Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer,” the controller) and Automate Admits, Inc. (“Automate Admits,” the processor) for the use of the Automate Admits platform (the “Service”). It describes how we process personal data on the Customer’s behalf. Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Roles of the parties
For personal data contained in Customer Data, the Customer is the controller (or, where the Customer acts on behalf of a third party, the processor), and Automate Admits is the processor (or subprocessor) acting on the Customer’s documented instructions. Automate Admits processes personal data only to provide and support the Service, as set out in this DPA, our Terms, and our Privacy Policy, or as otherwise instructed by the Customer in writing and as permitted by law.
2. Subject matter, duration & purpose
The subject matter is the provision of the Service. Processing continues for the duration of the Customer’s use of the Service and until data is deleted or returned as described below. The purpose is to receive, store, organize, transmit, and respond to messages and lead information through the Customer’s connected channels, including the optional AI agent.
3. Types of data & data subjects
- Types of personal data: contact identifiers (such as names, usernames, phone numbers, email addresses, and platform-scoped IDs), message content and media, call recordings and transcripts, insurance and benefits information (including date of birth and member ID) where eligibility verification is used, contact and lead details the parties choose to exchange, scheduling information, and account information for the Customer’s team.
- Special categories: because Customers are healthcare and treatment organizations, the personal data processed is likely to include health data, and may include substance use disorder records subject to 42 CFR Part 2 (see our QSOA).
- Categories of data subjects: the Customer’s end users (people who message the Customer’s connected accounts) and the Customer’s own team members and account users.
4. Processor obligations
- Process personal data only on the Customer’s documented instructions, including for international transfers, unless required by law (in which case we will inform the Customer where permitted).
- Ensure that personnel authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see Section 7).
- Assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting the Customer’s security, breach-notification, and impact-assessment obligations.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
5. Subprocessors
The Customer authorizes Automate Admits to engage the subprocessors below to provide the Service. We impose written data-protection obligations on each subprocessor and we remain responsible for their performance under this DPA. Where a business associate agreement is in place we say so; where one is not, we say that too.
- Amazon Web Services, Inc. (United States) — application hosting, database, object storage, and backups; the system of record where all Customer Data including protected health information is stored and processed. Business associate agreement in place.
- Paubox, Inc. (United States) — delivery of transactional and service email to the Customer’s team. Business associate agreement in place.
- Stedi, Inc. (United States) — insurance eligibility and benefits verification; receives patient name, date of birth, and insurance member ID together with the Customer’s provider identifiers. Business associate agreement in place.
- Anthropic, PBC (United States) — AI processing of the contact record and conversation content to generate replies. Does not train on the data. No business associate agreement.
- Meta Platforms, Inc. (United States) — receiving and sending messages through the Facebook Pages and Instagram accounts the Customer connects. No business associate agreement.
- Telnyx LLC (United States) — transport of SMS and voice, phone numbers, call recording, and speech-to-text transcription (which routes call audio to OpenAI Whisper via Telnyx). No business associate agreement.
- Cloudflare, Inc. (United States) — public marketing site, static-asset delivery, DNS, and CDN/DDoS protection. No protected health information.
- Block, Inc. (Square) (United States) — payment processing for Customer subscriptions. Billing data only.
Each subprocessor without a business associate agreement supports an optional feature the Customer can leave disabled. The current status of each is published on our Trust page and updated when it changes.
We will give notice of intended changes to subprocessors so the Customer has an opportunity to object on reasonable data-protection grounds.
6. Data subject requests
Taking into account the nature of the processing, Automate Admits will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligations to respond to requests from data subjects to exercise their rights. Where we receive a request directly from a data subject relating to Customer Data, we will, where lawful, direct them to the Customer or forward the request.
7. Security measures
Automate Admits maintains technical and organizational measures designed to protect personal data, including encryption in transit (TLS, with HSTS and enforced TLS to the database and object storage) and at rest (AWS KMS customer-managed key with rotation), role-based access control, optional two-factor authentication, PBKDF2 password hashing, per-organization audit logging, brute-force lockout, signature verification of incoming platform webhooks, automated daily backups with cross-region replication, and logical isolation of each Customer’s data in our multi-tenant environment enforced by an automated tenant-isolation audit in our release process. Further detail — including the controls we have not yet implemented — is on our Security page.
8. Personal data breach
Automate Admits will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help the Customer meet its notification obligations.
9. Deletion or return of data
Upon termination of the Service, and at the Customer’s choice, Automate Admits will delete or make available for return the Customer’s personal data, and delete existing copies unless retention is required by law. During the term, Customer Data is retained until the Customer deletes it — there is no automatic expiry — and Customers can delete individual contacts and conversations, disconnect channels, and request deletion of account data at any time, as described in our Privacy Policy.
10. Audits
Automate Admits will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security conditions.
11. International transfers
The Service and all subprocessors listed in Section 5 process personal data in the United States. Where required by applicable law, the parties will put in place an appropriate transfer mechanism.
12. General
If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls. Where Customer Data includes protected health information, the Business Associate Agreement controls as to that subject matter; where it includes records subject to 42 CFR Part 2, the Qualified Service Organization Agreement controls as to that subject matter. This DPA is governed by the laws of the State of Wyoming, consistent with the Terms.
To request a signed copy of this DPA, or for any data-protection question, contact privacy@automateadmits.com.