Legal · DPA

Data Processing Addendum

This DPA forms part of the agreement between Customer and MyOrbit Health, Inc. and governs our processing of personal data on Customer's behalf. Where Protected Health Information is involved, the Business Associate Agreement controls.

Last updated · August 13, 2026

Order of precedence

For Protected Health Information, the executed Business Associate Agreement controls over this DPA. For all other personal data, this DPA controls over conflicting terms in the underlying agreement. Request a countersigned copy at legal@myorbithealth.com.

01

Definitions

  • "Personal data" means information relating to an identified or identifiable individual that we process on Customer's behalf under the agreement.
  • "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • "PHI" means Protected Health Information as defined at 45 C.F.R. § 160.103.
  • "Subprocessor" means a third party engaged by us to process personal data on Customer's behalf.
  • "Security incident" means a confirmed unauthorized access to, acquisition of, or disclosure of personal data in our custody.
  • "Applicable privacy law" means U.S. federal and state privacy and health-data laws applicable to the processing, including HIPAA, the CCPA as amended by the CPRA, and comparable state statutes.

02

Roles of the parties

Customer determines the purposes and means of processing and is the controller or business (and, where applicable, the Covered Entity). We process personal data only on Customer's documented instructions and act as processor, service provider, and — for PHI — Business Associate. We do not determine the purposes of processing, and we do not use personal data for our own independent commercial purposes.

Service-provider certifications

As a service provider under the CCPA, we certify that we will not sell or share personal data; will not retain, use, or disclose it except to perform the services, for internal use to build or improve service quality as permitted, to detect security incidents, to comply with law, or as otherwise permitted by statute; will not combine it with personal data received from other sources except as permitted; and will comply with the same restrictions when engaging any subprocessor.

03

Scope and instructions

The subject matter, duration, nature, purpose, data categories, and data subjects are described in Annex A. We will notify Customer if, in our reasonable opinion, an instruction would violate applicable privacy law, and may suspend the affected processing until the instruction is amended or confirmed.

04

Confidentiality and personnel

Access to personal data is limited to personnel who need it to deliver the services. Personnel are bound by written confidentiality obligations that survive their engagement, receive privacy and security training at hire and annually, and are subject to disciplinary action for violations.

05

Security measures

We implement and maintain the technical and organizational measures set out in Annex B, appropriate to the risk. We may update those measures provided the overall level of protection is not materially reduced.

06

Subprocessors

Customer authorizes our use of the subprocessors listed at myorbithealth.com/subprocessors, which is Annex C to this DPA. We remain responsible for their performance, impose written obligations materially equivalent to ours, and execute a Business Associate Agreement with any subprocessor that may encounter PHI.

We will give at least thirty (30) days' notice before adding or replacing a subprocessor. Customer may object on reasonable, documented data-protection grounds within that period; if we cannot provide a commercially reasonable alternative, Customer may terminate the affected service without penalty for the remainder of the then-current term.

07

Data subject requests and cooperation

We provide functionality allowing Customer to access, correct, export, and delete personal data. If we receive a request directly from an individual whose data we process for Customer, we will not respond substantively — except to acknowledge receipt and redirect — and will forward it to Customer without undue delay. We provide reasonable assistance with data-protection assessments and regulator inquiries relating to the processing.

08

Security incident notification

We will notify Customer's designated contact without undue delay, and in any event within seventy-two (72) hours, after confirming a security incident affecting Customer's personal data, providing the nature of the incident, categories and approximate volume of data involved, likely consequences, and remedial steps taken or planned, as that information becomes available. For PHI, breach reporting follows the Business Associate Agreement and 45 C.F.R. § 164.410. Customer is responsible for any notification to individuals and regulators, and we will provide reasonable assistance. Our notification is not an acknowledgment of fault.

