Template addendum setting out how Care Tales processes personal data as a processor under GDPR and UK data protection law.
This is the template Care Tales offers. The version that binds the parties is the one they sign, with the bracketed details completed.
This Data Processing Addendum (the "DPA") is entered into by and between [CUSTOMER LEGAL NAME], a [ENTITY TYPE] with its principal place of business at [CUSTOMER ADDRESS] (the "Customer"), and Care Tales, Inc., a [STATE OF INCORPORATION] corporation with its principal place of business at [CARE TALES ADDRESS] ("Care Tales").
It forms part of the [NAME OF UNDERLYING AGREEMENT] between the parties dated [DATE] (the "Agreement") and applies to the extent Care Tales processes personal data to which the GDPR or UK data protection law applies.
1.1 "GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as incorporated into the law of the United Kingdom by the European Union (Withdrawal) Act 2018, read with the Data Protection Act 2018. "Data Protection Law" means the GDPR, the UK GDPR and any other applicable law on the protection of personal data.
1.2 "Controller", "processor", "data subject", "personal data", "processing", "special categories of personal data", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
1.3 "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
1.4 "Customer Personal Data" means personal data that Care Tales processes on the Customer's behalf under the Agreement.
1.5 "Subprocessor" means a processor engaged by Care Tales to process Customer Personal Data.
2.1 The Customer is the controller of Customer Personal Data. Care Tales is the processor. Where the Customer is itself a processor for a third party controller, Care Tales is a subprocessor and this DPA applies with references to the controller read accordingly.
2.2 Care Tales is an independent controller for data it processes for its own purposes and not on the Customer's behalf, namely account and billing records of the Customer's administrative contacts, service telemetry that does not identify patients and analytics on the Care Tales marketing site. That processing is outside this DPA and is governed by the Care Tales privacy policy.
2.3 The Customer is responsible for establishing a lawful basis for the processing it instructs, for meeting its own transparency obligations to data subjects and, where relevant, for its obligations concerning special categories of personal data under Articles 9 and 35 GDPR.
3.1 Subject matter. The provision of the Care Tales patient education platform, comprising interactive education modules delivered by QR code, link, embedded widget, web and mobile apps, an organization chat assistant, module analytics for the Customer and related support.
3.2 Duration. From the date of this DPA until the end of the Agreement and the completion of deletion or return under clause 11.
3.3 Nature of the processing. Collection, storage, retrieval, use, transmission to subprocessors including AI models for the generation of responses and content, aggregation into reports, erasure and destruction, all by automated means.
3.4 Purpose. To deliver patient education content to the Customer's patients in their language and at an appropriate reading level, to answer patient questions from the Customer's approved knowledge base, to report engagement to the Customer and to operate, secure and support the platform.
4.1 Categories of data subject. Patients and other members of the public who open a module or use the chat assistant, whether or not they hold an account; account holders on the web and mobile apps; and the Customer's staff and clinicians who hold provider or administrative access.
4.2 Categories of personal data.
(a) Patients without an account: module identifiers opened, timestamps, full user agent string, IP address truncated to a /24 on the hosted paths, bot flag, QR or link source, a persistent visitor identifier in browser storage, pages completed and per page timestamps, reading level and level switches, quiz answers including which wrong option was chosen, media and interface events, pre and post module survey answers, a rating and a free text rating comment and a phone number with a consent record where a link is sent by SMS.
(b) Chat assistant: verbatim patient messages and verbatim assistant responses, session metadata including page URL and title and message counts, per visitor counters and daily and lifetime usage rollups. On the embedded WordPress widget only, the full untruncated IP address, country, city, region, coordinates, browser, operating system, device type, language, timezone, screen size and referrer. The in-module assistant stores no message text, only counts.
(c) Account holders: email address, display name, photo, sign-in providers, role, timestamps, first and last name, phone number, reading level, organization membership, language, chosen health areas and an optional free text health area, per module progress, bookmarks, ratings, free text feedback, survey answers and stored chat history.
(d) Legacy account fields: where present from an earlier onboarding flow, date of birth, conditions, medications, gender, education, barriers, motivations, learning styles and confidence.
(e) Customer staff: the account fields above plus role, portal permissions, two factor enrolment state, internal connector grants and an audit log of connector calls.
