This Data Processing Addendum ("DPA") supplements the Terms of Service between SoftAge Systems, Inc. ("Vendor") and the healthcare organization ("Customer") governing the processing of personal data and Protected Health Information (PHI) within ZenXHealth.
1. Scope & Definitions
This DPA applies where Customer Personal Data or PHI subject to applicable privacy laws (including HIPAA, CCPA, and GDPR) is processed by Vendor in connection with providing the ZenXHealth platform services.
2. Security Obligations & Safeguards
Vendor implements and maintains technical, physical, and administrative safeguards designed to protect Customer Data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access. These include:
- AES-256 encryption at rest and TLS 1.3 encryption in transit.
- Strict role-based access control and multi-factor authentication.
- Independent annual SOC 2 Type II audits.
- Continuous vulnerability scanning and audit logging.
3. Sub-processors
Vendor uses verified sub-processors for infrastructure hosting (Azure / AWS) and transmission services (Surescriptions). All sub-processors are bound by data protection obligations consistent with this DPA and HIPAA requirements.
4. Inquiries
For DPA inquiries or to request an executed copy, contact info@softage.com.