer’s Personal Health Information unless directed in writing to do so by the Customer, except where required by law or where the request relates solely to the Company’s own information practices.
Timing of assistance. Where a Customer forwards to the Company a request from a patient or other end user to exercise privacy rights, the Company shall acknowledge the forwarded request without undue delay and in any event within seven (7) days of receipt, and shall provide the Customer with the assistance reasonably required to enable the Customer to substantively respond to the requester within thirty (30) days for requests under PHIPA, PIPEDA, or GDPR, or within forty-five (45) days for requests under CCPA, subject to any extensions permitted by the applicable law. The Company shall notify the Customer if it becomes aware that the Customer’s response is likely to be delayed beyond these timeframes.
8. Storage and Transfer of Personal Health Information
The Company shall store and Process Personal Health Information exclusively on servers and infrastructure located in Canada. The Company shall not transfer, disclose, or back-up Personal Health Information outside Canada except with the Customer’s prior express written consent and pursuant to safeguards that provide a level of protection substantially equivalent to that required by PHIPA. Routine support, monitoring, or administrative access to Personal Health Information by Company personnel located outside Canada, where required, shall be conducted in accordance with the Company’s policies and only where strictly necessary to deliver the Services, subject to access controls and audit logging.
The Company may transfer Personal Data (other than Personal Health Information) outside of Canada where reasonably necessary to deliver the Services, provided that the recipient is bound by privacy and security obligations contractually equivalent to those required of the Company under this DPA.
9. Security Incidents
The Company shall notify the Customer of any Security Incident affecting Personal Health Information without undue delay and in any event within seventy-two (72) hours after the Company becomes aware of it. The notification shall include, to the extent then known: (a) a description of the nature of the Security Incident, including, where possible, the categories and approximate number of data subjects and records affected; (b) the likely consequences; (c) the measures taken or proposed to address the Security Incident and to mitigate its possible adverse effects; and (d) the contact details of the Company’s privacy or security lead. The Company shall provide updates as additional information becomes available.
The Company shall cooperate with the Customer’s reasonable requests in connection with the investigation, containment, and remediation of any Security Incident, and shall assist the Customer in fulfilling any breach-notification obligations the Customer may have under PHIPA, including notification to affected individuals and the Information and Privacy Commissioner of Ontario.
The Company shall not make any public statement or notification to data subjects about a Security Incident affecting the Customer’s Personal Health Information without the Customer’s prior written consent, except where required by law.
10. Audits and Inspections
The Customer’s right to verify the Company’s compliance with this DPA shall be exercised in accordance with the following tiered process, which is intended to balance the Customer’s reasonable verification needs against the protection of the Company’s confidential systems, operational continuity, and other customers’ data:
(a) Security Questionnaire (default). On reasonable prior written request, and not more than once in any twelve (12) month period (except where required by law, by a regulator, or following a confirmed Security Incident affecting the Customer), the Customer may submit a written security questionnaire to the Company, and the Company shall respond within thirty (30) days. The Company may satisfy any such request by providing its most recent completed standard security questionnaire and security overview documentation.
(b) Security Documentation. In addition to or in lieu of paragraph (a), the Company may, at its option, satisfy any audit obligation under this Section by providing the Customer with security documentation reasonably evidencing the Company’s compliance with this DPA. Such documentation may include the Company’s security overview, architecture description, summary of administrative and technical controls, vulnerability scan or penetration testing summaries, internal attestations from the Company’s security or engineering leadership, and, if and when available, any third-party security audit reports, certifications, or attestations (such as SOC 2 Type II or ISO 27001). The Company is not obligated to obtain or maintain any particular third-party certification. All materials furnished under this paragraph shall be the Company’s Confidential Information and shall be treated by the Customer under its customary obligations of confidentiality.
The processes set out in paragraphs (a) and (b) are the sole and exclusive means by which the Customer may verify the Company’s compliance with this DPA. The Customer shall treat any information furnished under this Section as the Company’s Confidential Information, and shall not disclose such information to any third party (other than the Customer’s legal advisors under privilege, the Customer’s regulators, or as required by law) without the Company’s prior written consent.
11. Return or Destruction of Data
On termination or expiry of the MSA (or the Services, if this DPA is executed standalone), the Company shall, at the Customer’s written election: (a) return all Personal Health Information and Personal Data in the Company’s possession in a structured, commonly used, machine-readable format; or (b) securely destroy all such Personal Health Information and Personal Data, including any copies, using industry-standard media sanitization methods. The Company shall complete the return or destruction within thirty (30) days of the Customer’s instruction.
Notwithstanding the foregoing, the Company may retain Personal Health Information and Personal Data: (i) in routine backups for the period required by the Company’s standard backup retention schedule, provided that any retained data remains subject to the protections of this DPA and is not accessed for any other purpose; and (ii) to the extent required by applicable law, provided that such retained data is isolated, protected, and used solely for the purpose required by law.
