Data Processing Agreement - DPA

This Data Processing Agreement, including its schedules and exhibits (“DPA”), is entered into as of [Effective Date] by and between:

TeleVU Innovation Ltd., an Ontario corporation with an address at 9131 Keele Street, Unit A4, Vaughan, Ontario, Canada (“TeleVU” or “Processor”); and

[legal entity name], with an address at [address] (“ORG” or “Controller”).

TeleVU and ORG may be referred to individually as a “Party” and collectively as the “Parties.”

This DPA supplements and forms part of the Services Agreement between the Parties dated [date] governing TeleVU’s provision of the TelePresence AR platform, video-enabled remote support, and related services to ORG (the “Agreement”).

1. Purpose and Scope

1.1. This DPA governs TeleVU’s Processing of ORG Personal Data in connection with the Services.

1.2. The Parties acknowledge that, as between the Parties, ORG determines the purposes and means of Processing ORG Personal Data, and TeleVU Processes ORG Personal Data only on behalf of ORG and in accordance with the Agreement, this DPA, and ORG’s documented instructions.

1.3. This DPA applies to all ORG Personal Data Processed by TeleVU or TeleVU Sub-processors  in connection with the Services, including ORG employee or contractor account information, session metadata, live session communications, optional recordings, support information, and other information submitted, transmitted, generated, stored, or otherwise Processed through the Services.

1.4. To the extent ORG Personal Data includes information subject to applicable privacy, security, data-protection, health, employment, consumer, or other laws, the Parties will comply with their respective obligations under those laws.

2. Definitions

For purposes of this DPA:

2.1. “Applicable Data Protection Laws” means all privacy, data protection, data security, breach notification, and similar laws applicable to a Party’s Processing of ORG Personal Data under the Agreement, including, as applicable, Canadian privacy laws, U.S. federal and state privacy and breach notification laws, the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and other applicable laws.

2.2. “Business Purpose” means the limited purpose of providing, securing, maintaining, supporting, improving, and administering the Services for ORG, and complying with legal obligations, in each case as permitted by the Agreement and this DPA.

2.3. “Controller” means the entity that determines the purposes and means of Processing Personal Data. For purposes of this DPA, ORG is the Controller unless otherwise agreed in writing.

2.4. “Data Subject” means an identified or identifiable natural person to whom ORG Personal Data relates, including ORG employees, contractors, administrators, users, clients and other individuals whose Personal Data is Processed through the Services.

2.5. “Personal Data” means any information relating to an identified or identifiable natural person, including “personal information,” “personally identifiable information,” “personal data,” “personal health information (PHI)” or similar terms under Applicable Data Protection Laws.

2.6. “Process,” “Processing,” or “Processed” means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion, or destruction.

2.7. “Processor” means the entity that Processes Personal Data on behalf of a Controller. For purposes of this DPA, TeleVU is the Processor unless otherwise agreed in writing.

2.8. “Security Incident” means an actual or reasonably suspected unauthorized access to, acquisition of, disclosure of, use of, corruption of, deletion of, or other unauthorized Processing of ORG Personal Data, or a compromise of the confidentiality, integrity, or availability of ORG Personal Data.

2.9. “Services” means the TeleVU TelePresence AR platform, video-enabled remote support functionality, support services, administrative portal, and related services provided to ORG under the Agreement.

2.10. “Sub-processor” means any third party engaged by TeleVU to Process ORG Personal Data on TeleVU’s behalf in connection with the Services.

2.11. “ORG Personal Data” means Personal Data Processed by TeleVU on behalf of ORG in connection with the Services.

2.12. “ORG Data” means all data, content, records, files, audio, video, images, messages, session metadata, account data, support data, and other information submitted to, transmitted through, generated by, or stored in the Services by or on behalf of ORG, including ORG Personal Data.

  1. Roles and Responsibilities

3.1. ORG is responsible for determining the lawful basis, notices, consents, authorizations, and instructions required for the Processing of ORG Personal Data through the Services.

3.2. TeleVU will Process ORG Personal Data:

  1. to provide, secure, maintain, support, and improve the Services for ORG;
  2. in accordance with ORG’s documented instructions;
  3. as required by the Agreement or this DPA;
  4. as required by applicable law; or
  5. as otherwise expressly authorized by ORG in writing.

