Skip to main content

Be among the first to experience Heidi’s next chapter. Join the waitlist.

Heidi AI
Log inGet Heidi free
alt
alt

Resources

  • Explainers

  • FAQs

  • Progress Notes

  • Podcast

  • AI Tools

Why Heidi

  • Impact

  • Awards and Recognition

  • Evaluating Heidi

  • Patient Experience

Compliance

  • Trust Center

  • GDPR

  • HIPAA

  • AU/NZ

  • UK

  • Canada

Support

  • Help Centre

  • Heidi Guides

  • System Status

  • System Requirements

  • Contact Us

Legal

  • Privacy Policy

  • Terms of Service

  • Usage Policy

  • UKGDPR Policy

  • Accessibility

imxYAA

© 2026 Heidi. All rights reserved.

Heidi Desktop goes where the browser can’t.

Dictate anywhere on your screen, capture telehealth audio straight from the call,
and skip the second login.

Download for macOSDownload for Windows
  1. Home
  2. legal

Data Processing Agreement

Heidi Team

29 September 2026•

Table of Contents

  • 1. Definitions

  • 2. Scope, roles and instructions

  • 3. Customer obligations

  • 4. Processing limits, no AI training, and de-identified data

  • 5. Confidentiality and personnel

  • 6. Security

  • 7. Personal Data Breach notification

  • 8. Subprocessors

  • 9. Data Subject requests

  • 10. Impact assessments and consultation

  • 11. Audits

  • 12. International transfers

  • 13. Government and third-party requests

  • 14. Retention, return and deletion

  • 15. Liability

  • Annex 1 — Description of Processing

  • Annex 2 — Technical and Organisational Measures

  • Annex 3 — Subprocessors

  • Annex 4 — Jurisdiction-Specific Terms

This Data Processing Agreement (“DPA”) is incorporated into and forms part of the Heidi Master Services Agreement, Heidi’s Terms of Service, or any other agreement between Customer and Heidi that references this DPA (the “Agreement”), and governs Heidi’s Processing of Customer Personal Data. It is entered into between the customer that is a party to the Agreement (“Customer”) and the Heidi contracting entity identified in the applicable Order Form or, where none is identified, the Heidi entity determined by the Customer Location under the Agreement (“Heidi”). This DPA is deemed executed when the Agreement incorporating it takes effect or, if adopted later, when the parties agree, in accordance with the Agreement, to incorporate this DPA into the Agreement; no separate signature is required, although the parties may countersign it on request. This DPA replaces an earlier data processing agreement between the parties in respect of the same Services only where the parties expressly agree to that replacement.

1. Definitions

Capitalised terms not defined in this DPA have the meanings given in the Agreement. Where the Agreement uses “Content” rather than “Customer Data”, references to Customer Data include that Content, and references to “Output” include outputs generated for Customer. References to “Services” include the Platform and features provided under the Agreement. Where the Agreement uses “De-identified Information”, that term corresponds to “De-Identified Data” in this DPA. If the Agreement does not define “Customer Location” or “Subscription Term”, they mean, respectively, the Customer location used to determine the Heidi contracting entity and the applicable subscription or service term under the Agreement. Where the Agreement uses “Health Information”, that term corresponds to Personal Health Information as used in this DPA. Where the Agreement is not transacted through Order Forms, references to an Order Form mean the applicable subscription, plan or order, references to Fees mean the fees paid for the affected services, references to Users mean the individuals using the Platform under the Agreement, and references to Confidential Information mean non-public information required to be kept confidential under the Agreement. In this DPA:

1.1. “Applicable Data Protection Laws” means the data protection and privacy laws applicable to a party’s Processing of Personal Data under the Agreement, including, as applicable, the laws identified in the Parts of Annex 4 that apply to the Processing.

means the entity that determines the purposes and means of the Processing of Personal Data, and includes equivalent concepts under Applicable Data Protection Laws, such as “business” (California), “responsible party” (South Africa), “organisation” (Singapore), “health information custodian” (Ontario), “custodian” (Alberta), “APP entity” holding the information in its own right (Australia), and “agency” or principal (New Zealand).

1.2. “Controller”

1.3. “Customer Personal Data” means Personal Data contained in Customer Data that Heidi Processes on Customer’s behalf in connection with the Services, including Personal Health Information.

1.4. “Data Subject” means the identified or identifiable individual to whom Personal Data relates, and includes equivalent concepts under Applicable Data Protection Laws (such as “consumer”).

1.5. “Personal Data” means any information relating to an identified or identifiable individual, and includes “personal information”, “personally identifiable information”, “personal health information” and equivalent concepts under Applicable Data Protection Laws.

1.6. “Personal Data Breach” means a breach of Heidi’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Customer Personal Data Processed by Heidi or its Subprocessors.

