Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the Customer and Retaiva (registered business name and number: not yet published) (“Retaiva”). It applies to personal data contained in Customer Data that Retaiva processes to provide the Service.
1. Roles
The Customer determines the purposes and means of processing Customer Data and is the controller (or equivalent) of it. Retaiva processes Customer Data on the Customer’s behalf as a processor. Each party will comply with data protection law applicable to it.
2. Processing details
- Subject matter and duration: provision of the Service for the term of the Customer’s subscription and any post-termination export period.
- Nature and purpose: hosting, storage, retrieval, display, transmission, backup and deletion of Customer Data to provide the Service.
- Data subjects: the Customer’s staff, retail customers, suppliers and, for Plus Pharma, patients and prescribers.
- Personal data: names and contact details, transaction history, staff identifiers and, for Plus Pharma, dates of birth, allergy status, pharmacy notes, prescription and dispensing records and prescription documents.
3. Instructions
Retaiva will process Customer Data only on the Customer’s documented instructions, which are these terms and the Customer’s use and configuration of the Service, unless required by law. Retaiva will tell the Customer if it believes an instruction breaches data protection law, unless the law prohibits this.
4. Confidentiality
Retaiva will ensure that people authorized to process Customer Data are bound by confidentiality obligations and access it only as needed to provide, support or secure the Service.
5. Security
Retaiva will maintain appropriate technical and organizational measures, including those described on the Security page: encryption in transit and at rest, role-based access, logical separation of each business’s data, append-only audit records, backups, and restricted administrative access. The Customer is responsible for configuring user access, protecting its devices and credentials, and using the security features provided.
6. Subprocessors
The Customer authorizes Retaiva to use the subprocessors listed on the Subprocessors page. Retaiva will impose data protection obligations on each subprocessor at least as protective as this DPA and remains responsible for their performance. Retaiva will update the list and notify business owners before a new subprocessor processes Customer Data. The Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may cancel the affected Service.
7. International processing
Customer Data is hosted in the United States. The Customer acknowledges that Customer Data is transferred to and processed outside Trinidad and Tobago, and is responsible for any notice or authorization required for that transfer under law applicable to it. Retaiva will apply the safeguards in this DPA wherever Customer Data is processed.
8. Personal data incidents
Retaiva will notify the Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. The notice will describe what is known, the likely consequences and the measures taken or proposed, and will be updated as more is learned. Retaiva will cooperate with the Customer’s investigation and any notifications the Customer is required to make.
9. Requests from individuals
The Service provides tools for the Customer to access, correct, export, restrict and, where permitted, anonymize personal data. If Retaiva receives a request directly from an individual about Customer Data, it will refer the individual to the Customer and will not respond substantively unless required by law.
10. Return and deletion
The Customer can export Customer Data at any time during the subscription and for 30 days after termination. Afterwards, Retaiva will delete Customer Data from active systems, and it will expire from backups in the ordinary backup cycle, unless retention is required by law or a legal hold applies. Records the Customer has marked for retention in the Service will not be deleted through ordinary deletion requests.
11. Information and audits
Retaiva will make available information reasonably necessary to demonstrate compliance with this DPA, including a description of its security measures and subprocessors. Where that information is insufficient, the Customer may request an audit on reasonable notice, at its own cost, conducted in a way that does not compromise the security of other customers.
12. Term
This DPA applies while Retaiva processes Customer Data. Obligations that by their nature continue, including confidentiality and deletion, survive termination.
Questions about this addendum: support@retaivatt.com.