Salun-at

v1.37.2

Legal

Data Processing Agreement

Last updated: 8 July 2026

Draft — not legal advice. This document is a working draft for internal review and must be reviewed by qualified legal counsel before publication.

This Data Processing Agreement ("DPA") describes how Salun-at processes personal data on behalf of participating healthcare establishments. It supplements our Terms of Service and Privacy Policy and is intended to satisfy the accountability requirements of the Philippine Data Privacy Act of 2012 (RA 10173).

1. Roles of the Parties

  • Personal Information Controller (PIC): the healthcare establishment that determines the purposes and means of processing patient records it creates.
  • Personal Information Processor (PIP): Salun-at, which processes personal data only on the documented instructions of the establishment and as needed to provide the Service.

2. Scope and Purpose of Processing

Data categoryPurpose
Account and identity dataAuthentication, access control, notifications
Health metrics, allergies, medical records, lab resultsClinical record-keeping and display to authorized users
Appointments, admissions, referralsCare coordination within and across establishments
Technical and log dataSecurity, fraud prevention, and service reliability

3. Obligations of the Processor

Salun-at, as Processor, will:

  • process personal data only on the Controller's documented instructions;
  • ensure persons authorized to process data are bound by confidentiality;
  • implement appropriate technical and organizational security measures;
  • assist the Controller in responding to data-subject requests;
  • assist with breach notification, security, and impact assessments;
  • delete or return personal data at the end of the engagement; and
  • make available information necessary to demonstrate compliance.

4. Sub-processors

The Controller authorizes Salun-at to engage the following sub-processors, each bound by equivalent data-protection obligations:

Sub-processorFunctionLocation
ResendTransactional email delivery (OTP, notifications)[Placeholder]
Hosting / infrastructure providerApplication hosting and PostgreSQL database[Placeholder]
Web Push (VAPID) deliveryBrowser push notificationsClient browser vendors
Google (OAuth)Optional single sign-on[Placeholder]

We will inform Controllers of intended changes to sub-processors and give them the opportunity to object.

5. Security Measures

  • Encryption in transit via HTTPS with HSTS; strict Content Security Policy.
  • Password hashing with scrypt; role-based access control across all roles.
  • Database access restricted to the application; indexed, least-privilege queries.
  • Request logging with user context for auditability.
  • Automatic cleanup of stale push subscriptions and session controls.

6. International Transfers

Where personal data is transferred outside the Philippines (for example, to a hosting or email sub-processor), we ensure a comparable level of protection through contractual safeguards consistent with the Data Privacy Act. [Placeholder: identify transfer destinations and safeguards.]

7. Data Breach

Salun-at will notify the Controller without undue delay after becoming aware of a personal data breach and will cooperate in fulfilling the Controller's notification obligations to the National Privacy Commission and affected data subjects.

8. Return and Deletion

Upon termination of the engagement, Salun-at will, at the Controller's choice, return or securely delete personal data, except where retention is required by law.

9. Audit

Salun-at will make available information reasonably necessary to demonstrate compliance and will allow for and contribute to audits conducted by the Controller or an authorized auditor, subject to reasonable notice and confidentiality.

10. Contact

Data-processing inquiries and sub-processor notices — Lines For Growth (LFG), Data Protection Officer Aaron John N. Tamayo:
Email: aaronjohn.tamayo29@gmail.com
Phone: +63 966 789 0899