1.7. “Processing” (and “Process”, “Processed”) has the meaning given under Applicable Data Protection Laws and includes any operation performed on Personal Data, such as collection, use, storage, disclosure and deletion.

1.8. “Processor” means an entity that Processes Personal Data on behalf of a Controller, and includes equivalent concepts under Applicable Data Protection Laws, such as “service provider” (California), “operator” (South Africa), “data intermediary” (Singapore), “information manager” (Alberta), “agent” or “electronic service provider” (Ontario; New Zealand), and a processor of “consumer health data” (Washington; Nevada).

1.9. “Restricted Transfer” means a transfer of Customer Personal Data to a country or recipient that Applicable Data Protection Laws do not permit without additional safeguards, as further described in Annex 4.

1.10. “SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time, including any successor clauses adopted by the European Commission, which will automatically replace them for the purposes of this DPA.

1.11. “Subprocessor” means any third party appointed by or on behalf of Heidi to Process Customer Personal Data.

1.12. “Supervisory Authority” means an independent public authority responsible for supervising Applicable Data Protection Laws, including the regulators identified in Annex 4.

1.13. “US State Privacy Laws” means all applicable comprehensive US state consumer privacy laws and regulations, as amended, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and applicable US state consumer health data laws, including the Washington My Health My Data Act and Nevada SB 370.

2. Scope, roles and instructions

2.1. Roles. As between the parties and in respect of Customer Personal Data, Customer is the Controller (or, where Customer acts on behalf of a third-party Controller, a Processor) and Heidi is a Processor (or subprocessor, as applicable). Annex 4 maps these roles to the equivalent concepts under the laws of each region.

2.2. Instructions. Heidi will Process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers, unless required to do otherwise by law to which Heidi is subject (in which case Heidi will inform Customer of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest). The Agreement (including this DPA and each Order Form and Statement of Work), Customer’s and its authorised Users’ configuration of and use of the Services within the scope permitted by the Agreement, and any further written instructions agreed by the parties, constitute Customer’s complete documented instructions.

2.3. Instruction conflicts. Heidi will promptly inform Customer if, in Heidi’s opinion, an instruction infringes Applicable Data Protection Laws. Heidi may suspend the affected Processing until the parties resolve the conflict, and is not liable for a failure to perform to the extent caused by following Customer’s unlawful instruction.

2.4. Details of Processing. The subject matter, duration, nature and purposes of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.

3. Customer obligations

Customer is responsible for: (a) the accuracy, quality and lawfulness of Customer Personal Data and the means by which it was acquired; (b) establishing and maintaining a lawful basis for the Processing, including obtaining any consents and providing any notices required under Applicable Data Protection Laws (including any patient or individual consents required in the Customer Location); (c) ensuring its instructions comply with Applicable Data Protection Laws; and (d) configuring and using the Services (including retention settings, access controls and integrations) in a manner appropriate for the sensitivity of Customer Personal Data.

4. Processing limits, no AI training, and de-identified data

4.1. Purpose limitation. Heidi will not Process Customer Personal Data for any purpose other than: (a) to provide, operate, maintain, secure and support the Services in accordance with the Agreement; (b) to address, diagnose or prevent technical or security problems; and (c) to comply with law — in each case consistent with Customer’s documented instructions. Heidi will not use Customer Personal Data for advertising, or sell it, or disclose it to any third party for that third party’s own purposes.

4.2.No AI model training. No Customer Data (including Customer Personal Data and Output) will be used as an input to train, fine-tune, or otherwise improve any artificial intelligence model, including any generative artificial intelligence model or large language model, whether operated by Heidi or by any third party. This Section does not limit the use of Customer Data (including Customer Personal Data) to provide, operate, secure, support, test and evaluate the Services for Customer. Such testing and evaluation must comply with Customer’s documented instructions and must not train, fine-tune or adjust any AI model. Section 4.3 governs any permitted use of De-Identified Data, subject to the permissions and restrictions in the Agreement.

4.3. De-identified data. Heidi may create De-Identified Data from Customer Data and use it only to the extent permitted by the Agreement and Applicable Data Protection Laws. This DPA does not itself expand those permissions. Heidi will not attempt to re-identify De-Identified Data and will contractually require any recipient of De-Identified Data to commit to the same. Information is treated as De-Identified Data only if it meets the applicable definition in the Agreement and is no longer Personal Data under Applicable Data Protection Laws. Any continuing contractual restriction on the creation or use of that information, including a restriction on model training, remains effective after de-identification. The Privacy Policy describes processing and does not amend this DPA or expand those permissions.