3.3. TeleVU will not sell ORG Personal Data.

3.4. TeleVU will not use ORG Personal Data for cross-context behavioral advertising.

3.5. TeleVU will not retain, use, disclose, or otherwise Process ORG Personal Data outside the direct business relationship between TeleVU and ORG except as permitted by the Agreement, this DPA, ORG’s documented instructions, or applicable law.

3.6. TeleVU will not combine ORG Personal Data with Personal Data received from or on behalf of another customer, except as necessary to provide, secure, maintain, or support the Services, or as otherwise permitted by Applicable Data Protection Laws.

3.7. TeleVU will not attempt to re-identify anonymized, de-identified, or aggregated ORG Data except as required to provide the Services, investigate security issues, or comply with law.

3.8. Individuals under the age of majority. ORG acknowledges that the Services contain no paediatric-specific functionality and that TeleVU does not verify the age of any individual ORG enrols, records, or otherwise Processes through the Services. Where ORG uses the Services in relation to any individual under the age of majority in the applicable jurisdiction, ORG warrants that before doing so it has: (a) determined that such use is lawful; (b) established a lawful basis for the Processing, including any condition required for special-category or health data under Applicable Data Protection Laws; (c) obtained any consent or authorization required from a parent or legal guardian, or satisfied itself that the individual has capacity to consent under applicable law, and maintains a record of it; and (d) completed any data protection impact assessment or equivalent assessment required. ORG will indemnify TeleVU against any claim arising from ORG’s failure to comply with this Section.

4. Documented Instructions

4.1. ORG instructs TeleVU to Process ORG Personal Data for the purposes described in this DPA, the Agreement, applicable order forms, and Schedule 1.

4.2. TeleVU will promptly notify ORG if, in TeleVU’s reasonable opinion, an instruction from ORG infringes Applicable Data Protection Laws, unless prohibited by law from doing so.

4.3. TeleVU will not be required to comply with any instruction that would require TeleVU to violate applicable law or materially compromise the security of the Services.

 

5. Categories of Data and Processing Activities

5.1. Categories of ORG Personal Data may include:

  1. user registration information, including name, email address, username, role, portal association, and account credentials or authentication identifiers;
  2. device information, including device identifiers, device type, model, operating system, browser/client application information, IP address, language preference, and application version;
  3. usage information, including session information, access logs, timestamps, pages or features used, system events, and support interactions;
  4. TelePresence AR session data, including live audio, live video, screen or camera view, session metadata, and network/session telemetry;
  5. optional recordings, photographs, or videos captured through the Services where recording or capture functionality is enabled and initiated by an authorized user;
  6. support and troubleshooting information submitted by ORG users or administrators; and
  7. other Personal Data submitted by ORG or its authorized users through the Services.
  8. patient intake, consent, assessment, visit, or other forms completed through the Services, including notes, patient information as entered by authorized users, visit details, observations, history, reason for visit, clinical or operational comments, and other information collected or submitted in connection with a session, consultation, assessment, or visit;

5.2. ORG Data may include operational content visible, discussed, captured, or transmitted during a TelePresence AR session. The Parties agree that such content should be handled as confidential customer data, and if it includes Personal Data, it will be handled as ORG Personal Data.

 

6. Confidentiality

6.1. TeleVU will ensure that personnel authorized to Process ORG Personal Data are bound by confidentiality obligations.

6.2. TeleVU will restrict access to ORG Personal Data to personnel who require such access for a legitimate business need related to providing, securing, maintaining, or supporting the Services.

6.3. TeleVU will maintain internal policies requiring personnel to protect confidential and sensitive information and to report actual or suspected security incidents.

 

7. Security Measures

7.1. TeleVU will implement and maintain reasonable and appropriate administrative, technical, and other safeguards designed to protect the confidentiality, integrity, availability, and resilience of ORG Personal Data.