4.3 Special categories. Health data is or may be present, including which condition specific module a data subject opened, free text survey and rating answers, chat message content and the legacy fields at clause 4.2(d). The Customer instructs this processing knowingly.
4.4 Children. The platform has no age gate and collects no date of birth in the current flows. The Customer must not direct the platform at children below the applicable age of digital consent without putting its own controls in place.
5.1 Care Tales processes Customer Personal Data only on the Customer's documented instructions, which comprise the Agreement, this DPA and the Customer's configuration and use of the platform, unless required to process by Union or Member State law to which it is subject, in which case it will inform the Customer of that requirement before processing unless the law prohibits it on important grounds of public interest.
5.2 Care Tales will inform the Customer without delay if, in its opinion, an instruction infringes Data Protection Law.
5.3 Care Tales will not sell Customer Personal Data, will not use it for its own marketing and will not use it to train machine learning models. Care Tales does not train models. Personal data sent to Google Gemini goes through Google Cloud Vertex AI and is processed to return a result, not for model improvement.
Care Tales ensures that persons authorized to process Customer Personal Data are bound by an obligation of confidentiality that survives the end of their engagement, are trained on their obligations and are granted access only where their role requires it. Every staff and provider role is required to use TOTP two factor authentication.
7.1 Care Tales implements the technical and organizational measures described in the Care Tales security overview at [URL], which is incorporated into this DPA by reference and which the parties agree satisfies Article 32 GDPR in the context of this service.
7.2 That document also sets out the measures Care Tales has not implemented, including the absence of a SOC 2 report, an external penetration test, a Content Security Policy, a production access log of staff reads of patient data, automated retention deletion and application level field encryption. The Customer confirms it has assessed those gaps and considers the measures appropriate to the risk of the processing it instructs.
7.3 Care Tales will not materially reduce the overall level of security during the term.
8.1 The Customer gives Care Tales general written authorization to engage Subprocessors, subject to this clause.
8.2 The Subprocessors engaged as of the date of this DPA are listed in Schedule 1 and maintained at the Care Tales subprocessors page at [URL].
8.3 Care Tales will give the Customer at least 30 days notice by email before a new Subprocessor begins processing Customer Personal Data, except where a Subprocessor must be engaged sooner to prevent or resolve a security or availability incident, in which case notice is given as soon as practicable.
8.4 The Customer may object on reasonable data protection grounds within the notice period. The parties will work in good faith to find an alternative, and if none is available the Customer may terminate the affected part of the service without penalty for the remainder of the paid term.
8.5 Care Tales imposes on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA and remains fully liable to the Customer for a Subprocessor's performance.
9.1 Taking into account the nature of the processing, Care Tales will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise rights under Chapter III GDPR.
9.2 If Care Tales receives a request directly from a data subject, it will not respond on the merits and will forward the request to the Customer without undue delay, unless legally required to respond.
9.3 The Customer acknowledges two practical limits. There is no self service route for a patient without an account to reach or delete their own data, and no identifier such a patient ever sees, so identification depends on what the Customer can supply. There is also no automated retention schedule, so erasure must be requested rather than occurring on a timer. Deleting an account removes the user record and subcollections, organization membership, storage files and the authentication user. Deleting an organization recursively removes its visits, module sessions and chat transcripts from the live database. Deleted data can remain in the weekly database backups until they expire after 98 days.
10.1 Care Tales will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. That first notice carries what is known at the time. Care Tales will then provide the full description in clause 10.2 as soon as the information is available and in any event within 10 calendar days of becoming aware. Where the same incident is also a Breach of Unsecured PHI, clause 4 of the Care Tales business associate agreement runs on these same two windows.
10.2 The full report will describe, to the extent known and with updates as more is learned, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a contact point. The first notice will carry as much of this as is known when it is sent.
10.3 Care Tales will assist the Customer with its obligations under Articles 33 and 34 GDPR, and with Articles 32, 35 and 36 GDPR, taking into account the nature of the processing and the information available to Care Tales.
11.1 At the Customer's choice, Care Tales will delete or return all Customer Personal Data at the end of the provision of the services and delete existing copies, unless Union or Member State law requires storage.
11.2 The Customer must make its choice in writing within 30 days of the end of the Agreement. Absent a choice, Care Tales will delete.