5. Confidentiality and personnel

Heidi will ensure that every person it authorises to Process Customer Personal Data (including its employees, contractors and agents) is subject to a legally enforceable obligation of confidentiality, receives appropriate data protection and security training, and accesses Customer Personal Data only as needed to provide the Services, on a least-privilege basis.

6. Security

Heidi will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against Personal Data Breaches, as described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risks to individuals. Heidi maintains ISO/IEC 27001:2022, ISO/IEC 42001 and Cyber Essentials Plus certifications and a SOC 2 Type II attestation and will not materially decrease the overall security of the Services during a Subscription Term. Current certificates and security documentation are available via Heidi’s Trust Centre at trust.heidihealth.com.

7. Personal Data Breach notification

7.1. Heidi will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. The notification will describe, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach; and a contact point. Where all details are not available at first notification, Heidi will provide information in phases as it becomes available.

7.2. Heidi will investigate the Personal Data Breach, take reasonable steps to mitigate its effects, and reasonably cooperate with Customer’s own investigation and with Customer’s obligations to notify Supervisory Authorities and Data Subjects. Heidi will not notify a Supervisory Authority or Data Subject of a Personal Data Breach affecting Customer Personal Data on Customer’s behalf unless required by law or instructed by Customer.

7.3. Heidi’s notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability. This Section does not apply to unsuccessful attempts or activities that do not compromise Customer Personal Data (such as blocked attacks or pings). An incident involving Customer, its Users or its systems remains subject to this Section to the extent it constitutes a Personal Data Breach.

8. Subprocessors

8.1. General authorisation. Customer provides a general authorisation for Heidi to engage Subprocessors, and approves the Subprocessors listed at https://trust.heidihealth.com/subprocessors (the “Subprocessor List”, Annex 3), which identifies each Subprocessor’s role and location.

8.2. Notice of changes. Heidi will update the Subprocessor List at least 30 days before a new Subprocessor Processes Customer Personal Data, and provides a mechanism on the Subprocessor List page to subscribe to notifications of changes. Where a change is urgently necessary to maintain the security or continuity of the Services, Heidi may make the change sooner and will notify subscribed customers as soon as reasonably practicable, and Customer retains its objection rights below.

8.3. Objection. Customer may object to a new Subprocessor on reasonable grounds relating to data protection by written notice to compliance@heidihealth.com within 30 days of Heidi’s notice. The parties will work together in good faith to resolve the objection, which may include Heidi not applying the change to Customer’s data, offering a commercially reasonable alternative, or adjusting the affected configuration. If the objection is not resolved within 30 days of Heidi’s receipt of it, Customer may terminate the affected Order Form(s), solely with respect to those Services that cannot be provided without the new Subprocessor, by written notice and without penalty, and Heidi will refund the prepaid, unused Fees for the terminated Services for the remainder of the applicable Subscription Term.

8.4. Flow-down and responsibility. Heidi will enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA (including in relation to Restricted Transfers), and remains responsible to Customer for each Subprocessor’s performance of those obligations.

9. Data Subject requests

9.1. Customer may access, retrieve, correct, export and delete Customer Personal Data through the available functionality of the Services or by requesting Heidi’s assistance. Taking into account the nature of the Processing, Heidi will assist Customer, by appropriate technical and organisational measures and insofar as reasonably possible, in fulfilling Customer’s obligations to respond to Data Subject requests under Applicable Data Protection Laws (including access, correction, deletion, portability, restriction and objection requests).

9.2. If Heidi receives a request from a Data Subject relating to Customer Personal Data, Heidi will promptly notify Customer and will not respond to the request except on Customer’s documented instructions or as required by law (in which case Heidi will, to the extent permitted, inform Customer before responding). Where the Data Subject is a patient of Customer, the parties acknowledge that the request is ordinarily for Customer, as the party responsible for the clinical record, to answer.

10. Impact assessments and consultation

Taking into account the nature of the Processing and the information available to it, Heidi will provide reasonable assistance with data protection impact assessments, transfer risk assessments, and prior consultations with Supervisory Authorities that Customer reasonably considers required under Applicable Data Protection Laws, in each case in relation to Heidi’s Processing of Customer Personal Data. Heidi maintains standard due-diligence documentation (including completed assessment templates) available on request to reduce the burden of such assessments.

11. Audits

11.1. Reports first. Heidi will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including, on written request and subject to confidentiality: its then-current ISO/IEC 27001, ISO/IEC 42001 and Cyber Essentials Plus certificates, SOC 2 Type II report, penetration test summaries, and completed security questionnaires (also available via the Trust Centre). These reports may be shared with Customer’s competent Supervisory Authority.