7.2. TeleVU’s security measures will include, at a minimum:

  1. encryption of data in transit using secure protocols such as HTTPS/TLS, WebSocket, WebRTC, SSH, or other secure protocols appropriate to the Services;
  2. encryption of data at rest;
  3. access controls based on least privilege and need-to-know;
  4. unique accounts and authentication controls for personnel and users;
  5. multi-factor authentication where available and required for applicable administrative systems, cloud infrastructure, email, and version control;
  6. documented onboarding and offboarding controls, including timely revocation of access upon termination or role change;
  7. audit logging and monitoring of production systems, applications, databases, servers, message queues, load balancers, critical services, and IAM user/admin activities;
  8. secure retention of logs for at least one year, unless a longer period is required by the Agreement or applicable law;
  9. controls designed to prevent unauthorized access, deletion, or tampering with logging facilities and log information;
  10. vulnerability and patch management processes;
  11. change management procedures for production infrastructure, systems, and applications;
  12. separation of development and production environments where necessary;
  13. asset inventory and configuration management processes;
  14. secure disposal and sanitization of media and devices containing confidential or personally identifiable information; and
  15. incident response procedures.

7.3. TeleVU will maintain a written information security program aligned with recognized security frameworks and appropriate to the nature, size, and complexity of TeleVU’s business operations.

7.4. TeleVU will review and update its security policies and plans at least annually, and will track findings to resolution.

7.5. TeleVU will not materially decrease the overall security of the Services during the term of the Agreement.

8. Data Location and Cross-Border Processing

8.1. TeleVU processes Personal Information through Amazon Web Services for computing and storage purposes. TeleVU is committed to honoring customer data sovereignty and data residency requirements by utilizing AWS infrastructure in the customer’s applicable geographic region, where AWS Regions are available. For example, Personal Information for Canadian customers is processed and stored in Canada, and U.S. customers are served through an appropriate AWS Region within the United States.

Managed services used to operate the Services, such as authentication, are provided through AWS services within the AWS Region selected for the applicable deployment. Certain other service providers may Process limited Personal Data outside Canada where required to support the delivery, security, and operation of the Services, as described in Schedule 2.

8.2. Subject to the Agreement, TeleVU will Process ORG Personal Data in the locations necessary to provide the Services.

8.3. If ORG requires a specific data residency commitment, the Parties will document that commitment in the Agreement, or an order form.

8.4. TeleVU will not intentionally transfer ORG Personal Data to a new country or region that materially changes the risk profile of the Services without providing ORG with notice, unless the transfer is required by law or is necessary to maintain the security or continuity of the Services.

8.5. If a transfer mechanism is required under Applicable Data Protection Laws, the Parties will implement an appropriate transfer mechanism, such as Standard Contractual Clauses, an international data transfer agreement, or another lawful transfer mechanism.

8.6. TeleVU personnel who administer, support, secure, and maintain the Services are primarily located in Canada. Access to ORG Data by TeleVU personnel is limited to authorized personnel with a legitimate business need, including for support, troubleshooting, security, maintenance, incident response, and service administration. Such access is controlled through role-based access controls, least-privilege permissions, authentication controls, confidentiality obligations, and audit logging where applicable. Any access to ORG Data from outside Canada, including by authorized Sub-processors or service providers, will be handled in accordance with this DPA, the Agreement, applicable law, and any required transfer safeguards.

9. Sub-processors

9.1. ORG authorizes TeleVU to use Sub-processors to provide, secure, maintain, and support the Services, subject to the requirements of this Section.

9.2. TeleVU will conduct risk-based due diligence on Sub-processors that Process ORG Personal Data, including security and privacy review appropriate to the nature of the services and data involved.

9.3. TeleVU will enter into a written agreement with each Sub-processor that requires the Sub-processor to maintain privacy, confidentiality, and security obligations no less protective in substance than those required by this DPA.

9.4. TeleVU will maintain a list of Sub-processors used to provide the Services and will make the list available to ORG upon request.

9.5. TeleVU will provide at least thirty (30) days’ advance written notice of any new Sub-processor that will Process ORG Personal Data. ORG may object to a new Sub-processor on reasonable privacy or security grounds within 15 days of notice. If ORG reasonably objects, the Parties will work in good faith to resolve the objection.

9.6. The current known categories of Sub-processors and service providers may include cloud infrastructure providers, authentication providers, network transmission providers, customer support/ticketing providers, security providers, analytics or product-support providers, and other providers necessary to deliver the Services.

