Data processing addendum.
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Terms of Service or master agreement (“Agreement”) between BiotrackOS Ltd, registered in Scotland (No. SC737158) (“BiotrackOS”), and the customer entity identified in the applicable Order Form (“Customer”). It governs the processing of Personal Data by BiotrackOS on behalf of Customer in the course of providing the Service.
This DPA does not apply to Personal Data that BiotrackOS processes as its own controller, including Customer billing and commercial contact data, website visitor data, and data relating to direct personal-App accounts. Those activities are described in BiotrackOS’s Privacy Policy.
US healthcare customers (HIPAA): If your organisation is a HIPAA Covered Entity or Business Associate, a separate HIPAA Business Associate Agreement (BAA) is required before processing Protected Health Information (PHI) through BiotrackOS. A BAA is a distinct legal instrument from this DPA. Contact legal@biotrackos.com to request a BAA.
Definitions
“Personal Data”, “Special Category Data”, “Processing”, “Controller”, “Processor”, “Subprocessor”, “Data Subject”, and “Supervisory Authority” have the meanings given in applicable Data Protection Law. “Data Protection Law” means UK GDPR, the UK Data Protection Act 2018, EU GDPR 2016/679, the Australian Privacy Act 1988, and any applicable successor or equivalent legislation as amended from time to time. “Processing Instructions” means the instructions Customer gives BiotrackOS regarding how to process Personal Data, as set out in the Agreement, this DPA, and any Order Form. “Customer Personal Data” means any Personal Data relating to Members, patients, clinicians, dependants, and other Data Subjects submitted to, or generated within, the Service by or on behalf of Customer, as further described in §2. It does not include Personal Data that BiotrackOS processes as its own controller, such as data about the Customer entity itself (billing contacts, commercial correspondence, and administrator account data), which are described in BiotrackOS’s Privacy Policy.
§1 — Scope and roles
Customer controls how Member data is used. BiotrackOS processes it only on Customer’s instructions. Where Customer is itself a Processor for an upstream Controller, BiotrackOS acts as Subprocessor and the same obligations apply.
Customer determines the purposes and means of processing Member Personal Data and acts as Controller (or, in OEM, reseller, or delegated healthcare arrangements, as Processor for an upstream Controller). BiotrackOS acts as Processor — or where Customer is a Processor, as Subprocessor — and processes Personal Data solely on documented Processing Instructions from Customer, unless required to do so by applicable law.
If BiotrackOS considers that a Processing Instruction infringes applicable Data Protection Law, BiotrackOS will notify Customer immediately in writing. BiotrackOS will not be obliged to follow that instruction unless and until Customer confirms it in writing having considered BiotrackOS’s notification. BiotrackOS may suspend processing of the affected data pending that confirmation where necessary to avoid a breach of applicable law.
On matters of data processing, the order of precedence is: (1) applicable Standard Contractual Clauses or UK transfer instruments; (2) this DPA; (3) the Platform Terms of Service.
§2 — Subject matter
What data this DPA covers: health and identity data submitted or connected by Customer for enrolled Members.
- Nature of processing: ingestion, normalisation, storage, retrieval, presentation, and analysis of health and associated personal data.
- Purpose: provision of the BiotrackOS Service as described in the applicable Order Form.
- Duration: term of the Order Form, plus a 60-day export and deletion period following termination.
- Data subjects: Members, patients, employees, clinicians, dependants, and other individuals whose Personal Data Customer submits or connects to the Service. Persons under 18 are included only where expressly authorised in the Order Form.
- Categories of personal data:
- Account and contact identifiers (name, email address, job role)
- Device and wearable streams
- Laboratory results, medication and prescription data
- Genetic, genomic and epigenetic data
- Biometric data, where applicable
- Customer-entered observations and clinical records
- Derived insights, alerts and scores generated by the Service
- Authentication, access and audit records
- Connection credentials and source permissions (such as OAuth tokens)
Health data, genetic data, and applicable biometric data constitute Special Category Data under Art. 9 UK/EU GDPR and sensitive information under the Australian Privacy Act 1988.
§3 — Customer obligations
Customer represents and warrants that it will:
- Establish and maintain the lawful basis under Art. 6 UK/EU GDPR and the applicable Art. 9 condition for each category of Special Category Data processed, and document those bases.
- Provide Data Subjects with the transparency information required by applicable Data Protection Law before their data is submitted to the Service.
- Ensure that Processing Instructions given to BiotrackOS are lawful and compatible with applicable Data Protection Law.
- Obtain and maintain any user authorisations, consents, or professional permissions required for the specific deployment context.
- Notify BiotrackOS promptly if any Processing Instruction changes in a way that may affect the lawfulness of processing.