On the Customer’s request, the Company shall provide written certification of destruction, signed by an officer of the Company.
12. Records of Processing
The Company shall maintain accurate records of its Processing activities under this DPA sufficient to demonstrate compliance with this DPA and PHIPA, including records of access, disclosures, and Security Incidents involving Personal Health Information. The Company shall make such records available to the Customer on reasonable request.
13. Cooperation with Regulators
The Company shall provide reasonable cooperation to the Customer in responding to inquiries, investigations, or orders from the Information and Privacy Commissioner of Ontario or any other regulator with jurisdiction over the Customer’s handling of Personal Health Information, and shall not, except as required by law, respond directly to such regulators on matters concerning the Customer’s Personal Health Information without first notifying the Customer.
14. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the MSA. Where this DPA is executed as a standalone agreement, the parties shall be deemed to have agreed to the limitations of liability set out in the Company’s then-current standard MSA, available on request, except to the extent the parties agree otherwise in a signed writing. Nothing in this DPA limits any liability that cannot be limited or excluded under applicable law.
15. Term and Survival
This DPA takes effect on the Effective Date and continues until the later of (a) the termination or expiry of the MSA, and (b) the date on which the Company has returned or destroyed all Personal Health Information and Personal Data in accordance with Section 11. Provisions which by their nature should survive termination — including those relating to confidentiality, security, return or destruction, liability, and cooperation with regulators — shall so survive.
16. Order of Precedence
In the event of any conflict or inconsistency between this DPA and the MSA, this DPA prevails with respect to the Processing of Personal Health Information and Personal Data. In the event of any conflict between this DPA and PHIPA, PHIPA prevails.
17. Notices
Notices to the Company under this DPA — including notices of objections to Subprocessors, audit requests, and breach-related communications — shall be sent to learn@thehealthaisle.com. Notices to the Customer shall be sent to the contact set out in the Order Form, or where no MSA is in effect, to the contact most recently designated by the Customer in writing.
18. Governing Law and Dispute Resolution
This DPA is governed by and shall be construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to its conflict of laws principles. Where this DPA is incorporated into the MSA, the dispute-resolution provisions of the MSA apply. Where this DPA is executed standalone, the parties hereby irrevocably and unconditionally submit to the exclusive jurisdiction of the courts of the Province of Ontario.
19. Counterparts and Electronic Signatures
This DPA may be executed in counterparts, including by electronic signature, each of which shall be deemed an original and all of which together shall constitute one and the same instrument. Where this DPA is incorporated into the MSA as Schedule B, no separate execution is required; execution of the MSA constitutes execution of this DPA.
IN WITNESS WHEREOF, where this DPA is executed as a standalone agreement, the parties have caused this Data Processing Agreement to be duly executed and delivered as of the Effective Date.
Company:
The Health Aisle Inc.
By: ___________________________________
Name: Aliya Kassamali
Title: Authorized representative
I have authority to bind the Company.
Customer:
Legal name recorded in the Customer acceptance receipt
By: ___________________________________
Name: Authorized signatory recorded in the Customer acceptance receipt
Title: Authority recorded in the Customer acceptance receipt
I have authority to bind the Customer.
Schedule 1 — Details of Processing
Subject Matter of Processing: The provision of the Services to the Customer, including operation of the white-labelled educational platform, hosting of Customer and patient content, and related platform services.
Duration of Processing: The term of the MSA (or, where this DPA is standalone, the term during which the Services are provided), plus any post-termination period required to return or destroy the data in accordance with Section 11.
Nature and Purpose of Processing: Hosting, storage, transmission, display, access management, analytics necessary to deliver and improve the Services, and other Processing reasonably incidental to provision of the Services.
Categories of Data Subjects: Patients of the Customer, the Customer’s practitioners and staff (as Sub-Users), and individuals authorized by the Customer to access the Services.
Classification of Data (Personal Health Information vs. Personal Data). The following table classifies the categories of data Processed under this DPA. Classification is applied to the data set held by each party, as the definition of Personal Health Information under section 4 of PHIPA turns on whether the data “relates to” an identifiable individual’s health, healthcare, or health-services payment. Data may be Personal Health Information when held by the Company (in the context of the Services) and become Personal Data when transmitted in a minimized form to a Subprocessor without that health context.