9.7. The initial Sub-processor list is set out in Schedule 2.

 

10. AI/ML Processing

10.1. TeleVU will not use ORG Data, including ORG session data, audio, video, recordings, transcripts, notes, images, or metadata, to train, fine-tune, or improve any AI or machine-learning model, except with ORG’s prior written authorization.

10.2. TeleVU will not disclose ORG Data to any AI/ML provider unless:

  1. the AI/ML Processing is expressly enabled by ORG or authorized in the Agreement;
  2. the AI/ML provider is listed as a Sub-processor or otherwise approved in writing by ORG;

10.3. Any optional AI features, including automated notetaking, summarization, transcription, or translation, must be capable of being disabled at the organizational level for ORG.

10.4. TeleVU will provide ORG with written documentation identifying each AI/ML provider, the AI feature supported, the categories of ORG Data Processed, retention practices, no-training commitments, and opt-in/opt-out controls before enabling any AI feature for ORG.

 

11. Data Subject Rights and Assistance

11.1. Taking into account the nature of the Processing and the information available to TeleVU, TeleVU will reasonably assist ORG in responding to Data Subject requests relating to ORG Personal Data.

11.2. If TeleVU receives a request directly from a Data Subject relating to ORG Personal Data, TeleVU will direct the Data Subject to ORG or ORG’s portal administrator, unless otherwise required by applicable law.

11.3. TeleVU will not respond substantively to a Data Subject request regarding ORG Personal Data without ORG’s prior instruction, unless required by law.

11.4. TeleVU will provide reasonable assistance to ORG to access, correct, export, delete, or restrict ORG Personal Data to the extent such functionality is available through the Services or reasonably available to TeleVU.

 

12. Return and Deletion of ORG Data

12.1. TeleVU will retain ORG Data for as long as ORG’s account is active, as needed to provide the Services, as set out in the Agreement, or as required by applicable law.

12.2. Upon ORG’s written request, or upon termination or expiration of the Agreement, TeleVU will delete or return ORG Data in accordance with the Agreement, this DPA, and TeleVU’s data retention and disposal practices. Unless a longer retention period is required by applicable law, regulatory obligation, contractual obligation, dispute-resolution need, security investigation, backup-retention limitation, or other legitimate legal or operational requirement, TeleVU will delete customer-requested ORG Data within thirty (30) days of ORG’s written request.

12.3. TeleVU may retain limited information as necessary to comply with legal obligations, resolve disputes, enforce agreements, maintain security records, preserve evidence relating to an actual or suspected Security Incident, or complete ordinary-course backup and archival retention, provided such retained information remains protected in accordance with this DPA.

12.4. TeleVU will limit the number of personnel authorized to delete customer data.

12.5. Upon ORG’s request, TeleVU will provide written confirmation of deletion, subject to legal, security, and operational limitations.

 

13. Security Incident Notification

13.1. TeleVU will maintain a security incident response process for actual or reasonably suspected unauthorized access to, use of, disclosure of, acquisition of, corruption of, deletion of, or other unauthorized Processing of sensitive information.

13.2. TeleVU will notify ORG without undue delay and in any event within forty-eight (48) hours after TeleVU becomes aware of a Security Incident affecting ORG Data.

13.3. Security Incident notices will be sent to:

ORG Security Contact/s: [name, title, email, phone]
TeleVU Security Contact: security@televu.ca
TeleVU Privacy Contact: privacy@televu.ca

13.4. TeleVU’s notice will include, to the extent known at the time:

  1. a description of the Security Incident;
  2. the date and time of discovery;
  3. the categories of ORG Data affected or reasonably believed to be affected;
  4. the categories and approximate number of affected Data Subjects, if known;
  5. the known or suspected cause;
  6. mitigation and containment measures taken or planned;
  7. steps ORG may take to reduce risk;
  8. whether law enforcement, regulators, or forensic investigators are involved; and
  9. a TeleVU point of contact for follow-up.

13.5. TeleVU will investigate, contain, mitigate, document, and remediate Security Incidents in accordance with its incident response process.

13.6. TeleVU will preserve relevant evidence and maintain incident logs or corrective action plans as appropriate.

13.7. TeleVU will not notify regulators, law enforcement, ORG users, ORG employees, ORG customers, or the public about a Security Incident involving ORG Data unless required by law, authorized by ORG, or necessary to protect the security or integrity of the Services. Where legally permitted, TeleVU will consult with ORG before making such notification.