09

Audit and evidence

On written request, no more than once in any twelve-month period unless required by a regulator or following a confirmed security incident, we will provide our current third-party audit report, penetration-test executive summary, and completed security questionnaire under NDA. Where that evidence is genuinely insufficient to demonstrate compliance, Customer may conduct an on-site or remote audit on at least thirty (30) days' notice, during business hours, subject to confidentiality, without accessing other customers' data, and at Customer's expense.

10

Location of processing

Processing occurs in the United States. PHI is not stored or processed outside the United States. We do not offer these services in the European Economic Area, the United Kingdom, or Switzerland, and no standard contractual clauses are incorporated. If Customer requires processing in another region, that must be agreed in writing before any transfer.

11

Return and deletion

On termination or expiry, we will, at Customer's election made within thirty (30) days, make personal data available for export or delete it. Absent an election, we delete personal data from active systems within ninety (90) days, with encrypted backups aging out on their standard cycle. We may retain personal data where required by law, including HIPAA audit-log and medical-record retention obligations, and will continue to protect it under this DPA for as long as we hold it. Deletion certification is available on request.

12

Liability and term

Each party's liability under this DPA is subject to the limitations of liability in the underlying agreement, except where applicable law prohibits such limitation. This DPA takes effect when the underlying agreement takes effect and continues for as long as we process personal data on Customer's behalf.

Annex A

Details of processing

ItemDetail
Subject matterProvision of telehealth practice-management, intake, workflow, prescribing-integration, and administrative software
DurationThe term of the underlying agreement, plus the deletion period in Section 11
Nature and purposeHosting, storage, transmission, display, backup, support, security monitoring, and deletion, as instructed by Customer
Categories of data subjectsCustomer personnel and administrators; licensed providers; patients of the partner clinic; business contacts
Categories of personal dataIdentifiers and contact details; authentication metadata; professional licensure details; clinical and treatment information; prescription and pharmacy routing data; billing and transaction data; support correspondence
Sensitive dataHealth information, including PHI, and government identifiers where required for credentialing — processed only as instructed and under the BAA
FrequencyContinuous, for the duration of the agreement
RetentionAs instructed by Customer, subject to legal retention requirements

Annex B

Technical and organizational measures

Control areaMeasure
EncryptionTLS 1.2+ in transit; AES-256 at rest for databases, object storage, and backups; managed key storage with restricted administrative access
Access controlSingle sign-on with mandatory MFA; role-based least-privilege authorization enforced at the data layer; quarterly access review; same-business-day revocation on role change or departure
Tenant isolationLogical separation of customer data with authorization enforced server-side, not solely in the interface
Audit loggingActor, action, record, and timestamp logged for PHI access; retained at least six years on write-limited storage; monitored for anomalous access
Secure developmentMandatory peer review; automated dependency and secret scanning; static analysis; separate development, staging, and production environments; production data excluded from lower environments
Vulnerability managementContinuous automated scanning, third-party penetration testing at least annually and after significant change, remediation windows defined by severity
ResilienceEncrypted automated backups with periodic restore testing; documented business continuity and disaster recovery plans exercised at least annually
Incident responseDocumented plan covering detection, triage, containment, eradication, recovery, and post-incident review, with defined notification paths
Physical securityProcessing in audited third-party data centers with biometric or badge access control, monitoring, and environmental protection
PersonnelBackground screening where lawful, written confidentiality obligations, HIPAA privacy and security training at hire and annually
Risk managementAnnual HIPAA Security Rule risk analysis under 45 C.F.R. § 164.308(a)(1) with documented remediation tracking
Data minimization and deletionField-level collection limits, configurable retention, and verifiable deletion workflows

Further detail is published on our security page.

Annex C

Approved subprocessors

The current list of approved subprocessors, including each one's function, data categories, region, and Business Associate Agreement status, is published and maintained at myorbithealth.com/subprocessors and is incorporated into this DPA by reference. To receive email notice of changes, contact privacy@myorbithealth.com.

13

Contact and execution

To request a countersigned DPA or Business Associate Agreement, or to register a data-protection contact for notices, email legal@myorbithealth.com.