Effective date: May 1, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Public Health in Tech, LLC (“PHIT”) and the applicable customer or employer (“User”) that uses PHIT’s Services and requires PHIT to process Personal Data on User’s behalf.
This DPA applies only to the extent PHIT processes Personal Data on behalf of User in connection with the Services.
For purposes of this DPA:
“Personal Data” means information relating to an identified or identifiable individual that PHIT processes on User’s behalf in connection with the Services.
“Processing” means any operation performed on Personal Data, including collection, access, use, storage, disclosure, or deletion.
“Data Subject” means the individual to whom Personal Data relates.
“Security Incident” means a confirmed unauthorized access to, acquisition, disclosure, alteration, or destruction of Personal Data maintained by PHIT, excluding unsuccessful attempts or events that do not result in unauthorized access to Personal Data.
Capitalized terms not defined in this DPA have the meanings given in the applicable agreement or PHIT’s Terms of Use.
For Personal Data processed by PHIT on User’s behalf:
PHIT will process Personal Data only as reasonably necessary to provide the Services, in accordance with User’s documented instructions, the applicable agreement, and applicable law.
PHIT will not sell Personal Data processed on User’s behalf or use such Personal Data for purposes unrelated to providing the Services, except as permitted by the applicable agreement or law.
User is responsible for:
PHIT will ensure that personnel authorized to process Personal Data are subject to confidentiality obligations appropriate to their role.
PHIT will not disclose Personal Data except as necessary to provide the Services, as authorized by User, or as required by law.
PHIT will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, acquisition, use, disclosure, alteration, or destruction.
PHIT will maintain safeguards appropriate to the nature of the Personal Data and the risks associated with its processing.
If PHIT becomes aware of a Security Incident involving Personal Data processed on User’s behalf, PHIT will notify User without undue delay, to the extent required by applicable law.
PHIT will provide reasonably available information regarding the nature of the Security Incident and will take reasonable steps to investigate, mitigate, and remediate the Security Incident.
User authorizes PHIT to use third-party service providers that process Personal Data on PHIT’s behalf in connection with the Services (“Subprocessors”).
PHIT will require Subprocessors to maintain data-protection and confidentiality obligations appropriate to the services they perform.
PHIT remains responsible for its Subprocessors’ performance of their applicable data-processing obligations.
To the extent reasonably necessary, PHIT will provide reasonable assistance to User in responding to legally required requests from Data Subjects relating to their Personal Data processed through the Services.
User remains responsible for responding to Data Subject requests and determining whether a request is legally valid.
PHIT will retain Personal Data for as long as reasonably necessary to provide the Services or as otherwise required by the applicable agreement or law.
Upon termination of the applicable Services, PHIT will, at User’s direction, delete or return Personal Data, except to the extent retention is required by law or the information remains in routine backup or archival systems subject to appropriate protections.
PHIT will provide reasonable cooperation to User regarding legally required data-protection obligations applicable to PHIT’s processing of Personal Data, taking into account the nature of the processing and information reasonably available to PHIT.
PHIT may charge User its reasonable costs for material assistance beyond the ordinary scope of the Services where permitted by the applicable agreement.
As between PHIT and User, User retains all rights in Personal Data provided by or on behalf of User. Nothing in this DPA transfers ownership of Personal Data to PHIT. PHIT may use aggregated or de-identified information that does not identify User or an individual for legitimate business purposes, including analytics, security, product development, and improvement of the Services, to the extent permitted by applicable law.
This DPA remains effective for so long as PHIT processes Personal Data on User’s behalf. The obligations relating to confidentiality, security, data retention and deletion, and other provisions that by their nature should survive will survive termination of this DPA.
If there is a conflict between this DPA and the applicable agreement, this DPA will control solely with respect to the parties’ respective data-processing obligations. Except as expressly modified by this DPA, the applicable agreement remains unchanged and in full force and effect.
Questions regarding these Terms may be directed to Public Health in Tech, LLC at hello@publichealthintech.com.