13.8. Following resolution of a Security Incident, TeleVU will conduct a post-incident review and determine whether additional safeguards, policy updates, or corrective actions are appropriate.

 

14. Audits, Assessments, and Compliance Information

14.1. Upon ORG’s reasonable written request and subject to confidentiality obligations, TeleVU will provide information reasonably necessary to demonstrate compliance with this DPA, including applicable security policies, summaries of penetration testing or security assessments, compliance certificates, Sub-processor information, and other relevant documentation.

14.2. If TeleVU has current third-party certifications, audit reports, penetration-test executive summaries, or similar evidence applicable to the Services, TeleVU will provide such materials under NDA upon reasonable request, subject to redaction for security, confidentiality, or third-party restrictions.

14.3. TeleVU maintains a written information security program aligned with ISO/IEC 27001. If ORG requires any additional security, privacy, or compliance certification, assessment, registration, or equivalent attestation that is not available, TeleVU will state so in writing and, where applicable, provide any planned assessment timeline.

14.4. Upon reasonable prior written notice, subject to scheduling agreed between the Parties, and at ORG’s sole cost and expense, ORG may conduct a reasonable audit of TeleVU’s compliance with this DPA no more than once annually, unless a Security Incident affecting ORG Data or a material compliance concern reasonably requires an additional audit.

14.4.1 Audits must be conducted during normal business hours, with reasonable advance notice, in a manner that does not disrupt TeleVU operations or compromise the confidentiality, availability, or security of TeleVU systems or other customers’ data.

14.4.2 TeleVU may satisfy an audit request by providing independent third-party audit reports, certification materials, security questionnaires, or other documentation that reasonably addresses ORG’s audit objectives.

 

15. Legal Requests

15.1. If TeleVU receives a subpoena, court order, search warrant, government request, regulatory inquiry, or similar legal request seeking disclosure of ORG Data, TeleVU will promptly notify ORG unless prohibited by law, court order, or exigent circumstances.

15.2. TeleVU will make reasonable efforts to allow ORG to seek a protective order or other appropriate remedy before disclosure.

15.3. TeleVU will disclose only the minimum ORG Data legally required in response to a valid legal request.

 

16. Assistance with Compliance

16.1. TeleVU is committed to supporting ORG’s reasonable privacy, security, and compliance needs in connection with the Services. Taking into account the nature of the Processing and the information available to TeleVU, TeleVU will reasonably assist ORG with:

  1. security and privacy due diligence;
  2. data protection impact assessments;
  3. security assessments;
  4. regulator inquiries;
  5. breach notification obligations;
  6. Data Subject requests; and
  7. documentation of Processing activities.

16.2. Assistance that is within TeleVU’s standard support obligations will be provided as part of the Services. If ORG requests assistance, deliverables, reviews, documentation, technical support, legal support, audit support, or other services that exceed TeleVU’s standard support obligations, the Parties will mutually agree in writing on the applicable scope of work, timeline, fees, and expenses before TeleVU performs such additional services.

 

17. Confidentiality of ORG Data

17.1. ORG Data is ORG Confidential Information.

17.2. TeleVU will not disclose ORG Data except as permitted by the Agreement, this DPA, ORG’s documented instructions, or applicable law.

17.3. TeleVU will ensure that personnel with access to ORG Data are subject to confidentiality obligations and receive security awareness training as required by TeleVU policy.

 

18. Optional Recordings and Session Content

18.1. TeleVU will Process live TelePresence AR session audio, video, and metadata only as necessary to provide, secure, maintain, and support the Services.

18.2. TelePresence AR sessions will not be recorded by TeleVU unless recording functionality is enabled and recording is initiated by an authorized ORG user or otherwise expressly authorized by ORG.

18.3. Optional recordings, photos, or videos captured through the Services are ORG Data and will be protected under this DPA.

18.4. TeleVU will make optional recordings available only to authorized users based on role-based access permissions established and configured by ORG.

18.5. ORG may request deletion of recordings in accordance with Section 12.

 

19. Portal Isolation and Customer Data Segregation

19.1. TeleVU will implement logical access controls designed to prevent unauthorized access to ORG Data by other customers or unauthorized personnel.