Data Category |
Classification when held by Company |
Classification when transmitted (minimized) to a Subprocessor without health context |
Identifiers (name, date of birth, health-card number) |
PHI |
PHI (health-card number cannot be minimized without breaking service function) |
Contact information (email, phone) |
PHI (by context of Services) |
Personal Data (when transmitted alone, without clinic/course/health context) |
Account credentials (username, password hash) |
Personal Data |
Personal Data |
Billing and payment information (cardholder name, card metadata, transaction amount) |
Personal Data |
Personal Data |
Clinical records (diagnoses, treatment history, prescriptions, referrals, test results) |
PHI |
Not transmitted to Subprocessors outside Canada |
Biometric and vitals data (height, weight, heart rate, glucose) |
PHI |
Not transmitted to Subprocessors outside Canada |
Wellness and lifestyle inputs (exercise, nutrition, sleep, symptoms) |
PHI |
Not transmitted to Subprocessors outside Canada |
Care-related usage data (timestamps, feature interactions, audit trails within the clinical portions of the Service) |
PHI |
Not transmitted to Subprocessors outside Canada |
General usage and device data (page views, IP address, browser, device identifiers, session analytics) |
Personal Data |
Personal Data |
Practitioner-published content (courses, materials made available by the Customer to end users) |
Customer content (not PHI in itself) |
Customer content (served by CDN Subprocessors) |
Rationale. The above classifications reflect PHIPA’s definition of Personal Health Information, which requires the data to “relate to” an identifiable individual’s health, healthcare, or health-services payment. Where the Company transmits data to a Subprocessor without the surrounding clinical or health context (for example, transmitting only cardholder name, email, and transaction amount to a payment processor, with no clinic name, course title, or other health reference in the payload), the transmitted subset does not, in the hands of the Subprocessor, satisfy that “relates to” test and is Personal Data. The Company’s systems and instructions to Subprocessors shall be configured accordingly.
Schedule 2 — Technical and Organizational Security Measures
The Company maintains, at a minimum, the following safeguards (which may be updated from time to time, provided that the protection afforded is not materially diminished):
Encryption. Personal Health Information and Personal Data are encrypted in transit using industry-standard protocols (TLS 1.2 or higher) and at rest using industry-standard methods (AES-256 or equivalent).
Access controls. Role-based access applying least-privilege principles; multi-factor authentication for administrative and privileged accounts; user access reviewed periodically and on personnel changes.
Network and host security. Hosting on commercial cloud infrastructure with managed network controls, including firewalls and segmentation; endpoint and operating-system protections; automated vulnerability scanning and timely patching in accordance with the Company's standard maintenance practices.
Application security. Secure software development practices, including peer code review of changes affecting Personal Health Information, dependency scanning, and security testing of new features. The Company may engage third-party security testing (such as penetration testing) as the Company's security program matures.
Logging and monitoring. Logging of access to systems handling Personal Health Information; routine review of security-relevant events; audit log retention in accordance with applicable law.
Backup and recovery. Regular encrypted backups and documented operational practices for restoring data, which the Company will formalize into written disaster-recovery and business-continuity plans as the Company scales.
Physical security. Hosting in commercial data centres operated by reputable cloud providers with industry-standard physical access controls, environmental controls, and certifications applicable to those providers.
Personnel measures. Written confidentiality obligations for personnel with access to Personal Health Information; appropriate onboarding and access-revocation procedures; security and privacy awareness training.
Vendor management. Risk-appropriate due diligence on Subprocessors; contractual flow-down of relevant obligations; periodic review of Subprocessor security posture.
Incident response. Documented internal incident-response procedures; designated personnel responsible for security incident triage; post-incident review following any confirmed Security Incident.
Data residency. Personal Health Information stored and Processed on infrastructure located in Canada.
Schedule 3 — List of Subprocessors
The following Subprocessors are currently engaged by the Company to Process Personal Health Information or Personal Data in connection with the Services. The Company will update this list, and provide notice of changes, in accordance with Section 6 of this DPA. A current version of this list is also maintained at https://www.healthaislelearn.ca/legal/dpa#schedule-3-list-of-subprocessors.
Subprocessor |
Location |
Processing Activity |
Data Category (per Schedule 1) |
Stripe, LLC |
United States and other locations used by Stripe and its subprocessors |
Payment processing, subscriptions, refunds, and Practitioner payouts |
Personal Data needed for payments and identity checks; no Personal Health Information is intended |
BunnyWay d.o.o. (Bunny.net) |
Global edge network; account storage and replication settings apply |
Video streaming and content delivery for course videos and platform assets |
Course content and general usage data; no Personal Health Information is intended |
Supabase Pte. Ltd. |
Account-configured project region and other locations used by Supabase and its subprocessors |
Hosted database, authentication, APIs, and storage |
Account, profile, legal acceptance, seller, session, and usage data; no Personal Health Information is intended for this launch |
Vercel Inc. |
United States and other locations used by Vercel and its subprocessors |
Web hosting, deployments, content delivery, request routing, and server functions |
Request, session, account, and form data handled by the application; no Personal Health Information is intended for this launch |
Plus Five Five, Inc., doing business as Resend |
United States and other locations used by Resend and its subprocessors |
Transactional email, email verification, acceptance receipts, and platform notices |
Name, email address, message content, and delivery data; no Personal Health Information is intended |
If the Customer requires a point-in-time copy of the Subprocessor list, the Company shall provide one on request to learn@thehealthaisle.com.