This DPA applies when Healthdesk processes Personal Data on behalf of Customer.
01 Roles
- Customer is the Controller of End User data.
- Healthdesk is the Processor.
- Healthdesk processes data solely to provide the Services.
02 Scope of Processing
- Purpose: Providing Customer communications, automation, CRM integrations, advertising attribution, measurement, and optimization at Customer's direction.
- Categories of data: Contact and lead information; SMS, email, chat, social messaging, and call data; call recordings and transcripts where applicable; Mindbody and CRM customer and lead records; booking, purchase, transaction-value, and conversion information; advertising attribution and conversion-event data; and related technical metadata.
- Duration: For the term of the Agreement and limited retention thereafter for security and legal compliance.
- Healthdesk does not use Customer End User data for Healthdesk's own advertising.
- Healthdesk may transmit Customer-authorized attribution and conversion-event data, including hashed customer identifiers, to advertising platforms connected by Customer to provide attribution, measurement, and optimization.
- Customer is responsible for having the necessary rights, notices, permissions, and consents for data Customer instructs Healthdesk to process or transmit.
03 Customer Responsibilities
- Customer is solely responsible for lawful collection of Personal Data and consent.
- Customer represents it has provided all required notices and obtained all necessary permissions.
- Where Customer enables conversion measurement with an advertising platform, Customer represents that it holds the rights and lawful basis to permit the disclosure, that its own privacy notice discloses sharing with advertising partners for measurement, and that it honors applicable opt‑out requests.
04 Security
Healthdesk maintains reasonable administrative, technical, and physical safeguards to protect Personal Data.
05 Subprocessors
- Customer authorizes Healthdesk to use subprocessors including cloud hosting providers, messaging carriers, and infrastructure vendors necessary to provide 10DLC services.
- Healthdesk will impose reasonable data protection obligations on subprocessors.
06 Incident Notification
Healthdesk will notify Customer without undue delay upon discovery of a Personal Data breach affecting Customer Data.
07 Data Return or Deletion
Upon termination, Healthdesk will delete or return Personal Data upon request, except where retention is required by law or security needs.
08 No Sale of Data
Healthdesk does not sell Customer End User Personal Data and will not use it for Healthdesk's own advertising or other unrelated purposes, and the transmissions described in Section 02 are made solely on Customer's instruction and for Customer's own measurement.