19.2. TeleVU will maintain access controls based on least privilege and need-to-know and will restrict administrative access to production servers and databases to personnel with a business need.

19.3. TeleVU personnel will not access ORG Data except as necessary to provide, secure, maintain, support, or improve the Services, investigate or respond to a security issue, comply with law, or as otherwise authorized by ORG.

19.4. Upon ORG’s reasonable request, TeleVU will provide a written description of the logical portal-separation controls applicable to the Services, including database, storage, application, and network-layer isolation controls, to the extent disclosure does not compromise security or confidentiality.

 

20. Business Continuity and Disaster Recovery

20.1. TeleVU will maintain business continuity and disaster recovery plans designed to support continued operation or recovery of the Services in the event of a significant disruption.

20.2. TeleVU will test, review, and update its business continuity and disaster recovery plans at least annually.

20.3. TeleVU will maintain backup processes designed to support recovery of critical systems, records, and configurations in the event of disaster or media failure.

 

21. Return, Suspension, and Termination

21.1. This DPA will remain in effect for as long as TeleVU Processes ORG Personal Data.

21.2. Upon termination or expiration of the Agreement, TeleVU will return or delete ORG Data as set out in Section 12.

21.3. Sections intended by their nature to survive termination will survive, including confidentiality, deletion, audit, legal requests, and liability provisions.

 

22A. HIPAA

22A. HIPAA. Where ORG is a Covered Entity or Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), and TeleVU Processes Protected Health Information on ORG’s behalf, the Parties will execute TeleVU’s Business Associate Agreement prior to any such Processing. The Business Associate Agreement is incorporated into this DPA by reference and, in respect of Protected Health Information, controls to the extent of any conflict with this DPA.

22B. Order of Precedence

In the event of conflict between this DPA and the Agreement regarding Processing of ORG Personal Data, this DPA will control.

 

23. Liability

23.1. Each Party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, unless prohibited by Applicable Data Protection Laws.

23.2. Nothing in this DPA limits liability that cannot be limited under applicable law.

 

24. Governing Law

This DPA will be governed by the laws of the Province of Ontario, excluding conflict-of-law principles.

 

Schedule 1: Details of Processing

A. Subject Matter

TeleVU’s Processing of ORG Personal Data in connection with the provision of TelePresence AR platform access, video-enabled remote support, optional recording functionality, user administration, support, security, maintenance, and related services.

B. Nature and Purpose of Processing

TeleVU will Process ORG Personal Data to:

  1. create and administer user accounts;
  2. authenticate users;
  3. provide live TelePresence AR sessions;
  4. transmit live audio, video, and session metadata;
  5. store optional recordings, photos, or videos where enabled and initiated;
  6. provide customer support;
  7. maintain, secure, monitor, and troubleshoot the Services;
  8. comply with legal obligations;
  9. investigate suspected fraud, abuse, or Security Incidents;
  10. improve the Services, provided that ORG Personal Data is not used to train AI/ML models unless expressly authorized by ORG; and
  11. perform other Processing documented in the Agreement or authorized by ORG.

C. Duration of Processing

TeleVU will Process ORG Personal Data for the term of the Agreement and for such further period as is necessary to complete return or deletion in accordance with Section 12, or as required by applicable law. Retention of specific categories of ORG Personal Data is governed by Section 12 and any retention schedule agreed in the Agreement or an applicable order form.

D. Categories of Data Subjects

  1. patients and other individuals receiving care, assessment, consultation, or assistance through ORG’s use of the Services, who may include individuals under the age of majority;
  2. family members, guardians, caregivers, or other individuals present during or participating in a session;
  3. ORG employees, contractors, and administrators;
  4. clinicians, specialists, and other healthcare personnel using the Services;
  5. ORG users of connected devices or remote specialist portals;
  6. individuals who communicate with TeleVU support on behalf of ORG; and
  7. any other individual whose image, voice, or Personal Data is captured or submitted through the Services.