§4 — Processor obligations
We only process data on your instructions. Our staff are bound by confidentiality. We help you with data subject requests, breach notifications, and impact assessments. We remain responsible for our subprocessors’ performance.
- Process Personal Data only on documented Processing Instructions from Customer.
- Ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations, whether by contract or professional duty.
- Implement and maintain the technical and organisational security measures described in §5.
- Not engage a Subprocessor without prior authorisation from Customer as set out in §6.
- Remain fully responsible to Customer for the performance of each Subprocessor’s obligations under this DPA, as if BiotrackOS had performed those obligations directly.
- Assist Customer in fulfilling data subject rights requests within applicable statutory timeframes, including by providing technical means to retrieve, correct, restrict, or delete data.
- Assist Customer in meeting its obligations regarding breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities.
- Make available all information necessary to demonstrate compliance with this DPA and cooperate with reasonable audits as set out in §8.
§5 — Security measures
Data is encrypted at rest and in transit. Access requires MFA and is role-based. We pen-test annually and train staff regularly. We will not materially reduce security controls during the term.
BiotrackOS implements appropriate technical and organisational measures (“TOMs”) including:
- Encryption of data at rest (AES-256) and in transit (TLS 1.3 minimum).
- Role-based access control (RBAC) with least-privilege principles and multi-factor authentication (MFA) required for all personnel with access to Personal Data.
- Audit logging of data access and administrative events; logs are protected against unauthorised modification.
- Annual penetration testing by an independent third party; material findings are remediated and tracked to closure.
- A documented Incident Response Plan that is tested at least annually, with defined escalation paths for Personal Data Breaches.
- Regular security awareness training for all staff with access to Personal Data.
- Vulnerability management covering patch cycles and continuous monitoring.
BiotrackOS will not materially reduce the security controls described above during the term of any active Order Form without Customer’s prior written agreement. A detailed Security Schedule is available to enterprise customers on request at legal@biotrackos.com.
§6 — Subprocessors
These are the vendors that process Customer Member data behind the scenes. BiotrackOS remains responsible for their performance. We give 30 days’ notice before adding or replacing any of them.
Customer authorises BiotrackOS to use the following Subprocessors for the processing of Customer Personal Data. This list covers processing of Customer Member data only; BiotrackOS-controlled vendor relationships (such as billing and personal-App analytics) are described separately in the Privacy Policy.
| Subprocessor | Purpose | Data processed | Processing locations |
|---|---|---|---|
| Amazon Web Services | Infrastructure hosting and storage | All Customer Personal Data at rest and in transit | EU, UK, US, AU (Customer selects primary region at onboarding) |
| Mailgun Technologies Inc. | Transactional email delivery | Member name and email address | EU, US |
| Sentry (Functional Software Inc.) | Application error monitoring | Pseudonymised session and error data; no health data | EU, US |
Where AI inference providers are used to generate insights from Customer Personal Data, those providers are engaged as Subprocessors under separate contractual controls. Details are available on request.
BiotrackOS will notify Customer at least 30 days before adding or replacing any Subprocessor. Customer may object in writing within that period on reasonable and documented data-protection grounds. If BiotrackOS cannot reasonably accommodate the objection through mitigation or replacement, Customer may terminate the affected part of the Service on written notice, without penalty for that termination. All Subprocessors are bound by contractual obligations no less protective than this DPA, and BiotrackOS remains fully responsible for their performance.
§7 — International data transfers
When data moves across borders we use adequacy decisions, Standard Contractual Clauses, or UK transfer instruments. If a mechanism fails, we notify you and work to find an alternative; we may need to suspend affected transfers if none is available.
Where Personal Data is transferred outside the UK or European Economic Area, BiotrackOS relies on one or more of the following mechanisms:
- Adequacy decisions: where the destination country benefits from a valid adequacy decision under UK or EU law.
- EU Standard Contractual Clauses: the European Commission’s SCCs (Decision 2021/914), applying Module 2 (Controller to Processor) where Customer is Controller, or Module 3 (Processor to Processor) where Customer is itself a Processor. Transfer Impact Assessments are conducted where required.
- UK transfer instruments: the ICO’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable to the specific transfer. These are two distinct instruments.
- UK-US Data Bridge: for transfers to US recipients that have self-certified to the UK Extension of the US Data Privacy Framework.
The applicable SCCs and UK transfer instruments are incorporated into this DPA. Completed Annexes and Schedules are available on request at legal@biotrackos.com.
For Australia: where BiotrackOS discloses Personal Data to an overseas Subprocessor, BiotrackOS remains accountable for that disclosure in accordance with Australian Privacy Principle 8, unless Customer directs otherwise.