11.2. Audits. Where Applicable Data Protection Laws grant Customer an audit right that cannot reasonably be satisfied by the materials in Section 11.1, or following a Personal Data Breach affecting Customer Personal Data, or where required by a Supervisory Authority, Customer (or an independent auditor on its behalf that is not a competitor of Heidi and is bound by confidentiality) may audit Heidi’s compliance with this DPA, subject to: (a) at least 30 days’ written notice, unless a Supervisory Authority or Applicable Data Protection Laws require otherwise; (b) no more than one audit in any 12-month period, except where required by a Supervisory Authority or following a Personal Data Breach; (c) the parties agreeing in advance on the scope, timing, duration and security and confidentiality controls of the audit; (d) the audit being conducted during business hours, in a manner that does not unreasonably interfere with Heidi’s operations and does not give access to other customers’ data; and (e) Customer bearing its own costs and reimbursing Heidi’s reasonable time and expenses, except where the audit is required by Applicable Data Protection Laws or reveals, or follows, Heidi’s material non-compliance or a Personal Data Breach caused by Heidi. Customer will promptly share audit findings with Heidi, and the results are Confidential Information.

12. International transfers

12.1. Heidi stores Customer Personal Data in the regional hosting environment applicable to the Customer Location, as described in the Agreement and Heidi’s Trust Centre. Some Processing may be performed in another region by Heidi affiliates or Subprocessors identified in the Subprocessor List.

12.2. Neither party will make a Restricted Transfer of Customer Personal Data except in compliance with Applicable Data Protection Laws and the applicable Part(s) of Annex 4, which set out the transfer mechanisms relied on for each region (including the SCCs, the UK Addendum and the Swiss amendments). If a transfer mechanism relied on under this DPA is invalidated or superseded, the parties will work together in good faith to implement a lawful replacement, and Heidi may update Annex 4 to the extent required by Applicable Data Protection Laws.

13. Government and third-party requests

If Heidi receives a legally binding demand from a government authority or other third party for Customer Personal Data, Heidi will, unless legally prohibited: (a) promptly notify Customer and redirect the requester to Customer; (b) challenge any demand it reasonably considers unlawful and seek to limit its scope through available legal mechanisms; and (c) disclose only the minimum Customer Personal Data necessary to comply. Heidi does not provide any government with direct, unrestricted or back-door access to Customer Personal Data.

14. Retention, return and deletion

14.1. During the term. Customer may access, retrieve, correct, export and delete Customer Personal Data at any time during the term of the Agreement through the available functionality of the Services or by written request to Heidi, and may configure retention settings where available.

14.2. Export. On Customer’s written request made within 30 days after expiry or termination of the applicable Order Form or the Agreement, Heidi will make the associated Customer Data available for export in a commonly used, machine-readable format, as provided in the Agreement.

14.3. Deletion. Following expiry or termination of the Agreement, Heidi will delete Customer Personal Data as follows: (a) on Customer’s written deletion request, Heidi will delete Customer Personal Data from its systems (including those of Subprocessors) within 30 days of the request, except that deletion from backup and archival systems will occur within 90 days, during which the data remains isolated, protected and subject to this DPA; and (b) absent a request under (a) within 90 days of expiry or termination, Heidi will delete Customer Personal Data in accordance with its standard retention schedules. On written request, Heidi will certify in writing that it has complied with this Section.

14.5. Retention exceptions. Heidi may retain Customer Personal Data to the extent: (a) required by Applicable Data Protection Laws or other applicable law; (b) reasonably necessary to resolve a dispute between the parties; or (c) reasonably necessary to detect, prevent or address fraud, abuse or unsafe use of the Services — provided in each case that Heidi maintains the confidentiality of, and continues to apply this DPA to, the retained data and does not further Process it except for those purposes.

15. Liability

Each party’s and its affiliates’ total aggregate liability arising out of or relating to this DPA (including the SCCs and any Part of Annex 4), whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement, including any enhanced cap that the Agreement applies to breaches of confidentiality, security or privacy obligations. Nothing in this Section limits a Data Subject’s rights against either party under Applicable Data Protection Laws or the SCCs, or any liability that cannot lawfully be limited.

16. Term, precedence and general

16.1. Term. This DPA takes effect as described in its preamble and remains in force until Heidi has ceased all Processing of Customer Personal Data and completed its obligations under Section 14, notwithstanding the expiry or termination of the Agreement.

16.2. Precedence. In the event of a conflict, the order of precedence is: (a) the SCCs (and any other Annex 4 transfer mechanism); (b) any business associate agreement between the parties, in respect of protected health information; (c) the applicable Part(s) of Annex 4; (d) the body of this DPA; and (e) the Agreement. This DPA prevails over the Agreement with respect to the Processing of Personal Data, as provided in the Agreement.

