This Data Processing Addendum (“DPA”) is between Passing Lanes Solutions LLC (“HIPAAWorks”) and the customer that has accepted the HIPAAWorks Terms of Service (“Customer”). It forms part of the Terms and applies when HIPAAWorks processes personal data in Customer Content on Customer's behalf.
This DPA is not a Business Associate Agreement. The Service is not designed for PHI, and Customer must not provide PHI to HIPAAWorks.
1. Definitions
- “Applicable Privacy Law” means a law applicable to the processing covered by this DPA that regulates personal data or personal information.
- “Customer Personal Data” means personal data contained in Customer Content that HIPAAWorks processes on Customer's behalf.
- “Data Subject” means an identified or identifiable individual to whom Customer Personal Data relates.
- “Process” and “Personal Data” have the meanings given by Applicable Privacy Law.
- “Security Incident” means confirmed unauthorized access to, acquisition of, or disclosure, alteration, or destruction of Customer Personal Data in systems controlled by HIPAAWorks. It does not include unsuccessful attempts that do not compromise Customer Personal Data.
- “Subprocessor” means a third party engaged by HIPAAWorks to process Customer Personal Data on Customer's behalf.
Terms such as “controller,” “processor,” “business,” “service provider,” “contractor,” and “consumer” have the meanings given by the applicable law.
2. Roles and scope
For Customer Personal Data, Customer acts as the controller or business, and HIPAAWorks acts as the processor, service provider, or contractor, as applicable. The parties may each act independently for account administration, billing, security, legal compliance, and other processing for which each determines its own purposes and means.
This DPA applies only to processing needed to provide the Service under the Terms. Annex I describes the subject matter and instructions.
3. Customer instructions
HIPAAWorks will process Customer Personal Data only:
- to provide, secure, support, and maintain the Service;
- to generate Customer-requested outputs;
- as documented in the Terms, Privacy Notice, this DPA, and Customer's authorized use of Service features;
- on Customer's additional documented instructions that are consistent with the Service and law; or
- as required by law.
If law requires processing beyond Customer's instructions, HIPAAWorks will notify Customer before processing unless law prohibits notice.
HIPAAWorks will inform Customer if it reasonably believes an instruction violates Applicable Privacy Law. HIPAAWorks is not responsible for determining whether Customer's business or instructions comply with laws applicable to Customer.
4. Processing restrictions
To the extent an Applicable Privacy Law uses these concepts, HIPAAWorks will not:
- sell Customer Personal Data;
- share Customer Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by the Terms, this DPA, or law;
- combine Customer Personal Data with personal data received from another person or collected from HIPAAWorks' own interaction with an individual, except as permitted to provide the Service or by law; or
- use Customer Personal Data for targeted advertising.
HIPAAWorks may use information that has been aggregated or de-identified so it cannot reasonably identify Customer, a user, or another individual. HIPAAWorks will not attempt to re-identify de-identified information.
5. Customer obligations
Customer will:
- provide lawful instructions and all notices required for Customer Personal Data;
- obtain any required authorizations or consents;
- submit only data necessary for the Service;
- use appropriate roles and access controls;
- respond to Data Subjects concerning Customer's own processing; and
- comply with the Terms' prohibition on PHI.
Customer will not submit patient information, PHI, highly sensitive government identifiers, payment-card data, account credentials, or other data not necessary for the Service.
6. Confidentiality
HIPAAWorks will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security instructions.
7. Security
HIPAAWorks will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of Customer Personal Data. Current safeguards are summarized in Annex II.
Customer recognizes that security evolves and authorizes HIPAAWorks to update safeguards, provided updates do not materially reduce the overall protection of Customer Personal Data during a paid subscription term.
8. Security incidents
HIPAAWorks will:
- investigate a confirmed Security Incident;
- take reasonable steps to contain and remediate it;
- notify Customer without undue delay after confirmation when Applicable Privacy Law or this DPA requires notice; and
- provide information reasonably available to help Customer meet applicable notification obligations.
Notice does not constitute an admission of fault or liability.
For commercial customers, HIPAAWorks will provide notice of a confirmed Security Incident no later than 72 hours after confirmation.
Customer is responsible for providing current security-notice contacts and for incidents arising from Customer-controlled accounts, identity providers, devices, or exported files.
9. Subprocessors
Customer generally authorizes the Subprocessors identified in the Privacy Notice's Service Providers section. The current subprocessor list is available on request to [email protected].
HIPAAWorks will:
- impose data-protection obligations appropriate to each Subprocessor's processing;
- remain responsible for its obligations under this DPA when a Subprocessor performs them; and
- provide notice of a new Subprocessor that will process Customer Personal Data.
HIPAAWorks will provide reasonable advance notice of a new Subprocessor. If Customer reasonably objects, the parties will engage in reasonable discussion; if no alternative is available, Customer's remedy is termination of the affected Service.
10. Data Subject requests
Taking into account the nature of processing, HIPAAWorks will provide reasonable assistance for Customer to respond to verified Data Subject requests under Applicable Privacy Law.
