Legal
Data Processing Agreement
Last updated: 8 July 2026
This Data Processing Agreement ("DPA") describes how Salun-at processes personal data on behalf of participating healthcare establishments. It supplements our Terms of Service and Privacy Policy and is intended to satisfy the accountability requirements of the Philippine Data Privacy Act of 2012 (RA 10173).
1. Roles of the Parties
- Personal Information Controller (PIC): the healthcare establishment that determines the purposes and means of processing patient records it creates.
- Personal Information Processor (PIP): Salun-at, which processes personal data only on the documented instructions of the establishment and as needed to provide the Service.
2. Scope and Purpose of Processing
| Data category | Purpose |
|---|---|
| Account and identity data | Authentication, access control, notifications |
| Health metrics, allergies, medical records, lab results | Clinical record-keeping and display to authorized users |
| Appointments, admissions, referrals | Care coordination within and across establishments |
| Technical and log data | Security, fraud prevention, and service reliability |
3. Obligations of the Processor
Salun-at, as Processor, will:
- process personal data only on the Controller's documented instructions;
- ensure persons authorized to process data are bound by confidentiality;
- implement appropriate technical and organizational security measures;
- assist the Controller in responding to data-subject requests;
- assist with breach notification, security, and impact assessments;
- delete or return personal data at the end of the engagement; and
- make available information necessary to demonstrate compliance.
4. Sub-processors
The Controller authorizes Salun-at to engage the following sub-processors, each bound by equivalent data-protection obligations:
| Sub-processor | Function | Location |
|---|---|---|
| Resend | Transactional email delivery (OTP, notifications) | [Placeholder] |
| Hosting / infrastructure provider | Application hosting and PostgreSQL database | [Placeholder] |
| Web Push (VAPID) delivery | Browser push notifications | Client browser vendors |
| Google (OAuth) | Optional single sign-on | [Placeholder] |
We will inform Controllers of intended changes to sub-processors and give them the opportunity to object.
5. Security Measures
- Encryption in transit via HTTPS with HSTS; strict Content Security Policy.
- Password hashing with scrypt; role-based access control across all roles.
- Database access restricted to the application; indexed, least-privilege queries.
- Request logging with user context for auditability.
- Automatic cleanup of stale push subscriptions and session controls.
6. International Transfers
Where personal data is transferred outside the Philippines (for example, to a hosting or email sub-processor), we ensure a comparable level of protection through contractual safeguards consistent with the Data Privacy Act. [Placeholder: identify transfer destinations and safeguards.]
7. Data Breach
Salun-at will notify the Controller without undue delay after becoming aware of a personal data breach and will cooperate in fulfilling the Controller's notification obligations to the National Privacy Commission and affected data subjects.
8. Return and Deletion
Upon termination of the engagement, Salun-at will, at the Controller's choice, return or securely delete personal data, except where retention is required by law.
9. Audit
Salun-at will make available information reasonably necessary to demonstrate compliance and will allow for and contribute to audits conducted by the Controller or an authorized auditor, subject to reasonable notice and confidentiality.
10. Contact
Data-processing inquiries and sub-processor notices — Lines For Growth (LFG),
Data Protection Officer Aaron John N. Tamayo:
Email: aaronjohn.tamayo29@gmail.com
Phone: +63 966 789 0899