GDPR Compliant: This Data Processing Agreement (DPA) outlines our obligations and commitments to protect personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Introduction
This Data Processing Agreement ("DPA") is an integral part of the Terms of Service and Privacy Policy of Presora. It governs the processing of personal data by Presora on behalf of its users and ensures compliance with data protection regulations.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data (collection, storage, use, disclosure, etc.)
- Data Controller: The entity that determines the purposes and means of processing
- Data Processor: The entity that processes personal data on behalf of the controller
- Data Subject: The individual to whom the personal data relates
3. Data Processing Activities
Presora processes personal data for the following purposes:
- Providing healthcare prescription and patient management services
- Managing user accounts and authentication
- Processing medical records and prescriptions
- Platform analytics and performance improvement
- Communication and support services
4. Types of Personal Data Processed
| Data Category | Description | Purpose |
|---|---|---|
| Identity Data | Name, BMDC number, professional credentials | User verification and authentication |
| Contact Data | Email address, phone number, clinic address | Communication and support |
| Medical Data | Prescriptions, diagnoses, patient records | Healthcare services delivery |
| Technical Data | IP address, browser type, usage logs | Platform security and improvement |
5. Data Subject Rights
Presora respects the rights of data subjects under GDPR and similar regulations:
- Right to Access: Request access to your personal data
- Right to Rectification: Request corrections to your data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how your data is processed
- Right to Data Portability: Request your data in a portable format
- Right to Object: Object to data processing for certain purposes
6. Data Security Measures
We implement robust security measures to protect personal data:
- Encryption: End-to-end encryption for data in transit and at rest
- Access Control: Role-based access control and authentication
- Monitoring: Continuous monitoring and threat detection
- Backup: Regular backups with disaster recovery plans
- Training: Regular security awareness training for staff
7. Sub-Processors
We may engage third-party sub-processors to provide services. All sub-processors:
- Are bound by data processing agreements
- Meet GDPR compliance requirements
- Implement appropriate security measures
- Are subject to regular security assessments
| Sub-Processor | Service Provided | Data Processing Location |
|---|---|---|
| AWS (Amazon Web Services) | Cloud hosting and infrastructure | EU / US / Asia |
| Stripe | Payment processing | EU / US |
| SendGrid | Email delivery services | US |
| Twilio | SMS and communication services | US / EU |
8. International Data Transfers
Personal data may be transferred to countries outside the European Economic Area (EEA). Such transfers are conducted in compliance with GDPR requirements and using:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for countries with sufficient protection levels
- Binding Corporate Rules (BCRs) where applicable
9. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this agreement:
- Active Accounts: Data retained for the duration of account activity
- Inactive Accounts: Data retained for 24 months after account closure
- Legal Requirements: Retention may be extended to comply with legal obligations
- Anonymization: Data may be anonymized for analytical purposes
10. Data Breach Management
In the event of a data breach, Presora will:
- Notify affected parties within 72 hours of discovery
- Investigate the breach and implement remediation measures
- Document the breach and actions taken
- Cooperate with regulatory authorities as required
11. Liability and Indemnification
Presora is responsible for personal data processing activities conducted on behalf of users. Liability is limited to the extent permitted by applicable law and in accordance with the Terms of Service.
12. Audit Rights
Users may request audits of our data processing practices. Such audits shall:
- Be conducted at mutually agreed times
- Respect confidentiality and security requirements
- Be limited to reasonable scope and duration
- Be conducted at the requesting party's expense
13. Updates to This Agreement
This DPA may be updated to reflect changes in regulations, business practices, or technology. We will notify users of significant updates via email or platform notification.
14. Contact Information
For data protection inquiries, please contact our Data Protection Officer:
Email: support@presorahealth.com
Address: Dhaka, Bangladesh
Phone: +880 1234 567890
Compliance Status: GDPR Compliant · HIPAA Compliant · ISO 27001 Certified