11.3 Deletion will be completed within 30 days of the choice or the default taking effect, which is the window clause 9.4 of the Care Tales business associate agreement uses for protected health information. Weekly database backups are kept for 98 days and point in time recovery covers the preceding 7 days, so deleted data can persist in those for up to 98 days, subject to this DPA until it expires.
12.1 Care Tales will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
12.2 In the first instance Care Tales will respond to a written security questionnaire and provide its then current security overview. Care Tales holds no SOC 2 report or equivalent third party attestation and cannot offer one in place of an audit.
12.3 An inspection may be requested once in any twelve month period, or more often if required by a supervisory authority or following a personal data breach, on 30 days written notice, during business hours, subject to confidentiality and conducted so as not to disrupt the service or expose another customer's data. The Customer bears its own costs and Care Tales' reasonable costs for any inspection beyond the annual one.
13.1 Care Tales stores and processes Customer Personal Data in the United States. As of the date of this DPA: patient chat is processed by Gemini on Vertex AI in us-central1; Firestore databases are in Google's nam5 multi-region; Cloud Storage, App Hosting and functions are in us-central1; database backups are in Google's US multi-region. ip-api.com, which receives a truncated IP address only, is outside Google Cloud and its location is not contractually established. Care Tales will give notice under clause 8.3 before moving Customer Personal Data outside the United States.
13.2 For transfers of personal data from the European Economic Area to a country without an adequacy decision, the SCCs apply and are incorporated by reference, with Module Two (controller to processor) applying where the Customer is a controller and Module Three (processor to subprocessor) where the Customer is a processor.
13.3 For the purposes of the SCCs: the Customer is the data exporter and Care Tales is the data importer; the optional docking clause applies; under Clause 9 the parties select Option 2, general written authorization, with the notice period in clause 8.3 of this DPA; under Clause 11 the optional independent dispute resolution body does not apply; under Clause 17 the governing law is the law of [MEMBER STATE]; under Clause 18(b) the forum is the courts of [MEMBER STATE]. Annex I is populated by clauses 3 and 4 of this DPA and the parties' details above, Annex II by the Care Tales security overview and Annex III by Schedule 1.
13.4 For transfers from the United Kingdom, the UK Addendum applies to the SCCs, and in Table 4 the party that may end it is the importer.
13.5 Neither party has appointed an Article 27 representative or a data protection officer.
14.1 In the event of a conflict between this DPA and the Agreement in relation to the processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
14.2 Liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Law does not permit that.
14.3 This DPA is governed by the law that governs the Agreement, except where clause 13.3 requires otherwise.
14.4 This DPA may be executed in counterparts and by electronic signature.
[CUSTOMER LEGAL NAME]
Signature: [SIGNATURE]
Name: [PRINT NAME]
Title: [TITLE]
Date: [DATE]
Care Tales, Inc.
Signature: [SIGNATURE]
Name: [PRINT NAME OF AUTHORIZED SIGNATORY]
Title: [TITLE]
Date: [DATE]
| Subprocessor | Purpose and data | Location |
|---|---|---|
| Google Cloud and Firebase (Google LLC) | Hosting, authentication, database, storage, functions and backups. All Customer Personal Data | United States |
| Google Gemini on Vertex AI (Google LLC) | Chat responses, embeddings of patient questions, classification. Chat messages and turns, knowledge base extracts, system prompt, derived city and region, widget page text | us-central1, United States |
| Google Cloud Text-to-Speech (Google LLC) | Narration. Module text | United States |
| Google Cloud Translate (Google LLC) | Translation. Text submitted for translation | United States |
| ip-api.com | Coarse geolocation during chat. Truncated IP address only | Not established by Care Tales |
| Gmail SMTP (Google LLC) | Transactional email. Recipient address and message content | United States |
| Twilio Inc. | SMS delivery of module links. Phone number, message content, consent record | United States |
| Apple Inc., Google LLC, Microsoft Corporation | Optional sign-in providers. Authentication identifiers | United States |
| Google Analytics 4 (Google LLC) | Marketing site analytics only, not loaded on module or organization pages. Page views | United States |
This is a template. Care Tales may revise it for future customers at any time. A revision does not change an executed DPA, which can be changed only by written amendment, except that Schedule 1 is updated in the ordinary course under clause 8.