Legal

Data Processing Agreement

Our commitment to protecting personal data in compliance with GDPR and international data protection standards.

Last updated: January 2025 ~7 min read

GDPR Compliant: This Data Processing Agreement (DPA) outlines our obligations and commitments to protect personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

1. Introduction

This Data Processing Agreement ("DPA") is an integral part of the Terms of Service and Privacy Policy of Presora. It governs the processing of personal data by Presora on behalf of its users and ensures compliance with data protection regulations.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data (collection, storage, use, disclosure, etc.)
  • Data Controller: The entity that determines the purposes and means of processing
  • Data Processor: The entity that processes personal data on behalf of the controller
  • Data Subject: The individual to whom the personal data relates

3. Data Processing Activities

Presora processes personal data for the following purposes:

  • Providing healthcare prescription and patient management services
  • Managing user accounts and authentication
  • Processing medical records and prescriptions
  • Platform analytics and performance improvement
  • Communication and support services

4. Types of Personal Data Processed

Data Category Description Purpose
Identity Data Name, BMDC number, professional credentials User verification and authentication
Contact Data Email address, phone number, clinic address Communication and support
Medical Data Prescriptions, diagnoses, patient records Healthcare services delivery
Technical Data IP address, browser type, usage logs Platform security and improvement

5. Data Subject Rights

Presora respects the rights of data subjects under GDPR and similar regulations:

  • Right to Access: Request access to your personal data
  • Right to Rectification: Request corrections to your data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how your data is processed
  • Right to Data Portability: Request your data in a portable format
  • Right to Object: Object to data processing for certain purposes

6. Data Security Measures

We implement robust security measures to protect personal data:

  • Encryption: End-to-end encryption for data in transit and at rest
  • Access Control: Role-based access control and authentication
  • Monitoring: Continuous monitoring and threat detection
  • Backup: Regular backups with disaster recovery plans
  • Training: Regular security awareness training for staff

7. Sub-Processors

We may engage third-party sub-processors to provide services. All sub-processors:

  • Are bound by data processing agreements
  • Meet GDPR compliance requirements
  • Implement appropriate security measures
  • Are subject to regular security assessments
Sub-Processor Service Provided Data Processing Location
AWS (Amazon Web Services) Cloud hosting and infrastructure EU / US / Asia
Stripe Payment processing EU / US
SendGrid Email delivery services US
Twilio SMS and communication services US / EU

8. International Data Transfers

Personal data may be transferred to countries outside the European Economic Area (EEA). Such transfers are conducted in compliance with GDPR requirements and using:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with sufficient protection levels
  • Binding Corporate Rules (BCRs) where applicable

9. Data Retention

We retain personal data only as long as necessary for the purposes outlined in this agreement:

  • Active Accounts: Data retained for the duration of account activity
  • Inactive Accounts: Data retained for 24 months after account closure
  • Legal Requirements: Retention may be extended to comply with legal obligations
  • Anonymization: Data may be anonymized for analytical purposes

10. Data Breach Management

In the event of a data breach, Presora will:

  • Notify affected parties within 72 hours of discovery
  • Investigate the breach and implement remediation measures
  • Document the breach and actions taken
  • Cooperate with regulatory authorities as required

11. Liability and Indemnification

Presora is responsible for personal data processing activities conducted on behalf of users. Liability is limited to the extent permitted by applicable law and in accordance with the Terms of Service.

12. Audit Rights

Users may request audits of our data processing practices. Such audits shall:

  • Be conducted at mutually agreed times
  • Respect confidentiality and security requirements
  • Be limited to reasonable scope and duration
  • Be conducted at the requesting party's expense

13. Updates to This Agreement

This DPA may be updated to reflect changes in regulations, business practices, or technology. We will notify users of significant updates via email or platform notification.

14. Contact Information

For data protection inquiries, please contact our Data Protection Officer:

Email: support@presorahealth.com

Address: Dhaka, Bangladesh

Phone: +880 1234 567890

Compliance Status: GDPR Compliant · HIPAA Compliant · ISO 27001 Certified