E. Categories of Personal Data

  1. name;
  2. business email address;
  3. username or account identifier;
  4. role or permission level;
  5. authentication and login metadata;
  6. IP address;
  7. device identifier;
  8. device type, model, operating system, application version, browser/client information, and language preference;
  9. usage information;
  10. session metadata;
  11. support communications;
  12. audio, video, images, or recordings where captured through the Services;
  13. optional user profile information;
  14. other Personal Data submitted by ORG or its authorized users;
  15. health and clinical information, including patient identifiers, intake and consent form contents, assessment and visit records, clinical notes, observations, medical and family history, reason for visit, and clinical or operational commentary entered through the Services; and
  16. audio, video, and photographic recordings of consultations, assessments, or procedures, which may reveal health information about the individuals recorded.

 

F. Special Categories of Personal Data

The Services are used to Process special-category personal data within the meaning of Article 9(1) of the GDPR and the UK GDPR, namely data concerning health, and equivalent categories of sensitive personal information under Canadian and U.S. privacy laws, including personal health information.

Applied restrictions and safeguards: strict purpose limitation to the Business Purpose; encryption of the data in transit and at rest; role-based access control restricting access to personnel who require it to perform the Services; logging of access to health data; mandatory privacy and security training for personnel with access; background checks where legally permissible; contractual restrictions on onward transfer; and secure deletion at the end of the applicable retention period.

ORG remains responsible for identifying and documenting the condition under Article 9(2) of the GDPR, or the equivalent basis under other Applicable Data Protection Laws, on which it relies for the Processing of such data.

Schedule 2: Sub-processors List

The Data Processor (TeleVU Innovation Ltd.) uses the following sub-processors in connection with the tasks which the Data Processor carries out for the Data Controller (ORG). By entering into the Data Processing Agreement, the Data Controller approves the use of these sub-processors.

 

Sub-processor 1: Amazon Web Services

Sub-processor
Company’s full name Amazon Web Services Canada, Inc.
Services Amazon Web Services Canada, Inc. provides access to AWS cloud infrastructure and related services. Personal data processed by TeleVU’s platform will be stored and processed in the AWS North America region selected for the applicable deployment, such as Canada Central, Canada West, US East, US West, or another agreed AWS North America region. AWS does not publish the physical addresses of its data centers.

Backups, snapshots, replicas, and routine storage are configured by TeleVU to remain within the selected AWS region unless otherwise agreed with the customer. Limited AWS support, security, maintenance, or administrative access may be performed by AWS personnel or AWS affiliates from other locations in accordance with the AWS Data Processing Addendum and applicable AWS service terms.

Does the Data Processor have an agreement with the sub-processor which fulfils the requirements of the Data Processing Agreement? Yes. TeleVU’s use of AWS is governed by the applicable AWS Customer Agreement, AWS Service Terms, and AWS Data Processing Addendum. The AWS Data Processing Addendum is incorporated into the AWS Service Terms and applies when AWS services are used to process customer data. Where required, the AWS terms incorporate the applicable Standard Contractual Clauses, UK GDPR Addendum, Swiss Addendum, and other applicable data protection terms.
Data processing which the sub-processor participates in Cloud infrastructure hosting and related services, including compute, database, object storage, authentication, monitoring, logging, networking, backup, availability, and native AWS security services. This may include AWS services such as EC2, RDS, S3, Cognito, CloudWatch, CloudTrail, IAM, KMS, load balancing, and other AWS infrastructure and security services used by TeleVU’s telemedicine platform.

All personal data processed by TeleVU on behalf of the customer is hosted on AWS infrastructure within the selected AWS North America region, subject to the customer’s selected deployment configuration and any agreed data residency requirements.

Categories of personal data processed by the sub-processor All personal data processed by TeleVU on behalf of the customer, including account and authentication data of clinicians and administrative users, session metadata, real-time call media processed transiently, recordings of consultations if recording is enabled by the customer, images and files uploaded by users, patient identifiers, clinical content entered through the TeleVU Patient Portal if used, device data where applicable, audit logs, and aggregate platform performance metrics.
Categories of data subjects Patients receiving care through the customer’s telemedicine service, clinicians and other healthcare staff using the platform, administrative users who manage the platform, and other authorized users invited to participate in TeleVU-supported care, consultation, training, or support workflows.
Transfer to third countries
Does the sub-processor process personal data in a third country? Yes.
If yes, list all third countries Canada and, where the Organization’s deployment is configured for a United States AWS Region, the United States. All data at rest and in regular processing remains within the AWS Canada or US Region selected for the Organization’s deployment. Backups, snapshots, and replicas are restricted to the same Region.
If yes, state the basis for transfer (e.g. EU Commission’s SCC or Binding Corporate Rules) For transfers to Canada, the European Commission adequacy decision for Canada (Decision 2002/2/EC of 20 December 2001) in respect of recipients subject to PIPEDA. For transfers to or access from the United States, and in the event AWS provides global support involving limited and authenticated access from outside Canada or the United States, the AWS Data Processing Addendum incorporates the Standard Contractual Clauses as the lawful transfer mechanism.