16.3. Updates. Heidi may update this DPA on reasonable notice to Customer to the extent required to reflect changes in Applicable Data Protection Laws or the adoption of new transfer mechanisms, provided the update does not materially reduce the protection of Customer Personal Data.

16.4. Equivalent instruments. Where Applicable Data Protection Laws in the Customer Location require an equivalent instrument (however described), this DPA constitutes that instrument to the extent it may lawfully do so, as further provided in Annex 4.

16.5. Governing law. This DPA is governed by the law governing the Agreement, except as otherwise provided in Annex 4 or required by the SCCs.

Annex 1 — Description of Processing

ItemDescription
Subject matterHeidi’s provision of the Platform and Services under the Agreement: AI-assisted clinical documentation, research and knowledge, communication, patient-facing and assistive products and features, including task functionality and connections to other systems where enabled by Customer.
DurationThe term of the Agreement, plus the retention, return and deletion period in Section 14.
Nature and purposesCollection, recording, organisation, storage, retrieval, transcription, generation of documentation and outputs, preparation and execution of tasks and recording of task steps and results, storage and application of preferences and memory, transmission at Customer’s direction (including to systems Customer connects), and deletion — in each case to provide, operate, maintain, secure and support the Services on Customer’s documented instructions.
Categories of Personal DataUser account and professional data (names, contact details, role, specialty, credentials); patient identity and contact data; Personal Health Information and other special category data contained in consultations, transcripts, notes, documents, queries, connected systems, task instructions, task records and screen captures where those features are used (which may include information about health, sex life or sexual orientation, racial or ethnic origin, and other categories individuals disclose in a clinical setting); task instructions, steps and results; access tokens or credentials for authorised connections; preferences and memory; payment data; technical, device and usage data.
Categories of Data SubjectsCustomer’s Users (clinicians, staff and administrators); patients of Customer and other individuals whose information is contained in Customer Data (for example, family members or carers mentioned in a consultation).
Sensitive data protectionsProcessed subject to the safeguards in Annex 2, including encryption in transit and at rest, access controls and least-privilege access, de-identification and pseudonymisation controls where applied, logging, and staff confidentiality and training.
FrequencyContinuous, as initiated by Customer and its Users.
RetentionAs configured or instructed by Customer within the Services, and per Section 14 of this DPA. These requirements apply to all Customer Personal Data, including task records, screen captures, connection tokens or credentials and memory, and to copies held by Subprocessors and in backups as provided in Section 14.
SCC Annex mappingFor the purposes of the SCCs: Annex I(A) (parties) is completed by the Agreement and this DPA’s preamble; Annex I(B) is this Annex 1; Annex I(C) (competent supervisory authority) is determined under Clause 13 of the SCCs; Annex II is Annex 2 of this DPA; Annex III is Annex 3 of this DPA.

Annex 2 — Technical and Organisational Measures

MeasureDescription
Governance and certificationsInformation security management system certified to ISO/IEC 27001:2022; AI management system certified to ISO/IEC 42001; SOC 2 Type II attestation; Cyber Essentials Plus. Designated Data Protection Officer: Yassin Omar (compliance@heidihealth.com).
EncryptionPersonal Data encrypted in transit (TLS 1.2 or higher) and at rest (AES-256), with keys managed through a dedicated cloud key management service.
Pseudonymisation and de-identificationDe-identification and pseudonymisation pipelines applied where the Services or the Agreement provide for them, with separation of any information that could enable re-attribution and controls addressing singling out, linkability and inference.
Access controlRole-based access control on least-privilege principles; unique credentials; multi-factor authentication for internal access to production systems; quarterly access reviews; prompt de-provisioning on role change or departure; support access to Customer Data only with permission and on documented need.
Identity and authentication (product)Federated authentication through an enterprise identity provider supporting single sign-on (SAML/OIDC) and multi-factor authentication, configurable at the organisation level.
Network and infrastructure securityCloud infrastructure with logical tenant isolation, virtual private cloud segmentation, firewalls and web application firewalls, intrusion detection, hardening, and a managed vulnerability and patch management program.
Regional hostingCustomer Personal Data stored in the regional hosting environment applicable to the Customer Location; Subprocessor locations published in the Subprocessor List.
Logging and monitoringAudit logs of user access, data access, system changes and security events, retained for at least 12 months; continuous security monitoring and alerting; 24/7 incident response.
Secure development and testingSecure development lifecycle, code review, segregated environments, and at least annual independent penetration testing by an accredited (CREST) provider.
PersonnelBackground checks at hiring; binding confidentiality obligations; security and privacy training at onboarding and at least annually.
Vendor managementRisk-based Subprocessor due diligence before engagement and periodically thereafter; written contracts with flow-down obligations per Section 8.4.
Business continuity and incident managementDocumented business continuity, disaster recovery and incident response plans, tested at least annually; backup and restoration procedures; incident notification per Section 7 (in any event within 72 hours).
Physical securityProduction infrastructure hosted with leading cloud providers whose physical and environmental controls are independently certified and reviewed by Heidi at least annually.

