This Data Processing Addendum ("DPA") forms part of the Terms of Service between DVR Digital LLC, doing business as SafetyClinic.app ("SafetyClinic", "we", "us"), and the Customer ("you"), and applies to our processing of Personal Data on your behalf in providing the Service. Where this DPA conflicts with the Terms of Service on the subject of data protection, this DPA controls.
1. Definitions
Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in applicable data protection law, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended (CCPA/CPRA) (together, "Data Protection Law"). "Customer Personal Data" means Personal Data within Customer Data that we process on your behalf.
2. Roles of the parties
You are the Controller (or "business") of Customer Personal Data, and we are the Processor (or "service provider"). You are responsible for the accuracy and lawfulness of Customer Personal Data and for having a lawful basis to provide it to us. We process Customer Personal Data only on your documented instructions — which include the Terms of Service, this DPA, and your use of the Service — unless required by law (in which case we will inform you unless the law prohibits it).
3. Nature and purpose of processing (Annex)
- Subject matter: provision of the SafetyClinic.app workplace-safety and compliance Service.
- Duration: the term of the Terms of Service, plus any deletion period.
- Nature and purpose: hosting, storing, organizing, transmitting, displaying, securing, and supporting Customer Data as directed through the Service.
- Types of Personal Data: names, work email addresses, roles, organization membership, and any personal data contained in inspections, corrective actions, notes, photographs, contacts, and documents that Authorized Users choose to submit.
- Categories of Data Subjects: your Authorized Users and any individuals your Authorized Users reference in Customer Data (for example, staff, contractors, and site contacts).
- Prohibited data: the Service is not authorized for patient or clinical records, or protected health information (PHI) as defined under HIPAA, and you agree not to submit them. Employee occupational-health records created in the health & credential module (vaccination, fit-test and licence status for your own workforce) are employment records rather than PHI and are within scope of the Service.
4. Our obligations
We will: process Customer Personal Data only on your documented instructions; ensure personnel authorized to process it are bound by confidentiality; implement appropriate technical and organizational security measures consistent with Article 32 of the GDPR (see Section 7); taking into account the nature of processing, assist you with Data Subject requests and with your obligations regarding security, breach notification, and data protection impact assessments; make available information reasonably necessary to demonstrate compliance and allow for audits as described in Section 8; and, at your choice, delete or return Customer Personal Data at the end of the provision of services, except where retention is required by law.
5. Subprocessors
You authorize us to engage subprocessors to help provide the Service. Our current subprocessors are listed at safetyclinic.app/subprocessors. We impose data protection obligations on each subprocessor no less protective than those in this DPA and remain responsible for their performance. We maintain the subprocessor list and provide a mechanism to be notified of changes; you may object on reasonable data protection grounds, and if we cannot address the objection you may terminate the affected Service.
6. International transfers
Where we transfer Customer Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where applicable.
7. Security
We maintain technical and organizational measures designed to protect Customer Personal Data, including encryption in transit and at rest, tenant isolation through row-level security, least-privilege access controls, network controls, and logging and monitoring. We regularly review these measures and may update them provided the level of protection is not materially reduced.
8. Audits
On reasonable prior written request, and no more than once per year unless required by a Supervisory Authority or following a security incident, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where available, we may satisfy audit requests by providing third-party certifications or reports of our infrastructure providers.
9. Personal data breach
We will notify you without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data and will provide information reasonably available to help you meet your notification obligations. Our notification is not an acknowledgment of fault or liability.
10. Deletion and return
On termination or expiry of the Service, or on your written request, we will delete or return Customer Personal Data as described in the Privacy Policy and Terms of Service. Account deletion in the app removes Customer Data as described there; residual copies in encrypted backups are overwritten on our standard backup cycle.
11. CCPA / CPRA terms
To the extent we process Personal Data of California residents as a service provider, we will: process it only to perform the Service and for the business purposes set out in the Terms; not sell or share it; not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service; and not combine it with data from other sources except as permitted by the CCPA. We certify that we understand and will comply with these restrictions.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA supersedes any conflicting data protection terms previously agreed between the parties.
13. Contact
Data protection requests and questions about this DPA: support@safetyclinic.app.
DVR Digital LLC (dba SafetyClinic.app), 180 NW Saddlehorn Ct, Prineville, OR 97754.