 

Sub-processor 2: Zoho Canada Corporation

Sub-processor
Company’s full name Zoho Canada Corporation (operating as Zoho’s contracting entity for Canadian customers, part of the Zoho Corporation group)
Does the Data Processor have an agreement with the sub-processor which fulfils the requirements of the Data Processing Agreement? Yes. TeleVU has accepted the Zoho Data Processing Addendum, which includes the EU Standard Contractual Clauses as the basis for transfers where required and prohibits Zoho’s use of customer data for any purpose other than providing the contracted services.
Data processing which the sub-processor participates in Support ticket management and TeleVU’s internal support tooling. Zoho receives only the contents of support tickets raised by ORG staff with TeleVU, and any live chat conversations initiated by ORG staff from TeleVU’s website. Zoho does not have access to the telemedicine platform itself or to patient call data.
Categories of personal data processed by the sub-processor Contents of support tickets raised by ORG staff, names and contact details (typically work email address) of ORG staff who submit support tickets or initiate live chat, and any other information voluntarily included by ORG staff in support correspondence. TeleVU’s support guidance instructs users to avoid including patient data in tickets.
Categories of data subjects ORG staff (clinicians and administrators) who initiate support requests or live chat with TeleVU. Patient data subjects are not expected to be present in this processing.
Transfer to third countries
Does the sub-processor process personal data in a third country? Yes.
If yes, list all third countries Canada.
If yes, state the basis for transfer (e.g. EU Commission’s SCC or Binding Corporate Rules) Adequacy decision. Canada is recognised as providing an adequate level of protection for personal data under European Commission Decision 2002/2/EC of 20 December 2001 (the Canada adequacy decision), in respect of recipients subject to the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA). Zoho Canada Corporation is subject to PIPEDA.

 

Sub-processor 3: LiveKit, Inc.

Sub-processor
Company’s full name LiveKit, Inc.
Does the Data Processor have an agreement with the sub-processor which fulfils the requirements of the Data Processing Agreement? Yes. TeleVU has accepted the LiveKit Data Processing Addendum, which incorporates the EU Standard Contractual Clauses (Module 3, Processor-to-Processor) for transfers outside the EEA.
Data processing which the sub-processor participates in Real-time WebRTC media routing and signaling for the ORG’s telemedicine consultations. LiveKit does not store call audio, video, or data streams; recordings, if enabled, are uploaded directly to TeleVU’s AWS S3 bucket in the region selected for the ORG’s deployment. LiveKit’s analytics telemetry is retained encrypted for a maximum of 14 days.
Categories of personal data processed by the sub-processor Call audio and video streams transiting LiveKit’s regional infrastructure during active sessions, signaling metadata (participant identifiers, session identifiers, connection quality metrics), and IP addresses of session participants. No patient identifiers or clinical content from the Patient Portal are transmitted to LiveKit.
Categories of data subjects Patients and clinicians who participate in telemedicine consultations through the ORG’s deployment of the TeleVU platform.
Transfer to third countries
Does the sub-processor process personal data in a third country? Yes.
If yes, list all third countries United States (LiveKit Inc.’s corporate operations, support, and engineering access). Routine signaling and media processing for the ORG’s project is pinned to geographic regions.
If yes, state the basis for transfer (e.g. EU Commission’s SCC or Binding Corporate Rules) EU Standard Contractual Clauses (Module 3, Processor-to-Processor) per the LiveKit Data Processing Addendum, supplemented by region pinning as a technical measure that restricts data flows to the North America Region selected for the Organization’s deployment during normal operation.