Annex 3 — Subprocessors

The current list of Heidi’s Subprocessors, including each Subprocessor’s role and the location(s) in which it Processes Customer Personal Data, is maintained in our Trust Centre. The page includes a mechanism to subscribe to notifications of changes. Sections 8.2 and 8.3 of this DPA govern notice of, and objections to, new Subprocessors.

Annex 4 — Jurisdiction-Specific Terms

Each Part of this Annex 4 applies where, and to the extent that, Heidi’s Processing of Customer Personal Data is subject to the laws of the region named in that Part. If a Part conflicts with the body of this DPA, the Part prevails to the extent of the conflict. More than one Part may apply to the same Processing.

Part A — European Economic Area

1. Laws. “EU Data Protection Law” means Regulation (EU) 2016/679 (the “GDPR”), Directive 2002/58/EC, and the national laws implementing or supplementing them, as amended. Applicable Data Protection Laws include EU Data Protection Law where this Part applies.

2. Restricted transfers. To the extent a transfer of Customer Personal Data is a transfer out of the EEA to a country not covered by a European Commission adequacy decision, the SCCs are incorporated into this DPA and deemed executed by the parties, as follows: (a) Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is a Processor; (b) in Clause 7, the optional docking clause does not apply; (c) in Clause 9, Option 2 (general written authorisation) applies, and the time period is as set out in Section 8 of this DPA; (d) in Clause 11, the optional language does not apply; (e) in Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; (f) in Clause 18(b), disputes will be resolved before the courts of Ireland; and (g) the Annexes of the SCCs are completed as set out in Annex 1 of this DPA. Onward transfers by Heidi to Subprocessors outside the EEA are made under the SCCs (Module Three) or another valid transfer mechanism.

3. Supervisory authority; governing law. The competent Supervisory Authority is determined under Clause 13 of the SCCs. Where this Part applies, this DPA is governed by the laws of Ireland.

Part B — United Kingdom

1. Laws. “UK Data Protection Law” means the UK GDPR and the Data Protection Act 2018, each as amended (including by the Data (Use and Access) Act 2025), and the Privacy and Electronic Communications (EC Directive) Regulations 2003. Applicable Data Protection Laws include UK Data Protection Law where this Part applies.

2. Restricted transfers. To the extent a transfer of Customer Personal Data is a transfer out of the United Kingdom not permitted without safeguards under UK Data Protection Law (assessed under the statutory data protection test), the SCCs as completed in Part A and as modified by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner (the “UK Addendum”) apply: Tables 1 to 3 of the UK Addendum are completed with the information in this DPA and its Annexes; in Table 4, neither party may end the UK Addendum when the Approved Addendum changes.

3. Regulator; governing law. The relevant Supervisory Authority is the Information Commissioner’s Office. Where this Part applies, this DPA is governed by the laws of England and Wales.

Part C — Switzerland

1. Laws. “Swiss Data Protection Law” means the Swiss Federal Act on Data Protection of 25 September 2020 (“FADP”) and its ordinances, as amended. Applicable Data Protection Laws include Swiss Data Protection Law where this Part applies.

2. Restricted transfers. To the extent a transfer of Customer Personal Data is a transfer from Switzerland to a country not providing adequate protection under the FADP, the SCCs as completed in Part A apply with these amendments: references to the GDPR are read as references to the FADP; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); references to “Member State” do not prevent Data Subjects habitually resident in Switzerland from enforcing their rights in Switzerland; and, to the extent the FADP so requires, the SCCs also protect the data of legal entities.

3. Regulator. The relevant Supervisory Authority is the FDPIC.

Part D — United States

1. Service provider terms. Where US State Privacy Laws apply, Heidi is Customer’s “service provider” or “processor”, and Heidi will not: (a) “sell” or “share” Customer Personal Data (as those terms are defined under US State Privacy Laws); (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes described in this DPA and the Agreement, or outside the direct business relationship between the parties; or (c) combine Customer Personal Data with Personal Data it receives from other persons, except as permitted by US State Privacy Laws. Heidi certifies that it understands these restrictions and will comply with them. Heidi will notify Customer without undue delay if it determines it can no longer meet its obligations under US State Privacy Laws, in which case Customer may take reasonable and appropriate steps in accordance with the Agreement to stop and remediate any unauthorised Processing. Heidi grants Customer the rights to take such steps as US State Privacy Laws require.