If HIPAAWorks receives a request concerning Customer Personal Data, it may direct the requester to Customer unless law requires HIPAAWorks to respond directly. Customer is responsible for evaluating the request and giving lawful instructions.
Product immutability must not be treated as a blanket exception to an applicable individual right. Before this DPA is executed, the parties must adopt a process for deleting, correcting, restricting, or de-identifying actor names and emails in historical organization records where required while preserving the integrity of the business record.
11. Assistance and compliance information
HIPAAWorks will provide reasonable information needed for Customer's privacy impact assessments, regulator consultations, and compliance inquiries concerning the Service, considering the nature of processing and information available to HIPAAWorks.
Upon reasonable written request, HIPAAWorks will provide documentation reasonably necessary to demonstrate compliance with this DPA. Any audit will:
- occur no more than once annually unless required after a Security Incident or by a regulator;
- use existing third-party reports and written responses first;
- protect other customers' information and HIPAAWorks Confidential Information;
- avoid vulnerability testing or production disruption without prior written approval; and
- be at Customer's expense unless the audit identifies a material breach by HIPAAWorks.
12. Return and deletion
During the subscription, Customer may access or export Customer Personal Data through supported Service features.
After termination, HIPAAWorks will return or delete Customer Personal Data according to the Terms, the approved retention schedule, and Customer's documented instructions, except where:
- law requires retention;
- information is needed for security, fraud prevention, legal claims, or proof of consent;
- Customer has instructed HIPAAWorks to maintain an append-only organization record; or
- deletion from backup systems is not immediately feasible.
Information retained under an exception remains protected and may be used only for the reason it was retained. Backup copies will be isolated from ordinary use and deleted or overwritten under the approved backup lifecycle.
Upon Customer's written request and cancellation of the subscription, HIPAAWorks will delete Customer Personal Data from the Service, subject to the exceptions above.
13. International transfers
The Service is currently intended for U.S. customers and users.
Customer must not use the Service to transfer personal data governed by the GDPR, UK GDPR, or another international transfer regime. HIPAAWorks does not offer international transfer terms (Standard Contractual Clauses, UK Addendum, or equivalent) at this time.
14. Prohibited PHI and suspected submissions
Customer must not provide PHI. If either party suspects PHI was submitted, it will follow the no-PHI incident process and avoid including the suspected content in ordinary email, tickets, analytics, logs, or AI prompts.
HIPAAWorks may restrict, quarantine, or delete suspected content. The parties will cooperate to determine the minimum action required by law. This DPA does not convert HIPAAWorks into a Business Associate or waive any legal obligation that applies based on the actual facts.
15. Liability and conflicts
The liability provisions in the Terms apply to this DPA unless an executed order form expressly states otherwise.
If documents conflict regarding personal-data processing, this DPA controls. The Terms control all other matters.
16. Term
This DPA begins when Customer accepts the Terms or executes an order incorporating it and continues while HIPAAWorks processes Customer Personal Data.
Annex I — Processing details
Subject matter and purpose
Providing a multi-tenant SaaS workspace for organization profiles, HIPAA Security Rule self-assessment, identified-gap reporting, remediation guidance and tracking, evidence storage, report generation, account administration, security, communications, and subscription operations.
Duration
The subscription term plus the period described in the approved retention schedule and any permitted legal, security, or backup retention.
Nature of processing
Collection, recording, organization, storage, retrieval, display, use, transmission to authorized Subprocessors, generation of suggested text and reports, access control, security monitoring, support, export, restriction, deletion, and de-identification.
Data Subjects
- Customer workforce members and invited users;
- business contacts, privacy/security officers, approvers, and vendor contacts named by Customer; and
- other individuals whose non-PHI personal data Customer lawfully includes in Customer Content.
Patients are not an intended Data Subject category.
Categories of Customer Personal Data
- name, business email, organization role, and user identifier;
- organization membership and invitation information;
- names and roles of governance contacts;
- vendor/MSP contact or business information;
- actor name/email snapshots in remediation history;
- comments, notes, and other authorized business free text;
- filenames, images, PDFs, and metadata that Customer has reviewed to exclude PHI;
- support communications; and
- account, usage, security, and transaction metadata associated with a user.
Sensitive data
The intended service does not require PHI, patient information, consumer health data, government identifiers, financial account credentials, or other special- category data. Customer is prohibited from submitting it.
Frequency
Continuous or as initiated by authorized users during the subscription and retention period.
Annex II — Current safeguard summary
This summary describes current repository-backed controls and is subject to verification before execution:
- authenticated access through Clerk;
- supported Google/Microsoft SSO options, subject to live configuration verification;
- organization roles and server-side authorization;
- tenant isolation through Database Row-Level Security;
- private object storage under organization-scoped paths;
- short-lived signed links for file access;
- server-side subscription and tier enforcement;
- restricted database functions for sensitive writes;
- immutable completed assessment records and append-only activity paths;
- Stripe-signature verification before subscription changes;
- file-size, type, signature, and filename validation;
- data minimization for AI, analytics, logging, monitoring, and email;
- Sentry request body/header/cookie scrubbing with replay and tracing disabled;
- no service-role credential in the customer application;
- environment-based secret management; and
- documented cross-tenant abuse testing.