If any transfer mechanism is invalidated, suspended, or materially changed, BiotrackOS will notify Customer promptly and work to adopt an alternative valid mechanism. Where no lawful alternative is available, the affected transfers may need to be suspended until one is identified; BiotrackOS will notify Customer before any such suspension.
§8 — Data subject requests
BiotrackOS will notify Customer promptly — and in any event within 5 business days — of any data subject request received directly by BiotrackOS relating to Customer Personal Data. BiotrackOS will provide reasonable technical assistance to enable Customer to respond within applicable statutory timeframes. Customer is responsible for determining how to respond to data subjects and for any communications with them.
§9 — Personal data breach
If something goes wrong affecting your data, we notify you within 24 hours — in phases if necessary. We do not notify regulators or Members without your instruction, unless we are legally required to do so.
BiotrackOS will notify Customer without undue delay and, where possible, within 24 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. Initial notification may be provided in phases where complete information is not yet available; BiotrackOS will supplement the notification as further information becomes available. Notification will include, to the extent known at the time: (a) a description of the nature of the breach; (b) categories and approximate numbers of Data Subjects and records affected; (c) likely consequences; and (d) measures taken or proposed to address the breach.
BiotrackOS will not notify Supervisory Authorities or Data Subjects in respect of Customer Personal Data without Customer’s prior written instruction, unless BiotrackOS is required to do so by applicable law, in which case BiotrackOS will notify Customer first to the extent permitted by law.
§10 — Audit rights
BiotrackOS will make available all information reasonably necessary to demonstrate compliance with this DPA and will permit and contribute to audits, including inspections, conducted by Customer or a mandated third-party auditor, provided that: (a) Customer gives at least 30 days’ prior written notice (this notice period does not apply following a Personal Data Breach, a regulator request, or where Customer has a credible compliance concern); (b) audits occur no more than once per calendar year unless a specific compliance issue requires otherwise; (c) audits do not unreasonably disrupt BiotrackOS’s operations or compromise the security or confidentiality of other customers’ data; and (d) the auditor is bound by confidentiality obligations acceptable to BiotrackOS. BiotrackOS may satisfy audit requests through provision of current third-party audit reports (such as SOC 2 or ISO 27001) where these cover the relevant scope.
§11 — Deletion and return
When the contract ends, your data is deleted from active systems within 60 days. Backup copies are placed beyond use immediately and overwritten within 90 days. If you give no instruction, we delete by default.
Upon termination or expiry of the Agreement, BiotrackOS will:
- Make Customer Personal Data available for export for up to 60 days following the termination date.
- At the end of the 60-day export period — or earlier at Customer’s written election — delete or securely return all Customer Personal Data from active systems, as Customer elects in writing.
- Where Customer gives no deletion or return instruction within the 60-day period, BiotrackOS will delete Customer Personal Data from active systems by default.
- Immediately place encrypted backup copies beyond active use; those copies will be overwritten on the documented backup cycle, which does not exceed 90 days. BiotrackOS will not restore deleted Customer Personal Data from backup except where required for disaster recovery, security, or legal compliance; if restoration occurs, deletion instructions will be reapplied.
- Provide written certification of deletion upon Customer’s written request.
Residual data retained by law (for example, under tax or regulatory obligations) is retained only for the duration required and remains subject to the security obligations in this DPA.
§12 — US state privacy
Where Customer Personal Data includes personal information of California residents, BiotrackOS agrees to the restrictions applicable to service providers under the California Consumer Privacy Act (CCPA) as amended by the CPRA, including the prohibition on selling, sharing, retaining, using, or disclosing such personal information for any purpose other than performing the Service or as otherwise permitted by CCPA/CPRA. BiotrackOS will not combine personal information received from Customer with personal information received from other sources except as permitted by applicable law. Additional US state privacy obligations may be addressed in a separate schedule on request.
§13 — Existing customers
Order Forms signed before 5 August 2026 continue to operate under the data processing terms incorporated into those Order Forms unless Customer elects to adopt this DPA, at which point this DPA supersedes any prior data processing addendum or schedule in respect of the data-processing matters it covers. To adopt this DPA, Customer should notify BiotrackOS in writing at legal@biotrackos.com.
§14 — Execution
This DPA is incorporated automatically into all Order Forms signed on or after 5 August 2026. To execute a separately signed copy, request completed SCC or IDTA schedules, or enquire about a HIPAA Business Associate Agreement, contact legal@biotrackos.com.
Contact
Data Protection Officer: dpo@biotrackos.com
Legal enquiries: legal@biotrackos.com
BiotrackOS Ltd (SC737158) · Canniesburn Gate, 10 Canniesburn Drive, Bearsden, Glasgow, Scotland, G61 1BF