2. Consumer health data. Where Customer Personal Data includes “consumer health data” under applicable US state consumer health data laws, this DPA constitutes the processor contract those laws require, and Heidi will Process such data only pursuant to this DPA and Customer’s instructions.

3. HIPAA. Where Customer is a “covered entity” or “business associate” and Customer Data includes “protected health information” (each as defined under HIPAA), the business associate agreement entered into between the parties governs that protected health information and prevails over this DPA with respect to it. This DPA otherwise continues to apply to Customer Personal Data that is not protected health information.

4. Governing law. Where this Part applies and no other Part governs, this DPA is governed by the law governing the Agreement.

Part E — Canada

1. Laws. “Canadian Privacy Law” means the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy and health privacy legislation, including Ontario’s Personal Health Information Protection Act, 2004 (“PHIPA”), Alberta’s Health Information Act (“HIA”), and Québec’s Act respecting the protection of personal information in the private sector, each as amended. Applicable Data Protection Laws include Canadian Privacy Law where this Part applies.

2. Roles. Heidi Processes Customer Personal Data as Customer’s service provider: as an agent or electronic service provider for the purposes of PHIPA and O. Reg. 329/04 (and Heidi will not use personal health information except as necessary to provide the Services, will not disclose it except as this DPA and the Agreement permit, and will ensure its personnel are bound accordingly); as an information manager for the purposes of section 66 of the HIA, and this DPA constitutes the information manager agreement required by that section; and as a mandatary for the purposes of Québec law.

3. Hosting. Customer Personal Data of Canadian customers is stored in Canada (AWS Canada Central region), including backups. Subprocessors and their locations are identified in the Subprocessor List.

4. Québec. Where Québec law applies: Heidi will notify Customer without undue delay of any confidentiality incident involving Customer Personal Data and will assist Customer with its obligations to assess and record the incident and notify the Commission d’accès à l’information and affected persons; Heidi will assist Customer with privacy impact assessments relating to communications of Customer Personal Data outside Québec; and the person in charge of the protection of personal information at Heidi is Yassin Omar (compliance@heidihealth.com), as also identified in Annex 2.

5. Regulators. The relevant regulators include the Office of the Privacy Commissioner of Canada, the Ontario Information and Privacy Commissioner, the Alberta Office of the Information and Privacy Commissioner, and the Commission d’accès à l’information du Québec.

Part F — Australia

1. Laws. “Australian Privacy Law” means the Privacy Act 1988 (Cth), including the Australian Privacy Principles (“APPs”) and the Notifiable Data Breaches scheme, together with applicable State and Territory health records legislation, each as amended. Applicable Data Protection Laws include Australian Privacy Law where this Part applies. The parties acknowledge that Australian Privacy Law does not distinguish between controllers and processors and that each party may be an APP entity in respect of personal information it holds; as between the parties, Heidi handles Customer Personal Data only for Customer’s purposes as described in this DPA.

2. Security. Without limiting Section 6, Heidi will take the steps required under APP 11 to protect Customer Personal Data from misuse, interference and loss, and from unauthorised access, modification or disclosure.

3. Hosting and overseas arrangements. Customer Personal Data of Australian customers is stored in Australia (AWS Sydney region). Where any Processing is performed by a Subprocessor located outside Australia, Heidi will ensure that contractual safeguards are in place requiring the Subprocessor to handle the information in a manner consistent with the APPs, as contemplated by APP 8.1, and the Subprocessor and its location will be identified in the Subprocessor List. Heidi remains accountable for Customer Personal Data it discloses to overseas recipients in accordance with Australian Privacy Law.

4. Data breaches. Without limiting Section 7, upon becoming aware of an eligible data breach, or of circumstances giving reasonable grounds to suspect one, affecting Customer Personal Data, Heidi will notify Customer without undue delay and in any event within 72 hours, and will provide the information and cooperation Customer reasonably requires to conduct its assessment and meet its notification obligations under Part IIIC of the Privacy Act.

5. Health records laws. Where Customer Personal Data comprises health information, Heidi will Process it in a manner consistent with applicable Health Privacy Principles under State and Territory health records legislation, so as to enable Customer to meet its obligations under that legislation.

6. Contact; governing law. Heidi’s designated privacy contact for Australia is Yassin Omar (yassin@heidihealth.com). Where this Part applies, this DPA is governed by the laws of Victoria, Australia.

Part G — New Zealand

1. Laws. “NZ Privacy Law” means the Privacy Act 2020 and the Health Information Privacy Code 2020, each as amended. Applicable Data Protection Laws include NZ Privacy Law where this Part applies.

2. Agency. Heidi holds and Processes Customer Personal Data solely as Customer’s agent for the purposes of section 11 of the Privacy Act 2020, for the purposes of providing the Services and not for its own purposes (other than as expressly permitted by the Agreement).

3. Hosting and offshore safeguards. Customer Personal Data of New Zealand customers is stored in Australia. Heidi’s arrangements with Subprocessors include contractual safeguards requiring protection comparable to that required by NZ Privacy Law, consistent with IPP 12 and rule 12 of the Health Information Privacy Code.

4. Assistance. Heidi will assist Customer in meeting its obligations under NZ Privacy Law, including notifiable privacy breach assessment and notification, and access and correction requests. The relevant regulator is the Office of the Privacy Commissioner.

Part H — Singapore

1. Laws. “Singapore Privacy Law” means the Personal Data Protection Act 2012 and its regulations, as amended. Applicable Data Protection Laws include Singapore Privacy Law where this Part applies.

2. Data intermediary. Heidi Processes Customer Personal Data as Customer’s data intermediary. Heidi will comply with the protection and retention limitation obligations under Singapore Privacy Law, will notify Customer without undue delay of any data breach affecting Customer Personal Data so that Customer can meet its assessment and notification obligations to the Personal Data Protection Commission, and will assist Customer as described in this DPA.

3. Transfers. Where Customer Personal Data is transferred outside Singapore, Heidi will ensure the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to Singapore Privacy Law. Heidi’s Data Protection Officer is identified in Annex 2.

Part I — South Africa

1. Laws. “South African Privacy Law” means the Protection of Personal Information Act 4 of 2013 (“POPIA”), as amended. Applicable Data Protection Laws include South African Privacy Law where this Part applies. References in this DPA to Controller include “responsible party”, to Processor include “operator”, and to Personal Data include “personal information”, as defined in POPIA.

2. Security and notification. Without limiting Sections 6 and 7, Heidi will implement the measures contemplated by section 19 of POPIA and will notify Customer without undue delay of any security compromise (section 22) affecting Customer Personal Data, with sufficient information for Customer to meet its obligations.

3. Transfers; contact. Customer Personal Data of South African customers is stored in the European Union, which the parties agree provides a level of protection substantially consistent with POPIA for the purposes of section 72. Heidi will not transfer Customer Personal Data outside the EU/EEA except with adequate protections in compliance with section 72. Heidi’s Information Officer for South Africa is John Stanley Giles of Michalsons (john@michalsons.com). Where this Part applies, this DPA is governed by the laws of the Republic of South Africa.

Part J — United Arab Emirates

1. Laws. “UAE Data Protection Law” means UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, together with its executive regulations as and when issued, and, where applicable, the DIFC Data Protection Law No. 5 of 2020, each as amended. Applicable Data Protection Laws include UAE Data Protection Law where this Part applies.

2. Transfers. To the extent a transfer of Customer Personal Data out of the UAE requires safeguards under UAE Data Protection Law, the SCCs as completed in Part A also apply to that transfer, and the parties intend them to constitute appropriate safeguards notwithstanding the absence of UAE-approved standard clauses or adequacy determinations at the date of this DPA.

3. Health data. Heidi will accept health data relating to health services provided in the UAE only where storage and processing arrangements that comply with UAE health data laws, including Federal Law No. 2 of 2019, are in place, whether through hosting arrangements or an approval or exception granted by the competent health authority, and Customer must not submit such health data until Heidi has confirmed those arrangements.

4. Governing law. Where this Part applies, this DPA is governed by the laws of England and Wales (without affecting the governing law of the SCCs).

Part K — Indonesia

1. Laws. “Indonesian Privacy Law” means Law No. 27 of 2022 on Personal Data Protection (“UU PDP”), together with its implementing regulations as and when issued and, to the extent applicable, Government Regulation No. 71 of 2019 on Electronic Systems and Transactions, each as amended. Applicable Data Protection Laws include Indonesian Privacy Law where this Part applies. Customer is the personal data controller and Heidi is the personal data processor for UU PDP purposes.

2. Lawful basis. Customer warrants that it has a lawful basis under Article 20 of UU PDP for each Processing activity it instructs, including any consent required for the Processing of health information as specific personal data and for transfers outside Indonesia.

3. Transfers. For transfers of Customer Personal Data outside Indonesia, the parties rely on the binding contractual protections in this DPA as appropriate safeguards under Article 56, supported by any consent obtained by Customer. Where Customer Personal Data forms part of an electronic medical record subject to Indonesian health regulations requiring onshore storage, the parties will ensure the hosting arrangements comply with those regulations.

4. Breach. Heidi will provide the information required by Section 7 in time for Customer to meet its notification deadline of 3 x 24 hours under Article 46 of UU PDP, and will not notify the Indonesian authority or individuals directly unless required by law or instructed by Customer.

5. Governing law. Where this Part applies, this DPA is governed by the laws of the Republic of Indonesia.